Gameguru Mania Updated:10:44 AM CEST Sep,20
66 lottery login

91 club

okwin

bdg game

55 club

Playbonus.ca
CONTACT
Please e-mail us if you have news.

(c) 1998-2025 Gameguru Mania
Privacy Policy statement
SEARCH:
 Gameguru Mania News - Mar,19 2013 -  
EA's Origin Vulnerable to Remote Execution - briefly
(hx) 04:34 PM CET - Mar,19 2013 - Post a comment / read (5)
The chaps at [Re]Vuln have published a paper outlining vulnerabilities in EA's Origin that allow for remote code execution. The embedded video below shows the vulnerability in action.

The basic idea behind the attack is the following. Origin, much like Steam, uses a protocol - origin:// - to launch games on local systems. These links can be shortcuts on the local system or displayed on websites on the Internet. Attackers can make use of that by manipulating the links to load remote payloads on local systems.

While this still means that users need to click on those links, it is likely that mass distribution, for instance via email or a popular website, can lead to a series of attacks on user systems.

The attacker needs to reference a game installed on the user's PC for the payload to be loaded on it. This can be easily done via a brute force type of attack as Origin accepts multiple game IDs listed in the launch url. To make matters worse, the payload can be started with silent commands.

The only workaround right now is to only run games right from within Origin and not from shortcuts or websites. This may limit the available launch parameters right now and if you can't abstain from using shortcuts or links, make sure you only execute them on sites that you trust. Even better, right-click those links and analyze them to make sure that they do not include remote payload commands (check the paper for how this looks like, basically, you should find an IP or domain name near the end that references the attack server).
last 10 comments:
Apathy Curve(05:35 PM CET - Mar,19 2013 )
Excellent! That just leaves the question: electric chair or lethal injection?

heretic(08:04 PM CET - Mar,19 2013 )
That exploit is as good as the UPlay exploit. You can alter the code slightly to format someone's hard drive with it. Wonder how long until it is fixed.

Csimbi(11:18 PM CET - Mar,19 2013 )
John Riccitiello already resigned - not for this reason though.
Sooner or later they're going to have to please the users instead of burying them under rubbish.

Tom(07:19 PM CET - Mar,21 2013 )
Csimbi> John Riccitiello already resigned - not for this reason though.
Sooner or later they're going to have to please the users instead of burying them under rubbish.


EA is noted as one of the worst companies around and their shares have taken a huge drop. Resigned or fired, it was only a matter of time. He was brought in to help the company and instead it's only slid further and further down into the depths of shit. Good riddance I say and hopefully EA can pull themselves out of the toilette John put them into.

Csimbi(09:21 PM CET - Mar,21 2013 )
I would not mind EA going under.
Layoffs with severance packages would result in a few start-ups that might produce better games than EA ever did (or was holding back the employees from doing so).
It would also demonstrate that the power is still with the customers. At the very least, it should be an eye-opener for the other big ones that would remain.

All comments
 Add your comment (free registration required)

related cheats/trainer:

no results found


 External links
DFF NT: Edea's Corpse Appearance Set for Ultimecia PC game found on STEAM...
Just Ignore Them: Brea's Story Tape 1 PC game found on STEAM...
Olea's Descent cheats PC found on CHEATINGDOME...
RPG Maker MV - Alec Shea's Adventure Music Vol 1 PC game found on STEAM...
RPG Maker MV - Alec Shea's JRPG Music Pack PC game found on STEAM...
RPG Maker VX Ace - Alec Shea's Adventure Music Vol 1 PC game found on STEAM...
RPG Maker VX Ace - Alec Shea's JRPG Music Pack PC game found on STEAM...
Visual Novel Maker - Alec Shea's JRPG Music Pack PC game found on STEAM...