Three Million DiRT 3 Game Vouchers Stolen by Hackers

September 7, 2011 -

Codemasters and AMD have confirmed that over three million digital vouchers for Steam have been stolen for DiRT 3. According to a report from Industry Gamers (citing a Steam forum post), hackers used an .htaccess exploit that allowed them to gain access to an .sql database containing the codes. Those codes were meant to be used for a future AMD graphics card promotion.

"This past weekend, activation keys associated with free DiRT 3 game vouchers shipping with select AMD products were compromised," said AMD in a statement. "These activation keys were hosted on a third party fulfillment agency website, www.AMD4u.com, and did not reside on AMD's website. Neither the AMD nor Codemasters servers were involved."

"We are working closely with Steam, Codemasters, and our fulfillment agency to address the situation. AMD will continue to honor all valid game vouchers, however the current situation may result in a short delay before the vouchers can be redeemed."

The good news is that the huge batch of codes that were stolen can be traced, and Codemasters claims that they should be able to deactivate the codes in due time.

Source: Eurogamer by way of Industry Gamers


Comments

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

Stolen? That's bit of a stretch given how the keys were made available for the whole world to see.

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

I disagree (though it's quite possible I've misunderstood exactly what happened here).  If someone takes my stuff without my permission, my stuff has been stolen.  It doesn't matter if I've left my front door wide open with my stuff neatly piled in the doorway.

That does make me stupid but it doesn't make my stuff any less stolen.

 

Andrew Eisen

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

Taking your stuff against your will is stealing, but you're using that logic on something that doesn't apply. Stealing leaves the victim without what is theirs. Has anyone lost anything? No, they still have the codes, but the hackers (sic) have them too, which they can invalidate. So they might be able to acquire copies of Dirt3 without participating in the promotion, but Codemasters will not have fewer copies of the game as a result. That is, if they are digital downloads and not printed discs shipped in boxes. It might be applicable to accuse them of fraud if they attempt to redeem those vouchers, but stealing isn't. What they did would be more akin to eavesdropping, espionage,  or wiretapping.

Your definition of stealing is flawed, especially in the eyes of the law. That said, what happened was a deplorable act that resulted in an interruption of service for actual customers of AMD and Codemasters. It was rather pointless act as well since it's easier to acquire the DRM-free version from bittorrent. Given all that, it's a seriously dick move and they should stand to answer for the damage they did.

-Greevar

"Paste superficially profound, but utterly meaningless quotation here."

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

Replace "stole" with "misappropriate" if it makes you happy.

 

Andrew Eisen

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

It's more like an infringement of privacy, similar to trespassing.

-Greevar

"Paste superficially profound, but utterly meaningless quotation here."

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

Whatever, buddy.  I know you understand the specifics of what happened so I really don't care what you call it.

 

Andrew Eisen

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

I believe this situation is more akin to leaving all of your stuff in the middle of a busy intersection and then claiming that it was stolen when you come back 3 days later to find it all missing.

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

Not unless those keys were posted in plain text on the front page of AMD4u's website or something similar.  Hell, even my "open front door" analogy isn't applicable.

 

Andrew Eisen

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

They were stored in plain text. All you basically had to do was add /keys to the end of the URL.

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

"Not unless those keys were posted in plain text on the front page of AMD4u's website or something similar."

 

Andrew Eisen

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

I think it would be more apt to say you left your door unlocked. From an external perspective it would seem that your stuff was secure, but when more closely inspected the flaw is revealed.

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

That seem a fairer analogy. But then, on the internet, you'd have to account for thousands of people that keep trying the lock every day... You can argue it's good or bad, but it most definitely is common enough to take into account.

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

.htaccess exploit? I'd hardly call it an exploit. Hell, I wouldn't even call it a hack. The directories (plural. There was more than one: an SQL directory showing some keys in 3 sql files, and a keys directory showing ALL keys in plain text files) were WIDE OPEN (and continued to be such for hours after it was made public). A hack? More like a complete lack of security.

----
Papa Midnight

 
Forgot your password?
Username :
Password :

Poll

Will the FCC preempt state laws that limit municipal broadband services?:

Shout box

You're not permitted to post shouts.
Andrew EisenBecause it would be cool, would serve the game's fantastic art direction well and encourage people who've already played it to buy it again.08/01/2014 - 7:42pm
ZippyDSMleeWhy bother with an HD relese just repack the damn thing and promote it since it will play on the WIIU anyway....08/01/2014 - 7:04pm
Andrew EisenPlus, with Nintendo carrying the Wii U almost all by itself, it could help plug one of the unfortunately inevitable release schedule gaps.08/01/2014 - 3:23pm
Andrew EisenAn HD re-release would be cool though. It's a great game (and quite the looker, especially when up-rezzed) and more people should play it (the game had a limited release at a time when the Wii was all but dead an buried).08/01/2014 - 3:21pm
E. Zachary KnightSo no, people are not going to need to play the Wii game to undstand or enjoy the Wii U game.08/01/2014 - 1:27pm
E. Zachary KnightFrom what I understand, the two games have as much to do with eachother as Final Fantasy and Final Fantasy 2.08/01/2014 - 1:26pm
MaskedPixelanteIt's my secret hope that Nintendo announces Xenoblade HD to be released in the leadup to Xenoblade Chronicles X, or at least a mass market version of the first game so that people aren't going into this one blind.08/01/2014 - 12:40pm
PHX CorpI'm going to do a test stream later today, if anyone is intrested07/31/2014 - 2:40pm
Andrew EisenYes, I'm such a big Nintendo dork that I read Nintendo's quarterly financial reports.07/31/2014 - 2:09pm
Andrew EisenCool tidbit - Mario Kart 8 sales account for more than half of total Wii U software sales for the last quarter even though it was only available for the last third.07/31/2014 - 2:09pm
Andrew EisenStill a pretty cool promotion. Unfortunately for me, I'm not interested in purchasing Mario Kart 8 and I already owned or didn't want any of the free games on offer.07/31/2014 - 1:43pm
Andrew EisenInteresting that EU had 10 games to choose from while North America only had four.07/31/2014 - 1:41pm
MaskedPixelanteIt certainly worked, I probably would never have bought Mario Kart 8 if it didn't come with a free copy of Wind Waker HD.07/31/2014 - 1:14pm
Andrew EisenI imagine will see similar promotions like "Buy Mario Kart 8 get a download code for one of these specific games" but almost certainly not for all of its (however you would define) biggest releases.07/31/2014 - 11:24am
MaskedPixelanteI wonder if Nintendo is going to be doing "buy one get one free" promos for all their biggest releases going forward.07/31/2014 - 10:48am
MaskedPixelantehttp://www.mcvuk.com/news/read/special-report-retail-revolt-over-pc-code-strippers/013614007/31/2014 - 8:27am
ZippyDSMleeWouldn't they be able to afford and get done in a timely manner a general gba emluator for the 3DS? It seems to me if they want to make money off sales they need to do it.07/31/2014 - 7:25am
Sora-ChanAmbassador program, that's what I was looking for. Anyway the other games that have been made no longer exclusive to the early adopters got updates in their software. It'll only be a matter of time more than likely for the GBA to get the same treatment.07/31/2014 - 5:35am
Sora-ChanI might be naming it incorrectly when I say "founder" i mean the program for earlier adopters.07/31/2014 - 5:34am
Sora-Chanthe 3DS's GBA emulator was a rush job due to the founder program. No other GBA titles have been released on the 3DS yet. If/When they do get around to it, they'll more than likely update the emulation software.07/31/2014 - 5:32am
 

Be Heard - Contact Your Politician