PSA: Warning: Big Security Risk In Some Ubisoft PC Games

Post » Mon Jul 30, 2012 5:46 pm

http://www.rockpapershotgun.com/2012/07/30/psa-possible-security-risk-in-some-ubisoft-pc-games/

In a stunning development, Ubisoft's always on DRM seems to open a backdoor into users' PCs. It seems you should uninstall the games and find and disable the brower plug-in.

We’re currently investigating the full extent of this, but moralising and recrimination can come later. For now, the important thing is to warn folks who have certain Ubisoft games installed on their PCs that an apparent backdoor has been discovered in the Uplay infrastructure/DRM which may in theory allow any anyone so minded to install God knows what horrors on your PC. It isn’t confirmed as definite, but certainly proof of concept code is calling up Uplay windows and then loading other programs from websites that have nothing to do with Ubisoft. If Uplay is on your PC, I urge you to uninstall it and any games that use it immediately, until we know more. Update: the flaw lies specifically in a browser plugin Uplay quietly installs, and the general consensus is now that’s all you need to remove to protect yourself. See below for details on how to rid your PC of it.

Essentially, as described here, with the right piece of code any website can call up a Uplay window and from that might be able to slip a program install or launch of their choice onto your PC. Were someone with malevolent intent to inject the code onto a commonly-visited website, they might be able to gain control over any number of PCs – or install keyloggers, viruses and the like, or just plain old wipe your hard drive. The web security expert we pvssyd to says this could even occur via an email link, making this exploit a phisher’s dream if it’s as a bad as it sounds.

Says the expert we spoke to, “you could click on a weblink, thinking you were visiting the BBC News Website from a friendly list of bookmarks. Except it’d also install a program via UBISoft’s DRM plugin which wiped your hard drive. It is a genuine threat. All it would take is an exploited wordpress, say.”

But I come here not to sensationalise, but to warn. With news of this backdoor spreading like wildfire and proof of concept code already out there, there’s a very real chance that someone will try to achieve something unpleasant with it before Ubisoft can shut it down. That’s presuming it is what it appears to be, of course – this may turn out to be an exaggeration, especially as the internet does so love to mock Ubi’s notorious DRM, but so far the evidence very much points to this being as dangerous as it sounds. I’ve contacted Ubisoft for comment and will update as and when we know more. There’s been no response as yet, and other sites are reporting similar silence.

The fault does appear to specifically lie with a browser plugin Uplay installs rather than Uplay itself, so remove that from your Firefox/Chrome/IE/etc extensions as a priority, but I’m erring on the side of extreme caution and advocating the removal of anything associated with Uplay until this apparent threat is dealt with. Here’s how to locate and disable the errant plugin:


Firefox:
Tools – Add-ons – Plugins – Disable the Uplay and Uplay PC Hub plugins

Chrome:
Visit about:plugins and disable

Opera:
Settings – Preferences – Advanced – Downloads – Search “Uplay”, delete

(Via Revisor on our forums).


Contrary to what some parts of the web are currently screaming, this is not a rookit – it’s an exploit in a browser extension. Alas, the vast majority of folk with said browser extension will have been hitherto unaware that Uplay had installed it.

You can find the games which apparently include the exploit listed below. If you have any of them on PC, I would urge you to uninstall them and any Uplay applications as soon possible as a precautionary measure. If you have any of these games on your PC, you can also see the apparent exploit harmlessly in action with the link here.

We’ve tested with a PC that has never had Uplay installed on it. The exploit didn’t work at all. After installing Uplay alone, immediately the test link did indeed work, calling up the Uplay window, and then with that, booting the Windows Calculator. After uninstalling Uplay, the exploit once again didn’t work.
Calculator’s hardly scary of course, but if someone could use the exploit to slip another program onto your PC or run command lines, anything could happen. Frightening – even if there is still something of a question mark over exactly what level of access a nasty soul could go on to achieve. Additionally, this software would appear to allow Ubisoft to monitor PCs running Uplay, but again let’s wait for more details before any hammers of judgement are wielded.

It appears versions of some of these games are Uplay-free and thus in theory safe, but again it may be better to be paranoid than sorry. You can always reinstall later, right? I’d also urge you to check your list of installed programs in Windows, just in case an old install of the Uplay launcher/plugin is hanging around despite your having previously uninstalled any games that used it.

Here’s the list of titles known to be affected:

Assassin’s Creed II
Assassin’s Creed: Brotherhood
Assassin’s Creed: Project Legacy
Assassin’s Creed Revelations
Assassin’s Creed III
Beowulf: The Game
Brothers in Arms: Furious 4
Call of Juarez: The Cartel
Driver: San Francisco
Heroes of Might and Magic VI
Just Dance 3
Prince of Persia: The Forgotten Sands
Pure Football
R.U.S.E.
Shaun White Skateboarding
Silent Hunter 5: Battle of the Atlantic
The Settlers 7: Paths to a Kingdom
Tom Clancy’s H.A.W.X. 2
Tom Clancy’s Ghost Recon: Future Soldier
Tom Clancy’s Splinter Cell: Conviction
Your Shape: Fitness Evolved

I’m not at all certain that list is complete, given other games are known to use Uplay – From Dust, for instance. Check your program installs and browser extensions/plugins for any trace of it regardless – it might be there from an older install even though the game that carried it is no longer on your PC.


Again, more news as we have it.
User avatar
Kelly Osbourne Kelly
 
Posts: 3426
Joined: Sun Nov 05, 2006 6:56 pm

Post » Mon Jul 30, 2012 11:41 pm

:lmao: Their own DRM biting them in the ass. Classic :touched:

Good thing i've not bought any Ubisoft game since thye implemented that DRM.
User avatar
Darlene Delk
 
Posts: 3413
Joined: Mon Aug 27, 2007 3:48 am

Post » Tue Jul 31, 2012 2:35 am

Good thing i've not bought any Ubisoft game since thye implemented that DRM.
Same here. Hopefully this doesn't turn out so bad for the people who did, though.
User avatar
natalie mccormick
 
Posts: 3415
Joined: Fri Aug 18, 2006 8:36 am

Post » Mon Jul 30, 2012 11:12 pm

Thanks for posting this mate. Turns out I did indeed have the things running. Went ahead and disabled them.

If I start posing gay porm on this site, chances are this topic was made to late for my computer!
User avatar
Ash
 
Posts: 3392
Joined: Tue Jun 13, 2006 8:59 am

Post » Mon Jul 30, 2012 4:44 pm

I love the DRM, how could Ubisoft allow this to happen?!?!
User avatar
Reven Lord
 
Posts: 3452
Joined: Mon May 21, 2007 9:56 pm

Post » Tue Jul 31, 2012 3:01 am

Wow. Well, that's well done, Ubisoft. Good thing my backlog's so staggering I don't have any uPlay related games installed at the moment.

My question is, however: what in the bloody [censored] were they doing installing a browser plugin? Seriously. Why would a DRM scheme need to be sticking its nose into my web browser? Steam doesn't do that. GFWL doesn't do that. ...I won't touch Origin with a 20 foot pole coated in the strongest antibacterial known to man, but I doubt it does that.

If Ubisoft knows what's good for them they'll yank that plugin entirely, and hopefully have the good sense to hide under the nearest rock until this blows over. But...it's Ubisoft, so they'll probably just keep derping along off the PR disaster cliff.

I love the DRM, how could Ubisoft allow this to happen?!?!

notsureifserious.jpg.
User avatar
Tasha Clifford
 
Posts: 3295
Joined: Fri Jul 21, 2006 7:08 am

Post » Mon Jul 30, 2012 8:29 pm

Unsurprising, but irritating nonetheless.
User avatar
Alisia Lisha
 
Posts: 3480
Joined: Tue Dec 05, 2006 8:52 pm

Post » Mon Jul 30, 2012 5:37 pm

Hah. Well, good thing I don't really play games on my Computer, and I'm unsure of Ubisofts record, but this is a good way to destroy reputation!


Then again, a lot of people won't really care and they will just continue along and buy their products whether or not they stop what they're doing
User avatar
Add Me
 
Posts: 3486
Joined: Thu Jul 05, 2007 8:21 am

Post » Tue Jul 31, 2012 1:12 am

Could Ubisoft be any more fail? I haven't bought a Ubi Soft game since like 2003 or 04 at the latest.
User avatar
emily grieve
 
Posts: 3408
Joined: Thu Jun 22, 2006 11:55 pm

Post » Mon Jul 30, 2012 4:43 pm

:lmao: Their own DRM biting them in the ass. Classic :touched:

Good thing i've not bought any Ubisoft game since thye implemented that DRM.

Sometimes, irony is something to love when it happens. For all this DRM spouting nonsensical garbage i'm just glad it finally bit a company in the ass. Unfortunately this won't stop other companies from using it.
User avatar
Dragonz Dancer
 
Posts: 3441
Joined: Sat Jun 24, 2006 11:01 am

Post » Tue Jul 31, 2012 3:08 am

Hmm. I think the only thing I've ever run that has an Ubi logo is Shoot More Robots. Not that I realized it had anything to do with Ubi when I grabbed it during the Steam sale.
User avatar
Yvonne
 
Posts: 3577
Joined: Sat Sep 23, 2006 3:05 am


Return to Othor Games