Page 1 of 2 12 LastLast
Results 1 to 30 of 38

Thread: Ubisoft Uplay Security Exploit

  1. #1
    Pillow Talk
    Join Date
    Jan 2010
    Location
    Scotland
    Posts
    30

    Ubisoft Uplay Security Exploit

    If you have any of the following games installed which use "Uplay" , there is a potential security issue with it detailed over here on RPS. As of right now its not known exactly how serious it is, but you may want to uninstall Uplay as a precaution, and check your browser plugins.

    From RPS: Update: the flaw lies specifically in a browser plugin Uplay quietly installs, and the general consensus is now that’s all you need to remove to protect yourself.

    Firefox:
    Tools – Add-ons – Plugins – Disable the Uplay and Uplay PC Hub plugins

    Chrome:
    Visit about:plugins and disable

    Opera:
    Settings – Preferences – Advanced – Downloads – Search “Uplay”, delete


    From PCG: Ubi says “We have made a forced patch to correct the flaw in the browser plug-in for the Uplay PC application that was brought to our attention earlier today. We recommend that all Uplay users update their Uplay PC application without a Web browser open. This will allow the plug-in to update correctly. An updated version of the Uplay PC installer with the patch also is available from Uplay.com.

    Ubisoft takes security issues very seriously, and we will continue to monitor all reports of vulnerabilities within our software and take swift action to resolve such issues.”
    Last edited by Web_cole; 07-30-2012 at 09:54 AM.

  2. #2
    Social Worker
    Join Date
    Apr 2003
    Location
    Berlin
    Posts
    4,732
    Wohoo, I guess.

    Might want to clean up that list a little bit, I guess. AC III and BoA 4 aren't available yet, Your Shape: Fitness Evolved, Pure Football, and Just Dance 3 never got released on PC. I'd also assume that Anno 2070 does support Uplay?

  3. #3
    Pillow Talk
    Join Date
    Jan 2010
    Location
    Scotland
    Posts
    30
    I just copy pasta'd the list from RPS, I'll leave it as is for now, as I have no actual hands on experience with Ubi DRM one way or the other.

  4. #4
    Neo Acoustic
    Join Date
    Apr 2005
    Location
    Perth, Western Australia. Steam ID: Talorc
    Posts
    1,612
    Well I sure as hell don't remember Driver asking me if it could install a browser plug-in to firefox while I wasn't looking.

    I thought Firefox was supposed to stop third parties shitting up my browser with crapware add ons without permission!!

  5. #5
    Mad Chester
    Join Date
    Jul 2009
    Posts
    1,472
    No warning of any kind to users from ubi yet?

  6. #6
    Pillow Talk
    Join Date
    Jan 2010
    Location
    Scotland
    Posts
    30
    Quote Originally Posted by djotefsoup View Post
    No warning of any kind to users from ubi yet?
    This is really just breaking right now as far as I'm aware.

  7. #7
    Social Worker
    Join Date
    Jun 2009
    Location
    Teplice, Czech Republic
    Posts
    3,696
    PCGamer
    We’ve contacted Ubisoft for comment and they’re “looking into” the problem.
    I have no doubt this will be fixed today or tomorrow. Not a big problem for me, I disabled those two plugins the second I read about it.
    It does seem like an incredibly incompetent thing to do though.
    Ubi just can't catch a break, can they?
    It's like another day, another shit by Ubi.

  8. #8
    Hustle
    Join Date
    Jul 2002
    Location
    Land of Long White Cloud
    Posts
    427
    I didn't even know Uplay installed browser plugin. I don't remember ever giving permission. All I know is they got a new Uplay frontend and I have to install it to play the games I bought.

    FUUUUUUUUUUUU

  9. #9
    New Romantic
    Join Date
    Jul 2007
    Posts
    5,263
    Found it in Chrome, but oddly couldn't find it in IE. I guess it gets installed on whatever your default browser is?

  10. #10
    Social Worker
    Join Date
    Jun 2009
    Location
    Teplice, Czech Republic
    Posts
    3,696
    Quote Originally Posted by Dan_Theman View Post
    Found it in Chrome, but oddly couldn't find it in IE. I guess it gets installed on whatever your default browser is?
    I guess so, I also have it only in Firefox but not IE.

  11. #11
    Mad Chester
    Join Date
    Oct 2005
    Location
    Essen, Germany
    Posts
    1,318
    Assassins Creed II was too good a deal on steam... i fell for it even as i had sworn to never ever buy a ubi game again... What can i say, im an idiot!

  12. #12
    New Romantic
    Join Date
    Mar 2003
    Location
    In the now
    Posts
    7,457
    I do not see anything about plugins in chrome, do you mean the extensions or is that something separate?

  13. #13
    Mad Chester
    Join Date
    Nov 2009
    Posts
    1,280
    Great, another "always on" DRM that makes creates a vulnerability of the end-user being hacked.

  14. #14
    Goodluck!!
    Join Date
    May 2012
    Posts
    122
    Looks like it's not just your default browser. I have both Chrome and Firefox on my computer and the UPlay plugin was in both browsers.

  15. #15
    Social Worker
    Join Date
    Mar 2006
    Posts
    3,672
    Didn't know they could infect Opera like that... Luckily About:Config did not show anything in my Opera.

    Come to think of it, I haven't gotten a Ubisoft title in ages thanks to them hating the PC, so not much of a chance of getting infected.

    Thanks for the headsup though.

  16. #16
    World's End Supernova
    Join Date
    Jul 2008
    Location
    Washington State, XBL: Telefrog
    Posts
    16,229
    There's a Just Dance 3 for PC?

  17. #17
    Social Worker
    Join Date
    Dec 2006
    Location
    Oslo, Norway
    Posts
    2,173
    Quote Originally Posted by DeepT View Post
    I do not see anything about plugins in chrome, do you mean the extensions or is that something separate?
    chrome://plugins/

  18. #18
    Social Worker
    Join Date
    Jun 2009
    Location
    Teplice, Czech Republic
    Posts
    3,696
    Well the problem has been fixed! That was quick.

    Changelog:

    Fix addressing browser plugin.Plugin now only able to open Uplay application.

  19. #19
    Social Worker
    Join Date
    Jun 2003
    Location
    Deepest Wilt-shire in the United Kingdom!
    Posts
    3,960
    I have anno 2070 and it has never installed any plug-ins anywhere.

  20. #20
    Social Worker
    Join Date
    Dec 2006
    Location
    Munich, Germany
    Posts
    4,001
    Quote Originally Posted by cliffski View Post
    I have anno 2070 and it has never installed any plug-ins anywhere.
    Appearantly it's linked to UPlay 2.0 which came out a couple of days ago.
    Seems its updating itself once you start a UPlay linked game.

    So maybe you didn't run Anno 2070 in the last couple of days and therefore are still on UPlay 1.1.?

  21. #21
    Der Schulde How To Go
    Join Date
    Jun 2007
    Posts
    12,488


    fixed?

  22. #22
    Pillow Talk
    Join Date
    Jan 2010
    Location
    Scotland
    Posts
    30
    Maybe, still doesn't appear to be any "official" statement or acknowledgement from Ubi on the matter though, so proceed with caution.

  23. #23
    Spinning Toe
    Join Date
    Apr 2009
    Location
    Portugal
    Posts
    935
    Why do they need a plugin in the first place? To launch games? Steam doesn't use one. But to be fair lot's of application want to install plugins that's why I just just set click to play option on chrome for all plugins.

  24. #24
    Social Worker
    Join Date
    Jun 2003
    Location
    Deepest Wilt-shire in the United Kingdom!
    Posts
    3,960
    BF3 has one too, and to be honest, I love it. It's great on a multi-monitor setup to have the game loading the next level while I can browse through all my geeky BF3 stats. I assumed I'd hate it, until I saw it working, and I was very imrpessed by it. Pity about the games general load times, and problems changing servers (you need to restart).

  25. #25
    Der Schulde How To Go
    Join Date
    Jun 2007
    Posts
    12,488
    I suppose it's an feature done thinking in the future. Maybe they plan to have a uplay.com site with all your games, a social network and your stats and friends, a bit like the BF3 battlelog, with the option of launching the games from the web. In that case, it makes sense to have the plugin.

  26. #26
    Pillow Talk
    Join Date
    Jan 2010
    Location
    Scotland
    Posts
    30
    From PCG: Ubi says “We have made a forced patch to correct the flaw in the browser plug-in for the Uplay PC application that was brought to our attention earlier today. We recommend that all Uplay users update their Uplay PC application without a Web browser open. This will allow the plug-in to update correctly. An updated version of the Uplay PC installer with the patch also is available from Uplay.com.

    Ubisoft takes security issues very seriously, and we will continue to monitor all reports of vulnerabilities within our software and take swift action to resolve such issues.”

  27. #27
    Spinning Toe
    Join Date
    Apr 2009
    Location
    Portugal
    Posts
    935
    Fair enough, interesting applications could exist with plugin and it would be better that uplay one would be unique for all ubi games, for example if medal of honor uses a similar system for multplayer as BF3 would they have two different plugins? That would extend even more the number of plugins that is not a good thing given that evert one of them is a possible security exploit. Anyway waiting for the Uplay team to say that Win8 is a catastrophe because IE10 Metro is plugin free :)

  28. #28
    How To Go
    Join Date
    Jan 2004
    Posts
    14,658
    Well it was a mickey-mouse clown-shoes amateur security hole, but at least they fixed it quickly when notified.

  29. #29
    I thrust game designers Social Worker
    Join Date
    Sep 2007
    Location
    Tu ne cede malis sed contra audentior ito
    Posts
    4,870
    I hate wen *anybody* install anything on my browser withouth my permission.

    Is a bad practice. A big NO-NO, and everyone sould be stay the hell away from installing silently crap on my browser. If you really need it, let me make a choice about it.

  30. #30
    Mad Chester
    Join Date
    Jan 2011
    Location
    USA
    Posts
    1,412
    Fking Ubisoft. So what does this plugin do other than forcefully install itself?

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •