- Joined
- May 31, 2010
- Messages
- 317
Last night i was playing on a 6th RB server, and their setup is to have a
rotation of common maps as well as custom maps.
At the time of the incident, we were on an "Avalanche" map, although I
have no idea if it was modified. It appeared to be the stock map.
Their game server apparently crashed, and the server wasn't listed for
several minutes. Meanwhile, I went to the =eGO= 24/7 Avalanche server.
When I joined, I noticed substantial lag from the players, so I glanced at
my ping, and it was reporting 160... which usually it equilibriates at 90-100
So I opened up TCPVIEW.exe (Sysinternals Microsoft program for
viewing established connections) and to my surprise there were 'at least'
40 connections 'Established' to "Steamwebehlper.exe" and they all were
from suspicious looking websites. I remember one was even connected to
Facebook. I wished I'd taken a screenshot. I'm certain though that was
abnormal activity.
So I closed steamwebhelper.exe immediately, and my ping instantly
returned to what it should be, in fact, i'd never seen it so low before.
"88 ping", the rest of the night, it hovered around 95-100 and i monitored
it carefully.
I ended up blocking all connections to steamwebhelper.exe with my
firewall and noticed no functional difference in the hl2.exe program.
I also blocked steam.exe connections, and I disconnected from the vac
server, but that's to be expected. Thats neither here nor there though.
Anyways, I posted a message to Steam tech support, I doubt they'll be
able to resolve anything without any crash dump information. I thought
you should all be made ware of this vulnerability that affects the gameplay.
I personally will be blocking steamwebhelper.exe permanantly,
the only thing I believe it does, is assists the main steam.exe in viewing
store page products and websites internally.
I have a couple of theorys as how it happened, my first.... is that someone
intentionally crashed the server, and somehow was able to communicate
to hl2.exe some malformed code to make steamwebhelper.exe navigate to
many pages.
My second theory, is that there could be something in the 6th RB's intro
page, or at very least, could have served as a doorway, as it has a
"web control" built into it, that could potentially hijack a client.
Some things to think about.
rotation of common maps as well as custom maps.
At the time of the incident, we were on an "Avalanche" map, although I
have no idea if it was modified. It appeared to be the stock map.
Their game server apparently crashed, and the server wasn't listed for
several minutes. Meanwhile, I went to the =eGO= 24/7 Avalanche server.
When I joined, I noticed substantial lag from the players, so I glanced at
my ping, and it was reporting 160... which usually it equilibriates at 90-100
So I opened up TCPVIEW.exe (Sysinternals Microsoft program for
viewing established connections) and to my surprise there were 'at least'
40 connections 'Established' to "Steamwebehlper.exe" and they all were
from suspicious looking websites. I remember one was even connected to
Facebook. I wished I'd taken a screenshot. I'm certain though that was
abnormal activity.
So I closed steamwebhelper.exe immediately, and my ping instantly
returned to what it should be, in fact, i'd never seen it so low before.
"88 ping", the rest of the night, it hovered around 95-100 and i monitored
it carefully.
I ended up blocking all connections to steamwebhelper.exe with my
firewall and noticed no functional difference in the hl2.exe program.
I also blocked steam.exe connections, and I disconnected from the vac
server, but that's to be expected. Thats neither here nor there though.
Anyways, I posted a message to Steam tech support, I doubt they'll be
able to resolve anything without any crash dump information. I thought
you should all be made ware of this vulnerability that affects the gameplay.
I personally will be blocking steamwebhelper.exe permanantly,
the only thing I believe it does, is assists the main steam.exe in viewing
store page products and websites internally.
I have a couple of theorys as how it happened, my first.... is that someone
intentionally crashed the server, and somehow was able to communicate
to hl2.exe some malformed code to make steamwebhelper.exe navigate to
many pages.
My second theory, is that there could be something in the 6th RB's intro
page, or at very least, could have served as a doorway, as it has a
"web control" built into it, that could potentially hijack a client.
Some things to think about.





