Sony/BMG "fix" makes infected computers MORE vulnerable - Gearslutz.com

Gearslutz.com

All Advertisers
Go Back   Gearslutz.com > The Forums > So much gear, so little time!


Sony/BMG "fix" makes infected computers MORE vulnerable

New Reply New Reply Thread Tools Search this Thread
Old 16th November 2005   #1
Gear Guru
 
theblue1's Avatar
 
Joined: Mar 2005
Location: Long Beach, CA
Posts: 15,099

Thread Starter
Sony/BMG "fix" makes infected computers MORE vulnerable

[Mod: I put this here because I couldn't figure where it belonged... please feel free to move it as needed.]

Quote:
Sony DRM infection removal vulnerability uncovered

Tool is worse than original infection


SONY PULLS OFF ANOTHER blatant stupidity in the 'cure is worse than the disease' category. No, not the DRM infection itself, not the security compromising removal agreement, but the removal tool itself. Yes, this one appears to put you in MORE danger than the original rootkit. Silly Sony, no cookie.
According to Freedon To Tinker, the web based installer is a worse vulnerability than the original rootkit. More on the story here, FTT goes into detail. It seems the 'cure' from Sony involves downloading an ActiveX control called CodeSupport. This is a signed control that lets just about anyone download, install and execute arbitrary code on your machine.

See a problem? See a big problem? To make matters even funnier, the uninstaller, supposedly anyway, leaves this control on your machine. So, the Sony uninstaller is not a total uninstaller, it leaves a hole you can drive a truck through on your system, silently of course.

The more disturbing part is that it appears the control is signed. I wonder who at MS approved this, and how this blatant security hole got through the barest minimum of QC? Moral, if you bought Sony products, you are screwed. If it causes you problems, you are screwed more. If you uninstall, you are screwed yet harder. If you uninstall it yourself, you are a criminal under the DMCA. If you use an antivirus program to uninstall it, you spent money to fix Sony's problems, and you are still a criminal. That's what you get for buying music.
from Brit tech news mag: The Inquirer


And... it turns out this may be a VERY large problem for a VERY LARGE number of people, business -- and the government and the military -- which research shows are big recipients of Sony's software "largesse"...

Quote:
More than half a million networks, including military and government sites, were likely infected by copy-restriction software distributed by Sony on a handful of its CDs, according to a statistical analysis of domain servers conducted by a well-respected security researcher and confirmed by independent experts Tuesday.

... Using statistical sampling methods and a secret feature of XCP that notifies Sony when its CDs are placed in a computer, Kaminsky was able to trace evidence of infections in a sample that points to the probable existence of at least one compromised machine in roughly 568,200 networks worldwide. This does not reflect a tally of actual infections, however, and the real number could be much higher.

Each installation of Sony's rootkit not only hides itself and rewrites systems drivers, it also communicates back to Sony and the creators of the software, British company First 4 Internet and Phoenix-based SunnComm Technologies, who handled the Mac side for Sony.

... Kaminsky discovered that each of these requests leaves a trace that he could follow and track through the internet's domain name system, or DNS. While this couldn't directly give him the number of computers compromised by Sony, it provided him the number and location (both on the net and in the physical world) of networks that contained compromised computers. That is a number guaranteed to be smaller than the total of machines running XCP.
Wired


The Wired article goes on to state that one in 6 domain name servers showed 'knowledge' of the Sony address -- reflecting a very, very broad penetration of this Sony-sponsored spyware trojan.
theblue1 is offline   Reply With Quote
Old 16th November 2005   #2
Gear nut
 
Joined: Jun 2003
Posts: 118

That's so funny - or disturbing, I haven't decided! I might be a little behind the times, but didn't Microsoft pledge to crack the Sony code (this according to the 'Metro' newspaper, London edition, yesterday)?

fish
fishman is offline   Reply With Quote
Old 16th November 2005   #3
Gear Guru
 
theblue1's Avatar
 
Joined: Mar 2005
Location: Long Beach, CA
Posts: 15,099

Thread Starter
Yeah... I'm working from memory, here, but, as I remember it, MS promised to specifically address the Sony debacle with a fix that will appear, I think, as part of or an adjunct to, one of their PC security free tools (or maybe their new online scan... it's a bit hazy, my memory is.)
theblue1 is offline   Reply With Quote
Old 17th November 2005   #4
Gear maniac
 
Joined: May 2005
Posts: 222

atleast my zeppelin LP's never installed a rootkit into my stereo.
achtung baby is offline   Reply With Quote
Old 17th November 2005   #5
Gear addict
 
Joined: Jun 2005
Location: Tasmania, Australia
Posts: 305

meh.. and obviously their failing sales are due to piracy!... not to do with them treating their customers like crap...

Has anyone else noticed that the independant label sales are rising massively.. arent they subjected to piracy too?

major labels are just terrible these days it seems
__________________
The Gear-less Slut
username is offline   Reply With Quote
New Reply New Reply Submit Thread to Facebook Facebook  Submit Thread to Twitter Twitter  Submit Thread to LinkedIn LinkedIn 



Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread starter Forum Replies Last Post
PART 2:Must have "MICS"under 1k pr? Favorite "Sleeper" "ROOM" Mics? "Out of the Norm" betsy Low End Theory 41 6th July 2009 08:15 PM
"That's a great take! C'mon in let's fix it!" Is "Pro Tool" a verb? sawhorse The Moan Zone 4 23rd August 2006 03:03 AM
"K-Fed Makes Prime Time" Alex.T Rap + Hip Hop engineering & production 7 20th July 2006 07:15 AM
Spectral Computers, aka "Digital Corp" sucks ballz!!! Jay Kahrs The Moan Zone 27 12th July 2006 10:12 PM
New Rush "R30" DVD makes me sad rvwainscott The Moan Zone 16 10th July 2006 11:12 PM


All times are GMT +1. The time now is 07:36 AM.

Home - Search Forum - Contact Us - Terms Of Use - Advertise on Gearslutz - All Advertisers - Archive - Top
 
 
Powered by vBulletin®
Gearslutz.com LTD - UK Company Number 7597610.
Registered Office - 35 Ballards Lane, London, N3 1XW.
Hosted by Nimbus Hosting.

SEO by vBSEO ©2010, Crawlability, Inc.