Three Million DiRT 3 Game Vouchers Stolen by Hackers

September 7, 2011 -

Codemasters and AMD have confirmed that over three million digital vouchers for Steam have been stolen for DiRT 3. According to a report from Industry Gamers (citing a Steam forum post), hackers used an .htaccess exploit that allowed them to gain access to an .sql database containing the codes. Those codes were meant to be used for a future AMD graphics card promotion.

"This past weekend, activation keys associated with free DiRT 3 game vouchers shipping with select AMD products were compromised," said AMD in a statement. "These activation keys were hosted on a third party fulfillment agency website, www.AMD4u.com, and did not reside on AMD's website. Neither the AMD nor Codemasters servers were involved."

"We are working closely with Steam, Codemasters, and our fulfillment agency to address the situation. AMD will continue to honor all valid game vouchers, however the current situation may result in a short delay before the vouchers can be redeemed."

The good news is that the huge batch of codes that were stolen can be traced, and Codemasters claims that they should be able to deactivate the codes in due time.

Source: Eurogamer by way of Industry Gamers


Comments

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

Stolen? That's bit of a stretch given how the keys were made available for the whole world to see.

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

I disagree (though it's quite possible I've misunderstood exactly what happened here).  If someone takes my stuff without my permission, my stuff has been stolen.  It doesn't matter if I've left my front door wide open with my stuff neatly piled in the doorway.

That does make me stupid but it doesn't make my stuff any less stolen.

 

Andrew Eisen

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

Taking your stuff against your will is stealing, but you're using that logic on something that doesn't apply. Stealing leaves the victim without what is theirs. Has anyone lost anything? No, they still have the codes, but the hackers (sic) have them too, which they can invalidate. So they might be able to acquire copies of Dirt3 without participating in the promotion, but Codemasters will not have fewer copies of the game as a result. That is, if they are digital downloads and not printed discs shipped in boxes. It might be applicable to accuse them of fraud if they attempt to redeem those vouchers, but stealing isn't. What they did would be more akin to eavesdropping, espionage,  or wiretapping.

Your definition of stealing is flawed, especially in the eyes of the law. That said, what happened was a deplorable act that resulted in an interruption of service for actual customers of AMD and Codemasters. It was rather pointless act as well since it's easier to acquire the DRM-free version from bittorrent. Given all that, it's a seriously dick move and they should stand to answer for the damage they did.

-Greevar

"Paste superficially profound, but utterly meaningless quotation here."

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

Replace "stole" with "misappropriate" if it makes you happy.

 

Andrew Eisen

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

It's more like an infringement of privacy, similar to trespassing.

-Greevar

"Paste superficially profound, but utterly meaningless quotation here."

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

Whatever, buddy.  I know you understand the specifics of what happened so I really don't care what you call it.

 

Andrew Eisen

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

I believe this situation is more akin to leaving all of your stuff in the middle of a busy intersection and then claiming that it was stolen when you come back 3 days later to find it all missing.

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

Not unless those keys were posted in plain text on the front page of AMD4u's website or something similar.  Hell, even my "open front door" analogy isn't applicable.

 

Andrew Eisen

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

They were stored in plain text. All you basically had to do was add /keys to the end of the URL.

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

"Not unless those keys were posted in plain text on the front page of AMD4u's website or something similar."

 

Andrew Eisen

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

I think it would be more apt to say you left your door unlocked. From an external perspective it would seem that your stuff was secure, but when more closely inspected the flaw is revealed.

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

That seem a fairer analogy. But then, on the internet, you'd have to account for thousands of people that keep trying the lock every day... You can argue it's good or bad, but it most definitely is common enough to take into account.

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

.htaccess exploit? I'd hardly call it an exploit. Hell, I wouldn't even call it a hack. The directories (plural. There was more than one: an SQL directory showing some keys in 3 sql files, and a keys directory showing ALL keys in plain text files) were WIDE OPEN (and continued to be such for hours after it was made public). A hack? More like a complete lack of security.

----
Papa Midnight

 
Forgot your password?
Username :
Password :

Shout box

You're not permitted to post shouts.
ZippyDSMleePaypal shuts down Mega's payment system. https://torrentfreak.com/under-u-s-pressure-paypal-nukes-mega-for-encrypting-files-150227/03/01/2015 - 3:25pm
Matthew Wilsonvalvle planning to release a vr headset this year wtf http://www.pcgamer.com/valves-vr-headset-is-named-vive-and-htc-are-making-it/03/01/2015 - 1:05pm
ZippyDSMleeuuuhhhggg in other news been sick since last night.....uuhggg.....I iwsh it did not hurt so much when my tummy wants to leave my body..02/28/2015 - 11:39pm
ZippyDSMleeBrings me to the Q why alt costumes would be needed in competition anyway... http://www.eventhubs.com/news/2015/feb/28/dead-or-alive-community-aims-ban-over-120-overly-sexualized-costumes-dead-or-alive-5-last-round/02/28/2015 - 11:36pm
MonteThough from a business side, i would agree with the article. While it would be smarter for developers to slow down, you can't expect EA, Activision or ubisoft to do something like that. Nintnedo's gotta get the third party back.02/28/2015 - 4:36pm
MonteThough it does also help that nintendo's more colorful style is a lot less reliant on graphics than more realistic games. Wind Waker is over 10 years old and still looks good for its age.02/28/2015 - 4:33pm
MonteWith the Wii, nintnedo had the right idea. Hold back on shiny graphics and focus on the gameplay experience. Unfortunatly everyone else keeps pushing for newer graphics and it matters less and less each generation. I can barely notice the difference02/28/2015 - 4:29pm
MonteON third party developers; i kinda think they should slow down to nintendo's pace. They bemoan the rising costs of AAA gaming, but then constantly push for the best graphics which is makes up a lot of those costs. Be easier to afford if they held back02/28/2015 - 4:27pm
Matthew Wilsonhttp://www.forbes.com/sites/insertcoin/2015/02/28/the-world-is-nintendos-if-only-theyd-take-it/ I think this is a interesting op-ed, but yeah it kind of is stating the obvious.02/28/2015 - 2:52pm
prh99The government probably doesn't need an app, but I was think more along the lines of a company that was going to sell the collected info. “If you're not paying for the product, you are the product” sometimes even if you pay.02/28/2015 - 1:50pm
E. Zachary KnightWhat better way for the government to keep track of you than to get you to install an app that lets you insult the government.02/28/2015 - 11:03am
prh99No, but I looked it up and it's basically spyware. Their privacy policy says their apps tracks among other things your location and browsing habits via cookies.02/28/2015 - 8:20am
Ryan RardinHas anyone here heard of an app called iCitizen? It's basically Yelp for politicians.02/28/2015 - 5:16am
Andrew EisenAh, not linked in the way you (and everyone else) want and expect. That's true.02/27/2015 - 10:06pm
Matthew Wilsonthey are not linked in a way that tracks purchases though. the fact that they have to send a code for the other system shows that they are not linked in the way it counts.02/27/2015 - 9:39pm
Andrew EisenAccounts are already linked. Have been for quite a while. Also, Mario vs. Donkey Kong was announced as a cross-buy title during last January's Nintendo Direct.02/27/2015 - 9:25pm
Matthew Wilsonhttp://www.vg247.com/20…/…/27/olli-olli-3ds-wii-u-cross-buy/ I wounder if this is a sign that Nintendo may finally link accounts across the 3ds/wiiu in the near future.02/27/2015 - 9:18pm
prh99http://www.romanoriginals.co.uk/invt/70931?colour=Blue The dress does comes in white and blue but both have black lace and a sheer back top, I don't see gold or brown. 02/27/2015 - 8:54pm
ZippyDSMleeDungeons was a so bad so good game to me so I been keeping up with its sequel which will more of a Dungeon Keeper clone. As for pre order out of 7 preorders I was not burnt by 2... Add my contempt of most of modern game design.Ya I have all kinds of hurt.02/27/2015 - 8:40pm
MechaTama31I don't even want to know...02/27/2015 - 8:22pm
 

Be Heard - Contact Your Politician