Jump to content


Photo

EA Origin Security Flaw Could Expose Tens of Millions of Players


  • Please log in to reply
11 replies to this topic

#1 BlueBlur

BlueBlur

    Code Breaker!

  • Members
  • 726 posts
  • NNID:Pokemaster94
  • Fandom:
    Pokemon, Mario, and Sonic the Hedgehog

Posted 20 March 2013 - 08:29 AM

Thing are looking worse and worse for EA it seems :(

 

revuln-ea-origin-exploit.jpg?w=720&h=480

When it rains, it pours: Electronic Arts, currently grappling with game-breaking SimCity server issues as well as the surprise resignation of CEO John Riccitiello, might have to add “millions of players at risk of being hacked” to its list of woes.

It seems EA’s Origin gaming service may place tens of millions of players (the service has around 40 million members total) at risk thanks to a design flaw that allows a hacker to execute malicious code on a targeted user’s system remotely. EA Origin is EA’s digital distribution platform as well as anti-piracy mechanism, operating as a sort of relay between players and EA’s game servers similar to Valve’s older, more popular Steam service. EA games like DICE’s Battlefield 3 or EA Maxis’ SimCity require the EA Origin client to run, and it’s an exploitable flaw in that process on Windows PCs, whereby the Origin client employs web-like addresses to access games, that’s at issue.

The paper outlining the exploit, titled “EA Origin Insecurity (When Local Bugs Go Remote.. Again),” was actually published in late February, so it’s likely making waves now because of all this other EA-related chatter — it didn’t just happen yesterday, in other words — but it is worth being aware of what’s at stake, since EA hasn’t addressed the problem, and there may be steps you can take to safeguard yourself until they do.

The research team responsible for outing the exploit operates under the company name [Re]Vuln Ltd. and consists of two people: one a former security researcher for Research in Motion, the other describing himself as an “independent security researcher.”

How does the exploit work? According to the researchers, if you’re launching an EA Origin game from a website or desktop shortcut, a hacker could abuse the “Origin URI handling mechanism,” meaning Origin links styled by the URI handler as “origin://” plus game, game ID, command parameters and an attacker’s payload. The exploit still requires hackers suss your game ID, but if they do, they could easily slip attack code in — say a remote DLL file — through the URI handler, then use that code to crack open your system.

Assuming the exploit checks out — [Re]Vuln offers a video of the hack as evidence and, according to the BBC, just demonstrated the attack at the Black Hat Europe conference – the researchers advise using a URL-blocker like URLProtocolView to impede Origin’s URI handler. While this means you wouldn’t be able to run EA Origin games from shortcuts or Internet sites with custom command parameters, the researchers say you can still launch games securely from within the Origin game client itself.

The researchers discovered a similar flaw in Valve’s Steam client last October: URLs beginning “steam://” that allow hackers to slip in malicious code. The bigger question, then, is why EA didn’t act last year to address this. Also: why Valve hasn’t yet addressed the issue with its apparently still-vulnerable Steam client.


source


Edited by VGCrasher, 20 March 2013 - 08:30 AM.


#2 Nollog

Nollog

    Chain Chomp

  • Banned
  • 776 posts
  • NNID:Nollog
  • Fandom:
    Creepy Stalker Girl

Posted 20 March 2013 - 08:43 AM

The researchers discovered a similar flaw in Valve’s Steam client last October: URLs beginning “steam://” that allow hackers to slip in malicious code. The bigger question, then, is why EA didn’t act last year to address this. Also: why Valve hasn’t yet addressed the issue with its apparently still-vulnerable Steam client.

source

Because they're not idiots.


Warning: Cannot modify header information - headers already sent by (output started at /home/thewiiu/public_html/ips_kernel/HTMLPurifier/HTMLPurifier/DefinitionCache/Serializer.php:133) in /home/thewiiu/public_html/ips_kernel/classAjax.php on line 328
{"success":1,"post":"\n\n
\n\t\t<\/a>\n\t\t\n\t\n\t\t\n\t\t
\n\t\t\t\n\t\t\t\t


#3 Cozmo

Cozmo

    Chain Chomp

  • Members
  • 630 posts

Posted 20 March 2013 - 09:45 AM

nintendo did thre smart thing in not using orgin :P



#4 emmonsh

emmonsh

    Red Koopa Troopa

  • Banned
  • 61 posts

Posted 20 March 2013 - 09:47 AM

pretty sure this doesnt effect consoles. only pcs  and as long as you dont give the ok to dl the client  should be no problem



#5 Cozmo

Cozmo

    Chain Chomp

  • Members
  • 630 posts

Posted 20 March 2013 - 10:01 AM

pretty sure this doesnt effect consoles. only pcs  and as long as you dont give the ok to dl the client  should be no problem

 

oh well then i guess it is still good that they ddnt bc now they dont look bad for using it :P



#6 Alex Wolfers

Alex Wolfers

    Thy Fur Consumed

  • Members
  • 2,768 posts
  • NNID:AxGamer
  • Fandom:
    Furry Fandom,gaming,trolling

Posted 20 March 2013 - 11:28 AM

All this crap makes me wonder if EA is even fixable. If so they are still probably going to be crippled in the end.

Signature_DK.png


#7 Colinx

Colinx

    Pokey

  • Members
  • 1,301 posts
  • Fandom:
    Animal Crossing & SeaWorld

Posted 20 March 2013 - 11:41 AM

No wonder why the CEO left. LOL. Nice job just leaving a pile of dirt on someone else's desk.  :laugh:


2lvmghw.png


#8 Plutonas

Plutonas

    Pokey

  • Members
  • 1,319 posts

Posted 20 March 2013 - 11:47 AM

and what about ps4 and 720... which use the same tech as pcs... x86... hehe  Or even steambox.


Edited by Plutonas, 20 March 2013 - 11:47 AM.


#9 Alii

Alii

    Cheep-Cheep

  • Members
  • 104 posts
  • NNID:zangoose
  • Fandom:
    Animal Crossing / Kirby / Pokemon

Posted 20 March 2013 - 12:32 PM

Thank god i did'int make an origin's account,

Last week i was tempted to get Sim's City,

Look's like i'll just forget about that.

 

Good luck with that EA.  <_<


small_zpsfe204a57.jpg


#10 TheSparrow87

TheSparrow87

    Thwomp

  • Members
  • 320 posts

Posted 21 March 2013 - 03:16 AM

Played Warp for the first time in ages yesterday,

found a malicious DLL file this morning after Chrome started acting weird.

Hope I managed to remove everything and nothing was really compromised.



#11 SoldMyWiiUAndLeftTheForums

SoldMyWiiUAndLeftTheForums

    Pokémon Trainer

  • Members
  • 4,168 posts

Posted 21 March 2013 - 05:12 AM

Another screw up from EA, with all the news about EA over the last 2-3 months which most of it might I say has been bad news, I can't see them lasting much longer.



#12 Pjsprojects

Pjsprojects

    Chain Chomp

  • Members
  • 681 posts
  • Fandom:
    BF4-pc,GTA-360,Splinter cell-pc

Posted 21 March 2013 - 06:09 AM

Great, just gone back in to pc gaming after leaving it for ten years and this is the sort of problems that put me off in the first place.


Posted Image

Add me on Miiverse !! I'm from England but the world is a lot smaller online!




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Anti-Spam Bots!