Any mitigation ? Is it possible to disable this browser plugin ?
Ubisoft "Uplay" DRM exposed as rootkit
31–40 of 148 posts
Re: Ubisoft "Uplay" DRM exposed as rootkit
#32Oh hell no. I can't believe this shit... and Tom Clancy's Ghost Recon: Future Soldier was such a good game too. T_T Next time I want to play an Ubisoft game I'm just going to pirate it. EDIT: I buy 99% of my video games through Steam, and when the games I get through Steam want to use their own launcher (play, windows live games, or EA's Origin, for example) I always get peeved.. to find out it allows arbitrary remot…
Then of course you have to wait for the damn thing to sign in every time you want to play the game "Connection failed, do you want to retry?"
Re: Ubisoft "Uplay" DRM exposed as rootkit
#33Any mitigation ? Is it possible to disable this browser plugin ?
Re: Ubisoft "Uplay" DRM exposed as rootkit
#34Oh hell no. I can't believe this shit... and Tom Clancy's Ghost Recon: Future Soldier was such a good game too. T_T Next time I want to play an Ubisoft game I'm just going to pirate it. EDIT: I buy 99% of my video games through Steam, and when the games I get through Steam want to use their own launcher (play, windows live games, or EA's Origin, for example) I always get peeved.. to find out it allows arbitrary remot…
I hate the hoop jumping in modern games. I was playing Street Fighter 4 recently and it comes up with "oh, you want to save your single player game? You have to create a MicrosoftWindowsBingGamesPhone8ForXboxLive.Net account" . Then of course you have to wait for the damn thing to sign in every time you want to play the game "Connection failed, do you want to retry?"
Meaning: I feel your pain, brother.
Re: Ubisoft "Uplay" DRM exposed as rootkit
#35Why does Tavis Ormandy ( http://seclists.org/fulldisclosure/2012/Jul/375 ) keep putting fully usable proof of concept exploits out for widely deployed software without giving a vendor time to prepare a patch, or in this case, even notifying them? Off the top of my head, I remember he did this for the windows help center exploit and the java web start exploit. I can't understand why you would do this. You could at lea…
Also, that's probably the quickest way to get them to release a fix.
Re: Ubisoft "Uplay" DRM exposed as rootkit
#36Earlier quoted context omitted.
Because the company wasn't acting in good faith? IMHO they put that there on purpose and they deserve to be exposed as evil bastards that they are.
Do you have any evidence they put that here on purpose or are you just spreading rumors? It could as well be shoddy programming.
Instead, they ask for their interns to build the "solution" that makes my computer part of the Borg.
I really don't feel compassion in this case towards the company (towards the users is a different story, no doubt)
Re: Ubisoft "Uplay" DRM exposed as rootkit
#37Why does Tavis Ormandy ( http://seclists.org/fulldisclosure/2012/Jul/375 ) keep putting fully usable proof of concept exploits out for widely deployed software without giving a vendor time to prepare a patch, or in this case, even notifying them? Off the top of my head, I remember he did this for the windows help center exploit and the java web start exploit. I can't understand why you would do this. You could at lea…
Very few comapnies will pay for this type of exploit, even fewer will offer a thanks. It's easier to get them fixed this way.
If the vendor tries to delay you for months or ignores you, sure. But it doesn't even seem like he tested the exploit here to understand whether it was a serious threat.
Re: Ubisoft "Uplay" DRM exposed as rootkit
#38Re: Ubisoft "Uplay" DRM exposed as rootkit
#39Why does Tavis Ormandy ( http://seclists.org/fulldisclosure/2012/Jul/375 ) keep putting fully usable proof of concept exploits out for widely deployed software without giving a vendor time to prepare a patch, or in this case, even notifying them? Off the top of my head, I remember he did this for the windows help center exploit and the java web start exploit. I can't understand why you would do this. You could at lea…
I asked a question. If you're going to downvote me for having a wrong opinion, you should at least respond and tell me me the answer to my question, like 'this is proper behavior for a security researcher because X'.
Re: Ubisoft "Uplay" DRM exposed as rootkit
#40I'm not sure if that's what the OP implied, but I'm not sure this was done on purpose. "Never attribute to malice that which is adequately explained by stupidity". Ubisoft is well know for their aggressive anti-pirating practices (cloud saves for instance), but that's just too idiotic. Here's taviso's mail on seclists: http://seclists.org/fulldisclosure/2012/Jul/375 I hope ubisoft reacts quickly.