secret club Profile Banner
secret club Profile
secret club

@the_secret_club

16,772
Followers
0
Following
9
Media
65
Statuses

secret club is a not-for-profit reverse-engineering group; publishing new research on popular software. No ads, no cookies, just research.

Don't wanna be here? Send us removal request.
Pinned Tweet
@the_secret_club
secret club
4 years
Two years ago, secret club member @floesen_ reported a remote code execution flaw affecting all source engine games. It can be triggered through a Steam invite. This has yet to be patched, and Valve is preventing us from publicly disclosing it.
74
739
2K
@the_secret_club
secret club
4 years
Third times a charm; @the_secret_club member mev showcases their remote code execution 0-day for CS:GO. This has been reported to Valve 5 months ago with no response from Valve.
16
119
468
@the_secret_club
secret club
4 years
On the topic of our previous thread, we have @brymko @cffsmith @scannell_simon showcasing their remote code execution 0-day for CS:GO. This has been reported to Valve months ago, but they have neither paid them nor acknowledged the exploit.
12
110
408
@the_secret_club
secret club
4 years
Valve ignoring security researchers is not just specific to the secret club. Here we see Bien Pham demonstrate his Remote Code Execution exploit that has not been patched for over a year.
@bienpnn
Bien 🇻🇳
4 years
As you may know, @the_secret_club recently posted videos about Source Engine games RCE. I was also ignored by Valve for a year. Here's the demonstration of my report. RCE can be achieved by connecting to a malicious server, then the chain will be completed when game is restarted.
7
62
292
9
99
372
@the_secret_club
secret club
4 years
Two years ago, slidybat reported a remote code execution affecting Team Fortress 2. It can be triggered by joining a community server. It has yet to be patched.
6
90
363
@the_secret_club
secret club
4 years
After two years, Valve has patched the critical remote code execution exploit disclosed by @floesen_
2
28
148
@the_secret_club
secret club
2 years
Improving MBA Deobfuscation using Equality Saturation by @fvrmatteo and @mr_phrazer .
1
74
140
@the_secret_club
secret club
4 years
Here we see researcher teapotd demonstrate his remote code execution vulnerability in CS:GO that is yet to be patched by Valve!
@teapotddd
teapotd
4 years
Here's a demonstration of one of the exploits that I have reported - an unconditional RCE that can be reliably triggered by entering a malicious server.
1
15
75
0
15
56
@the_secret_club
secret club
4 years
Here we see researcher teapotd with multiple CRITICAL 0days in Source Engine games that have been known by Valve for years
@teapotddd
teapotd
4 years
I've seen some people recently shared their *negative* experience with Valve bug bounty program. I have decided to share my frustration as well. @the_secret_club @floesen_
Tweet media one
5
11
103
4
10
55
@the_secret_club
secret club
4 years
We can currently only verify this specific exploit in CS:GO. We can not say for sure if and when things have been patched in other games throughout the time without us being notified about it.
1
2
41
@the_secret_club
secret club
4 years
"Why anticheats block overclocking tools" by @daax_rynd
1
13
32
@the_secret_club
secret club
5 years
“Applied Reverse Engineering: Exceptions And Interrupts” by @daax_rynd
1
9
27
@the_secret_club
secret club
4 years
Redacted on request from Microsoft.
1
0
8
@the_secret_club
secret club
3 years
@0x00ffah @vm_call the discord is the public club 🥷
0
1
4
@the_secret_club
secret club
5 years
0
0
2