EA's Origin Leaves Gamers Vulnerable to Hackers

4.8
Research group ReVuln has found a potentially dangerous URI exploit within EA's Origin client which could leave as many as 40 million gamers vulnerable.

The ReVuln team gave a presentation last week at the Black Hat security conference in Amsterdam. Apparently, getting someone to click on an "origin://" prefixed link is all it takes, as the Origin client then downloads a dynamic link library file to the victim's computer. The ReVuln team has also released a paper, detailing the exploit, which mentions a similar vulnerability discovered in Valve's Steam platform last year.

Speaking to Ars Technica, Electronic Arts says the company is aware of the issue, and seems to be addressing the problem in some manner.

"Our team is constantly investigating hypotheticals like this one as we continually update our security infrastructure", said an EA spokesperson.

Posted:

Source: http://au.ign.com/articles/2013/03/19/eas-origin-has-an-exploit-leaving-gamers-vulnerable-to-hackers

Comments

"EA's Origin Leaves Gamers Vulnerable to Hackers" :: Login/Create an Account :: 169 comments

If you would like to post a comment please signin to your account or register for an account.

Soldier_Posted:

iHTML
Maya
Ozar Guys this problem is fixed now


Good.


This is good to hear as this would of been a huge problem


Yeah it would've.

undisclosedPosted:

Well thanks EA. (I hope you know I'm being sarcastic)

BruPosted:

Maya
Ozar Guys this problem is fixed now


Good.


This is good to hear as this would of been a huge problem

Soldier_Posted:

Ozar Guys this problem is fixed now


Good.

Soldier_Posted:

Evol
Moiros If this applies to Xbox too there might be a problem with Microsoft as well.


i don't think it is with MS
but its all good now its been fixed.


I think MS is fine.

MultitaskPosted:

Moiros If this applies to Xbox too there might be a problem with Microsoft as well.


i don't think it is with MS
but its all good now its been fixed.

OzarPosted:

Guys this problem is fixed now

DLTPosted:

Evol
Relations Well done for fixing it so fast, things could of went bad real fast...


lol yep hackers could of taken advantage.


You would still need to click on an Origin:// link before anything bad could happen, and it's not like that prefix would be un-noticeable when you click it.

MultitaskPosted:

Relations Well done for fixing it so fast, things could of went bad real fast...


lol yep hackers could of taken advantage.

MultitaskPosted:

glad it got handle quick great job EA :)