Heroes of Might and Magic Community
visiting hero! Register | Today's Posts | Games | Search! | FAQ/Rules | AvatarList | MemberList | Profile


Age of Heroes Headlines:  
5 Oct 2016: Heroes VII development comes to an end.. - read more
6 Aug 2016: Troubled Heroes VII Expansion Release - read more
26 Apr 2016: Heroes VII XPack - Trial by Fire - Coming out in June! - read more
17 Apr 2016: Global Alternative Creatures MOD for H7 after 1.8 Patch! - read more
7 Mar 2016: Romero launches a Piano Sonata Album Kickstarter! - read more
19 Feb 2016: Heroes 5.5 RC6, Heroes VII patch 1.7 are out! - read more
13 Jan 2016: Horn of the Abyss 1.4 Available for Download! - read more
17 Dec 2015: Heroes 5.5 update, 1.6 out for H7 - read more
23 Nov 2015: H7 1.4 & 1.5 patches Released - read more
31 Oct 2015: First H7 patches are out, End of DoC development - read more
5 Oct 2016: Heroes VII development comes to an end.. - read more
[X] Remove Ads
LOGIN:     Username:     Password:         [ Register ]
New Server | HOMM1: info forum | HOMM2: info forum | HOMM3: info forum | HOMM4: info forum | HOMM5: info forum | MMH6: wiki forum | MMH7: wiki forum
Heroes Community > Heroes 6 - The New Beginning > Thread: Warning: Big Security Risk With Uplay
Thread: Warning: Big Security Risk With Uplay
Storm-Giant
Storm-Giant


Responsible
Undefeatable Hero
On the Other Side!
posted July 30, 2012 01:58 PM

Warning: Big Security Risk With Uplay

article in rockpapershotgun

This is utterly stupid. Thanks to godness that I don't have a single Ubi game with Uplay installed right now
____________

 Send Instant Message | Send E-Mail | View Profile | Quote Reply | Link
Nelgirith
Nelgirith


Promising
Supreme Hero
posted July 30, 2012 02:01 PM

Quote:
article in rockpapershotgun

This is utterly stupid. Thanks to godness that I don't have a single Ubi game with Uplay installed right now

Aren't you playing H6 ?


Anyone playing the following games might be affected :
Assassin’s Creed II
Assassin’s Creed: Brotherhood
Assassin’s Creed: Project Legacy
Assassin’s Creed Revelations
Assassin’s Creed III
Beowulf: The Game
Brothers in Arms: Furious 4
Call of Juarez: The Cartel
Driver: San Francisco
Heroes of Might and Magic VI
Just Dance 3
Prince of Persia: The Forgotten Sands
Pure Football
R.U.S.E.
Shaun White Skateboarding
Silent Hunter 5: Battle of the Atlantic
The Settlers 7: Paths to a Kingdom
Tom Clancy’s H.A.W.X. 2
Tom Clancy’s Ghost Recon: Future Soldier
Tom Clancy’s Splinter Cell: Conviction
Your Shape: Fitness Evolved

 Send Instant Message | Send E-Mail | View Profile | Quote Reply | Link
Storm-Giant
Storm-Giant


Responsible
Undefeatable Hero
On the Other Side!
posted July 30, 2012 02:06 PM
Edited by Storm-Giant at 14:09, 30 Jul 2012.

Nope. After a long break, one year ago I managed to get a beta key, tried it and realized that this wasn't worth it. Eventually I was right

If I've been following everything about this in the last 13 months is because I've been bringing all the news to the spanish community la Torre de Marfil ^^

Oh, and btw, pay attention to this year Gamescom, Ubi may have something to say about M&M
____________

 Send Instant Message | Send E-Mail | View Profile | Quote Reply | Link
markkur
markkur


Responsible
Legendary Hero
Once upon a time
posted July 30, 2012 02:16 PM

"Almost" beyond belief. Seems UBI isn't much concerned with PC protection. I remember when I installed H5; Webroot identified a exe. concerning data-collection that was listed as a critical threat...now this.

<imo>UBI really needs to get out of self-destruct mode and fast.

 Send Instant Message | Send E-Mail | View Profile | Quote Reply | Link
Brukernavn
Brukernavn

Hero of Order
posted July 30, 2012 02:26 PM

This is a MAJOR security risk, giving outright full access to your computer from any website that takes advantage of the UPlay plugin. Ubisoft installs this plugin on your computer when you install UPlay on purpose and without warning. Completely outrageous!

 Send Instant Message | Send E-Mail | View Profile | Quote Reply | Link
War-overlord
War-overlord


Responsible
Undefeatable Hero
Presidente of Isla del Tropico
posted July 30, 2012 02:43 PM
Edited by War-overlord at 14:45, 30 Jul 2012.

Damnit, I cannot find the bloody plugin in my IE. But it is there, since it tests positive. Does anyone know a way to disable it in IE from the outside and without deleting Uplay? I want to keep being able to play Heroes.
I've managed to disable it in Firefox, but I realy dislike using Firefox.
____________
Iron from Ice.

 Send Instant Message | Send E-Mail | View Profile | Quote Reply | Link
Elvin
Elvin


Admirable
Omnipresent Hero
What if Elvin was female?
posted July 30, 2012 03:01 PM

On the bright side of things uplay is already working on a patch which should be ready this afternoon.

Also it has come to my attention that while the current exploit allows the launch of an already installed software, it does not allow the injection of maleware.

In any case.. shame on ubi.
____________
DON'T BE A NOOB, JOIN A.D.V.E.N.T.U.R.E.

 Send Instant Message | Send E-Mail | View Profile | Quote Reply | Link
Tsar-Ivor
Tsar-Ivor


Promising
Legendary Hero
Soli deo gloria
posted July 30, 2012 03:12 PM
Edited by Tsar-Ivor at 15:13, 30 Jul 2012.

Quote:
In any case.. shame on ubi.


Abit of my grand-mother in you Elvin

I was infuriated by the fact that I require internet access in order to install the damn game, anything more is just 'icing on the cake'.
____________
"What is a man? A miserable pile of secrets."

 Send Instant Message | Send E-Mail | View Profile | PP | Quote Reply | Link
OmegaDestroyer
OmegaDestroyer

Hero of Order
Fox or Chicken?
posted July 30, 2012 03:23 PM
Edited by OmegaDestroyer at 15:23, 30 Jul 2012.

Quote:
On the bright side of things uplay is already working on a patch which should be ready this afternoon.


I wouldn't hold my breath if I were you.
____________
The giant has awakened
You drink my blood and drown
Wrath and raving I will not stop
You'll never take me down

 Send Instant Message | Send E-Mail | View Profile | Quote Reply | Link
Elvin
Elvin


Admirable
Omnipresent Hero
What if Elvin was female?
posted July 30, 2012 03:28 PM

I know better than that
____________
DON'T BE A NOOB, JOIN A.D.V.E.N.T.U.R.E.

 Send Instant Message | Send E-Mail | View Profile | Quote Reply | Link
hobo2
hobo2


Promising
Known Hero
posted July 30, 2012 06:57 PM

Well, Heroes VI has been dead on my computer ever since 1.51 came out and broke the game with a botched (and non-optional, non-revertible) update download. Ubisoft's customer service was simply to suggest that maybe I wanted to uninstall the game and try again - admitting no culpability and not even offering an apology.

This is a really serious security problem and makes the choice extremely easy: Heroes VI isn't just getting scrubbed off my computer, it's not coming back. That is not only the last straw, it's a really big last straw and I don't even feel like I'm over reacting a little bit.

 Send Instant Message | Send E-Mail | View Profile | Quote Reply | Link
Storm-Giant
Storm-Giant


Responsible
Undefeatable Hero
On the Other Side!
posted July 30, 2012 07:47 PM
Edited by Storm-Giant at 19:54, 30 Jul 2012.

Version 2.0.4 seems to be released with the fix --> proof

and official statement
____________

 Send Instant Message | Send E-Mail | View Profile | Quote Reply | Link
blizzardboy
blizzardboy


Honorable
Undefeatable Hero
Prince of Poetry
posted July 31, 2012 12:24 AM
Edited by blizzardboy at 00:25, 31 Jul 2012.

Ooooooooh, so that's what that was. I didn't even connect the dots. I thought maybe it was a malware I accidentally picked up at some point.

My Firefox disabled it
____________

 Send Instant Message | Send E-Mail | View Profile | Quote Reply | Link
tabachanker
tabachanker


Hired Hero
posted July 31, 2012 03:23 AM
Edited by tabachanker at 03:25, 31 Jul 2012.

I discover this "gift" from Uplay yesterday in my Firefox plugins.  I tried a lot of things to get rid of them but each time I started Heroes VI, the plugins were back again in Firefox.

You can disable them via Firefox (Keyboard shortcut CTRL-SHIFT-A) and they seem to stay disabled, at least.

Today, when I saw this warning, I tried another thing to get rid of them permanently.  It seems to work alright, the plugins doesn't appear anymore in my Firefox and doesn't reappear after playing Heroes VI.  Also, the game seems to work alright.

Here's what I've done to get rid of them (do this at your own risk!) :
* Open Windows Explorer (Keyboard shortcut: Windows key + E)
* Navigate to folder "C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\".  This is the default directory.  Also, I have Win7 64 bits, so if you have another Windows, it may be in another folder (like "program files" without the "x86" part).
* Rename the file "npuplaypc.dll" to anything else.  I renamed it "npuplaypc.dlll" (extra "l" at the end).

By only renaming the file (without deleting it), you can rename it back if something goes wrong with your game.  Also, this seems to make U(can't)play think you still have the plugins installed in Firefox (since the registry key is still there).  So it didn't try to reinstall them in my browser... yet.
____________

 Send Instant Message | Send E-Mail | View Profile | Quote Reply | Link
Brukernavn
Brukernavn

Hero of Order
posted July 31, 2012 11:56 AM

Quote:
The browser plug-in that we used to launch the application through uplay.com ... [snip] ... An automatic patch was launched that fixes the browser plug-in so that it will only open the Uplay application.

I don't want you to be able to open ANY applications on my computer without my permission! Thankfully I don't have UPlay installed, and hopefully never will.

 Send Instant Message | Send E-Mail | View Profile | Quote Reply | Link
hobo2
hobo2


Promising
Known Hero
posted July 31, 2012 05:30 PM

Yeah, the reassurance doesn't reassure me at all. People already demonstrated how the Uplay plug-in capability to remotely start itself could be hijacked to start other things. I have no faith that people can't figure out how to hijack the capability of the new version.

Uplay is not going back on my machine. Ever. They've already shown that they can't be trusted with my computer's security and I don't trust them with my computer's security.

 Send Instant Message | Send E-Mail | View Profile | Quote Reply | Link
Jump To: « Prev Thread . . . Next Thread »
Post New Poll    Post New Topic    Post New Reply

Page compiled in 0.0325 seconds