I still think it was likely some sort of VB exploit they used as valve is running a very old version. Perhaps this is also a good example of the benefits of services like cloudflare whos premium service can catch and stop sql injections. However, there is always a way in so it is not as though this could have been totally avoided. I am just glad to see Valve give it to us strait verses the bs that Sony pulled.