1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Sony, Rootkits and Digital Rights Management Gone Too Far

Discussion in 'Security and Privacy' started by charlesvar, 2005/11/01.

  1. 2005/11/01
    charlesvar

    charlesvar Inactive Alumni Thread Starter

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    http://www.sysinternals.com/blog/2005/10/sony-rootkits-and-digital-rights.html

    Regards - Charles
     
  2. 2005/11/02
    McTavish

    McTavish Inactive

    Joined:
    2005/06/24
    Messages:
    576
    Likes Received:
    1
    This is outrageous and almost beyond belief.
    I’ll make sure none of my hard earned cash goes to Sony again.
    Thanks for the heads-up Charles.
     

  3. to hide this advert.

  4. 2005/11/03
    JoeHobart

    JoeHobart Inactive Alumni

    Joined:
    2004/05/19
    Messages:
    919
    Likes Received:
    1
    it will be fun to see how this turns out. still hasnt gotten picked up by msnbc/cnn type news outlets, but its one slow news cycle from getting some strong press. Boy oh boy will it be fun to watch the marketing weasels spin it when it does.

    I'm really curious how mark is able to get away with that, i'd never be able to post that kind of stuff, the legal department keeps a special furnace stoked to burn that kind of stuff, thats why theres no joeblog :(
    -----
    This Service Pack removes the cloaking technology component that has been recently discussed in a number of articles published regarding the XCP Technology used on SONY BMG content protected CDs. This component is not malicious and does not compromise security. However to alleviate any concerns that users may have about the program posing potential security vulnerabilities, this update has been released to enable users to remove this component from their computers
    http://updates.xcp-aurora.com/
     
  5. 2005/11/03
    charlesvar

    charlesvar Inactive Alumni Thread Starter

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    http://secunia.com/advisories/17408/



    Then as of 11/02:
    http://news.com.com/Sony+to+patch+copy-protected+CD/2100-7355_3-5928608.html?tag=nefd.lede

    Regards - Charles
     
  6. 2005/11/03
    McTavish

    McTavish Inactive

    Joined:
    2005/06/24
    Messages:
    576
    Likes Received:
    1
  7. 2005/11/03
    charlesvar

    charlesvar Inactive Alumni Thread Starter

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    Thanks McTavish for the reference to the beeb :)

    I've been waiting for this to hit the large news outlets and like Joe really curious how this will be spun.

    As an aside for anyone that's interested on how to prevent the software from installing: from my reading, having autorun on or off is irrelevant (if you're not aware of the software), playing the disc does the install. This can only be installed on a system with Admin rights, anything less will trigger a request to change user, provided very conveniently by the Sony software.

    The other way is to use process control software such as ProcessGuard or System safety Monitor which intercept executions and asks for permission.

    Regards - Charles
     
    Last edited: 2005/11/03
  8. 2005/11/04
    Dennis L Lifetime Subscription

    Dennis L Inactive Alumni

    Joined:
    2002/06/07
    Messages:
    2,557
    Likes Received:
    2
    As most of us, Sony's wake-up call rings loud and clear ..
    I'm the good guy, trust me... "said the spider to the fly ".
    With the playing field jaded with such irresponsible activity the user is forced again to review security and the cost(s) to implement it.
     
  9. 2005/11/04
    Hugh Jarss

    Hugh Jarss Inactive

    Joined:
    2002/07/22
    Messages:
    908
    Likes Received:
    6
    (with apologies for missing this thread when I posted earlier today)

    here's the other BBC article - a couple more points, including Philips' attitude (these are "music delivery systems ", not Compact Discs, so cannot carry the CD logo)
    one way would be to avoid putting lookalike discs (without the CD logo) into your machine :p but soon, the way things are going, that option will severely limit your choice of music...

    I found the points about Macs and Linux interesting too.

    ==

    If you put "sony van zant CD" into Google you currently get MR's Sysinternals blog, top of the list ;) - put "van zant CD" and MR's blog is still only 3rd result down

    best wishes, HJ.
     
    Last edited: 2005/11/04
  10. 2005/11/05
    charlesvar

    charlesvar Inactive Alumni Thread Starter

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    More on Sony: Dangerous Decloaking Patch, EULAs and Phoning Home

    http://www.sysinternals.com/blog/2005/11/more-on-sony-dangerous-decloaking.html


    Security-spooked Users Slap Sony CD On Amazon
    By Gregg Keizer, TechWeb News

    http://www.techweb.com/showArticle.jhtml?articleID=173403155

    Regards - Charles
     
  11. 2005/11/05
    charlesvar

    charlesvar Inactive Alumni Thread Starter

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    Hi Dennis,

    Certainly agree - thats what makes this particular case so troublesome.

    My take on "good" guys in other ways is not very complimentary.

    One of my neuralgia points is software that installs startups when not necessary and this IMH does "damage" over the long run because that slows the system down, creates potential conflicts, and makes the "upgrade" treadmill that much faster. This is really myopia on the part of software vendors who seem to have no compunction about cluttering up systems w/o regard of the consequences to the user.

    Most people, judging from what I've seen and read here and elsewhere aren't aware of it, what they are aware of - my system is slow or some other conflict caused problem which can very subtle and hard to diagnose. Even if they are aware of it, aren't sure what to do about it - would it be harm full to stop them, where to get the info, it won't stay disabled, not listed in msconfig, etc?

    A classic case, a friend purchased a new HP printer. Of the five startups - four were totally unnecessary, and disabled them. The functions that were disabled are executed as soon as needed anyway. I've got a Dell printer/scanner, same deal, the scanner "Button manager" is a startup, and to add insult to injury, not accessible thru msconfig, had to use autoruns to disable it.

    Regards - Charles
     
    Last edited: 2005/11/05
  12. 2005/11/08
    charlesvar

    charlesvar Inactive Alumni Thread Starter

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    For everybody's FYI: what rootkits are and how they work:

    Windows rootkits in 2005, part one

    http://www.securityfocus.com/infocus/1850?ref=rss

    Regards - Charles
     
  13. 2005/11/09
    charlesvar

    charlesvar Inactive Alumni Thread Starter

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    Computer Associates has declared Sony's DRM Rootkit as spyware.
    http://www3.ca.com/securityadvisor/pest/collateral.aspx?cid=76345

    Regards - Charles
     
  14. 2005/11/10
    Top Dog

    Top Dog Inactive

    Joined:
    2002/01/07
    Messages:
    102
    Likes Received:
    0
    There evidently is a trojan out now that uses the Sony Rootkit to hide itself. Just as Mark Russinovich predicted, of course.

    A partial list of Sony CD titles with the Rootkit include:
    (according to -> http://www.eff.org/deeplinks/archives/004144.php )

    Trey Anastasio, Shine (Columbia)
    Celine Dion, On ne Change Pas (Epic)
    Neil Diamond, 12 Songs (Columbia)
    Our Lady Peace, Healthy in Paranoid Times (Columbia)
    Chris Botti, To Love Again (Columbia)
    Van Zant, Get Right with the Man (Columbia)
    Switchfoot, Nothing is Sound (Columbia)
    The Coral, The Invisible Invasion (Columbia)
    Acceptance, Phantoms (Columbia)
    Susie Suh, Susie Suh (Epic)
    Amerie, Touch (Columbia)
    Life of Agony, Broken Valley (Epic)
    Horace Silver Quintet, Silver's Blue (Epic Legacy)
    Gerry Mulligan, Jeru (Columbia Legacy)
    Dexter Gordon, Manhattan Symphonie (Columbia Legacy)
    The Bad Plus, Suspicious Activity (Columbia)
    The Dead 60s, The Dead 60s (Epic)
    Dion, The Essential Dion (Columbia Legacy)
    Natasha Bedingfield, Unwritten (Epic)
    Ricky Martin, Life (Columbia) (labeled as XCP, but, oddly, our disc had no protection)

    Several other Sony-BMG CDs are protected with a different copy-protection technology, sourced from SunnComm, including:

    My Morning Jacket, Z
    Santana, All That I Am
    Sarah McLachlan, Bloom Remix Album

    This is not a complete list.


    I've also read that some high performance game machines CD/DVD's can be 'disconnected' from windows on a reboot after rootkit infection.

    Nasty - Nasty
     
  15. 2005/11/11
    charlesvar

    charlesvar Inactive Alumni Thread Starter

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    Yep, and here it is:

    http://news.bitdefender.com/NW193-en--First-Trojan-Using-Sony-DRM-Detected.html

    Regards - Charles
     
  16. 2005/11/11
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
  17. 2005/11/12
    charlesvar

    charlesvar Inactive Alumni Thread Starter

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    Sony to Suspend Making Antipiracy CDs
    http://www.wjla.com/news/stories/1105/277015.html

    A senior Homeland Security official at Security Fix:
    http://blogs.washingtonpost.com/securityfix/2005/11/the_bush_admini.html

    Regards - Charles
     
  18. 2005/11/12
    charlesvar

    charlesvar Inactive Alumni Thread Starter

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
  19. 2005/11/13
    Alchemy

    Alchemy Inactive

    Joined:
    2002/01/07
    Messages:
    18
    Likes Received:
    0
    Based on the following blog entry from the Microsoft AntiMalware Engineering Team, Microsoft will also treat the rootkit component of this as malware and will provide detection and removal in its tools, including the monthly Malicious Software Removal Tool.

    Anti-Malware Engineering Team

    We can only hope that Sony suffers financially from this poor decision.

    Steph
     
  20. 2005/11/14
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    With Class Action lawsuits in California and New York and probably some others a little later, I think they will be seriously stung.

    With additional loss of revenue from those of us who plan to avoid their stuff, they will be hurt even more.

    What I haven't read is that anyone plans to go after the folks that wrote this abomination for Sony and then compounded their mistake by turning some poodle puppy programmers loose to attack Dr. Mark Russinovich and his findings. At a guess, he has forgotten more than most of them have learned.
     
  21. 2005/11/14
    charlesvar

    charlesvar Inactive Alumni Thread Starter

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    http://www.dslreports.com/forum/remark,14783731~days=9999

    SONY throws in the towel ... for now.

    This is a ongoing thread at dslreports - in which the big news is this:

    Kevin McAleavey of BOClean has determined that
    If this indeed turns out to be the case, Sony is truely s c r e w e d because their only legal defense is the EULA.

    So it is very important that everyone turn off autoplay, which was always a good idea anyway, but this sort of thing makes it imperative.


    Another thread at dsl on the legal ramafications of trying to remove not only the rootkit but also the other components, among which are "phone home" and CD filtering software that the Rookit intalled, that the current providers of "removal" tools are not supplying because of DCMA legal implications: Microsoft will wipe Sony's 'rootkit' and more http://www.dslreports.com/forum/remark,14802823~days=9999

    Regards - Charles
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.