Clicky

It seems to be a browser-only thing, so if you disable the Uplay plugins (why are there even plugins?) you should be fine I guess

To be absolutely sure you could delete everything from Ubisoft on your pc

To test this exploit: Clicky

Luckily Kaspersky already blocked that site for me because of this exploit (Note that that site isn't harmful, just shows what it could do - it only opens up the calculator).

13 years ago*

Comment has been collapsed.

Deleted

This comment was deleted 1 year ago.

13 years ago
Permalink

Comment has been collapsed.

sigh ubisoft...

13 years ago
Permalink

Comment has been collapsed.

Ubisoft is going to the dogs. I wish Valve would take over it already.

13 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 6 years ago.

13 years ago
Permalink

Comment has been collapsed.

Possible Security Risk In Some Ubisoft PC Games ???

you just have to install ANY DRMed Ubisoft game to be unsafe right away (same goes for Origin)

13 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 3 years ago.

13 years ago
Permalink

Comment has been collapsed.

must DRM work in windows ring 0 level so, no, I was not fooling around. think of it as installing a rootkit.

13 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 3 years ago.

13 years ago
Permalink

Comment has been collapsed.

to be honest I was thinking more about SecuROM and Tages while commenting)

about origin... use wireshark or some sniffer and amaze yourself (oh! and use some process viewer and lock it on origin :D)

and I accept steam as DRM (only exception) as it is not satanic like many others

13 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 3 years ago.

13 years ago
Permalink

Comment has been collapsed.

that is good news, I guess the german ban, which leads automatically to an european ban, paid off, I'd not use other version than germany one anyway, even if german is my 5th language.

in the news: http://www.youtube.com/watch?v=01Gdr0DP5Mk

if you don't understand german, the EULA states you allow them to grab your hardware and software information (hence the banhammer) AND SENDING IT to their marketing partners, it is illegal to use it as a spyware, and you have security experts confirming it on the news

origin grabbing your personnal info: http://www.youtube.com/watch?v=6lGUOFjMuQA

as you can see in the latter it grabs which disease you have and sexual orientation the player have and also skype info, you can find dozens of youtube videos of origin sniffing all your machine

so from your tests, and I see you are no LOLcat, it seems EA started using their heads, as I said, good news!

13 years ago
Permalink

Comment has been collapsed.

13 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 3 years ago.

13 years ago
Permalink

Comment has been collapsed.

I clearly felt that already the way you took the conversation hehe, I am not a nazi DRM hater either, people do what they want to do, but some DRM -are- satanic (too bad because I'd buy the games :) and they should inform themselves about what they are installing

13 years ago
Permalink

Comment has been collapsed.

Hahahah.

13 years ago
Permalink

Comment has been collapsed.

lol :D

13 years ago
Permalink

Comment has been collapsed.

I'm glad I've been boycotting Ubisoft since their stupid "always-online" DRM. None of that crap on my machine, woo!

13 years ago
Permalink

Comment has been collapsed.

=.=

13 years ago
Permalink

Comment has been collapsed.

Good job, Ubisoft.

13 years ago
Permalink

Comment has been collapsed.

indeed!

13 years ago
Permalink

Comment has been collapsed.

Epic fail.

13 years ago
Permalink

Comment has been collapsed.

The amount of irony in UPlay being an anti-piracy measure is increasing evermore

13 years ago
Permalink

Comment has been collapsed.

This Torrentfreak article mentions the name of the person, who found the vulnerability.

13 years ago
Permalink

Comment has been collapsed.

Scumbag Ubisoft :/

13 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 3 years ago.

13 years ago
Permalink

Comment has been collapsed.

sighs From what I can gather, once I've disabled the plugins, I'm safe and can keep playing AC2, right?

13 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 3 years ago.

13 years ago
Permalink

Comment has been collapsed.

Okay, good. I'd be pissed otherwise.

13 years ago
Permalink

Comment has been collapsed.

I think so. You and I... Ubisoft, I trusted you ;-;

13 years ago
Permalink

Comment has been collapsed.

Can someone tell me why no anitvirus/security company hasn't blacklisted the hell out of that plugin?

13 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 3 years ago.

13 years ago
Permalink

Comment has been collapsed.

They fail. I got two trojans the past month thanks to some exploit. Avira is supposed to be good, it picked up something but the trojan still got through both times. Me mad.

13 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 3 years ago.

13 years ago
Permalink

Comment has been collapsed.

I am seriousy considering getting NoScript after this, even if it is a hassle but I'll check click-to play first. I've never heard of it before. Thanks.

13 years ago
Permalink

Comment has been collapsed.

Good thing i dont play ubicrap games

13 years ago
Permalink

Comment has been collapsed.

Heh, NoScript blocked the code on the exploit test link :)

Interestingly enough, it seems although I do have both Heroes of Might and Magic VI and Prince of Persia: The Forgotten Sands installed, I do not have the exploitable plugin.

13 years ago
Permalink

Comment has been collapsed.

Heh, only Ubisoft game I have that's on that list I didn't even know uses Uplay cause I haven't even installed it. I just got it as part of a bundle. Still, just to be safe I checked to see if I had the stuffs on my computer and I didn't so yay.

13 years ago
Permalink

Comment has been collapsed.

Thanks. Looks like I have one game on the list. Haven't installed it yet, but hopefully I'll remember to disabled the plugin when I do.

13 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 1 year ago.

13 years ago
Permalink

Comment has been collapsed.

Anyone happen to have a contact e-mail address for Ubisoft? I scanned their website and couldn't find anything. As one of the shrinking group of PC users who was (reluctantly) not boycotting them before this news broke, I'd like to share my displeasure with them. Not that it's likely to make a difference, but whatever.

13 years ago
Permalink

Comment has been collapsed.

uPlay has just been updated to 2.04, anyone care to test if the exploit has been fixed?

13 years ago
Permalink

Comment has been collapsed.

"There are reports on the Ubi forums that Uplay has been updated to version 2.04, which if the commenter is accurate bears the note “‘Fix addressing browser plugin. Plugin now only able to open uPlay application.” If your Uplay hasn’t/won’t update to version 2.04, I’d get rid of it and its plugin for now. To be honest I’d get rid of the plugin regardless, until we’re sure the problem’s been resolved."

13 years ago
Permalink

Comment has been collapsed.

From what I've read, it is essentially a rootkit, although it doesn't appear as though that was the intention. The plugin itself is coded really poorly. In essence they wanted you to be able to launch games from a browser, but didn't put anything in to prevent websites from launching other programs.

I imagine they'll have a quick fix out in a few days, but unfortunately the damage from negative publicity has already started. At least it won't be as bad as Sony's rootkit years ago.

13 years ago
Permalink

Comment has been collapsed.

There's literally hundreds of vendors who managed to implement their own pseudo-protocol for that, especially if it concerns playing on multiplayer-servers. None of them uses a browser addon D; For example: steam://run/<game>

Start Sanctum - open steam://run/91600 in a browser.

13 years ago
Permalink

Comment has been collapsed.

I was just stating that as far as rootkits are concerned, this would be classed as one which means they're potentially facing a backlash like Sony received.

The fact that there are so many other developers who have accomplished the same as you mentioned, makes it even more of a blunder for Ubisoft.

I think the moral of the story is, check the interns work before implementation. If you play Diablo 3 at all, you'll know that even companies like Blizzard have been slipping up on basic things lately.

13 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 3 years ago.

13 years ago
Permalink

Comment has been collapsed.

"Exploitable DRM utility" doesn't have the same snappy linkbait qualities as "OMFG UBISOFT ROOTKIT".

13 years ago
Permalink

Comment has been collapsed.

My uplay just updated, and steam closed itself :\

13 years ago
Permalink

Comment has been collapsed.

Haha, shame on them

13 years ago
Permalink

Comment has been collapsed.

Closed 13 years ago by WarrantOfficer.