Ubisoft "Uplay" DRM exposed as rootkit; dozens of
Page 1 of 3 Goto page 1, 2, 3  Next
tainted4ever
VIP Member



Posts: 11336

PostPosted: Mon, 30th Jul 2012 12:21    Post subject: Ubisoft "Uplay" DRM exposed as rootkit; dozens of
Ubisoft "Uplay" DRM exposed as rootkit; dozens of popular games hacked

http://news.ycombinator.com/item?id=4311264
http://seclists.org/fulldisclosure/2012/Jul/375

So if you have an original Ubisoft game installed, uninstall it...
Back to top
Kurosaki




Posts: 5673
Location: germany
PostPosted: Mon, 30th Jul 2012 12:35    Post subject:
lol, seriously? Very Happy.... gratz ubishit! Very Happy
Back to top
Saner




Posts: 6877
Location: Uk
PostPosted: Mon, 30th Jul 2012 12:37    Post subject:
I bought Driver during the Steam sale, I played it for all of 0 minutes because uPlay wouldnt let me.

So I uninstalled it there and then Very Happy

guess I wont be reinstalling it anytime soon, piece of shit.


ragnarus wrote:

I saw things like that in here and in other "woman problems" topics so...... Am I the only one that thinks some authorities needs to be alerted about Saner and him possibly being a rapist and/or kidnapper ?Smile

Saner is not being serious. Unless its the subject of Santa!
Back to top
polosistealth




Posts: 3447

PostPosted: Mon, 30th Jul 2012 12:37    Post subject:
link didn't work for me lol
this is bullcrap


Intel i7 14700K | Gainward RTX4090 Phantom GS 24GB | 32GB DDR5 Corsair Vengeance RGB 6000mhz | SSD nvme Samsung 970EVO 500GB | SSD 2TB Sandisk Ultra 3D | SSD 2TB NVME Crucial P5 Plus |
Creative Sound BlasterX G6 | Fractal Meshify 2 XL | Logitech G703 | Corsair RM850x White | HyperX Cloud | DELL S2721DGF 27" 165hz Gsync + Sony 55XH9077 4K @ 120hz + VRR
Back to top
garus
VIP Member



Posts: 34200

PostPosted: Mon, 30th Jul 2012 12:38    Post subject:
snip


Last edited by garus on Tue, 27th Aug 2024 21:44; edited 1 time in total
Back to top
JBeckman
VIP Member



Posts: 34984
Location: Sweden
PostPosted: Mon, 30th Jul 2012 12:42    Post subject:
I guess it's similar to the browser interaction that Steam, Origin and LIVE also use but here it's not secured enough and can be exploited should such be desired, interesting info regardless, will be fun to see how Ubisoft reacts.
Back to top
4treyu




Posts: 23131

PostPosted: Mon, 30th Jul 2012 12:44    Post subject:
Well, I'm even gladder now that I never bought any of those games (not even the Prince of Persia pack with that awesome discount during the steam sale), and never will buy one.
Back to top
frogster




Posts: 2860

PostPosted: Mon, 30th Jul 2012 12:51    Post subject:
what exactly that means for me ?
what this exploit do ?
i have might and magic and anno, but is on my home computer. is shutdown since 1 week ago Smile.
Back to top
dezztroy




Posts: 6590
Location: Sweden
PostPosted: Mon, 30th Jul 2012 12:52    Post subject:
polosistealth wrote:
link didn't work for me lol
this is bullcrap


Worked for me, definitely not bullshit.

Ubisoft better get a lot of shit for this.

frogster wrote:
what exactly that means for me ?
what this exploit do ?
i have might and magic and anno, but is on my home computer. is shutdown since 1 week ago Smile.


It lets any website open any application you have on your computer, and then giving those applications input without asking you. Basically.
Back to top
frogster




Posts: 2860

PostPosted: Mon, 30th Jul 2012 12:56    Post subject:
ah, thats all ?
uplay plugin in my chrome is disabled since install Razz
so i'm fine.

l.e.
reminder to check ie and firefox. i'm not using them, but just in case Smile.
Back to top
inz




Posts: 11914

PostPosted: Mon, 30th Jul 2012 13:00    Post subject:
frogster wrote:
ah, thats all ?


Yeah, no worries! Laughing
Back to top
no9999




Posts: 3437
Location: Behind you...
PostPosted: Mon, 30th Jul 2012 13:02    Post subject:
Contact every gaming related website you know and tip them.....lets make UbiCrap pay for their ********* drm.

Back to top
frogster




Posts: 2860

PostPosted: Mon, 30th Jul 2012 13:16    Post subject:
inz wrote:
frogster wrote:
ah, thats all ?


Yeah, no worries! Laughing


well, i'm a bit more advanced than the regular user.
i mean no worries for me Smile. like i said disabled that crap plugin since i installed uplay.

not like probably the rest of 90% uplay users.
it is a serious hole, and i presume they can easly patch it.

but on the other hand, one week ago i could not play h6 in weekend because of user/pass problem. and they solved 3 days later.

in ie 9 you need check active.x filtering (tools menu). ( i dint find any uplay plugin, but i dont use ie at all, someone knows where it should apear ? nothing on tools/manage addons.)

in chrome : about:plugins uncheck : Uplay PC - Version: 1.0.0.0 (Disabled) Uplay PC Plugin

in firefox : tools -> addons -> plugins : there are 2 uplay plugins, disable both.
Back to top
blackdochia




Posts: 4377
Location: 9th Circle of Hell
PostPosted: Mon, 30th Jul 2012 13:19    Post subject:
Back to top
no9999




Posts: 3437
Location: Behind you...
PostPosted: Mon, 30th Jul 2012 13:20    Post subject:
blackdochia wrote:
http://www.strategyinformer.com/news/19179/ubisofts-uplay-blasted-as-rootkit-installs-unsecure-browser-plug-in

http://www.eurogamer.net/articles/digitalfoundry-uplay-has-serious-security-vulnerability

http://www.rockpapershotgun.com/2012/07/30/psa-possible-security-risk-in-some-ubisoft-pc-games/

Story already on!!!!

Disaster PR incoming!


Im feeling all warm and fuzzy inside
Back to top
blackdochia




Posts: 4377
Location: 9th Circle of Hell
PostPosted: Mon, 30th Jul 2012 13:22    Post subject:
I'm really curious what their PR will say about this... Gonna be fun!
Back to top
Interinactive
VIP Member



Posts: 29452

PostPosted: Mon, 30th Jul 2012 13:23    Post subject:
⁢⁢


Last edited by Interinactive on Tue, 5th Oct 2021 04:04; edited 1 time in total
Back to top
Saner




Posts: 6877
Location: Uk
PostPosted: Mon, 30th Jul 2012 13:23    Post subject:
They will add a feature to stop any code being executed without paying them royalty rights first.

Any executed code will also require a constant internet connection


ragnarus wrote:

I saw things like that in here and in other "woman problems" topics so...... Am I the only one that thinks some authorities needs to be alerted about Saner and him possibly being a rapist and/or kidnapper ?Smile

Saner is not being serious. Unless its the subject of Santa!
Back to top
blackdochia




Posts: 4377
Location: 9th Circle of Hell
PostPosted: Mon, 30th Jul 2012 13:24    Post subject:
Nfohumpers! Have more corporate ideas than any CEO out there!
Back to top
sabin1981
Mostly Cursed



Posts: 87805

PostPosted: Mon, 30th Jul 2012 13:27    Post subject:
Jesus fucking Christ... just when you think Ubisoft can't sink any lower. With all the destructive practices that pathetic company engages in constantly, you'd think SOMEONE would have stepped in and said "Enough is enough."

Back to top
blackdochia




Posts: 4377
Location: 9th Circle of Hell
PostPosted: Mon, 30th Jul 2012 13:31    Post subject:
sabin1981 wrote:
Jesus fucking Christ... just when you think Ubisoft can't sink any lower. With all the destructive practices that pathetic company engages in constantly, you'd think SOMEONE would have stepped in and said "Enough is enough."



No!No!No!

You've got it all wrong! It's called innovative thinking: screw up your customer in any way you can!
Back to top
no9999




Posts: 3437
Location: Behind you...
PostPosted: Mon, 30th Jul 2012 13:32    Post subject:
Time to place your bets !!



Awesome
Back to top
blackdochia




Posts: 4377
Location: 9th Circle of Hell
PostPosted: Mon, 30th Jul 2012 13:34    Post subject:
Black Thursday for Ubi?!

We can only hope!
Back to top
Neon
VIP Member



Posts: 18935
Location: Poland
PostPosted: Mon, 30th Jul 2012 13:45    Post subject:
Interinactive wrote:
LOL
Back to top
pillermann




Posts: 2577

PostPosted: Mon, 30th Jul 2012 14:11    Post subject: Re: Ubisoft "Uplay" DRM exposed as rootkit; dozens
tainted4ever wrote:
original Ubisoft game


Reaction
Back to top
H4wkeye




Posts: 4699
Location: CTU
PostPosted: Mon, 30th Jul 2012 14:51    Post subject:
I just tried that test link. It opened Uplay and calculator without me ever touching the PC. Fuck you Ubisoft, everyone should just gather up and file a lawsuit against you pieces of shit.
Back to top
russ80




Posts: 4679
Location: Romania
PostPosted: Mon, 30th Jul 2012 14:53    Post subject:
Time to burn Ubishit...

Cool Face


Main PC : I7 12700, MSI Ventus RTX 4090 24gb, Alienware AW3423DW QD-OLED
Laptop : I5 4200H @ 3400mhz boost, GTX 850m 2gb Vram DDR3, 4gb RAM DDR3
Derpsole : Playstation 5 disc edition, Ninty Switcherino
TV+audio: LG CX 65" / Sonos ARC + SL ones + Sonos sub 3
VR Headset: Meta quest 2 airlinked
Back to top
sabin1981
Mostly Cursed



Posts: 87805

PostPosted: Mon, 30th Jul 2012 14:53    Post subject:
H4wkeye wrote:
I just tried that test link. It opened Uplay and calculator without me ever touching the PC. Fuck you Ubisoft, everyone should just gather up and file a lawsuit against you pieces of shit.


The worst thing is.. that calculator bit? That was added by someone else as an example of how powerful and dangerous this backdoor is. The plugin allows the remote user to execute programs via html.

Fucking Ubisoft.
Back to top
chiv




Posts: 27530
Location: Behind You...
PostPosted: Mon, 30th Jul 2012 14:57    Post subject:
opened the link.. blocked by antivirus. meh.


ubisoft makes me sad, because i like their games... just such a pity they seem to hate their customers with a fucking passion.


Back to top
H4wkeye




Posts: 4699
Location: CTU
PostPosted: Mon, 30th Jul 2012 14:58    Post subject:
sabin1981 wrote:
H4wkeye wrote:
I just tried that test link. It opened Uplay and calculator without me ever touching the PC. Fuck you Ubisoft, everyone should just gather up and file a lawsuit against you pieces of shit.


The worst thing is.. that calculator bit? That was added by someone else as an example of how powerful and dangerous this backdoor is. The plugin allows the remote user to execute programs via html.

Fucking Ubisoft.


Jesus, how the FUCK does a company as big as Ubisoft, make such a massive fuck up!? Amateurs would not make such a mistake. It just shows the level of interest they have in making games and software for it. I really hope this fucking destroys them and their shares.
Back to top
Page 1 of 3 All times are GMT + 1 Hour
NFOHump.com Forum Index - PC Games Arena Goto page 1, 2, 3  Next
Signature/Avatar nuking: none (can be changed in your profile)  


Display posts from previous:   

Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB 2.0.8 © 2001, 2002 phpBB Group