{"id":42114,"date":"2012-07-30T14:10:32","date_gmt":"2012-07-30T12:10:32","guid":{"rendered":"http:\/\/mygaming.co.za\/news\/?p=42114"},"modified":"2012-07-30T14:12:29","modified_gmt":"2012-07-30T12:12:29","slug":"ubisofts-uplay-drm-installs-rootkit-leaves-pc-vulnerable-to-attack","status":"publish","type":"post","link":"https:\/\/mygaming.co.za\/news\/business\/42114-ubisofts-uplay-drm-installs-rootkit-leaves-pc-vulnerable-to-attack","title":{"rendered":"Ubisoft&#8217;s Uplay DRM installs rootkit, leaves PC vulnerable to attack"},"content":{"rendered":"<p>Another day, another DRM controversy &#8211; and today it&#8217;s allegations that Ubisoft&#8217;s Uplay DRM installs a rootkit that exposes your PC to browser-based intrusion. Or maybe it&#8217;s an Abstergo Industries plot.<\/p>\n<p>The claims comes via white hat hacker, Tavis Ormandy, who published an exploit that allows remote control of any PC with Uplay installed.<\/p>\n<p>&#8220;While on vacation recently I bought a video game called Assassin&#8217;s Creed Revelations,&#8221; he wrote over on goodie hacker news site, <a href=\"http:\/\/seclists.org\/fulldisclosure\/2012\/Jul\/375\" target=\"_blank\">Seclists<\/a>.<\/p>\n<p>&#8220;I didn&#8217;t have much of a chance to play it, but it seems fun so far. However, I noticed the installation procedure creates a browser plugin for its accompanying Uplay launcher, which grants unexpectedly (at least to me) wide access to websites.\u201d<\/p>\n<p>Most of Ubisoft&#8217;s recent games require Uplay, including the Assassin&#8217;s Creed series and the new Tom Clancy&#8217;s Ghost Recon: Future Soldier.<\/p>\n<p>According to security experts, though, it looks like the vulnerability may have been quite unintentional.<\/p>\n<p>&#8220;Functionality in the Uplay browser extension, that normally enables games to be launched from a web browser, turns out can also be used to launch any other program on the system,&#8221; an anonymous expert told CVG.<\/p>\n<p>&#8220;In the demonstration making its rounds on the internet, the code launched a calculator.&#8221;<\/p>\n<p>Ubisoft has apparently declined comment, but probably because they&#8217;re too busy fixing it to answer the phone.<\/p>\n<h5>Source: <a href=\"http:\/\/www.computerandvideogames.com\/360644\/ubisoft-uplay-hacked-data-allegedly-exposes-security-flaw\/?cid=OTC-RSS&amp;attr=CVG-General-RSS\" target=\"_blank\">CVG<\/a><\/h5>\n<h3 class=\"my-4\">Related Articles<\/h3>\n<p><strong><a href=\"http:\/\/mygaming.co.za\/news\/news\/40695-student-arrested-over-wii-homebrew-hack.html\">Student arrested over Wii homebrew hack<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/mygaming.co.za\/news\/news\/40245-sony-hackers-plead-guilty-to-attacks.html\">Sony hackers plead guilty to attacks<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/mygaming.co.za\/news\/news\/37968-man-jailed-for-hacking-call-of-duty.html\">Man jailed for hacking Call of Duty<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/mygaming.co.za\/news\/news\/34093-how-sony-plans-to-protect-your-psn-account.html\">How Sony plans to protect your PSN account<\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>White hat hacker exposes Uplay security risk<\/p>\n","protected":false},"author":159,"featured_media":42124,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_enabled":true,"_sma_x_custom_text":"","_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[2,3],"tags":[31,197,2219,5976,4378,733,5975],"class_list":["post-42114","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-business","category-pc","tag-active","tag-hack","tag-megarom","tag-rootkit","tag-security-hack","tag-ubisoft","tag-uplay"],"_links":{"self":[{"href":"https:\/\/mygaming.co.za\/news\/wp-json\/wp\/v2\/posts\/42114","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mygaming.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mygaming.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mygaming.co.za\/news\/wp-json\/wp\/v2\/users\/159"}],"replies":[{"embeddable":true,"href":"https:\/\/mygaming.co.za\/news\/wp-json\/wp\/v2\/comments?post=42114"}],"version-history":[{"count":1,"href":"https:\/\/mygaming.co.za\/news\/wp-json\/wp\/v2\/posts\/42114\/revisions"}],"predecessor-version":[{"id":42129,"href":"https:\/\/mygaming.co.za\/news\/wp-json\/wp\/v2\/posts\/42114\/revisions\/42129"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mygaming.co.za\/news\/wp-json\/wp\/v2\/media\/42124"}],"wp:attachment":[{"href":"https:\/\/mygaming.co.za\/news\/wp-json\/wp\/v2\/media?parent=42114"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mygaming.co.za\/news\/wp-json\/wp\/v2\/categories?post=42114"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mygaming.co.za\/news\/wp-json\/wp\/v2\/tags?post=42114"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}