Ubisoft Uplay browser plugin security concerns

Ubisoft Uplay browser plugin security concerns

Unread postby Makena » 30 Jul 12, 8:06 pm

http://www.rockpapershotgun.com/2012/07 ... -pc-games/

http://www.vg247.com/2012/07/30/ubisoft ... -pc-files/

I imagine this is just a bit of a (Large) screw up, but it's pretty easy to disable the plugin (chrome://plugins/ in Chrome, Tools, addons, plugins in Firefox.).

Just a heads up for anyone playing Ubisoft games, which might be a few people due to the recent Steam sales.

Here is the full list of potential ‘at-risk’ titles:

    Assassin’s Creed II
    Assassin’s Creed: Brotherhood
    Assassin’s Creed: Project Legacy
    Assassin’s Creed Revelations
    Assassin’s Creed III
    Beowulf: The Game
    Brothers in Arms: Furious 4
    Call of Juarez: The Cartel
    Driver: San Francisco
    Heroes of Might and Magic VI
    Just Dance 3
    Prince of Persia: The Forgotten Sands
    Pure Football
    R.U.S.E.
    Shaun White Skateboarding
    Silent Hunter 5: Battle of the Atlantic
    The Settlers 7: Paths to a Kingdom
    Tom Clancy’s H.A.W.X. 2
    Tom Clancy’s Ghost Recon: Future Soldier
    Tom Clancy’s Splinter Cell: Conviction
    Your Shape: Fitness Evolved


EDIT: More intelligent thread title.
Last edited by Makena on 30 Jul 12, 9:28 pm, edited 2 times in total.
ImageImage
Makena

User avatar
Has 1 million gon bucks
 
Online
Posts: 1552
Joined: 22 May 04, 4:00 pm
Location: Melbourne

Re: Ubisoft dun goofed. (Maybe)

Unread postby Mythor » 30 Jul 12, 8:09 pm

Went ahead and disabled the plugins in Firefox, just in case. I think describing it as a rootkit is unfair, since it seems like it wasn't intentional.

But wow. As if we needed even more reason to dislike their UPlay system. :(
"Wasabi is a sometimes food." - Elmo
Image
Mythor

User avatar
TF2 Admin
 
Offline
Posts: 7166
Joined: 10 Jun 04, 5:45 pm
Location: San Francisco

Re: Ubisoft dun goofed. (Maybe)

Unread postby Matty » 30 Jul 12, 8:19 pm

Well, time to get rid of the ubisoft DRM on my games.
Matty

User avatar
Never goes to sleep
 
Offline
Posts: 4104
Joined: 26 Aug 10, 12:23 pm
Location: Adelaide

Re: Ubisoft dun goofed. (Maybe)

Unread postby Makena » 30 Jul 12, 9:11 pm

Updates on the story via RPS, the key bit is you can just disable the plugins, and:

Contrary to what some parts of the web are currently screaming, this is not a rookit – it’s an exploit in a browser extension.
ImageImage
Makena

User avatar
Has 1 million gon bucks
 
Online
Posts: 1552
Joined: 22 May 04, 4:00 pm
Location: Melbourne

Re: Ubisoft dun goofed. (Maybe)

Unread postby MunchY » 30 Jul 12, 9:25 pm

I have uPlay for HOMM. But I can't see any plugins in my Firefox for it? Should I be freaking out or continue to not really care?
Image
MunchY

Rozmosis
 
Offline
Posts: 738
Joined: 8 Nov 06, 3:30 pm

Re: Ubisoft dun goofed. (Maybe)

Unread postby Makena » 30 Jul 12, 9:27 pm

MunchY wrote:I have uPlay for HOMM. But I can't see any plugins in my Firefox for it? Should I be freaking out or continue to not really care?


If under Tools -> addons -> plugins, you have neither Uplay PC or the Uplay PC Hub plugins, then continue to not care.

If you have them, disable them, and go back to not caring :)
ImageImage
Makena

User avatar
Has 1 million gon bucks
 
Online
Posts: 1552
Joined: 22 May 04, 4:00 pm
Location: Melbourne

Re: Ubisoft dun goofed. (Maybe)

Unread postby MunchY » 30 Jul 12, 9:29 pm

Makena wrote:
MunchY wrote:I have uPlay for HOMM. But I can't see any plugins in my Firefox for it? Should I be freaking out or continue to not really care?


If under Tools -> addons -> plugins, you have neither Uplay PC or the Uplay PC Hub plugins, then continue to not care.

If you have them, disable them, and go back to not caring :)

Yeah not there at all! Thanks a lot anyway Makena!
Image
MunchY

Rozmosis
 
Offline
Posts: 738
Joined: 8 Nov 06, 3:30 pm

Re: Ubisoft Uplay browser plugin security concerns

Unread postby PalZer0 » 31 Jul 12, 12:21 am

Wow. Just when I think Ubisoft can't be any more stupid, they pull this out of their arse.
DRM is like kids. The less you have, the better.

#ati on GameSurge - unofficial ATi support channel
Twitter | Facebook | Steam | Xfire | Raptr
PalZer0

User avatar
Offline? What's 'offline'?
 
Offline
Posts: 3281
Joined: 29 Mar 07, 5:22 pm

Re: Ubisoft Uplay browser plugin security concerns

Unread postby Makena » 31 Jul 12, 12:36 am

Via RPS:

Update – Ubisoft may have plugged the hole, but it’s difficult to know for sure as they don’t appear to be discussing the issue. There are reports on the Ubi forums (thanks, Imperial Dane) that Uplay has been updated to version 2.04, which if the commenter is accurate bears the note “‘Fix addressing browser plugin. Plugin now only able to open uPlay application.” If your Uplay hasn’t/won’t update to version 2.04, I’d get rid of it and its plugin for now. To be honest I’d get rid of the plugin regardless, until we’re sure the problem’s been resolved.
ImageImage
Makena

User avatar
Has 1 million gon bucks
 
Online
Posts: 1552
Joined: 22 May 04, 4:00 pm
Location: Melbourne

Re: Ubisoft Uplay browser plugin security concerns

Unread postby Kinky__ » 31 Jul 12, 8:59 pm

The first comment in the second link sums up my thoughts pretty well.

“potential” “theoretically” “could” “could” “theoretically” “potential” “could”

Hm
Kinky__

User avatar
TF2 Admin
 
Offline
Posts: 47
Joined: 21 May 12, 2:02 pm
Location: Perth, WA.

Re: Ubisoft Uplay browser plugin security concerns

Unread postby Makena » 31 Jul 12, 9:02 pm

Kinky__ wrote:The first comment in the second link sums up my thoughts pretty well.

“potential” “theoretically” “could” “could” “theoretically” “potential” “could”

Hm


At the time that article was written, it wasn't confirmed, they can't outright say "This is happening", when it may not have been actually true.

Anyway, Uplay should auto update itself next time you run it, meant to fix this exploit. But no harm in leaving them disabled if you don't care about the website/social stuff Ubisoft have with Uplay.
ImageImage
Makena

User avatar
Has 1 million gon bucks
 
Online
Posts: 1552
Joined: 22 May 04, 4:00 pm
Location: Melbourne

Re: Ubisoft Uplay browser plugin security concerns

Unread postby PirateEggs » 1 Aug 12, 1:30 am

Shouldn't Anno 2070 be in that list? It uses UPlay too.

They used this to make their plugin, their actual site seems to be down at this present time. I wonder why? :|
Image
PirateEggs

User avatar
Jedi Upstart
 
Offline
Posts: 616
Joined: 21 May 10, 8:14 am
Location: Adelaide

Re: Ubisoft Uplay browser plugin security concerns

Unread postby Makena » 1 Aug 12, 8:46 am

PirateEggs wrote:Shouldn't Anno 2070 be in that list? It uses UPlay too.

They used this to make their plugin, their actual site seems to be down at this present time. I wonder why? :|


No idea, I pulled the list from RPS, but as it has been updated, I don't think it really matters anymore :)
ImageImage
Makena

User avatar
Has 1 million gon bucks
 
Online
Posts: 1552
Joined: 22 May 04, 4:00 pm
Location: Melbourne


Return to GON Lounge

Who is online

Users browsing this forum: Captplatypus, DeusR3x, Google [Bot] and 4 guests

x

#{title}

#{text}