gamers

Valve confirms Half-Life 2 Source Code Leak

Keldyn   on 03 October 2003 - 09:18 · 51 comments & 12213 views

Advertisement (Why?)
A security breach is being blamed for the leak of the HL2 source code which started with an unnamed individual reportedly gaining access to Gabe's own personal email account and workstation.... -Keldyn

As quoted by Gabe Newell:

"Yes, the source code that has been posted is the HL-2 source code...

Ever have one of those weeks? This has just not been the best couple of days for me or for Valve.

Yes, the source code that has been posted is the HL-2 source code....


Here is what we know:

1) Starting around 9/11 of this year, someone other than me was accessing my email account. This has been determined by looking at traffic on our email server versus my travel schedule.

2) Shortly after-wards my machine started acting weird (right-clicking on executables would crash explorer). I was unable to find a virus or Trojan on my machine, I reformatted my hard drive, and reinstalled.

3) For the next week, there appears to have been suspicious activity on my webmail account.

4) Around 9/19 someone made a copy of the HL-2 source tree.

5) At some point, keystroke recorders got installed on several machines at Valve. Our speculation is that these were done via a buffer overflow in Outlook's preview pane. This recorder is apparently a customized version of Remote-Anywhere created to infect Valve (at least it hasn't been seen anywhere else, and isn't detected by normal virus scanning tools).

6) Periodically for the last year we've been the subject of a variety of denial of service attacks targeted at our web servers and at Steam. We don't know if these are related or independent.


News source: 3dnewz




What I'd appreciate is the assistance of the community in tracking this down. I have a special email address for people to send information to, helpvalve@valvesoftware.com. If you have information about the denial of service attacks or the infiltration of our network, please send the details. There are some pretty obvious places to start with the posts and records in IRC, so if you can point us in the right direction, that would be great.

We at Valve have always thought of ourselves as being part of a community, and I can't imagine a better group of people to help us take care of these problems than this community."


Gabe

Update: An email transcript dated the 27th of September (that I won't link to) highlights security flaws in Valve's operations, and mentions that some members of Valve were pushing for a peer-to-peer distribution method for Half-Life 2 shortly before release, in the hope of not crippling the direct download servers, and leaving Steam customers without their game.

In the email, the owner of a Half-Life 2 fan site tricked another Valve employee into thinking he was someone else, and then got confidential information from him. Significantly, the Valve employee stated that they - at the time - had no email verification software, and so emails could be faked by a skillful hacker. Presumably security has now been tightened.

Post a comment · Send to friend Comments · There are 51 additional comments
#1 Jasco on 03 Oct 2003 - 09:39
Shame, shame...
#2 Beast_4thHM on 03 Oct 2003 - 09:43
It was stollen! amazing... someone tried hard to get it
(4 replies) #3 Jon on 03 Oct 2003 - 10:15
Why is the word Access a link to BT Broadband services??
#3.1 Keldyn on 03 Oct 2003 - 10:29
subliminal marketting...

#3.2 mr_da3m0n on 03 Oct 2003 - 11:13
Yeah what the hell? Smart tags?!

Neowin has sunk veeeeery low >.<

But i forgive you guys, you know I love you.


At first I tought I had some adware installed, but then realized it was the website. And they don't show in Mozilla, nor galeon. And surely not in Safari.
#3.3 Keldyn on 03 Oct 2003 - 11:23
#3.4 djze on 03 Oct 2003 - 15:43
It's vibrant media's text ads, many sites are starting to use it
(6 replies) #4 Dissolved on 03 Oct 2003 - 10:57
Hmm, i wonder if he was useing Windows
#4.1 mr_da3m0n on 03 Oct 2003 - 11:14
QUOTE

Our speculation is that these were done via a buffer overflow in Outlook's preview pane


You know anything else than OUTLOOK runs on?
#4.2 chuayw2000 on 03 Oct 2003 - 11:50
Isn't there Office for Mac? But anyway i think he was really using windows....
#4.3 kev64 on 03 Oct 2003 - 14:54
QUOTE
Isn't there Office for Mac?


Office yes, Outlook no.
#4.4 mr_da3m0n on 03 Oct 2003 - 14:55
There's office for the mac, in fact i'm using it every day

But not Outlook -- the PIM+Email program on the Mac is called Entourage.
#4.5 Coolme on 03 Oct 2003 - 18:42
how did they come up with the name
QUOTE
Entourage
anyway?
#4.6 mr_da3m0n on 04 Oct 2003 - 06:17
Makes more sense to me than "Outlook" actually
(2 replies) #5 DOCa Cola on 03 Oct 2003 - 11:19
oh no, i hoped it was fake
#5.1 Keldyn on 03 Oct 2003 - 11:22
umm... This article is to confirm that it is not fake.
#5.2 DOCa Cola on 03 Oct 2003 - 11:29
hu? have i missunderstood something? the hl2 source was leaked - i hoped it was only a fake, but here is the confirm

DOCa Cola
#6 iomayho on 03 Oct 2003 - 11:32
i think its a conspiracy..., their atitude toward this issue is much less severe than what i expected....
#7 Floyder on 03 Oct 2003 - 11:33
owned :
#8 SimplyPotatoes on 03 Oct 2003 - 11:39
oh wait , this sucks.... there are already a lot of forums open talking about flaws in the code

Last edited by 34433 on 03 Oct 2003 - 11:48
#9 biorK on 03 Oct 2003 - 11:39
a sad day for all hl2 pre-fans
(6 replies) #10 ZombieFly on 03 Oct 2003 - 11:53
this is very odd. there doesnt appear to be a lot of fuss about this at all. If you were Gabe, wouldn't you be going ape about this, not casually explaining how someone hacked ur pc, and then lamely ask a community of ar** licking muppets to help you out. [honestly, have you read some of the comments on that forum, "i kneel before you master" etc, what a gang of Tards]

it all stinks a bit to me. Suddenly the code is out there, what will value do now? accept the possibilty of a zillion hacks to the closely guarded hl2 multiplayer? no, they'll have to recode. Oh, thats convenient. Whats the bets that the release date now slips into 2004? The community will accept that recoding to prevent hacks is acceptable, however they wouldnt just have accepted another delay. I watch this with interest, as lets face it, nobody outside of valve would know the hl2 code was genuine anyway at this stage.


#10.1 KCKitsune on 03 Oct 2003 - 12:00
unless they compiled the code and ran the game. Now I agree with you on Gabe's reaction being too mild, but maybe he doesn't want to come across as a raving psychopath.
#10.2 ZombieFly on 03 Oct 2003 - 12:02
i was under the impression that u'd need a compiler for that? and what about all the resources such as textures and maps etc?
#10.3 PabUK on 03 Oct 2003 - 12:18
I don't find his attitude very odd, I find it quite admirable considering what they must be going through because of all this.
#10.4 mr_da3m0n on 03 Oct 2003 - 14:45
Lots of free compilers around, plus you can easily warez Visual Studio...

As for textures, this is where you're right -- you can't run the game without the data files, textures, maps, models, paths, sounds -- which were not leaked.

#10.5 suprfli on 03 Oct 2003 - 21:23
this sounds crazy but i know a guy who is very close to valve and he told me more than a year ago that HL2 is nothing but hype. he said valve has never done any coding on it and only uses the hype of HL2 to promote their existing productions and f**k w/the media to inadvertantly continue the promotion train.

this latest development, gabes seemingly lack of outrage and the prospect of waiting "another year. it will be done when it's done" only seems too convenient.

btw, what's the reward money for helping to turn this person or persons in? if the source code to a project i worked on for years that would make millions was leaked wouldn't you offer a sizeable reward? imagine if the longhorn source code was released. MS won't even release the source code to NT even though they are end of lifing it.
#10.6 suprfli on 03 Oct 2003 - 21:25
btw, the fact that the data files, textures, maps, models, paths, sounds weren't leaked only further possibly validates what i heard. it seems awfully convenient that a hacker would have complete access to HL2 but only release the source and not the whole thing when it is supposedly "nearly finished."

why wouldn't this hacker release the latest internal beta?!?!
#11 kljs on 03 Oct 2003 - 12:01
reverse psychology.
#12 dougkinzinger on 03 Oct 2003 - 12:09
Can I have it???
#13 Solarix on 03 Oct 2003 - 12:11
its not fake trust me took about 3 min to compile kinda usless to me tho , i wanted to see if i could port it using quake AHAH kinda worked but too bad i cant release anything o well it was ogod while it lasted..
#14 Fredde87 on 03 Oct 2003 - 12:17
I would think they would delay it another month now and then remake a lot of things with it

I have had a look at it and it looks good for the cheaters and bad for us anti-cheaters... Ohh well the world will never be cheat free
#15 nookadum on 03 Oct 2003 - 12:23
Bah, as it seems to me, the leak of the source code shouldn't change anything.

Steam would destroy all those who try to use a modified version of HL, HL2, CS, etc. I mean, that's why Steam is for right?

Also, what are people gonna do with the source code when they don't have the supplementary objects that go with it? Such as the models, sounds, textures, etc...
#16 chorpeac on 03 Oct 2003 - 12:27
rediculous.....
#17 kemical on 03 Oct 2003 - 12:28
this attack is probably just to weed out the stupid ones
#18 SimplyPotatoes on 03 Oct 2003 - 12:50
maybe valve should make it open source now!!! free to use for people and companies have to pay themfor it?
(4 replies) #19 Caleb on 03 Oct 2003 - 13:02
I hope that the f-a-g who did it gets caught and they'll tear his ballz out !
#19.1 Neobond on 03 Oct 2003 - 13:09
but that would hurt!

Oh yea
#19.2 Yakkob on 03 Oct 2003 - 14:09
and what if its a bird?
#19.3 mr_da3m0n on 03 Oct 2003 - 14:57
Yeah what about birds? I'm very suspicious of the doves...
#19.4 nookadum on 04 Oct 2003 - 07:27
Lesbian seagull...
#20 rob.derosa on 03 Oct 2003 - 16:46
It even made the BBC

BBC News Online
#21 LANCEL0T on 03 Oct 2003 - 18:12
Honestly, the last few weeks there were more and more news items about Half-Life 2 going to be postponed until later this year. This source-leak could well be a "believable" scam by Valve just to get away with the launch delay (they kept insisting, everytime they were asked, HL2 was going to be released September 30, 2003). To be honest, I think it's for a part true and a part scam.
#22 Hypertoad on 03 Oct 2003 - 18:16
It wasn't leaked it was stolen.
#23 Kashida on 03 Oct 2003 - 18:34
wouldnt have been such a big deal if they released the game 3 days ago like they were supposed too
#24 RauL on 03 Oct 2003 - 18:46
I don't like what theyre going to introduce with STEAM , but I dont like neither waht those idiot monkeys are going to make with the HL2code , I can see now exploits , multiplayer cheats , etc . . . shame , shame .... true . . .

(Personally after all the work done with that (HL2) , I would go ballistic and , and rewrite the whole thing even if that means delaying the game launch 3 years more or a simultaneously release with Duke Nukem Forever)
#25 Chicane-UK on 03 Oct 2003 - 19:07
Ouch.. that is really really bad, and I can only imagine Gabe and the guys at Valve are just feeling totally violated.

I hope those responsible are bought to justice as soon as possible.. I think its fair to say they will be taking a real pasting.

Heh.. could be id trying to sabotage the HL2 code so that they can get Doom ]|[ out first :p

#26 Avi on 03 Oct 2003 - 19:23
Hmmm, lol. Don't they know to never connect machines with source code to the Internet or to a network connected to one.
#27 TooPackShaker on 03 Oct 2003 - 23:53
well so much for this game
#28 Kashida on 04 Oct 2003 - 02:10
<plays taps>
#29 Freakz on 04 Oct 2003 - 17:06
its a sad day when people are so impatient to steal someones code.. what has the world come to when not even hard work can be rewarded :'(

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)