the most edgy hacker steam inventory

Поделиться
HTML-код
  • Опубликовано: 1 фев 2025

Комментарии • 561

  • @wizardz4lyf502
    @wizardz4lyf502 3 года назад +4046

    tf2 has an insane history of items being "cheated" into existence and i am eternally thankful cheesmo brought it up. Great vid!

    • @firemaana6440
      @firemaana6440 3 года назад +27

      even people without items get messages like 'Man.. I repoprted you for Duping' and it's never any other reason

    • @SavouryLobster
      @SavouryLobster 3 года назад +12

      Same with CSGO. That's why you can't get your skins back after being scammed anymore.

    • @nya69
      @nya69 3 года назад +47

      @@firemaana6440 thats just a generic scam message meant to scare people, valve hasnt support granted any items in ages n doesnt care abt the old duped items, the bug cheesmo was talking abt was when a guy found how to give literally any item based on ID n gave himself the mvm heavy bots minigun the deflector n a previous 1 i dont know the details of but i believe the finder was given a sunbeams maxs head

    • @firemaana6440
      @firemaana6440 3 года назад

      @@nya69 Don't worry, I was just joking

    • @fredderf4655
      @fredderf4655 3 года назад +7

      duped shovel?????

  • @KexX1901
    @KexX1901 3 года назад +3335

    „If you kill someone…“
    „…in Game?“
    „Yeah I hope ingame“
    Hahahahaha

    • @arthurarsin
      @arthurarsin 3 года назад +35

      didn't even notice the joke until i saw the comment, that's hilarious

    • @Trolju
      @Trolju 3 года назад +1

      cuz twitch rules are dumb ...

    • @wojtekpolska1013
      @wojtekpolska1013 3 года назад +24

      @@Trolju no lmao, its a joke. nothing about twitch rules

    • @minds777
      @minds777 3 года назад +15

      @@wojtekpolska1013 no he had to make the comment “in game” just to reinsure twitch

    • @HappyVLR
      @HappyVLR 2 года назад

      Xd

  • @whoops6325
    @whoops6325 3 года назад +1354

    "i just put name tags on items" lmao fuckin golden

    • @donkitphp
      @donkitphp Год назад +71

      That's literally all he does. Not even a scipt kiddie. Ohne acting like he's some bigbrain hackerman is the cringiest shit ever.

    • @kwaygz
      @kwaygz Год назад

      @@donkitphp awesome but who asked

    • @donkitphp
      @donkitphp Год назад +31

      @@kwaygz I mean you replied lmao

    • @kwaygz
      @kwaygz Год назад

      @@donkitphp you have no idea

    • @donkitphp
      @donkitphp Год назад

      @@kwaygz why are you a leet haxor that could teach me all of the programming languages to become a l33t h4x0r too? Lmao

  • @IxMeTutorials
    @IxMeTutorials 3 года назад +1694

    As the CS:GO UI is built with web technologies, this is basically just about breaking the css layout with obscure unicode characters, just like you often see it on the web. It's unlikely that there are actual exploits possible with this beyond breaking the layout of your client UI.

    • @Michael-dj6pd
      @Michael-dj6pd 3 года назад +33

      unless it can somehow activate escape characters, that can affect more than the UI.

    • @Luna0wl
      @Luna0wl 3 года назад +59

      New World has this problem right now you're able to inject html into your chat and fuck with UI and even crash the game with bad data injected in item descriptions.

    • @S4NSE
      @S4NSE 3 года назад +18

      web technologies lmao

    • @brazy6491
      @brazy6491 3 года назад +40

      @@Luna0wl no thats a completely different problem, new world just didnt sanitize their chat box and the game took it at face value, easy fix. cs:go and tf2 are written this way, manipulating game memory is alot worse than what happend on new world

    • @pixelthec
      @pixelthec 3 года назад +5

      I tested and with this script there might be some potential to break the UI even more but it's so unpredictable that doesn't worth the nametags' price just to test everything out ingame. But no actual exploits really, just some weird visual stuff.

  • @SrikarMaddula
    @SrikarMaddula 3 года назад +1041

    I was wondering why this hadn't been uploaded yet. That shit was so cool on steam. Cheesmo has an insane profile. I really hope I win one of those p250s.

    • @MaxxerOfPepsi
      @MaxxerOfPepsi 3 года назад +2

      i already have a p250 pretty much like that :D

    • @904
      @904 3 года назад +1

      @@MaxxerOfPepsi with the name like that?

    • @MaxxerOfPepsi
      @MaxxerOfPepsi 3 года назад +13

      @@904 yeah its not the same name as the one in the video but yeah it makes the hud go wonky

    • @SrikarMaddula
      @SrikarMaddula 3 года назад +1

      @@MaxxerOfPepsi Damn that's cool af. If I had one like that, I might just start using the p250 lol

    • @MaxxerOfPepsi
      @MaxxerOfPepsi 3 года назад +1

      @@SrikarMaddula i mean shit id trade it if you got anything good to offer me lol

  • @KrypeAV
    @KrypeAV Год назад +44

    In dota 2 the Chinese skin community had figured out a bunch of exploits, the most basic of which was to simply put html links to pictures in description tags for items, rendering them ingame if you clicked on the item. This was a welcome addition to the dota skin community until valve stopped it. The explained that anytime someone loaded the skin in game (as in if they got matched in a game lobby or even just spectating a live game through the in game client) the person that had access to the server the html picture was on could just get the IP address of anyone that loaded it (because they are technically downloading the picture from the server to view it). It was a silly and short time where tags were abused and I hope it never happens to CS.

    • @pondbear1433
      @pondbear1433 Год назад +12

      Boy do I have news for you about something that happens in the votekick menu

    • @dantepaz5028
      @dantepaz5028 4 месяца назад

      @@pondbear1433 fr?

  • @Gr0
    @Gr0 3 года назад +470

    kinda cool how he's open about alot of this stuff, most hacker nerds i have encountered are edgy like title says

    • @durax-0xf
      @durax-0xf 3 года назад +151

      not a hacker, script kiddie
      he said it himself he just used a script

    • @fuckyoutube420
      @fuckyoutube420 2 года назад +3

      @Anonymous User yeah thats y he corrected him, Cheesmo isnt a hacker. Scripter is different little boy

    • @Anna-senpai
      @Anna-senpai Год назад +26

      @@durax-0xf not a skid. he knows hes not a hacker and doesnt try to make it sound crazier than it is.

    • @prodKossi
      @prodKossi Год назад +6

      @@Anna-senpai Yea, One is the one hyping him up to be a h4ckerman - he seems like a good dude

    • @yikes710
      @yikes710 Год назад

      he's not a fuckin hacker lmfao, dude literally told you that he got sent a github link after asking a bunch of people. you people are so gullible it's insane

  • @starplatixum
    @starplatixum 3 года назад +84

    lmao the arabic translates to "in the name of god, the most kind, the most forgiving"

    • @sk27322
      @sk27322 3 года назад +1

      yeah

    • @Reichstaubenminister
      @Reichstaubenminister 2 года назад +1

      Kind of funny. Back then it was a meme when you found out, now it seriously seems like a sign.

    • @ThisUsernameSystemF-ckingSucks
      @ThisUsernameSystemF-ckingSucks Год назад +2

      @@Reichstaubenminister A sign? tf are you talking about?

    • @Reichstaubenminister
      @Reichstaubenminister Год назад +8

      @@ThisUsernameSystemF-ckingSucks I don't remember.

    • @IsolatePlz
      @IsolatePlz 7 месяцев назад

      ​@@ThisUsernameSystemF-ckingSucks A sign of dementia

  • @Halloweenharen
    @Halloweenharen 3 года назад +346

    Got into a wingman game with this guy and got to have a look at a few of his weapons, fun stuff

    • @asthmakid1858
      @asthmakid1858 3 года назад +46

      I played with Brad Pitt also wingman and he said he is going to make actor from me, so funny these things happen right.

    • @mattacer
      @mattacer 3 года назад +12

      @@asthmakid1858 Yeah, I remember meeting Zeus yesterday. Friendly guy

    • @asthmakid1858
      @asthmakid1858 3 года назад +11

      @@mattacer wow,that's crazy all this stuff happened to people in this comment section

    • @herrmanncs
      @herrmanncs 3 года назад +3

      Guys iam actually gay

    • @sorriiez
      @sorriiez 3 года назад +2

      @@herrmanncs ehh and?..

  • @tybs33
    @tybs33 Год назад +5

    4:17 "what if you like can put commands through a nametag" that question aged really well, atleast there was only the player name exploit for now

  • @foxxer64
    @foxxer64 Год назад +4

    I would love if someone made a channel like this, documenting expoits and explaining the history of bugs etc

  • @shadows7936
    @shadows7936 3 года назад +711

    Enough with the clickbait, Cheesmo isn't a hacker lol

    • @GamblingPalace1
      @GamblingPalace1 3 года назад +10

      He pretty much just does shit offline, don’t think he’s accomplished anything alone.

    • @chinchilla_462
      @chinchilla_462 3 года назад +56

      yeah just playing around with a script and throwing around knowledge doesn't make you a hacker, heavily agree with you

    • @idspiel
      @idspiel 3 года назад +1

      hes not a hacker.. zzz its common u can even buy everywhere

    • @idspiel
      @idspiel 3 года назад

      ure hacker when u exploit the web online.. penetrate.. solved maths.. solved coding etc.. entering government sites.n

    • @idspiel
      @idspiel 3 года назад

      @xxxcept a hacker means you invade what is already there..

  • @wojtekpolska1013
    @wojtekpolska1013 3 года назад +45

    10:24 actually no, they gave him the item back (obviously untradable) - it's name of the gun is "Deflector" - its the normal minigun, but it has ability to shoot rockets out of the sky.
    Not that much overpowered, so there wasnt much harm giving it to a single person.

    • @the-jar
      @the-jar 2 года назад +6

      Do you have proof he still has it? He gave himself one but from everything I’ve heard it was removed and they simply gave him another custom unusual like they did to other people. Even the wiki says it was taken away from him

    • @QuackZack
      @QuackZack Год назад +1

      He no longer has it after they patched it out and removed it. Also the deflection ability would be overpowered, as it deflects all projectiles and would negate ALOT of burst damage and make projectile classes extremely useless. It was only meant for a bot AI to use.

    • @wojtekpolska1013
      @wojtekpolska1013 Год назад +2

      @@QuackZack " Also the deflection ability would be overpowered, as it deflects all projectiles and would negate ALOT of burst damage and make projectile classes extremely useless"
      It doesn't matter, there are literally "VALVE" weapons, with insane stats, that are in the accounts of valve employees.
      One player having a weapon that's a little bit stronger doesn't matter that much

    • @QuackZack
      @QuackZack Год назад +4

      @@wojtekpolska1013 Complete difference between a Valve employee that rarely joins or play TF2 to goof around with an OP weapon compared to a regular player that could literally join every casual match and ruin it if he wanted it.

    • @wojtekpolska1013
      @wojtekpolska1013 Год назад +2

      @@QuackZack no lol, there are hundreds of casual servers, and giving heavy the ability to shoot rockets is not even that gamebreaking. he still dies to spies, snipers, sentries, pyros, etc.
      its not overpowered, literally only 1 person in the world has that item, and its not even that OP.

  • @Spookex166
    @Spookex166 3 года назад +117

    Anyone remember the old SFUI Vote Passed nametags with color?

    • @TheRealSlav
      @TheRealSlav 3 года назад

      Yeah

    • @S4NSE
      @S4NSE 3 года назад

      yep

    • @poopooman9658
      @poopooman9658 3 года назад +1

      yeah my awp still has it

    • @TheRealSlav
      @TheRealSlav 3 года назад

      @@poopooman9658 can you still do that?

    • @VeveSigma
      @VeveSigma 3 года назад +2

      @@poopooman9658 yeah but the glitch does not work anymore, you only see the name of the command

  • @Sundrip
    @Sundrip 3 года назад +28

    7:02 "Back in the day, me and you baby" 💀💀

  • @cringgamer5801
    @cringgamer5801 7 месяцев назад +4

    This account was so edgy i edged all night all over the place and i only had 1:30 hours of sleep💀

  • @Kinonear
    @Kinonear 2 года назад +19

    Someone who doesn't know csgo would be confused. Like "Why the hell his mind blows up so much to just a interface location change?"

  • @americantoastman7296
    @americantoastman7296 Год назад +3

    "so, if you kill someon-" "IN GAME RIGHT??" Bruh xD

  • @dancingenginier5707
    @dancingenginier5707 2 года назад +6

    the guy who gave himself the minigun (it was specil in that it could delete proectiles like rockets and pipes) was the guy who got the unusual cheaters lement (halo looking hat) that the guy was talking obout

  • @miinus8972
    @miinus8972 Год назад +3

    ohnepixel predicted the votekick html exploit in this vid

  • @teh_productions
    @teh_productions 2 года назад +2

    This type of hacking that doesn't interfere with other players and it's strictly for cosmetic purposes like this I have no problems with.

  • @buzzbya
    @buzzbya Год назад +2

    this is the true meaning of hacker, not people who pay for aimbot and walls

  • @KillerDragoon87
    @KillerDragoon87 Год назад +1

    I couldn’t imagine a corporation as big as Valve not being protected by SQL injection, but maybe communicating through a script instead of intended text boxes could be a vulnerability valve didn’t consider. Very interesting.

    • @judfps
      @judfps Год назад +1

      aged well

    • @Rusty49
      @Rusty49 Год назад

      i was wondering if someone was gonna say this@@judfps

    • @Alex-bi8ob
      @Alex-bi8ob Год назад

      what happened@@Rusty49

    • @Rusty49
      @Rusty49 Год назад

      @@Alex-bi8ob people were injecting malicious code through their name and in workshop maps

  • @zeushvh
    @zeushvh 2 года назад +4

    this guy just gets fascinated by so little things lol... every video if it isnt normal csgo "OMG HACKER PROFILE" lol.

  • @endrimaris3806
    @endrimaris3806 4 месяца назад

    Never report your bugs/glitches unless there is a bounty program. Devs rarely show appreciation for bug reporting

  • @9bytehub
    @9bytehub 2 года назад +1

    Some of yall were born to deep dive into this stuff. Its interesting

  • @elmeramuro
    @elmeramuro 6 месяцев назад +2

    My SG used to be named "Are you sure you want to leave this online lobby?" from a label quit lobby text. It was patched out, very sad

    • @ickyconcrete5370
      @ickyconcrete5370 3 месяца назад

      Yeah sad times, kept the name tag on it as a reminder.

  • @FredTheSpider
    @FredTheSpider 7 месяцев назад

    Not an edgy hacker or a skid, just a bored fella breaking stuff for fun

  • @realmackle
    @realmackle 2 года назад +8

    I'm best friends with someone that uses this script. Everyone is so utterly confused when they pick their guns up, it's really funny

    • @SeeOCD
      @SeeOCD 2 года назад +2

      Is he willing to share the script? :P

    • @TEA-mg5eb
      @TEA-mg5eb 2 года назад

      finna need that bru

  • @Almostbakerzero
    @Almostbakerzero 3 года назад +13

    id think this would enable cross-site scripting rather than sql injections. sql injections would require the name to be executed by steam servers which is unlikely if they properly sanitize their db. cross-site scripting means putting executable code somewhere where its executed by a client accessing the text. this might happen in the context of a person viewing your inventory in a web browser or viewing your gun in game or maybe in the "kill screen".

    • @dameck9570
      @dameck9570 3 года назад +1

      I was about to write that👍🏼

    • @blocksource4192
      @blocksource4192 2 года назад +1

      That's what i was thinking as well, rather than outdated exploits that don't even work on some web servers, I would rather think an XSS injection could be more common here, however theres possibilities that the UI most likely doesn't have the actual JS engine even enabled/loaded, which would make it impossible, and second to that, I doubt they would store steam cookies in the html for the UI.

  • @generalmisery
    @generalmisery 3 года назад +4

    remember trillux getting banned for finding the zeus bug and only after big drama they unbanned him. Valve does not give a shit about their players.

    • @de_trixa
      @de_trixa 3 года назад +1

      he got banned from faceit not valve lol you cant get banned for using glitched that are already in the game

  • @Velho2
    @Velho2 3 года назад +8

    1:48 "in finland we kill people for fun" :DDDDD

  • @P0KEBLOX
    @P0KEBLOX 3 года назад +67

    Sorry but this is driving me nuts and here is an explanation in laymans terms.
    The client communicates with the steam servers through something called an API (Application Programming Interface) which is the same thing the trading bots and this script uses.
    The API should have the same name restrictions as the client but some times A) the programmer forgets or B) At the time of making it they only expected the API to be public which means they didn't need to validate the name to make sure to weird characters are in it.
    You wouldn't really have to worry about SQL injection because most modern database API's only let you execute one command per line so SELECT `items` FROM inventory; would work but something like SELECT ``DELETE items from INVENTORY` items` FROM inventory wouldn't as multiple commands are being used. Another reason you wouldn't have to worry about it is the fact that the database API's also do something called escaping which just means it removes the extra ` that allows you to execute multiple commands.

    • @mihalis1010
      @mihalis1010 3 года назад +2

      You could just run a drop table instead. I'm sure they have backups of their backups, but Valve needs apparently needs to be pushed to do something about their game which is very clearly broken.

    • @tacokoneko
      @tacokoneko 2 года назад

      is it possible with DOTA 2 i want to try it

    • @benjulesprice
      @benjulesprice Год назад +1

      @@mihalis1010 The strings are obviously escaped. You really think their public API has oversight as crazy as this? Not saying it's impossible but definitely not that trivial.

  • @noeldev
    @noeldev 3 года назад +9

    So basically this is just a glitch you can do with the csgo API from my understanding, i doubt name tags could actually execute any commands through it unless valve messed up the code big time, which is possible just look up the crate depression lol

    • @durax-0xf
      @durax-0xf 3 года назад +2

      theres no csgo api afaik and you cant call nametag uses through web api

    • @benjulesprice
      @benjulesprice Год назад

      @@durax-0xf maybe not an API but per se but you can communicate with the server directly bypassing any sort of client side validation (in this case character restrictions).

  • @cholimba
    @cholimba 3 года назад +3

    i probably wouldnt report a free unboxing bug, atleast not for the time no one else knows about it. I wouldnt sell my items i unbox but just for the unboxing experience it would be hella fun i think

  • @michaelkaren5028
    @michaelkaren5028 3 года назад +21

    This is the kind of "hacker" I like

    • @yikes710
      @yikes710 Год назад

      bro is literally some kid that found a github link, hacker is a crazy term for him lmfao

  • @DaniRentz
    @DaniRentz 3 года назад +10

    I still waiting for the moment when Ohne is drinking when suddenly he is surprised and spits on the screen xddd

  • @Cssisabeautifulthang
    @Cssisabeautifulthang 3 года назад +2

    These lootbear adds are crazy

  • @Pokemoncafe-m7i
    @Pokemoncafe-m7i 5 месяцев назад

    Cheesmo is the calmest hacker I've ever seen

  • @qujc
    @qujc Год назад +2

    this aged well (cs2 name xxsl exploit)

  • @thatslegit
    @thatslegit 2 года назад

    guys a real chad, literally having the nuke codes to csgo and he chooses to mess with nametags only

    • @Dubulcle
      @Dubulcle 5 месяцев назад

      "Nuke codes" lol

  • @Reichstaubenminister
    @Reichstaubenminister 2 года назад +3

    If a CS:GO Nametag ever gets exploited through SQL Injection because someone forgot to escape a parameter, I will eat a broom. And PowerShell isn't just a new cmd.exe, it's an entire programming language that can interact with .NET Framework.

    • @Oliverii
      @Oliverii 2 года назад +1

      nah fam powershell is just a blue cmd.exe
      ik man insane

    • @Reichstaubenminister
      @Reichstaubenminister 2 года назад

      @@Oliverii No, it is not. Try to run a .ps1 script via cmd.exe.

    • @Oliverii
      @Oliverii 2 года назад +1

      @@Reichstaubenminister yeah i can
      It seems to me that you just have skill issue fam 💀

  • @alyxburke
    @alyxburke 3 года назад +40

    I worked out another way to do this after the stream. I really believe there’s huge potential in these name tag bugs

    • @shipy490
      @shipy490 3 года назад

      how did you do it?

    • @alyxburke
      @alyxburke 3 года назад

      @@shipy490 magic

    • @SrikarMaddula
      @SrikarMaddula 3 года назад +13

      I really hope that doesn't involve scripting. Or stuff that's borderline bannable. Although if the method turns out to be too easy, people might come with game breaking bugs that will cause Volvo to step in.

    • @alyxburke
      @alyxburke 3 года назад +4

      @@SrikarMaddula it’s definitely not difficult but it’s also not bannable because you’re not interacting with vac secured servers

    • @kememlemems723
      @kememlemems723 3 года назад +13

      @@SrikarMaddula Volvo owns valve comfirmed

  • @TruthJX
    @TruthJX 3 года назад +7

    Maybe it uses an HTTPS proxy that intercepts data going from you to Valve, for example when you rename an item. The outgoing data with the text you entered could be intercepted and changed and then sent out, possibly circumventing the in game / in app text restrictions.

    • @romanianfps
      @romanianfps 3 года назад +1

      Lmao no... you need mental help

    • @eclipse632
      @eclipse632 3 года назад

      @@romanianfps ????? are you mentally stable yourself? the suggestion this guy made could probably work, although it's much easier to just run some custom panorama js in-game to do it imo

    • @romanianfps
      @romanianfps 3 года назад

      @@eclipse632 Why the fuck would a custom text use a fucking http proxy dude? Its literally just special characters that haven't been blocked yet by valve 🤣🤣🤣

    • @eclipse632
      @eclipse632 3 года назад

      @@romanianfps the reason something like that is needed is because nametags do not allow you to use certain special characters (e.g paragraph separator) in nametags legitimately, personally I have no experience in doing something like that so never tried it as it wasn't first thing to come to my mind when I did it myself, but yes that would probably work, and something like that is necessary

    • @romanianfps
      @romanianfps 3 года назад

      @@eclipse632 actually you and the other guy I right I just fully looked into it

  • @lezlienewlands1337
    @lezlienewlands1337 Год назад

    IIRC the custom weapon that the guy spawned in was the "Deflector". Used by robots in MVM that could destroy pipes and rockets.

  • @Kisukalat
    @Kisukalat Год назад +3

    As someone in chat said he sounds like a rich kid who just bought the script

  • @Wanis23
    @Wanis23 3 года назад +2

    Anxiety bookmark Sadge. It feels like dying everynight.

  • @grrr-ou9oc
    @grrr-ou9oc Год назад

    a little bit of cyber security info
    an injection typically runs code on the server, this is where all the economy breaking bugs will be
    something scarier than that would be an ACE exploit, allowing code to be run on the computer of anyone who views the skin. one minute, you're checking out cool skins, the next minute your computer is being used to mine some form of crypto

  • @cx5_
    @cx5_ 3 года назад +54

    I love that so much, I can still remember when I clapped a nametag on my c4 and thought I was super unique haha
    "Explosive Toaster" will always have a special place in my heart xd

    • @hexx_2864
      @hexx_2864 Год назад +1

      how do you get c4 to your inventory?

    • @SuperGRIMED
      @SuperGRIMED Год назад

      Haha i still got the russian calculator on my c4 :)

    • @flaggboi
      @flaggboi Год назад +2

      9/11 never forget is mine

  • @jakakumar9449
    @jakakumar9449 3 года назад +42

    that is so interesting

  • @siorzen1473
    @siorzen1473 Год назад

    I found may be his old account? On steam, same glitches on profile, groups , but VAC banned

  • @k7y
    @k7y 3 года назад +4

    checks are made on client side, by talking to the API straight you can bypass the checks. Simple

    • @Aparino
      @Aparino 3 года назад

      Yes but how

    • @durax-0xf
      @durax-0xf 3 года назад +1

      theres no api for csgo and afaik you cant call a nametag use through the web api

  • @ExodiumTM
    @ExodiumTM 2 года назад +1

    4 seconds in and it's already obvious he's Finnish lol

  • @VeveSigma
    @VeveSigma 3 года назад

    the story with the colored name was a bug that allowed to use the name code for the vote command comfimation, it was up for a few year but go patched now you can't even use the original command anymore the text was this #SFUI_vote_failed

  • @Papi_John
    @Papi_John Год назад +1

    I wonder if these will still exist in CS2. (more than likely they will)

    • @Matsyir
      @Matsyir Год назад

      They do still work in CS2, but the UI is a bit smaller by default, so the vertical nametags aren't as tall unless you set UI scale to 110%. Also, when having multiple weapons with vertical nametags, in csgo the nametags of the upper weapons overlap onto weapons below them, but in CS2 the nametags seem to just get cutoff / stop being rendered where it hits the gun below it. (I only have two weapons with these nametags right now so I couldn't test that much, it probably cuts off even more if you have vertical knife+2 vertical weapons)
      Realistically though, if Valve ever wanted to fix this, they easily could without even messing with anyone's inventory. They just need to stop rendering the weird newline character (it's not a normal newline it's this character: 
), and they could also similarly enforce a client-side character limit to prevent the 21 character nametags. They could basically just re-enforce whatever limitations they want on nametags as they're loaded or rendered - remove any banned characters and limit the length. (I hope they don't but admittedly it is pretty ridiculous that this is possible lol, imagine if someone used these at a major, bit of a bad look for cs/valve)

  • @zakizdaman
    @zakizdaman Год назад

    "SQL injection" nice viewers
    It's arbitrary code execution

  • @romancewastaken
    @romancewastaken 2 года назад +1

    its really simple, i also have a nametag with super long unicode and it stretches the ui. you just use cheat engine

  • @yikes710
    @yikes710 Год назад +1

    bro is literally some kid that found a github link, hacker is a crazy term for him lmfao

  • @xxi7052
    @xxi7052 3 года назад +32

    Ladies and gentleman, in 2021 putting unicode symbols into csgo name tags is considered dirty hacking. Wow

    • @durax-0xf
      @durax-0xf 3 года назад

      the interesting part is with the LINE SEPARATORS which dont work with manual inputs

  • @TianyuQi
    @TianyuQi 3 года назад

    at least no one had made a csgo name tag inject rce out of this

  • @TheWizardsOfOz
    @TheWizardsOfOz 10 месяцев назад +1

    This guy could be finnish.

  • @01dom
    @01dom 3 года назад

    A simple prevention would be to allow only normal characters

    • @salsa221
      @salsa221 3 года назад

      yeah valve has to be pretty lazy to allow this

    • @cringer8107
      @cringer8107 3 года назад

      they actually removed many symbols i used in previous names which im very say about :(

    • @sarminder4357
      @sarminder4357 3 года назад

      @@salsa221 sounds like valve.

    • @salsa221
      @salsa221 3 года назад

      @@cringer8107 yeah you used to be able to change color and stuff

  • @Sakrosankt-Bierstube
    @Sakrosankt-Bierstube 11 месяцев назад

    0:40 i would argue that.. the UI is just exactly showing what the nametag is and grabs as much space as it needs to show it. Imo; it knows exactly what to do with the line-seperators, because they are showed exactly how a line-seperated is supposed to be shown.

    • @lahtin3n
      @lahtin3n 10 месяцев назад

      There is no arguing that this is poor UI design and if a QA team would have noticed this, it would never have made it to a release.

    • @Sakrosankt-Bierstube
      @Sakrosankt-Bierstube 10 месяцев назад

      @@lahtin3n You obviously don't understand anything about game development or how QA works. First of all; QA doesn't test every case there possibly could theoretically be. It is and was never intended to use special characters which result in a line-break. Period. There was no need to test for it because it's a obvious bug that this was possible and no QA tester ever wastes time on intentionally producing a bug to test if the UI is still good. It doesn't make sense, it's a waste of time, nobody does it. They test the intended usecase and possible allowed combinations and that's it. Requesting QA to test every possible theoretical situation would mean days of testing just for the nametag and creating a huge set of data to test them.
      Also UI designers say "hei, this is designed for a name without any line-breaks". That's it. They don't implement it, they don't test it, they have no other part but saying that line-breaks are not intended in the design. So no, UI designers are not connected to this "problem" at all.
      And despite all that they still implemented it in a way that it doesn't completly break if there are a few line-breaks. He obviously use a bug to completly escalate with them and it technically still didn't break. So... if you ever want to critize QA, Designer, Developers, whoever again.. use your brain to understand what you are criticizing and use proper arguments.

  • @Joshua-n4v
    @Joshua-n4v 5 месяцев назад

    I love to see people who use scripts to get things who arent jack asses

  • @DxrkXlnT
    @DxrkXlnT Год назад

    you heard it dont note it

  • @KryzysX
    @KryzysX 3 года назад +3

    So "بسم الله الرحمان الرحيم" has become a Big Exploit in CS GO? Ok.

  • @aqua-t1j
    @aqua-t1j Год назад

    Fun fact doing this didint get me VAC banned.

    • @aqua-t1j
      @aqua-t1j Год назад

      @@ThemasterPink it being open source has nothing to do if u get vac banned or not, a cheat can be open source and get me banned.

    • @ThemasterPink
      @ThemasterPink Год назад

      Responded to the wrong pers lol

    • @aqua-t1j
      @aqua-t1j Год назад

      @@ThemasterPink lmao

  • @wii1mii
    @wii1mii 3 года назад +1

    You ment RCE (Remote Code Execution) not SQL Injection. Sql is just a database...

  • @stephenyoung1484
    @stephenyoung1484 Год назад +2

    Need to ban the rat languages from the game.

  • @Tw122y52
    @Tw122y52 2 года назад +1

    Lol, it became so easy to do that every person could talk in discord with same inventory(

  • @thiennguyen9747
    @thiennguyen9747 3 года назад +2

    In Dota2 back in the day, they can dub "Key" which are used as a currency in Dota2,
    i think Valve banned China server or something because they exploited a lot of dubs.
    ITS cRAZY

  • @PodróżezAkwarystyką
    @PodróżezAkwarystyką Год назад

    I think on cs2 they will patch it, but there also will be some more bugs like this

  • @lyam276
    @lyam276 Год назад

    hacker no, haxor yes

  • @blocksource4192
    @blocksource4192 2 года назад +6

    Idk, as a programmer this dude looks like the textbook definition of a script kiddie. And I mean literally...

  • @waezsdrfxgchvjbknlm
    @waezsdrfxgchvjbknlm 2 года назад

    i wonder if with burpsuite you could just capture a packet to rename the weapon and just insert illegal unicode characters there

  • @Furby.1987
    @Furby.1987 10 месяцев назад

    also reported some stuff to different developers and the reaction from them can be rly different... had developers paying for findings and had some which were rly angry cuz of it... as example: I dont report to Bohemia anymore

    • @MoopLL
      @MoopLL 9 месяцев назад

      ???

  • @andrius4210
    @andrius4210 3 года назад +2

    what extensions is he using to see the float bar on every item?

  • @BradyRipz
    @BradyRipz 2 года назад

    I can expose an admin of TGP sharking me over $3500 in skins when I was new to trading

  • @wuwuwuwuwuwuwuwuwuwuwuwuwu4376
    @wuwuwuwuwuwuwuwuwuwuwuwuwu4376 Год назад +1

    copy pastes premade script = hacker

    • @Makgoh
      @Makgoh 5 месяцев назад

      Coding and hacking is mostly that

  • @illgetmyDad
    @illgetmyDad Год назад

    Rocket league gave players that found game breaking bugs a white hat car topper they’re worth a ton on money now only like 30 in existence

  • @Sgt.Guncat
    @Sgt.Guncat 2 года назад +1

    Back in the day a buddy of mine showed me an exploit that you could use any cosmetic combo so you could combine hats,coats etc. in tf2 if you modified a windows file profile picture wouldnt load anymore but that was the only downside. I deinstalled it after a couple days but it was a cool lottle exploit.

  • @WekyWekDuck
    @WekyWekDuck 2 года назад

    Valve customer support has been shit for the past few years

  • @Pooorple
    @Pooorple 2 года назад

    What are you using to display all that extra info on steam?

  • @mValerianW
    @mValerianW 2 года назад

    Imagine this guy will have burning gloves some day

  • @blazepine
    @blazepine 8 месяцев назад

    reminds me of the time i put a nametag on the bomb. i got a couple of questionis on how i did that, but it was so long ago now i don't even remember anymore.
    probably a tutorial on youtube though somewhere if you look it up

  • @finja8896
    @finja8896 3 года назад

    this was uploaded on my birthday :D

  • @RamsLiff
    @RamsLiff 3 года назад +8

    "you'll break ALL CS " LOL, he Just probably used something to exploit the chars unicode representation, this wont break the game at all.

    • @aslanxdd
      @aslanxdd 3 года назад +5

      Ohne doesn't really know how any of this works. He thinks this is all some kind of hacket shit haha

    • @RamsLiff
      @RamsLiff 3 года назад +1

      @@aslanxdd not even kidding, the char representation is one of the First things you learn at least in C programming, and people think this is sort of hack, you cant do nothing with It. Saw people saying you can manipulate memory with this, I dont know How you can do that, because for me It doesnt even make Sense at ALL. You can manipulate Memory If there's a array in scanf for example , but for this to happen in VALVE is rare, Very rare, probably wont happen at all, this is like beginner error

  • @arslors
    @arslors 3 года назад +4

    The most finnish accent I've ever heard

    • @YungClique
      @YungClique 3 года назад +5

      More sweden

    • @adak
      @adak 3 года назад +2

      The most finnish accent you'll ever hear is Hydraulic Press Channel's

    • @nukkonyan
      @nukkonyan 3 года назад

      sounds norwegian tbh, am swedish myself.

  • @grqfes
    @grqfes 2 года назад

    10 min of pure info

  • @pretinhobasico6539
    @pretinhobasico6539 3 года назад +2

    Cheesmo it's a legend to me. I changed my profile to look like his profile.

    • @szavask1
      @szavask1 3 года назад

      vc ta em todos os cortes possíveis cara

  • @CabbageGod
    @CabbageGod 3 года назад +26

    I don't think this guy knows what he's talking about. I believe he is what we call a "script kiddie." He's as much of a hacker as the people spinbotting in casual lobbies. He even said he got this from someone else's github. He seems to know nothing about injection or how client-server authority works. I do this kind of thing for a living, it's pretty easy to spot when someone doesn't really know what they are talking about or are bolding lying, IE when he was talking about his steam profile. I was able to recreate the bugs he used entirely inside the steam client, but in the original video he claimed he had to use some script to do it.

    • @omer7124
      @omer7124 3 года назад +9

      About the other video, just used code in his browser's console. He doesnt code it, just finds it. I don't see him bragging or claiming that he invented/coded these 'exploits' so I don't really get where you're coming from.
      As for the name tags that's very simple and I'm positive there are online guides for renaming stuff with weird characters. Again, he didn't claim he invented the exploit. No reason to criticize him.
      In my opinion his profile is a pretty cool showcase of these exploits. Seeing them all on one profile is nice and creative, I don't see a reason to complain.

    • @TiSnDd
      @TiSnDd 3 года назад

      Were you able to recreate the name tag thing?

    • @sosanuts7665
      @sosanuts7665 3 года назад

      @@TiSnDd fr im tryna do the same thing but i cant find nun abt it yet

    • @pixelthec
      @pixelthec 3 года назад +2

      You are right about the "script kiddie" thing. For renaming the items he uses someone else's script which he barely understands. On stream he also stated that he looked at the script's source codes but he doesn't know if it's safe because he doesn't really understand it.
      This glitch isn't rare because it's hard to do. It's rare because people who have the knowledge doesn't care about it. Anyone with a little bit of programming knowledge (especially py) can remake this one in half an hour max.

    • @jarnine9803
      @jarnine9803 3 года назад +1

      I dont think it harms game play like cheaters do, its more of a customisation if any thing, it dont really brake your game just moves your gun icon up higher ingame. Things like rocket jump scrips or edgy auto binds are worst but still aloud.

  • @timlarsson3634
    @timlarsson3634 3 года назад +2

    Dude i am trying to sleep😂😂

  • @ALLCAPS
    @ALLCAPS 4 месяца назад

    I could patch this in 4 minutes... not really special.

  • @scxnezz
    @scxnezz 2 года назад

    wait i was in a game with someone who had a name like this on his ak a couple days ago. The script must have leaked through the community or I actually met one of the few people who actually have it

  • @eddiebernays514
    @eddiebernays514 2 года назад

    steam is so popular and seems so goddamn vulnerable.

  • @lonkyz9572
    @lonkyz9572 3 года назад

    what is this extencion ohnepixel is using for steam inventory?

  • @P4GrAnGeR
    @P4GrAnGeR Год назад

    Wonder how these look on CS2

  • @satine6328
    @satine6328 2 года назад

    Take a look at "Secret CSGO nametag exploits" and u got ur answer. This is easy af to do.

  • @Zinox..
    @Zinox.. 3 года назад

    7:02 me and you baby we used to have fun

  • @1doctorjazz
    @1doctorjazz 3 года назад +1

    MY LEGENDARY "DROP *" HOWL IS STILL BEING TALKED ABOUT LETS GO :DDDDDDDDDD