Steam inventory helper extension for Yandex browser. Vulnerability in the Steam Inventory Helper extension and how to exploit it

The Steam service seems to be one of the most popular trading platforms dedicated to various types of gaming applications and other types of content. One of the key features of this service seems to be the presence of profiles with built-in capabilities for performing various manipulations with other users, such as selling, buying, exchanging, and so on.

Steam Inventory

Since this service requires the ability to perform certain actions, there are a number of methods to simplify them. First of all, this is a special extension for steam inventory helper, which allows you to make exchanges, purchases and sales much faster and more conveniently than usual.

This extension is available for download in the built-in Google application store, which allows you not to waste time searching for it. Among the functionality of the application, it should be noted:

  • Accelerating the sale and purchase of items due to the absence of the need to confirm actions;
  • Simplified acquisition of various sets in cases where the user already owns one of its parts;
  • Automation of calculating the cost of exchange items, allowing you to evaluate the benefits of a transaction before it is completed;
  • A huge number of other functions related, first of all, to the interface and things worn by the hero.

Due to such features, such an extension seems to be an ideal tool for using the Steam service.

Installing the extension

Before the user can appreciate all the benefits that this kind of add-on brings, it will need to be downloaded and installed. In the case of the Yandex browser, you will need to go not to , but to the analogue for the Google Chrome browser. Since both of these programs are created on the same software base, we can talk about good compatibility of applications for them.

After the desired add-on is found, you must click the install button, and then confirm your intention in the dialog box. After a short download and installation process, you will need to enable the installed add-on in the appropriate menu. To do this, you will need to open the settings (the icon with three horizontal stripes), and then select the add-ons tab.

There, having selected the desired item, you must click Enable, which will allow you to use all the functions of the extension.

Video to help


For quite a long time, since 2015 I have been aware of a certain vulnerability that can be interestingly exploited. But I thought that it would quickly become popular and be fixed, but it didn’t turn out that way. All vulnerability is related to things Dota 2, or rather with their signatures. As you know, when you give an item in Dota 2, you can sign it. And the thing is that if the person who opens your Steam inventory has the extension installed Steam Inventory Helper, then the html code in the signature will start playing.

In the first picture there is no extension, in the second it is installed:

The only thing I managed to get out of this vulnerability was playing music and sounds; other scripts did not work. (most likely this is due to the extension policy, which does not allow the use of many other functions)

So, how to reproduce all this yourself:
1) Upload the file with music to any hosting. (but keep in mind that the directory should be shorter, because the signature has a limitation)
2) Next, insert your link into the desired place in this code:

3) Send any item to someone using the “Wrap as a gift” function.

Did you help? Rate it, add it to your favorites, support me :)

Introduction

1) Steam Inventory Helper

Top 1 of all extensions. For those who are involved in trading, purchasing games and everything related to exchange. Works with all items in your inventory.

You can download it from the official Google website by writing in the search "steam inventory helper"
If you use other browsers, download from their stores.

Functional:

2) Enhanced Steam

And this extension is useful for almost every Steam user. It harmoniously complements Steam with a lot of new functionality.

You can download it from the official website:

Functional:

  • The extension can highlight and also put tags in the store on products that you already have, that are on your wish list, for which you have a coupon, that are in your inventory, and for which you have a guest pass. All colors are customizable. Works both in search and in a regular list.
  • Synchronization with third-party sites. Enhanced Steam can collect information from some good sites and display it directly on the product page. For example, this way you can quickly find out the game’s rating on Metacritic or Opencritic. And right on the page there will be links to various useful resources like SteamDB, Steam Card Exchange or PCGaming Wiki. It also displays approximate statistics of purchased copies, the number of players, players for 2 weeks and the average duration of the game.
  • Game performance evaluation. A new section will appear on the game page, which will show the results of a user survey on the performance of this game. While the survey can be completed by anyone who has purchased the game, the results generally provide a rough picture of performance. They are also able to identify certain problems, for example, lack of support for modern resolution.
  • Quick sale and transformation into gems. This extension, like the previous one, has built-in functionality for quickly selling items directly from your inventory. Although for this it is better to use the previous extension. This feature can be disabled in the settings. But turning an item into gems is not available in other expansions.
  • Enhanced Steam adds a number of useful links to popular resources such as SteamRep, SteamDB, BackpackTF and others to user profiles. Links are customizable and have multiple icon styles. The function also adds a permanent link to the profile.
  • Custom themes and profile backgrounds. The extension has the ability to select multiple themes and any wallpaper available on Steam, which will be displayed to you and everyone who uses Enhanced Steam. Unfortunately, users without this extension will not notice the changes.
  • Third party DRM warnings. Plates will appear on the store pages notifying whether this game requires any third-party program to run (for example, Rockstar SocialClub, Ubisoft Uplay, GFWL, Denuvo and others)
  • A bunch of other little things: "Early Access" tiles in the list of games, displaying the amount of all spent funds on the account page, displaying the amount of all transactions on the Trade Promotion, cleaning the site itself from various, useless elements (trademark symbols in product names, the "install" button Steam", "About Steam", etc.), warnings about region mismatch, automatic age verification if necessary, HTML5 player instead of outdated Flash, a button to check system requirements, the date of purchase of the application on the game page, information about product prices in different regions, and many, many other functionalities.
  • The extension is notable for the fact that it has been in development for a very, very long time and is constantly receiving updates. Almost any function can be enabled/disabled at will. I recommend it to every Steam user!

WinAuth— advanced Steam Guard client for PC. There is support for Battle.net, Google Authenticator, etc.
Website | Github

Idle Master— automatic farming of cards for beginners.
Github | Steam

ArchiSteamFarm (ASF)— automatic farming of cards for advanced players.
Github | Steam

GiftSeeker— automatic participation in game drawings on steamgifts.com and other similar sites.
| FAQ

Browser plugins

Enhanced Steam— the largest extension with many useful features. Improved navigation, price comparisons by region and date, and much more. The Chrome version has better functionality.
Website | Github | Steam | | Firefox | Opera

Steam Inventory Helper— automation of work with inventory and trading platform. Possibility to mass sell cards, etc.

AutoJoin for SteamGifts— automatic entry into distributions on steamgifts.com.
| Firefox

Scripts for Tampermonkey and Greasemonkey

Tampermonkey— browser extension, necessary for the scripts listed below to work.
Website | | Firefox

Steam Web Tools— convenient work with equipment, basket, etc. Partially duplicates the functionality of Enhanced Steam. Among the distinctive features are adding items to the cart in a list with one click, sending several Gifts from the inventory at a time, and grouping identical items in the inventory.
Website | Github

Automatically view the list of recommendations- useful for sales, during which they give cards for viewing a list of recommendations.
Reddit

Sites and links

help.steampowered.com - official Steam support
store.steampowered.com - weekly discounts
steamstat.us - server status
steamdb.info - the largest database of games and users

Answers to frequently asked questions

Q: Won't Steam ban me for all these programs?
A: No, all these programs are safe and do not violate Steam rules. Only ASF with a large number of accounts (>100) is potentially dangerous; read the documentation before using it.

Q: When using these programs, will my account and inventory items be stolen?
Oh no. At the time of writing this material, all programs in it have been tested and are safe. In theory, it is possible that the author of any of these programs could release a malicious update, but this option is extremely unlikely. We recommend using Steam Guard if you are afraid or have little understanding of account security.

Q: What are the links to GitHub and how to download from it?
A: GitHub - application hosting, etc. In our case, it contains links for open source programs. If you don’t understand anything about this, then download ready-made assemblies from the “Releases” section.


If you actively use the Steam Marketplace, you will probably need the Steam Inventory Helper utility, which will significantly simplify the process of putting items up for sale and allow you to monitor in detail the pricing policy of items.

Benefits of Steam Inventory Helper

  • When exchanging items with other users, you will see the average cost of an item on the Marketplace. In this way, you can exchange items most profitably and make a profit;
  • The ability to quickly sell a large number of items from inventory without the need to confirm actions through an authenticator;
  • Ability to monitor prices of items in third-party stores;
  • The ability to instantly purchase an item - without confirmation or additional actions;
  • You can find out about sold items directly in your browser thanks to the corresponding alerts.

In addition to Google Chrome, the Steam Inventory Helper extension is also available for Yandex Browser. Installation follows the same analogy - follow the link, click “Install”, after which the extension will be installed.

If you have already installed Steam Inventory Helper for Google Chrome before, then for Yandex Browser you do not need to install or download anything additional - as soon as you open the window, the extension icon will be available to you in the upper right corner of the browser.

If you don't understand the benefits of this extension, here are some interesting facts:

    • Your purchases and sales on the Steam Marketplace will be carried out many times faster;
    • To further speed up the sales process, you don't have to adjust the price yourself, confirm actions through an authenticator, or do any other unnecessary work. Just click on the Sell button and the extension will put your item up for sale at a price a few cents cheaper so that the transaction takes place as soon as possible;
    • Now you don't have to sell items individually. You can put a whole set of your things on the Marketplace by pressing just one button;
    • You can monitor the prices of items in different currencies thanks to the region change function. You won’t be able to buy a game for another currency, but you can find out its cost;
    • When making an exchange with a friend, you will see how much money he offers you the goods for and, comparing this with his offer, you will always know whether this or that transaction is profitable;

  • Now you don't have to always log into Steam or check your email to see what you managed to sell. Alerts about the completed transaction will come to you directly in your browser window;
  • Thanks to additional interface elements, you can select items in the inventory, change the region in the internal settings and make changes to the usability of the extension.

No bans, blocking or other troubles. The extension is fully compatible with the digital store and is not a cheat program or hack.

If you want to remove the extension, just right-click on the Steam icon in the browser window, and then select “Remove from browser”.

Steam Inventory Helper adds additional elements to the interface only if you work with Steam through a browser. That is, nothing will change in your client.

All liked it? Tell your friends!



error: Content is protected!!