EA's Game Distribution Platform Origin Hack


Written by: (@QuintLyn) | March 18, 2013 4:50 pm

EA's Game Distribution Platform Origin Hack
19 Comments

A bug in EA’s game distribution platform, Origin allows hackers to hijack players PCs.

Today is proving to be an interesting day for EA. First they announce the list of games they are offering as an apology to gamers who suffered issues during SimCity‘s launch. Then, EA CEO John Riccitiello submitted his resignation. And now, we have a bug in Origin that allows attackers to access users’ computers remotely.

According to a demonstration at the Black Hat security conference in Amsterdam more than 40 million people could be affected by this. A paper written by ReVuln researchers Donato Ferrante and Luigi Auriemma to accompany the demonstration states:

The Origin platform allows malicious users to exploit local vulnerabilities or features by abusing the Origin URI handling mechanism, in other words, an attacker can craft a malicious Internet link to execute malicious code remotely on [a] victim’s system, which has Origin installed.

Researchers from ReVuln also spoke with ArsTechnica about the bug, stating that it takes seconds to execute and in some cases doesn’t even require the user being attacked to interact with it, can be used to access both PCs and Macs. Essentially, it works by manipulating uniform resource identifiers on EA’s site to automatically start games on the victim’s computer, which allows the attacker to use Origin to install malicious files on them.

Haven’t we seen this before?

In October, the same research group demonstrated something similar with Valve’s store platform, Steam. Attackers could set up URLs starting with “Steam:// to fool applications into thinking they were accessing safe code. Users were advised to turn off the automatic launching of Steam URLs to avoid the exploit.

Origin’s works in a same way, by exploiting a function that allows sites to start games remotely.

EA response

An EA spokesperson sent an email to ArsTechnica saying: “Our team is constantly investigating hypotheticals like this one as we continually update our security infrastructure.”

The good news here is that at least it was researchers that figured it out first.

 

 


  • http://twitter.com/greencactaur green cactaur

    Wow ever since this whole Sim city crap, EA has been getting so much slack. I LOVE IT. It may be the masochist in me, but I love seeing companies like EA burn

    • wut

      I think you mean sadist

      • oh boy

        green cactaur is the worst kind of masochist there is – an idiot

    • http://www.facebook.com/spankthismonkey Thomas Vu

      slack? I think you been flak

      • Zerek

        been? i think you mean..mean :P

        • http://www.facebook.com/spankthismonkey Thomas Vu

          lol

  • dragontheory42

    Im glad I read the whole thing, cause a normal consumer would have just phreaked out and assumed they were hacked. Glad they found out first that it “CAN” be done. Didnt somthing like that happen with playstation?

    • KShadow

      A typical alarmist title to a report. Why not say “researchers reveal origin exploit.”

      • http://www.facebook.com/kevin.cox.5817 Kevin Cox

        I’m guessing you missed the obvious sarcasm in the title and took it instead as them trying to be sensationalist.

        You think too much. Just read the articles they post if it interests you. Smart people can think for themselves. Dumb people can’t but they’re ignored anyway.

        • KShadow

          Hi Kevin,

          Yes, I guess I am dumb because I missed the “sarcasm”, that’s why I read the whole thing from a reputable source right? All you have to do is to read the Facebook comments to the picture above. It is clear that the majority did not read the article and took the title for face value; ergo, the title creates negative opinions towards the subject that is portrayed with a less than accurate statement. Your scholarly eloquence in this matter is exemplary to everyone reading this thread. I will take your advice and remove the GTV feed since it is no longer interesting to me and mainly tailored towards a certain type of crowd. Anyway, I am going to stop here because as you stated: “Smart people can think for themselves. Dumb people can’t but they’re ignored anyway.”

          • http://www.facebook.com/kevin.cox.5817 Kevin Cox

            i was referring the WoW article title you referenced as the one that was “obviously sarcastic.” Guess I should’ve made that more obvious.

            “tailored towards a certain type of crowd”……

            ….people with a sense of humor?

            “I am going to stop here because as you stated: “Smart people can think for themselves. Dumb people can’t but they’re ignored anyway”

            Guess I’m not dumb then. I’ll let you figure out why. Cheers :)

  • Matthew Burns

    Another EA problem, shocking.

  • Eric Davenport

    People use Origin?

  • Mike Richardson

    Why do I think that EA brings all of this stuff upon themselves.

  • http://twitter.com/QuietNine Quiet

    On what planet is security researchers publicly releasing and demonstrating proof of concepts passed off as “hypotheticals?” Only on EA’s planet.

  • LusitanGaming

    i love the “… investigating hypotheticals…” remark, clearly that guys at ReVuln are lying, right ^^

  • Revanhavoc

    My God, I would have called this kind of story fantasy when Origin first came out. That was obvious naivete on my part! Never underestimate hackers. It’s like Mike B.’s worst nightmare – I remember him going on an on about evil origin and Gary was all like “Oh get over yourself – what do you think it’s going to take over the world or something??”

    Apparantly so, Gannonator, apparantly so…

    • DoctorOverlord

      I hope they can get MikeB on TWIMMO or another show to talk about this, it should be entertaining :)

  • http://twitter.com/dularr Dularr

    From the article it doesn’t seem that Origin got hacked, but it does seem to be a nasty gap in EA security. Wow, just simply wow. Just shows you need a remote authenticator for any of the online games.

RECOMMENDED FOR YOU
Take a Poll

What Is Your Most Anticipated MMO?

View Results

Loading ... Loading ...
Monday
6 pst

The Republic

Star Wars The Old Republic

Tuesday
9:30 pst

After Dark

Live Call In Show

n/a

Monty's Minute

Have Questions? He Has Answers

Wednesday
3 pst

OMGLOL

League Of Legends Drama

6 pst

Guildcast

Guild Wars 2

8 pst

Klaus & Squirrel

Gameplay Duo

Thursday
8 pst

Legendary

World of WarCraft

Friday
3 pst

TWIMMO

This Week In MMO



TOP GAMES
Guild Wars 2 MMO News
Genre: MMORPG Fantasy
Developer: Arenanet
Metacritic Score: 90
The Elder Scrolls Online MMORPG News
Genre: MMORPG Fantasy
Developer: Zenimax
Metacritic Score: n/a
World of Warcraft MMO News
Genre: MMORPG Fantasy
Developer: Blizzard
Metacritic Score: 82
SWTOR MMO News
Genre: MMORPG SciFi
Developer: Bioware
Metacritic Score: 85
League of Legends News
Genre: MOBA
Developer: Riot
Metacritic Score: 78