The Orange
Member
(07-30-2012, 09:42 AM)
Ubisoft DRM features exploit that allows arbitrary code execution (update: patched) #1

Edit:

Seems to have been patched already, so update Uplay and it should be ok:

Originally Posted by iNvidious01: View Post
Original OP content below:

http://news.ycombinator.com/item?id=4311264

The important bit of that post:

Quote:
Ubisoft installs a backdoor that allows any website to take over your computer. The Sony BMG rootkit was also DRM and required product recall when it was discovered.
The original post for the hack:

http://seclists.org/fulldisclosure/2012/Jul/375


Fixes before people start going crazy:

Originally Posted by SparkTR:
You want to fix this? Disable the plug-in in your browser. Done. People talking about reformatting their PCs are making me facepalm.
Quote:
Google chrome users: You can go to "about:plugins" and disable this and all other things that might expose you to extra security risks such as "Microsoft Office" (even "Native Client") or any other plugins that exposed in there by 3rd party without any confirmation.
Last edited by The Orange; 07-30-2012 at 03:24 PM.
Yagharek
Member
(07-30-2012, 09:44 AM)

Yagharek's Avatar
#2

Megaton.

Wonder why it took so long to prove it was rootkit?
Corky
Nine out of ten orphans can't tell the difference.
(07-30-2012, 09:45 AM)

Corky's Avatar
#3

So if I once installed uplay on my pc I can't get rid of all it's traces?
flipswitch
Member
(07-30-2012, 09:45 AM)

flipswitch's Avatar
#4

There goes me buying Watchdogs on PC.
Ryoku
Member
(07-30-2012, 09:45 AM)

Ryoku's Avatar
#5

Fuck Ubisoft on their stance on PC games.
GrizzNKev
Member
(07-30-2012, 09:45 AM)

GrizzNKev's Avatar
#6

Damn. ACIII PC delayed for an extra year?
mclem
Member
(07-30-2012, 09:46 AM)
#7

Thought one: There was a Just Dance 3 on PC?

Thought two: Anno isn't listed. Omission, or is it actually exempt?
GoncaloCCastro
Member
(07-30-2012, 09:46 AM)

GoncaloCCastro's Avatar
#8

Well this is crap! I bought the Assassin's Creed Pack on steam's sale!
TyrantGuardian
Member
(07-30-2012, 09:47 AM)

TyrantGuardian's Avatar
#9

Lol, fuck Ubisoft. Bought Anno and Driver on the Steam sale. Guess I'm never installing either once I build my new PC.
blamite
Member
(07-30-2012, 09:47 AM)

blamite's Avatar
#10

I once installed and then uninstalled From Dust on Steam. Should I kill may laptop before it kills me?
JaseC
Member
(07-30-2012, 09:47 AM)

JaseC's Avatar
#11

Originally Posted by GrizzNKev: View Post
Damn. ACIII PC delayed for an extra year?
When it comes to Ubi and delaying PC releases, any excuse will do.
Sethos
Member
(07-30-2012, 09:47 AM)

Sethos's Avatar
#12

Looks like it's time to re-install Windows, thanks UbiShaft - Delay some more PC titles while your at it :)
SirIgbyCeaser
Yes, it's the surprising adventures of me, Sir Igby Chicken Caesar
(07-30-2012, 09:47 AM)

SirIgbyCeaser's Avatar
#13

Isn't this the first step in getting it banned from products? Good news???
endresults
Member
(07-30-2012, 09:47 AM)
#14

BOOM goes the dynamite. Ubi gets all that's coming their way this time.
trinest
(07-30-2012, 09:48 AM)

trinest's Avatar
#15

The only thing good from this is when it crumbles and Ubisoft patches out Uplay.
Game Guru
Member
(07-30-2012, 09:49 AM)

Game Guru's Avatar
#16

And this is why companies need to just use Steam's DRM if any. Seriously, Valve would've never had something like this.
EightBitNate
Banned
(07-30-2012, 09:49 AM)
#17

Wow, so that explains why Watchdogs looks so good. It's actual footage.
Cisce
Member
(07-30-2012, 09:50 AM)

Cisce's Avatar
#18

Now I'm glad that I actually missed out on Anno 2070's Steam sale. Otherwise, I'd be re-installing my PC right now.
HP_Wuvcraft
(07-30-2012, 09:50 AM)

HP_Wuvcraft's Avatar
#19

Done on purpose or not (which I highly doubt it was), this is an extremely stupid fail.
Maxwood
Member
(07-30-2012, 09:50 AM)

Maxwood's Avatar
#20

Ubicrap takes a whole new meaning.
reptilescorpio
Member
(07-30-2012, 09:50 AM)

reptilescorpio's Avatar
#21

Jeez and I wasn't far off installing Driver San Fran too! Also already have a copy of AC3 paid for on GMG. Hopefully they clear this up nice and fast to avoid the shit hitting the fan for them.
fabricated backlash
Member
(07-30-2012, 09:50 AM)

fabricated backlash's Avatar
#22

Why am I not surprised... this shit is depressing.
SparkTR
Member
(07-30-2012, 09:52 AM)

SparkTR's Avatar
#23

Uplay sucks, but the title is misleading.
Des0lar
will learn eventually
(07-30-2012, 09:52 AM)

Des0lar's Avatar
#24

FUCK I just bought from Dust during the Steam sale. I knew it was a fucking bad idea to buy a Ubi game....
Ryoku
Member
(07-30-2012, 09:52 AM)

Ryoku's Avatar
#25

Originally Posted by Game Guru: View Post
And this is why companies need to just use Steam's DRM if any. Seriously, Valve would've never had something like this.
No. No DRM at all would be lovely. Valve worship is something I don't get. Great company, but the worship is not needed.
GrizzNKev
Member
(07-30-2012, 09:53 AM)

GrizzNKev's Avatar
#26

Originally Posted by JaseC: View Post
When it comes to Ubi and delaying PC releases, any excuse will do.
All Ubi PC games delayed to 2015 while new, more restrictive DRM is invented.
Omikaru
Member
(07-30-2012, 09:53 AM)

Omikaru's Avatar
#27

Well fuck. Glad I never installed uPlay on my newest machine.

Almost did though. Was very close to buying the Assassin's Creed pack on Steam.
Enco
Member
(07-30-2012, 09:53 AM)

Enco's Avatar
#28

Originally Posted by TyrantGuardian: View Post
Lol, fuck Ubisoft. Bought Anno and Driver on the Steam sale. Guess I'm never installing either once I build my new PC.
Anno has a 3 activation limit. Why the fuck would you buy it?

Lol Ubi you piece of shit. No AC3 for me.
Iceblade
Member
(07-30-2012, 09:54 AM)

Iceblade's Avatar
#29

Can anyone explain what this means? Like, Ubisoft's DRM allows anyone to get into your PC? Or just Ubisoft itself?
-Cade
Member
(07-30-2012, 09:54 AM)

-Cade's Avatar
#30

So what's the easiest way to fix this? Bought SC:C last Steam sale and played it a few times.
EscoBlades
(07-30-2012, 09:55 AM)

EscoBlades's Avatar
#31

Aye caramba!!
Zevenberge
Junior Member
(07-30-2012, 09:55 AM)

Zevenberge's Avatar
#32

I don't really understand it. Basically installing a Ubisoft game enables random sites to hack your PC? If so, why on earth would a company do that?
SparkTR
Member
(07-30-2012, 09:56 AM)

SparkTR's Avatar
#33

Originally Posted by Iceblade: View Post
Can anyone explain what this means? Like, Ubisoft's DRM allows anyone to get into your PC? Or just Ubisoft itself?
People are exaggerating. Uplay just installs a web browser plug-in that has poor security standards. There's nothing to suggest it can be used to alter protected Windows processes or Ubisoft games. You want to fix this? Disable the plug-in in your browser. Done. People talking about reformatting their PCs are making me facepalm. This is more down to incompetence than malicious intent, and I don't expect competence from Ubisoft.
Last edited by SparkTR; 07-30-2012 at 09:59 AM.
Jintor
Lit himself on fire to get
a mod to tag him
(07-30-2012, 09:56 AM)

Jintor's Avatar
#34

Well fucking shit.
TemplaerDude
(07-30-2012, 09:57 AM)

TemplaerDude's Avatar
#35

This is not going to go over well.
GoofsterStud
Member
(07-30-2012, 09:57 AM)

GoofsterStud's Avatar
#36

I am glad that Uplay has been outed as the rootkit it is. I only hope they come up with a way to completely remove all traces for their loyal customers.
MNC
(07-30-2012, 09:58 AM)
#37

Well, fuck. There goes me playing any Ubisoft game on my PC.
Haunted
(07-30-2012, 09:58 AM)

Haunted's Avatar
#38

wow!

Ubi will be getting a shitton of backlash for that, if true. And it'll definitely have a visible negative impact on PC sales (and deservedly so) if they continue to do so.
Ryoku
Member
(07-30-2012, 09:58 AM)

Ryoku's Avatar
#39

Originally Posted by Zevenberge: View Post
I don't really understand it. Basically installing a Ubisoft game enables random sites to hack your PC? If so, why on earth would a company do that?
You can disable it through your web browser. People get pissed at terrible service from Ubisoft on the PC front, and this just adds to their reasons.
areal
Member
(07-30-2012, 09:58 AM)

areal's Avatar
#40

Originally Posted by EightBitNate: View Post
Wow, so that explains why Watchdogs looks so good. It's actual footage.
Connection is power...
Game Guru
Member
(07-30-2012, 09:58 AM)

Game Guru's Avatar
#41

Originally Posted by Ryoku: View Post
No. No DRM at all would be lovely. Valve worship is something I don't get. Great company, but the worship is not needed.
Well, I said if a company must use DRM... I would prefer it if Steam's games didn't have DRM either.
Last edited by Game Guru; 07-30-2012 at 10:01 AM.
Lemonte
Member
(07-30-2012, 09:59 AM)

Lemonte's Avatar
#42

Now I regret even more buying Driver San Francisco. Game doesn't even work properly.
Tomat
Member
(07-30-2012, 10:00 AM)

Tomat's Avatar
#43

More like Ufail am I right?

I'll be here all week, I've got nothing better to do.
Ryoku
Member
(07-30-2012, 10:00 AM)

Ryoku's Avatar
#44

Originally Posted by Game Guru: View Post
Well, I said if a company must use DRM... I would prefer it if Steam's games didn't have DRM either.
You do realize that you don't own the games that you pay money to buy on Steam, and that they can be taken from you at anytime, right?
Visualante2
Member
(07-30-2012, 10:01 AM)

Visualante2's Avatar
#45

Mother fuckers. No mention of this in the EULA at all?

Guessing this breaks some EU law and would require a recall if not, as with the Sony products.

e. I think you're over reacting when it comes to the 'rootkit' comparison. It's a browser plugin, surely you can just disable the browser plugin? Or is there some deep seeded authorisation given to the plugin on your computer's hardware?
Last edited by Visualante2; 07-30-2012 at 10:06 AM.
-Cade
Member
(07-30-2012, 10:03 AM)

-Cade's Avatar
#46

Originally Posted by SparkTR: View Post
People are exaggerating. Uplay just installs a web browser plug-in that has poor security standards. There's nothing to suggest it can be used to alter protected Windows processes or Ubisoft games. You want to fix this? Disable the plug-in in your browser. Done. People talking about reformatting their PCs are making me facepalm. This is more down to incompetence than malicious intent, and I don't expect competence from Ubisoft.
You're a gentlemen and a scholar, thanks.
TheD
Member
(07-30-2012, 10:04 AM)
#47

Uhh, I don't see how this is a rootkit.

This just looks like a normal exploitable software flaw.
Frankie Williamson
Junior Member
(07-30-2012, 10:05 AM)

Frankie Williamson's Avatar
#48

Ubisoft is just such a dreadful company. Thankfully, I have not installed any of the games listed.
Iceblade
Member
(07-30-2012, 10:05 AM)

Iceblade's Avatar
#49

Originally Posted by SparkTR: View Post
People are exaggerating. Uplay just installs a web browser plug-in that has poor security standards. There's nothing to suggest it can be used to alter protected Windows processes or Ubisoft games. You want to fix this? Disable the plug-in in your browser. Done. People talking about reformatting their PCs are making me facepalm. This is more down to incompetence than malicious intent, and I don't expect competence from Ubisoft.
Thanks, nice to see some level-headedness amongst all of the silly quickfire reactions in here.
Dingotech
Member
(07-30-2012, 10:06 AM)

Dingotech's Avatar
#50

Originally Posted by SparkTR: View Post
People are exaggerating. Uplay just installs a web browser plug-in that has poor security standards. There's nothing to suggest it can be used to alter protected Windows processes or Ubisoft games. You want to fix this? Disable the plug-in in your browser. Done. People talking about reformatting their PCs are making me facepalm. This is more down to incompetence than malicious intent, and I don't expect competence from Ubisoft.
Thanks just diabled the addins.

Will UPlay still run with the addins disabled? I'd like to play more Driver at some point...