Overclockers Australia Forums
OCAU News - Wiki - QuickLinks - Pix - Sponsors  

Go Back   Overclockers Australia Forums > Software Topics > PC Games

Notices


Sign up for a free OCAU account and this ad will go away!
Search our forums with Google:
Reply
 
Thread Tools
Old 30th July 2012, 10:55 PM   #16
lithos
Member
 
Join Date: Oct 2010
Posts: 5,382
Default

Quote:
Originally Posted by Sundance View Post
The sickening thing is I expect Ubisoft to arrogantly brush it off. And it will really wind me up and make me angry. Appalling company.
So, thousands, possibly hundreds of thousands, of people could get their computers utterly violated and their digital life destroyed, in the worst case scenario. Passwords taken, credit card numbers stolen, identities lifted.

But that's a sacrifice Ubisoft's willing to have you make; remember, the minor (according to Ubisoft...) profit they make off PC game sales is far more important than your security!
__________________
Quote:
Originally Posted by Sankari View Post
Almost anything is considered a major event in Adelaide. People will line up to watch someone reverse park a Tarago.

lithos is offline   Reply With Quote

Join OCAU to remove this ad!
Old 31st July 2012, 12:45 AM   #17
Chris McMahon
Because I said so!
 
Chris McMahon's Avatar
 
Join Date: Jun 2001
Location: Gold Coast, Queensland
Posts: 3,979
Default

I'm going to sticky this thread.

From the article:
Quote:
Here’s how to locate and disable the errant plugin:
Firefox:
Tools – Add-ons – Plugins – Disable the Uplay and Uplay PC Hub plugins

Chrome:
Visit aboutlugins and disable

Opera:
Settings – Preferences – Advanced – Downloads – Search “Uplay”, delete
I just checked my browser and found, then disabled, the plug-ins.
__________________
"Every normal man must be tempted at times to spit upon his hands, hoist the black flag, and begin slitting throats." | Henry Louis Mencken (1880-1956) | OCAU Forum Member #158 | Games Forum Admin | My GamersGate Games / Steam Games | Feeling sad?ಠ_ಠ

Last edited by Chris McMahon; 31st July 2012 at 12:58 AM.
Chris McMahon is offline   Reply With Quote
Old 31st July 2012, 3:34 AM   #18
Chris McMahon
Because I said so!
 
Chris McMahon's Avatar
 
Join Date: Jun 2001
Location: Gold Coast, Queensland
Posts: 3,979
Default

Ubisoft has now issued a patch.

Quote:
“We have made a forced patch to correct the flaw in the browser plug-in for the Uplay PC application that was brought to our attention earlier today. We recommend that all Uplay users update their Uplay PC application without a Web browser open. This will allow the plug-in to update correctly. An updated version of the Uplay PC installer with the patch also is available from Uplay.com.

Ubisoft takes security issues very seriously, and we will continue to monitor all reports of vulnerabilities within our software and take swift action to resolve such issues.”
Source.
__________________
"Every normal man must be tempted at times to spit upon his hands, hoist the black flag, and begin slitting throats." | Henry Louis Mencken (1880-1956) | OCAU Forum Member #158 | Games Forum Admin | My GamersGate Games / Steam Games | Feeling sad?ಠ_ಠ
Chris McMahon is offline   Reply With Quote
Old 31st July 2012, 10:22 AM   #19
Lucifers Mentor Thread Starter
Member
 
Join Date: Feb 2003
Posts: 4,144
Default

Thanks for keeping this updated Chris.
Lucifers Mentor is online now   Reply With Quote
Old 31st July 2012, 10:29 AM   #20
Pinkeh
Member
 
Pinkeh's Avatar
 
Join Date: Nov 2008
Location: Sydney
Posts: 7,247
Default

Ah what a shame. Stopped buying UbiDRM crap years ago.
__________________
Photography: Gear, Flickr
ASUS P8P67 EVO, Core i5 2500K, Sapphire 6970x2, 32GB Corsair Vengenance RAM, WD Caviar Black 4TB, Green 4x 3TB, NZXT Phantom Red Full Tower, Cosair TX950 PSU | QNAP412 4x2TB Hitachi 7k3000 RAID5 | BF3 Stats
Pinkeh is offline   Reply With Quote
Old 31st July 2012, 10:50 AM   #21
power
Member
 
power's Avatar
 
Join Date: Apr 2002
Location: brisbane
Posts: 27,072
Default

buy then install/download Ubi game, crack never worry again - sorry Ubi but your DRM shits me... But occasionally you make a good game, however I will never put up with intrusive DRM.
__________________
this is who we are.
power is online now   Reply With Quote
Old 31st July 2012, 6:49 PM   #22
Mithickus
Member
 
Mithickus's Avatar
 
Join Date: Mar 2002
Location: Melbourne, Vic
Posts: 616
Default

Is Uplay = Ubisoft game launcher?

I have some Assassin's Creed games installed through steam, but my browsers don't have the Uplay plugin.

I can't find anything called Uplay on my computer. What should I be looking for/how should I be looking for it?
Mithickus is offline   Reply With Quote
Old 31st July 2012, 6:58 PM   #23
Sledge
Member
 
Join Date: Aug 2002
Location: Adelaide
Posts: 3,109
Default

even though it's been patched now with the new UPlay install..
http://uplay.ubi.com/en-GB
I'm pretty sure i got some free games from Ubisoft at one stage.. though i can't remember what, or how to access them lol...
Assassins Creed 1 & 2, Hawx 1 & 2... got the serial for Hawx 2.. none of the others..anyone know if the others need serials to work?
i've got the downloaders for the above games..and a TagesSetup_x64.exe

Edit, just logged into my Ubisoft account, it says no orders found..
But i found an email i sent to myself with the other Keys
So is UPlay different to the Tages protection?

Last edited by Sledge; 31st July 2012 at 7:23 PM.
Sledge is offline   Reply With Quote
Old 1st August 2012, 4:33 AM   #24
Chris McMahon
Because I said so!
 
Chris McMahon's Avatar
 
Join Date: Jun 2001
Location: Gold Coast, Queensland
Posts: 3,979
Default

Quote:
Originally Posted by Mithickus View Post
Is Uplay = Ubisoft game launcher?
Yes.

Quote:
I have some Assassin's Creed games installed through steam, but my browsers don't have the Uplay plugin.
Uplay was removed from Steam copies of AC some time after release. But AC isn't the only game affected. Eg if you bought Anno 2070 at the recent steam sale, it has Uplay.

Quote:
I can't find anything called Uplay on my computer. What should I be looking for/how should I be looking for it?
Read the article linked in the first post. It tells you there.

Quote:
Originally Posted by Sledge View Post
even though it's been patched now with the new UPlay install..
So is UPlay different to the Tages protection?
The cause of the problem is that as well as acting as an always on DRM, Uplay also functions as a "steam-like" system with achievements, game purchases and points. You get points from gameplay of a Ubisoft game. eg Beat Settlers 7 on average get 70 "Uplay points".

As the Uplay launcher is running constantly while the game is (the DRM part), the game tells Uplay you earned the reward and Uplay tells Ubisoft's servers - that keep your Uplay user account.

The Uplay account on the Ubisoft servers also allows you buy games, maps and other in-game items (with points or real money) . Once you buy something from Ubisoft, via your browser, the Ubisoft website launches Uplay to tell it what you're purchased.

And there's the problem.

How do they tell Uplay to launch? Easy, they install addons to all browser that accept the code from Ubisoft's website and then launch Uplay. The only issue with that is they didn't hard code it to just launch Uplay. It will launch anything you tell it to.

So not only will the addon launch "uplay.exe" it will launch anything already installed on your PC. Eg ftp to download a trojan. Policy editor to turn off restrictions, Telnet, remote desktop, anything.

That's why this issue is serious.

And because the vulnerability is in a browser addon already marked as "safe" no anti-virus will pick it up, no Microsoft patch will remove it, even updating your browser just reinstalls it along with all your other addons.

The problem is that you have to logon to Uplay for the fix to launch. People who don't read this thread and haven't played a Uplay game in awhile still have the vulnerability. ie If you purchased AC two years ago, finished it and haven't played it since.

Now that this exploit is widely know, I expect it to be added to every fishing website out there.
__________________
"Every normal man must be tempted at times to spit upon his hands, hoist the black flag, and begin slitting throats." | Henry Louis Mencken (1880-1956) | OCAU Forum Member #158 | Games Forum Admin | My GamersGate Games / Steam Games | Feeling sad?ಠ_ಠ
Chris McMahon is offline   Reply With Quote
Old 3rd August 2012, 3:28 PM   #25
issa2006
Member
 
issa2006's Avatar
 
Join Date: Feb 2006
Location: AUSTRALIA (ADL)
Posts: 2,485
Default

you can disable in firefox 13.0.1, but how do i uninstall it completely?
__________________
2700k+Fatal1ty Z68 Professional Gen3/i-ram 4g -32g ddr3 1600/2xssd in raid 0(sam 120g M-830)+ hdds+sound card+g19/g9x etc....27" 120 +3d samsung +7" touch screen etc...(gig oc 670 x2 sli)1250psu evermax+water cooling (oc4.8)ghz etc-win7 64bit +eboostr+supercache 5(3600+mb/sec hdd access)
issa2006 is offline   Reply With Quote
Old 4th August 2012, 1:10 AM   #26
Chris McMahon
Because I said so!
 
Chris McMahon's Avatar
 
Join Date: Jun 2001
Location: Gold Coast, Queensland
Posts: 3,979
Default

Quote:
Originally Posted by issa2006 View Post
you can disable in firefox 13.0.1, but how do i uninstall it completely?
http://www.ghacks.net/2010/10/02/how...-from-firefox/
__________________
"Every normal man must be tempted at times to spit upon his hands, hoist the black flag, and begin slitting throats." | Henry Louis Mencken (1880-1956) | OCAU Forum Member #158 | Games Forum Admin | My GamersGate Games / Steam Games | Feeling sad?ಠ_ಠ
Chris McMahon is offline   Reply With Quote
Old 4th August 2012, 1:06 PM   #27
issa2006
Member
 
issa2006's Avatar
 
Join Date: Feb 2006
Location: AUSTRALIA (ADL)
Posts: 2,485
Default

Quote:
Originally Posted by Chris McMahon View Post
dos not work in v13 no info where plugin is installed, it just says ver + name of plug in, not location(am i wrong?)

forgot to put in aboutlugins in address bar...says name of plugin , not location, but i should find it
__________________
2700k+Fatal1ty Z68 Professional Gen3/i-ram 4g -32g ddr3 1600/2xssd in raid 0(sam 120g M-830)+ hdds+sound card+g19/g9x etc....27" 120 +3d samsung +7" touch screen etc...(gig oc 670 x2 sli)1250psu evermax+water cooling (oc4.8)ghz etc-win7 64bit +eboostr+supercache 5(3600+mb/sec hdd access)

Last edited by issa2006; 4th August 2012 at 1:08 PM.
issa2006 is offline   Reply With Quote
Old 4th August 2012, 1:43 PM   #28
Chris McMahon
Because I said so!
 
Chris McMahon's Avatar
 
Join Date: Jun 2001
Location: Gold Coast, Queensland
Posts: 3,979
Default

Quote:
Originally Posted by issa2006 View Post
dos not work in v13 no info where plugin is installed, it just says ver + name of plug in, not location(am i wrong?)

forgot to put in aboutlugins in address bar...says name of plugin , not location, but i should find it
You have to enable the plugin first. The it will tell you the .dll location.
__________________
"Every normal man must be tempted at times to spit upon his hands, hoist the black flag, and begin slitting throats." | Henry Louis Mencken (1880-1956) | OCAU Forum Member #158 | Games Forum Admin | My GamersGate Games / Steam Games | Feeling sad?ಠ_ಠ
Chris McMahon is offline   Reply With Quote
Old 5th September 2012, 5:19 PM   #29
Philll
Member
 
Philll's Avatar
 
Join Date: Dec 2008
Location: NSW
Posts: 10,958
Default

No more Ubi DRM

http://bit.ly/Tl5thp
__________________
Steam | Pay less for Steam games | 'Linux gaming'
Philll is offline   Reply With Quote
Old 5th September 2012, 5:39 PM   #30
FiShy
Member
 
FiShy's Avatar
 
Join Date: Aug 2001
Posts: 7,607
Default

Quote:
Originally Posted by Philll View Post
No more Ubi DRM

http://bit.ly/Tl5thp
Thats huuuge, i might start playing ubi games..... if they are any good
__________________
Quote:
Originally Posted by PabloEscobar View Post
If I was videoing a transvestite in the shower, The T/D ratio would be 2:1... Nearing acceptable levels.
FiShy is offline   Reply With Quote
Reply

Bookmarks

Sign up for a free OCAU account and this ad will go away!

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +10. The time now is 6:03 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd. -
OCAU is not responsible for the content of individual messages posted by others.
Other content copyright Overclockers Australia.
OCAU is hosted by Internode!