Three Million DiRT 3 Game Vouchers Stolen by Hackers

September 7, 2011 -

Codemasters and AMD have confirmed that over three million digital vouchers for Steam have been stolen for DiRT 3. According to a report from Industry Gamers (citing a Steam forum post), hackers used an .htaccess exploit that allowed them to gain access to an .sql database containing the codes. Those codes were meant to be used for a future AMD graphics card promotion.

"This past weekend, activation keys associated with free DiRT 3 game vouchers shipping with select AMD products were compromised," said AMD in a statement. "These activation keys were hosted on a third party fulfillment agency website, www.AMD4u.com, and did not reside on AMD's website. Neither the AMD nor Codemasters servers were involved."

"We are working closely with Steam, Codemasters, and our fulfillment agency to address the situation. AMD will continue to honor all valid game vouchers, however the current situation may result in a short delay before the vouchers can be redeemed."

The good news is that the huge batch of codes that were stolen can be traced, and Codemasters claims that they should be able to deactivate the codes in due time.

Source: Eurogamer by way of Industry Gamers


Comments

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

Stolen? That's bit of a stretch given how the keys were made available for the whole world to see.

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

I disagree (though it's quite possible I've misunderstood exactly what happened here).  If someone takes my stuff without my permission, my stuff has been stolen.  It doesn't matter if I've left my front door wide open with my stuff neatly piled in the doorway.

That does make me stupid but it doesn't make my stuff any less stolen.

 

Andrew Eisen

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

Taking your stuff against your will is stealing, but you're using that logic on something that doesn't apply. Stealing leaves the victim without what is theirs. Has anyone lost anything? No, they still have the codes, but the hackers (sic) have them too, which they can invalidate. So they might be able to acquire copies of Dirt3 without participating in the promotion, but Codemasters will not have fewer copies of the game as a result. That is, if they are digital downloads and not printed discs shipped in boxes. It might be applicable to accuse them of fraud if they attempt to redeem those vouchers, but stealing isn't. What they did would be more akin to eavesdropping, espionage,  or wiretapping.

Your definition of stealing is flawed, especially in the eyes of the law. That said, what happened was a deplorable act that resulted in an interruption of service for actual customers of AMD and Codemasters. It was rather pointless act as well since it's easier to acquire the DRM-free version from bittorrent. Given all that, it's a seriously dick move and they should stand to answer for the damage they did.

-Greevar

"Paste superficially profound, but utterly meaningless quotation here."

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

Replace "stole" with "misappropriate" if it makes you happy.

 

Andrew Eisen

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

It's more like an infringement of privacy, similar to trespassing.

-Greevar

"Paste superficially profound, but utterly meaningless quotation here."

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

Whatever, buddy.  I know you understand the specifics of what happened so I really don't care what you call it.

 

Andrew Eisen

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

I believe this situation is more akin to leaving all of your stuff in the middle of a busy intersection and then claiming that it was stolen when you come back 3 days later to find it all missing.

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

Not unless those keys were posted in plain text on the front page of AMD4u's website or something similar.  Hell, even my "open front door" analogy isn't applicable.

 

Andrew Eisen

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

They were stored in plain text. All you basically had to do was add /keys to the end of the URL.

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

"Not unless those keys were posted in plain text on the front page of AMD4u's website or something similar."

 

Andrew Eisen

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

I think it would be more apt to say you left your door unlocked. From an external perspective it would seem that your stuff was secure, but when more closely inspected the flaw is revealed.

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

That seem a fairer analogy. But then, on the internet, you'd have to account for thousands of people that keep trying the lock every day... You can argue it's good or bad, but it most definitely is common enough to take into account.

Re: Three Million DiRT 3 Game Vouchers Stolen by Hackers

.htaccess exploit? I'd hardly call it an exploit. Hell, I wouldn't even call it a hack. The directories (plural. There was more than one: an SQL directory showing some keys in 3 sql files, and a keys directory showing ALL keys in plain text files) were WIDE OPEN (and continued to be such for hours after it was made public). A hack? More like a complete lack of security.

----
Papa Midnight

 
Forgot your password?
Username :
Password :

Poll

Will Code Avarice's Paranautical Activity make its way back onto Steam?:

Shout box

You're not permitted to post shouts.
MaskedPixelanteGOG has a four day countdown to their next publisher. All hints suggest Disney, but no guarantee it'll be LucasArts.10/24/2014 - 6:58am
Neo_DrKefkawith a neutral party Moderating it. I've been waiting a long time for a GamerGate to happen but now all I want is the healing to start. Weird huh? Gamers don't need to be attacking gamers we should all be on the same side10/24/2014 - 12:39am
Neo_DrKefkaRight now from what I seen your tweet and the other guys tweet there are hard feelings. Until we start a dialogue with each other I think it will get worse before it will get better. I hope you guys work something out meet in a neutral stream10/24/2014 - 12:37am
Neo_DrKefkaThanks James. Even if a hot/hard headed person likes me thinks the public needs to sit down and discuss this together. We all might not agree right now but if the public does not start talking to each other we are not going anywhere.10/24/2014 - 12:36am
james_fudgeHey guys I had a nap because, getting old! I'll take a look.10/24/2014 - 12:01am
Matthew Wilsonjames needs to contact Totalbiscuit than10/23/2014 - 10:07pm
Neo_DrKefkaJames said earlier he went into a stream earlier informed them who he was and they didn't care. If James is trying to talk lets set something up?10/23/2014 - 9:38pm
Matthew WilsonTotalbiscuit has been trying for months, no one that is anti gg seems to want to talk with him on camera10/23/2014 - 9:20pm
Neo_DrKefkaHey James check your twitter. Check with Totalbiscuit see if you can get a round table discussion stream going see if he can get some pro gg people and you can get some gamejournopros. Both sides have been hurt, doxxed its time every1 sits down and talks10/23/2014 - 9:05pm
Matthew Wilsonthe wiiu will support up to 8 gc controllers http://www.smashbros.com/us/howto/entry10.html10/23/2014 - 7:50pm
quiknkoldmewtwo is a timed free exclusive. you can purchase him if you dont have both.10/23/2014 - 7:15pm
Neo_DrKefka@Monte A month and a half ago we had a lot of streams about solutions now all the streams are KingofPol styled rants about getting drunk. All Gamergate is about to many is for people to use the movement to jump start careers.10/23/2014 - 7:12pm
Neo_DrKefkaWhose stream where you in James?10/23/2014 - 7:02pm
Matthew Wilsonyup they are holding mewtwo hostage lol10/23/2014 - 5:59pm
MaskedPixelanteApparently Mewtwo is going to be a free download to anyone who bought both versions of Smash 4.10/23/2014 - 5:41pm
TechnogeekYou would also think that if GG gave a shit about journalistic ethics, Game Informer would have been the very first line of their boycott list.10/23/2014 - 5:32pm
MaskedPixelanteRidley confirmed for Smash Wii U... as a stage buddy like the Yellow Devil and flying man.10/23/2014 - 5:31pm
prh99Rather than trying to spin it as some sort of artistic choice, they should just say they don't want to rework the engine to either decouple the mechanics or make them work at 60fps.10/23/2014 - 5:25pm
Matthew Wilsonubisoft is made to look worse now. wiiu smash is 1080p 60fps lol10/23/2014 - 5:02pm
MonteYou would think that, if GG were really about journalistic ethics, their streams would be more conerned with Shadows of mordor(a REAL controversy involing a major publisher) than with the FALSE jounralistic controversy around Quinn10/23/2014 - 4:49pm
 

Be Heard - Contact Your Politician