Slashdot Mirror


Trojan Using Sony DRM Rootkit Spotted

Analise writes "The Register reports on the first trojan using Sony's DRM rootkit. A newly discovered variant of the Breplibot trojan makes use of the way Sony's rootkit masks files whose filenames begin with '$sys$'. This means that any files renamed this way by the trojan are effectively invisible to the average user. The malware is distributed via an email supposedly from a reputable business magazing requesting that the businessperson verify his/her attached 'picture' to be used for an upcoming issue. Once the payload is executed, the trojan then installs an IRC backdoor on affected Windows systems."

92 of 597 comments (clear)

  1. Rant Time... by Anonymous Coward · · Score: 2, Interesting

    Sony, you are despicable loathing scum who will no longer get another penny from me. For deliberately putting computers I maintain at risk to save a penny on your end, I find you guilty as charged. Microsoft should be suing you for such as well. In fact everyone just gang up on Sony and charge with those attorneys. Burn in hell bastards...

    1. Re:Rant Time... by freedom_india · · Score: 5, Funny
      With California filing a class-action suit, i think more states and consumers should file suits NOT just for damaging their computers, but delibrate unauthorized entry into another person's property which is a crime.

      Seriously i wish some Sony officials got what Worldcomm's Ebbers got: 25 years for entering into another property without permission, vandalism, etc. The less privileged have got far worse sentences for lesser crimes all along

      And more so, Sony should replace EVERY affected computer with a brand new Vaio.

      --
      "Doing what i can, with what i have." ~ Burt Gummer
    2. Re:Rant Time... by xlr8ed · · Score: 5, Funny
      Sony should replace EVERY affected computer with a brand new Vaio



      That would be a crime in itself...
    3. Re:Rant Time... by PeteDotNu · · Score: 3, Insightful

      "And more so, Sony should replace EVERY affected computer with a brand new Vaio"

      I'd prefer the cash alternative.

      --
      My other processor is big-endian.
    4. Re:Rant Time... by mmzplanet · · Score: 4, Funny

      "And more so, Sony should replace EVERY affected computer with a brand new Vaio." Upon the annoucement of this, Sony sees record sales of its DRM'd CDs.

    5. Re:Rant Time... by MaTriXxx1 · · Score: 2

      >> Sony should replace EVERY affected computer with a brand new Vaio. What??? dude come on.... thats like replacing a turd sandwich with a giant douche.... Vaios are by FAR the worst systems I have had to fix. Advertly.... if Sony was to PAY for a new system, Id go with a new AMD 64, 3500, wo0t

      --
      Do NOT goto this URL http://www.forthesims.com
    6. Re:Rant Time... by NormalVisual · · Score: 3, Informative

      California is *not* filing a class-action suit. A private lawyer is filing a suit on behalf of a number of California residents, but the state is not involved with it. Apparently both the submitter of the earlier Sony story and approving "editor" failed to actually read the article that was submitted.

      --
      Please stand clear of the doors, por favor mantenganse alejado de las puertas
    7. Re:Rant Time... by mwood · · Score: 3, Informative

      "So how do you put a corporation in jail?"

      Revoke their import/export licenses.

      Stop the trading of their securities.

      Lots of other ways. You need all kinds of permissions to do big business. Those permissions can be withdrawn.

  2. Jobseekers rejoice! by Ooblek · · Score: 5, Funny

    It's just a rumor, but Sony should have some Engineering and Executive positions open in 3....2....1...

    1. Re:Jobseekers rejoice! by portwojc · · Score: 4, Insightful

      It's not the enginners fault. It's the ones that decided to put it out.

    2. Re:Jobseekers rejoice! by Daniel_Staal · · Score: 5, Insightful

      Remember: Sony didn't write the rootkit. They bought it from someone else.

      Now, the question is, what department thought it was a good idea? Sales and Marketing? Legal? Somebody had to think it was worth the money...

      --
      'Sensible' is a curse word.
    3. Re:Jobseekers rejoice! by Fx.Dr · · Score: 3, Interesting

      Does this now mean that Sony is open to criminal negligence lawsuits as well?

    4. Re:Jobseekers rejoice! by Guppy06 · · Score: 4, Funny

      " Remember: Sony didn't write the rootkit. They bought it from someone else."

      Remember: your Friendly Neighborhood Crack Dealer didn't grow the coca. They bought it from someone else.

    5. Re:Jobseekers rejoice! by ConceptJunkie · · Score: 2, Insightful

      Yeah, Sony only delivered it to people just trying to listen to music.

      I sure (Insert Your Favorite Murderer Here) didn't manufacture the bullets he used to kill his victims either.

      --
      You are in a maze of twisty little passages, all alike.
    6. Re:Jobseekers rejoice! by NickFortune · · Score: 3, Insightful
      Remember: Sony didn't write the rootkit. They bought it from someone else.

      That sounds like you're letting Sony off the hook, but I don't think it works like that. I mean, suppose I were to sell you a poisoned soda and that as a result you nearly die. Would it matter if I bought the poison from someone else?

      Not to mention trying to conceal its presence and lying about its function.

      I think Sony stand to take a hiding over this one.

      --
      Don't let THEM immanentize the Eschaton!
    7. Re:Jobseekers rejoice! by 3dr · · Score: 5, Funny

      No, you don't wait to get fired.

      If a task is against your principles, ask for a different task. If none exist, ask for a transfer. If impossible, then quit.

      Principles are greater than profits.

      Or you can be spineless and sell out.

    8. Re:Jobseekers rejoice! by Lemmy+Caution · · Score: 4, Interesting

      Eh, that's a little "I was only following orders" for my blood.

      If I'm working for a homicidal maniac and I build a gun for him, I'm not innocent when he goes on a rampage.

      Werner Heisenberg claims that he sabotaged the Nazi atomic bomb effort. If that's true, this would have been a very different world if he had just decided to be a "good engineer." (Yes, Godwin, blah blah. I don't think it applies.)

    9. Re:Jobseekers rejoice! by jcr · · Score: 2, Insightful

      It's not the enginners fault. It's the ones that decided to put it out.

      Bullshit. The engineers are the ones who should know right from wrong. Sony wouldn't even have attempted this if their so-called "engineers" hadn't played along.

      -jcr

      --
      The only title of honor that a tyrant can grant is "Enemy of the State."
    10. Re:Jobseekers rejoice! by jcr · · Score: 2

      Remember: Sony didn't write the rootkit. They bought it from someone else.

      This makes no difference at all in their culpability, as I'm sure the Judge will explain to them.

      -jcr

      --
      The only title of honor that a tyrant can grant is "Enemy of the State."
    11. Re:Jobseekers rejoice! by CowboyBob500 · · Score: 2, Interesting

      Exactly, and I happen to think that the scientists are at least partly responsible.

      I was recently called up by a pimp (consultancy agent) and he asked if there was any company I wouldn't want to work for. I said anyone connected directly with the defence industry and he told me that I'd be surprised how many people also said that.

      As far as I'm concerned, if I write software for a guided missile for example, and that missile happens to kill innocent civilians (even if by mistake) then I feel like there'd be at least some blood on my hands too - which I don't want.

      Bob

    12. Re:Jobseekers rejoice! by MightyMartian · · Score: 4, Insightful

      Oh gimme a break. The media companies are delerious with the power granted them by their whores in Congress. The engineers, I'm sure, were given no real choice in the matter. Remember, it is RIAA, the MPAA and all those sleeze bag politicians who'd sell their own mothers for a little political cash who have produced this abomination. If you want to solve the problem, tell all the people in your district that your congressman is a hooker sucking off the teats of media giants, and tell them to make this kind of behavior an election issue.

      --
      The world's burning. Moped Jesus spotted on I50. Details at 11.
    13. Re:Jobseekers rejoice! by bmwm3nut · · Score: 2, Insightful

      I was recently called up by a pimp (consultancy agent) and he asked if there was any company I wouldn't want to work for. I said anyone connected directly with the defence industry and he told me that I'd be surprised how many people also said that.

      As far as I'm concerned, if I write software for a guided missile for example, and that missile happens to kill innocent civilians (even if by mistake) then I feel like there'd be at least some blood on my hands too - which I don't want.


      i'm not questioning your stance, and i respect your opinion on this, i just wanted to express another opinion on working for the defence industry. my brother works for a company that makes tank ammo. and he's super anti-war and doesn't trust the government, and all that, so i asked why he works for the company. he said that his job is to design the safest tank ammo possible. so he can have a zero defect rate where a defect is something that ends up killing the soldiers in the tank. the man is always going to fight wars (he always has) and people are going to get killed for the sake of lining the man's pockets. but if you can prevent more of our young soldiers for dying, then i think you've done good. so don't think of working for the defence industry as helping the man kill people, view it as helping keep the wars shorter and saving more of our soldiers. the man will fight the war with whatever technology is available.

    14. Re:Jobseekers rejoice! by jcr · · Score: 2, Insightful

      if I write software for a guided missile for example, and that missile happens to kill innocent civilians (even if by mistake) then I feel like there'd be at least some blood on my hands too - which I don't want.

      I have a rather different take on that. My position is that weapons are necessary, until and unless all threats to peace are neutralized (which isn't going to happen.) I would have no problem at all working on a weapon, as long as it wasn't a waste of tax money, as many weapons projects are. I'd have no qualms at all about working on the Manhattan project, for example.

      If you refuse to ever have any blood on your hands, who do you expect to defend your family? I'm alive today, because men like my my uncle John went to war in 1941.

      -jcr

      --
      The only title of honor that a tyrant can grant is "Enemy of the State."
    15. Re:Jobseekers rejoice! by MightyMartian · · Score: 2, Interesting

      No, they likely have a mortgage to pay and kids to feed and educate. No matter how you try to conflate this with organized crime or Nazis or whatever it is precisely you're bit of hyperbole is attempting to do, engineers are paid to do a job, and part of that job is doing what management tells them. If management's orders put lives at risk, then yes, I could see putting it on the line, but for some stupid security measure, why bother? You tell your superiors that this is a rootkit and there could be security and public relations repurcussions, and you've done your job.

      --
      The world's burning. Moped Jesus spotted on I50. Details at 11.
    16. Re:Jobseekers rejoice! by forand · · Score: 3, Insightful

      The problem with your analogy is that the developers, in all likilihood, did not know what this is going to be used for. Sony purchased the rootkit from another company which may have some valid reason for making these. The part that is so bad is NOT the rootkit itself but that it was included in the CD.

    17. Re:Jobseekers rejoice! by LarsG · · Score: 3, Insightful

      Sony purchased the rootkit from another company which may have some valid reason for making these.

      First 4 Internet made the XCP DRM system, rootkit and all. Their business model is to develop and sell DRM products to the music industry. So the programmers at F4I must have been deaf and blind in order not to know that the rootkit would be distributed on 'audio' CDs.

      --
      If J.K.R wrote Windows: Puteulanus fenestra mortalis!
    18. Re:Jobseekers rejoice! by PetriBORG · · Score: 2, Insightful
      Remember that the rootkit was bought by Sony from a 3rd party, so it was a drop in. Hell, considering that Sony has other CDs that already launched DRM programs, Sony programmers may have done nothing at all. Its likely that it was some 20 minute job. They would have further prevented people from complaining about it by having a completely different QA-programmer test the rootkit who knew nothing about its intended use, or completely ignored QA's opinion on the ethics. Once they knew it worked... No matter how much anyone complained, they had no say in it, only the decision maker (aka exec bastard).

      The real question is, how far up the chain did this idea get spawned from. I would bet that it started by one of the execs complaining about how easy their last DRM programs were killed (Everyone remember the hold-shift hack? Yes? Good, moving on).

      In any event, remember, ethical choices require knowledge of intent.

      I'll ignore the Godwin and move on. ;-)

      --
      Pete/Petri "damn, my chainsaw is clogged with 1's and 0's again." --clyde
    19. Re:Jobseekers rejoice! by Lemmy+Caution · · Score: 2, Interesting

      See, the main problem I see with this defense comes from my experience in the industry: engineers are usually too eager to please, too enthusiastic about giving their bosses a solution. I've seen so many developers enjoy an almost conspiratorial glee in showing off just how clever and even devious they can be in delivering to management. I don't think it really takes a lot of hiding-the-truth from the engineers. They only have to frame it as a problem, and the engineers trip over each other to show how smart they are with a solution.

      The ethical questions themselves never get raised. Partially, it may because ethics are seen as outside rationality.

    20. Re:Jobseekers rejoice! by crabpeople · · Score: 3, Insightful

      "Principles are greater than profits."

      profits yes. floating just above the poverty line, no.

      but maybe when you get a real job and have a real "im going to be out on the fucking street again if i dont suck up my ego" moment, then you will see.

      but yeah, im sure crazy joe down on the corner who dances for nickles every day is sure happy that his spine is in good health.

      --
      I'll just use my special getting high powers one more time...
    21. Re:Jobseekers rejoice! by PetriBORG · · Score: 2, Interesting
      Excellent points. I still feel that knowledge of intent is more important. If you were a programmer writing code for the NSA or other Three Letter Agency, how could you be ever sure that the program you are making to spy on Some Guy isn't used incorrectly? I don't believe you can. You can only make the best choice to your knowledge.

      But in this case, I would bet that this 'product' was made by said 3rd parties with this in mind - to sell it to Sony or whoever and that they went to Sony, not that Sony found them. So here the 3rd party programmers share responsibility with The Man at Sony, but vast bulk of responsibility goes with those who at the helm that make the choices.

      This is the problem I have with large corps (american or otherwise) that choose to do these things. If you are management, and making those choices, then you must bear 80-90% of the responsibility. Even if your subordinates did help you do such a thing, you are the most to blame. The man who runs the drug cartel is more to blame for the drug problem then the drug dealer or drug user (ha, thats probably just as close to Godwin as I need to be, heh).

      --
      Pete/Petri "damn, my chainsaw is clogged with 1's and 0's again." --clyde
    22. Re:Jobseekers rejoice! by jafac · · Score: 2, Insightful

      It does not matter if it was the Engineer's fault. Can you say Scapegoat? I knew you could. Who plays golf with the CEO? The Engineer? Or the VP of Distribution and IP Protection?

      "that damn engineer, he said he had the technology to fool the hackers out there so they couldn't detect our DRM. . . ."

      Or, another phrase comes to mind; ". . . you have failed me for the last time. . . "

      --

      These are my friends, See how they glisten. See this one shine, how he smiles in the light.
  3. Boycott Sony by Winckle · · Score: 5, Interesting

    I reccomend voting with our wallets, and not purchasing Sony/BMG products. Also see here

    Also here is the company that created the DRM technology.

  4. Nice Job Sony by xlr8ed · · Score: 5, Funny

    You might want to add a couple of more zeros to the settlement check you are thinking about

    1. Re:Nice Job Sony by Devil's+BSD · · Score: 2, Funny

      from $100,000,000
      to $000,100,000,000.00?

      --
      I'm the Devil the Windows users warned you about.
  5. A Natural Rights perspective by dada21 · · Score: 5, Insightful

    Irregardless of the existence of government, the natural rights of an individual cannot be given away (you can't sell yourself into slavery, you can't tell a higher power that it's ok to kill you). One such right is the right to private property, closed to others' prying eyes or presence.

    One great force behind this right is that past acts bear no allowances for future acts. If I let you into my house yesterday, you have no right to be here today. I may contractually allow you to come and go as you please, but I have to willfully sign the contract with witnesses noting the act.

    Sony's DRM uses government force (through copyright provisions) to settle its legality. They say that by using their property, you have to permanently give up your natural right to private property (free speech Statists wrongfully call it Right to Privacy). Sony is wrong.

    By violating numerous natural rights, Sony has opened itself to a demand for restitution. I wholeheartedly believe that corporate protections are wrong, as is copyright. My solution? Go after Sony through the shareholders directly (they own the business and allowed the breach of a basic human right). Demand restitution for the trojan if you receive it.

    Imagine if you buy a Saab and Saab has an agreement stating "If you turn the car on, you allow two Saab employees to ride in your trunk and search your house for proof you might install a non-Saab oil filter." You've signed nothing. The two Saab employees open your house door, take up residence and leave the door wide open. Two typical pro-copyright arguments: You're not allowed to install non-Saab oil filters or how else would Saab make money? Why would they design cars?

    This is the problem with copyright. Instead of individuals protecting proprietary information of value (books, music, etc) and producing it in the best way over anyone else (live shows, subscriptions to new music, etc), they say "copy us and government will use force against you."

    It's all wrong. Don't publicly say anything valuable to you. Don't think you can come in my home because you did once before. Don't think you can rape me because a note in your pocket says you're allowed to, and I let you in without checking your pockets.

    1. Re:A Natural Rights perspective by GungaDan · · Score: 2, Insightful

      A natural right to private property??? No. This is a LEGAL right - an artificial construct of an organized society. Interesting post all around. You had me right up until you said "irregardless."

      --
      Eloi are stupid, throw morlocks at them!
    2. Re:A Natural Rights perspective by Anonymous Coward · · Score: 2, Informative
    3. Re:A Natural Rights perspective by jotok · · Score: 4, Insightful

      I am with you on almost everything except this:

      One such right is the right to private property, closed to others' prying eyes or presence.

      To me, this doesn't seem as "self-evident" as the other rights (Life, Liberty, freedom to pursue happiness, etc.) in the D of C. But it does seem to make sense as a possible necessary qualification to achieve the other three: I could live, be free, and try to be happy without owning anything, but it might be exceedingly difficult.

      Just sayin'.

      (Also, "irregardless" is not a word)

    4. Re:A Natural Rights perspective by dada21 · · Score: 2, Interesting

      The natural right to private property that you take an active role in maintaining and upgrading has been recognized for hundreds of years. Locke, George, and dozens of others have successfully debated it.

      Google for some great links.

    5. Re:A Natural Rights perspective by Surt · · Score: 2, Interesting

      Who grants the natural right to property?

      For example, I own the world. So I can go anywhere I please, including into 'your' home which is really mine.

      You might suggest that the state decides who owns what, and the state says you own your home. But if so, then they also have the power to decide what the limits on that ownership are, including the powers of copyright.

      If you rely on the force of the state to create property rights, then you pretty much have to go along with the whole legal system in determining who has what assorted rights. The state has decided that copyright and property rights are both to exist, and that it will offer to use its force in defending those rights in certain ways. You can live with the legal system, or you can work with others to change it, or you can resist it (though your odds of doing that effectively seem quite low).

      --
      "Who is the Journal of Quantum Physics going to believe?" --Stephen Hawking
    6. Re:A Natural Rights perspective by iambarry · · Score: 5, Funny

      If I let you into my house yesterday, you have no right to be here today
      While you may be correct WRT US property laws, it seems to me that vampire rules call for a vampire to have free reign over your house in perpetuity if they are ever invited in. Perhaps Sony is operating using Vapire law rather than US law?

      BTW - irregardless

    7. Re:A Natural Rights perspective by AndersOSU · · Score: 2, Insightful

      Interesting post.

      One nit, Sony is almost certainly structured as a limited liability corp. specifically so that you can't go after the shareholders. Do you think that LLCs are wrong?

      In my opinion LLCs are very valuable because they allow ordinary people to invest in corporations without becoming personally, legally and financially responsible for that companies actions. While this certainly can have the effect of diffusing fault, I feel that this is out weight by the positive economic impact of facilitating investments. Do you disagree?

      You said that you feel that corporate protections are wrong, do you consider limited laiblity to be a personal or corporate protection? I tend to think that it is a personal protection.

    8. Re:A Natural Rights perspective by PlusFiveTroll · · Score: 2, Insightful

      Who grants the natural right to property?

      You do, I do. Do you think the 'state' just pulled the property laws out of there collective ass (ok for some states i'll say yes). Most of Texas current property laws are an extension of 'natural' property laws.

      Texas tresspass laws are great. If you tresspass on my property, you have the legal right to leave in a body bag. Not the states force, my own.

      Maybe you should read around here a little.

    9. Re:A Natural Rights perspective by Wylfing · · Score: 3, Insightful
      Who grants the natural right to property?

      This drives me insane. What are they teaching kids in school these days anyway? Natural rights are not granted. They are naturally yours because you are human being. They can neither be granted nor taken away. That's why you cannot sign a contract (at least, you can't in the U.S.) that says "I agree to sell myself into slavery in exchange for $100." It's not enforceable, because you cannot sign away a natural right.

      Small rant: This complete lack of understanding of natural rights leads to a lot of rotten decision-making. As soon as you start thinking the state "grants rights" (it doesn't), you start thinking it's OK for the state to take them away (it's not). In fact, it's exactly the reverse. You grant powers to the state, and you can take them away. The government has powers only at your whim.

      --
      Our intelligent designer has never created an animal that we couldn't improve by strapping a bomb to it.
  6. From the article, virus firms response by matt+me · · Score: 2, Interesting

    "The response of anti-virus firms, some of which have only promised to flag up rather than block system changes made by Sony-BMG's rootkit, remains unclear. "
    Ooh fun to be had here. Sony are gonig to love this publicity.

    Ha ha. I have little respect for these companies who I see to be the same as those who four hundred years ago sold "herbs" to protect you from the plague. These ppl still profit from ppl's lack of knowledge.

    1. Re:From the article, virus firms response by Lisandro · · Score: 5, Insightful

      I know i should be shocked and offended by retarded attemps at DRM lock-in by Sony... but i can't.

          I'm loving this. I just can't wait to see what happens when antivirus/spyware vendors decide to consider the Sony rootkit as an attack vector and remove it accordingly... will it show up as "Sony.CDcopyprotection.malware"? "F4I.XCP.Aurora"? How about the information about it? Will we see legal battles between antivirus vendors and Sony? Class action lawsuits from consumers? I'm already preparing some popcorn for the event!

  7. Oh noes! by taskforce · · Score: 4, Funny

    Early reports indicate the IRC backdoor is used by the propagator of the virus to bombard you with random chat messages from #windowshelp. So far the most common phrases appearing are "how do i reformat" and "how do i download the internet?"

    --
    My 3D Texturing Skinning work (under construction)
  8. Really easy test to see if you're vulnerable by HMC+CS+Major · · Score: 5, Interesting

    Since there was some confusion about how you can tell if this rootkit is installed, remember that it hides files beginning with '$sys$' -

    1) If you're not using windows, you're fine.
    2) Create a file on your desktop ('test.txt' should be fine). Rename the file to '$sys$test.txt'.

    If the file is gone, you're vulnerable.

    1. Re:Really easy test to see if you're vulnerable by pegr · · Score: 2, Informative

      Since there was some confusion about how you can tell if this rootkit is installed, remember that it hides files beginning with '$sys$' -

      1) If you're not using windows, you're fine.
      2) Create a file on your desktop ('test.txt' should be fine). Rename the file to '$sys$test.txt'.

      If the file is gone, you're vulnerable.

       
      How about a "read-only" way?
      Boot with Knoppix
      At the command prompt:
      $su bash
      #mkdir cdrive
      #mount /dev/hdc cdrive -o ro,noexec
      #find cdrive -name $sys$* -print

      Any hits? You got da SonySyph...

  9. That's not all by JumperCable · · Score: 5, Funny

    I hear the trojan witter is also using an unusual distribution method. Ricky Martin CDs.

  10. $sys$porn by KinkoBlast · · Score: 2

    Evil? Yes. But there are uses! Not that it has any affect on my Mac or Ubuntu box...

    Well, I was debating buying a PS3 instead of a Nintendo Revolution. Not anymore!

  11. Back again to Windows Security by Tibor+the+Hun · · Score: 5, Interesting

    Can anyone explain if this rootkit prompts for a password when installing (during the autorun, I presume)

    As an OS X user, I'd find it slightly odd that my music CD is prompting me for an administrative password.

    But to stay on topic, I'm sure this is but one of the many exploits that will be based on this rootkit.
    Does anyone have a comprehensive list of CDs that install it, and is it true that Sony has been using it since April?

    --
    If you don't know what AltaVista is (was), get off my lawn.
    1. Re:Back again to Windows Security by danrik · · Score: 3, Interesting

      No, because 99.975% of Windows users run as super users.

      On OS X, accounts marked as Administrators are really regular users who happen to have sudo powers, so you have to type in your password.

    2. Re:Back again to Windows Security by JadeNB · · Score: 2, Informative
      Can anyone explain if this rootkit prompts for a password when installing (during the autorun, I presume)
      Under Windows, when you're logged in as the administrator, you don't need any further password to proceed with, say, installing a rootkit. If you're a Home user, you can't give limited privileges, so you have no option, for the vast majority of crappily-written software, but to install it as an administrator (albeit with Spybot S&D and StartupMonitor running in the background to catch the seventeen start-up items it thinks you now need).
    3. Re:Back again to Windows Security by Tibor+the+Hun · · Score: 2, Interesting

      OK, I've found a partial list, but according to the article SONY/BMG are not releasing a complete list:

      Trey Anastasio, Shine (Columbia)
      Celine Dion, On ne Change Pas (Epic)
      Neil Diamond, 12 Songs (Columbia)
      Our Lady Peace, Healthy in Paranoid Times (Columbia)
      Chris Botti, To Love Again (Columbia)
      Van Zant, Get Right with the Man (Columbia)
      Switchfoot, Nothing is Sound (Columbia)
      The Coral, The Invisible Invasion (Columbia)
      Acceptance, Phantoms (Columbia)
      Susie Suh, Susie Suh (Epic)
      Amerie, Touch (Columbia)
      Life of Agony, Broken Valley (Epic)
      Horace Silver Quintet, Silver's Blue (Epic Legacy)
      Gerry Mulligan, Jeru (Columbia Legacy)
      Dexter Gordon, Manhattan Symphonie (Columbia Legacy)
      The Bad Plus, Suspicious Activity (Columbia)
      The Dead 60s, The Dead 60s (Epic)
      Dion, The Essential Dion (Columbia Legacy)
      Natasha Bedingfield, Unwritten (Epic)

      --
      If you don't know what AltaVista is (was), get off my lawn.
    4. Re:Back again to Windows Security by jcostantino · · Score: 4, Funny

      The delicious irony in that is that titles like, "Healthy in Paranoid Times," "Get Right With the Man," "Nothing is Sound," "The Invisible Invasion," "Phantoms," "Life in Agony," and "Suspicious Activity" all install the rootkit and compromise your computer.

      --
      Reviews with a twist! http://www.sardonicbastard.com
    5. Re:Back again to Windows Security by NSObject · · Score: 5, Interesting
      It looks like there's an OS X version as well, but from a different source. Here's a reader comment from macintouch.com...

      Darren Dittrich followed up on the discovery that Sony was playing a dirty trick on its customers, secretly installing a malware-style "root kit" on their computers via audio CDs:

      I recently purchased Imogen Heap's new CD (Speak for Yourself), an RCA Victor release, but with distribution credited to Sony/BMG. Reading recent reports of a Sony rootkit, I decided to poke around. In addition to the standard volume for AIFF files, there's a smaller extra partition for "enhanced" content. I was surprised to find a "Start.app" Mac application in addition to the expected Windows-related files. Running this app brings up a long legal agreement, clicking Continue prompts you for your username/password (uh-oh!), and then promptly exits. Digging around a bit, I find that Start.app actually installs 2 files: PhoenixNub1.kext and PhoenixNub12.kext.

      Personally, I'm not a big fan of anyone installing kernel extensions on my Mac. In Sony's defense, upon closer reading of the EULA, they essentially tell you that they will be installing software. Also, this is apparently not the same technology used in the recent Windows rootkits (made by XCP), but rather a DRM codebase developed by SunnComm, who promotes their Mac-aware DRM technology on their site.
    6. Re:Back again to Windows Security by _xeno_ · · Score: 4, Informative

      Short answer: No, it just assumes you're running as an administrator, which is generally true.

      Much longer answer:

      Windows XP comes from two roots: Windows as a DOS shell, and Windows NT. Both of these operating systems encouraged running as Administrator, for a variety of reasons.

      Windows as a DOS shell is easy to explain, it was a single-user system, and therefore really had no security system in place at all. This single-user style persisted through to Windows ME, and is essentially "emulated" in Windows XP Home by having the users, by default, run as Administrators. (You can change them to regular users after creating new accounts, though.) By default, Windows XP Home doesn't require passwords on accounts - you just click on the user account you want to use, and you're logged in. So even making "less privileged" users isn't all that helpful. (I believe, by default, Windows XP Home DOES disable the built-in Administrator account, though.)

      Anyway, Windows NT is another story. Technically, an "Administrator" account is just a normal user account that just happens to belong to the Administrators group. Because Windows NT's security model is much more complicated than the Unix security model (and I'd argue much more robust), essentially the Administrators group is a group with all permissions set to "allow." (There is a super-user under Windows NT. It's called "SYSTEM" and it's essentially identical to root under Unix.)

      But anyway, Windows NT's security model is very complicated. Combined with no ability to "sudo" in Windows NT 4, most people who used NT just made themselves Administrators so that they didn't have to poke around the miriade of settings and ACLs to give them permissions to do whatever they needed to do.

      Windows 2000 added "Run As" which allows you to essentially "su" and switch to another account when starting a program. This meant that it would in theory be possible to administer a system from a non-privileged account, much like Mac OS X does.

      But the damage was already done. Most of the Windows software had been written for Windows 9x or assumed that you'd be an administrator under Windows NT. So attempting to run as a non-privileged account required constantly using the Run As feature to run the programs you needed to use as an administrator. (For a while, Winamp wouldn't run under a non-privileged account.) Of course, this meant that since most programs were running as administrator ANYWAY, you really weren't gaining much security.

      Now, with Windows XP Pro, this is starting to change. Microsoft now requires user programs to run on non-privileged accounts. It's much clearer where user-specific information goes. But the damage has been done. Windows XP Home defaults to an administrator account for all new accounts. Most people are used to not having to enter a password to change their system settings and don't understand the concept of a non-privileged account.

      So almost everyone using Windows is running as an administrator, and therefore there's no need to require a password to install a rootkit. They already have the permissions they require.

      --
      You are in a maze of twisty little relative jumps, all alike.
  12. Sony's actions recently mean they've lost my money by hattig · · Score: 3, Interesting

    I don't know if they are selling these DRM encrusted music discs in the UK, but if they are, each and every one of them will be breaching the 1990 Computer Misuse Act, and in a way that the act does cover - namely it alters the system without your approval or knowledge. What is doubly sad is that the software was written by a British company. Still, makes it easier to sue them.

    Secondly, does this rootkit install even if you are logged in as a normal Windows user, not Administrator? That suggests a security hole in Windows. However I suspect the issue is Windows making users Administrator by default, which is a really dumb system, security wise.

  13. Ahhh, Sony by PhilHibbs · · Score: 5, Funny

    It wouldn't be right if the day went by without a Sony Rootkit story on Slashdot. Seriously, I can't get enough of this story, it's what Slashdot was invented for.

  14. SONY, redefining DRM by Anonymous Coward · · Score: 5, Funny

    Disappearing Rootkit Malware

  15. Fun with $sys$ by Anonymous Coward · · Score: 5, Funny

    Sony just loves everyone $sys$anally. They are the greatest company ever when it comes to technology $sys$that $sys$sucks. Everyone is gonna love $sys$to $sys$hate Sony, and they will $sys$not buy any Sony product that they see. It's because Sony loves $sys$to $sys$fuck $sys$with their customers.

    1. Re:Fun with $sys$ by merphle · · Score: 3, Funny

      Could it be?! Is "$sys$" the new "^H^H^H"?

    2. Re:Fun with $sys$ by meringuoid · · Score: 3, Interesting
      Could it be?! Is "$sys$" the new "^H^H^H"?

      Probably. Since the Sony Rootkit is the big story at the moment, this thread will get read by a lot of people. That post went to +5, and it's got Slashdot memeicity all over it.

      I wouldn't use it as a straight drop-in replacement for ^H^H^H, though; that merely implies 'I nearly wrote this - whoops!' $sys$ conveys malevolence. So, for instance, if someone were to write

      We must invade Iraq to look for oil^H^H^HWMD

      would suggest that oil is at least part of the purpose of the invasion, and that it's just not diplomatic to mention it. A careless typo that reveals too much of what you're thinking. On the other hand

      We must invade Iraq to look for $sys$oil WMD

      would suggest that oil is the real purpose of the invasion, and that this is being deliberately hidden by a lot of bullshit about WMD. A subtext deliberately trojaned in and kept dark.

      Use the $sys$ prefix in place of ^H^H^H to lend a nastier, more malevolent tone to what it is you're editing out.

      --
      Real Daleks don't climb stairs - they level the building.
  16. sony vs. microsoft by doyoulikegoatseeee · · Score: 3, Interesting

    so does this at all put sony in hotwater with microsoft legally? perhaps this rootkit, trojan email or not, violates the windows eula.

  17. Lawsuits if this thing DDoSes the net by G4from128k · · Score: 3, Interesting
    I've often wondered if non-users of product X can sue the maker of product X if said product causes a major disruption of the internet.


    If someone creates a worm that exploits a negligent design flaw in Sony's DRM or Microsoft Windows, then couldn't the affected sue Sony or Microsoft? This would include non-users of these products whose internet usage was disrupted. And as someone who does NOT use DRMed Sony CDs or Microsoft Windows, I have NOT agreed to these company's EULAs with all their legalese of limited liability. Thus non-users may have more rights to sue than users of these products.

    IANAL. Any thoughts?

    --
    Two wrongs don't make a right, but three lefts do.
  18. Infected with DRM by saskboy · · Score: 4, Interesting

    Here's the Slashdot crowd's chance to get the phrase invented by a Slashdotter out in the public eye. It's important that the public learn that DRM is a bad thing, and this is simply one way to tell them plainly how it is bad. DRM breaks their computer, or makes their life more difficult.

    "Infected with DRM"
            Sony's rootkit has also been linked to Windows crashes, which isn't surprising to me. Most spyware causes instability in Windows because it is poorly written and designed to break parts of Windows to protect itself from removal. Sony writes, "This component is not malicious and does not compromise security. However to alleviate any concerns that users may have about the program posing potential security vulnerabilities, this update has been released to enable users to remove this component from their computers."
    The incongruence of their words, is not startling to me, as they are playing a PR game to hide the fact that they messed up people's computers, and made them vulnerable to an attack that hasn't gained popularity yet, but now surely will. Virus writers will be able to easily hide their virus files using programs like Sony's cloaking DRM. Sony is lying that their cloaking DRM does not compromise security of an infected computer.
    http://www.informationweek.com/story/showArticle.j html?articleID=173601122

    --
    Saskboy's blog is good. 9 out of 10 dentists agree.
    1. Re:Infected with DRM by Tsiangkun · · Score: 2, Interesting

      Don't buy music Infected with DRM.

  19. Re:Sony's actions recently mean they've lost my mo by Daedala · · Score: 3, Informative

    El Reg says that Sony UK says they are not selling them in the UK.

    --
    What I say does not represent the views of my employers, my friends, my cats, or myself.
  20. Being ignorant == fair game? by dsands1 · · Score: 4, Informative

    Sony President Defends Rootkit
    The President of Sony BMG's Global Digital Business, Thomas Hesse, defends Sony's installation of a rootkit by declaring, "Most people, I think, don't even know what a Rootkit is, so why should they care about it?"

    Source

    --
    "What is the answer?" (Silence) "In that case, what is the question?" --Gertrude Stein
    1. Re:Being ignorant == fair game? by ScrewMaster · · Score: 2, Insightful

      Most people, I think, don't even know what a Rootkit is ...

      They do now.

      --
      The higher the technology, the sharper that two-edged sword.
  21. Re:On what platforms does Sony DRM rootkit work? by dbc · · Score: 3, Interesting

    Yes, but, what OS's other than Microsoft products allow surf-by and auto-mount driver installs that diddle low level file system api's? Why is no one angry at Microsft about this Sony fiasco?

    I'm thinking that outside of users that habitually surf and/or listen to music as root, that Linux and OS X users should be just a wee bit safer than the casual Windows user.

    Sure, Linux can be rooted. Now, your homework assignment is to go burn me a disk with music on it that will root my Linux box merely by being inserted, and won't let me listen to the music until my box has been rooted. I like classical.

  22. Re:Suprise suprise by froi · · Score: 5, Funny

    I'm still waiting for a worm that uses the Sony rootkit to hide itself, spreads to many computers, and then DDoS sony.com. They'd have a hard time knowing what press release to put out if that ever happened.

  23. Legality by Jerk+City+Troll · · Score: 2, Insightful

    If some bored teenager devised and distributed such a rootkit, he or she would be accused of costing businesses millions and thrown in jail for 10 years. Can someone explain to me why Sony is not getting prosecuted for "hacking" here? What makes them exempt (aside from whatever civil lawsuits are being brought against them)?

  24. A variant of that trojan ... by Anonymous Coward · · Score: 5, Interesting

    The sales manager at the company I work for recently received a variant of this worm, and after finding that the attachment "didn't do anything" forwarded it on to me to find out why. I extracted the attachment and analysed it in IDA and discovered that it connected to one of two IRC servers and joined a specific channel.

    So posing as the trojan I logged onto the IRC channel. I idled there for a while watching the channel op send commands to the connected bots, and decided to have a go myself. The channel was +m but I could PRIVMSG the bots, and a bit more work in IDA revealed the command set - which contained an unload command. So I scripted my irc client to send a msg to every non-op in the channel with the command .. suddenly they all quit and the room was empty except for me and the op.

    "OH SHIT" he typed. He was more shocked than anything, and then more curious than angry. We ended up having a rather long and interesting conversation about our respective jobs. He told about his bot network, what he uses them for (in the UK it's for harvesting email addresses, apparently), the ££ he gets for it - it's a full time job for him - and who writes most of the bot software (his partner.) He was no stereotypical teenage script kiddie either, more a computer professional turned to the 'dark side' of IT .. I felt quite akin to him in many ways.

    All in all, it was fascinating. (Btw, our firewall blocked the trojan from connecting to IRC and it was fairly easily to remove from the sales manager's laptop)

  25. Boycott isn't going to do squat by Fujisawa+Sensei · · Score: 2, Insightful

    Boycott isn't going to do squat to a company the size of Sony. If Sony BMG's profits actually go down, they'll just blame music pirate and file sharers. Then they'll get laws even worse than the DCMA passes. Everybody who get trojaned with the help of Sony's rootkit needs to sue Sony.

    --
    If someone is passing you on the right, you are an asshole for driving in the wrong lane.
  26. Major event by openfrog · · Score: 2, Interesting

    This could end up being a turning point. The organisations pusing for DRM will easily and swiftly realise what this leads to:

    All their heavy public relations work to portray the reluctant consumers as merely "pirates" is on for a trying test.

  27. antivirus vendors violate DMCA? by jimbro2k · · Score: 5, Interesting

    IF antivirus vendors do start removing the sony rootkit, won't that qualify as circumvention of a copyright device and put them in clear violation of the DMCA? This just keeps getting better and better.

    --
    There is not nearly enough love in the world, but there is far too much trust.
    1. Re:antivirus vendors violate DMCA? by CowboyBob500 · · Score: 2, Insightful

      Presumably only if they are a US anti-virus company. It could also be a marketing war for the anti-virus firms. Only the non-US ones will be able to clear-up the Sony malware, e.g. Kaspersky.

      Bob

    2. Re:antivirus vendors violate DMCA? by PhoenixPath · · Score: 4, Interesting

      McAfee is the first. Detects, removes, *and* prevents re-installation.

      See below:

      http://www.betanews.com/article/Antivirus_Firms_Ta ke_On_Sony_DRM/1131641594

  28. Maybe it's Sony's new way of advertising... by turthalion · · Score: 2

    "This trojan has been brought to you by...

    Sony.

    When your files are too important to be seen by anyone.
    Just $sys$ it."

    --
    Michael Coyne
    http://turthalion.blogspot.com
  29. Remember Intuit's TurboTax debacle? by sizzzzlerz · · Score: 5, Interesting
    Several years ago, Intuit infested your computer with their own DRM software when you installed their TurboTax software. Of course, the packaging said nothing about it but once it was discovered, the shit hit the fan. They first denied doing anything wrong, then when forced to admit that presence of this software, they insisted it did no harm to the owner's computer. Once again, their logic was that all buyers of the software were thieves and this was protecting their I.P.. Finally, when sales of the product dropped sufficiently, they provided a mechanism to remove said-DRM software, however, TurboTax would no longer run.

    The following year, all traces of this were removed in the next version and, afaik, it has never returned. I, for one, however, haven't bought their product since and don't plan to ever buy from them again.

    I guess Sony just wasn't paying attention.

  30. That list of CDs can't be right by macslut · · Score: 3, Funny

    That list of CDs can't be right. Those albums are all over the P2Ps. That's exactly what the rootkit is supposed to prevent from happening!

  31. This assumes your interpretation of Natural Rights by jd · · Score: 3, Insightful
    In some countries (such as Britain) there is no law of trespass. There is a law against breaking and entering, there is a law against causing damage and there are numerous privacy laws, but if you aren't causing a problem then your ancient (pre-enclosures act) rights cannot be abbridged. Further, if there is a traditional, ancient right-of-way through your land, then you have absolutely no rights whatsoever to block, divert or otherwise interfere with that right-of-way. You may own the land on paper, but the land owns itself in many ways, in the eyes of the law.

    Furthermore, in most (if not all) countries, "land ownership" does NOT include mineral rights (which are arguably a significant part of the land) and can often be overruled or dismissed by the Government should they decide they can make better use of the land (5th Amenndment in the USA includes this provision, I believe). As such, it is not really ownership and can - at best - be called borrowing from the State.

    There are countries in which private ownership of any kind simply isn't recognized at all. Everything is communal. Such societies don't seem to be any less rights-respecting than any other. Indeed, the USA - which has more codified rights than almost any other country - has one of the worst records of any country for actually honoring what is codified. Indeed, not only is it not honored, even when the courts rule against it, the US Government doesn't always respect those decisions. (The Sioux won in the Supreme Court to have the Black Hills revert to them - that was something like 40 or 50 years ago and the US Government is still refusing to honor the ruling.) Even when it does respect them, it has the power to replace any judge that rules against them (as threatened by DeLay over the Terri Schaivo case) which does damage any semblance of independence or impartiality.

    I do believe there are Natural Rights. I believe there is a Natural Right for any individual to be seen for oneself, that there is a Natural Right for any individual to improve their quality of life, that there is a Natural Right for any individual to hold to any beliefs they so choose, that there is a Natural Right for any individual or group to privacy and that there is a Natural Right for any individual or group to maximise potential and minimise harm.

    Most of these are what Republicans and Libertarians would consider obnoxiously socialist. The only way to maximise potential is to maximise the flow of information and to guarantee the practicalities of learning that information in a manner that is useful and usable. In other words, maximal quality education and minimal restraint on learning. In practice, if you're from a poor family in a poor area in the US, the only way to learn is to be good at sports or be in the military. Oh, and be male. Poor females in the US are left to rot, regardless. The only way to be good at sports in the US seems to be to take dangerous (and eventually lethal) drugs. Brain damage and other sporting injuries are pretty common. The US military is routinely accused of fraudulant claims in recruitment efforts, violent abuse (sometimes lethal) against recruits and persecution of non-Christians. Rape of females in the US military also appears to be a common complaint - and rarely investigated.

    Rights - Natural or otherwise - are only meaningful if enforcable. This is one reason the original version of the Magna Carta stipulated the right to seize (by force, if necessary) judicially-awarded compensation or enforce judicially-awarded rulings against the Government (in that case, the king). In other words, nobody - absolutely nobody - was above the law, and nobody could use executive priviledges to abuse the law or anything else. Name me one country that has such a provision today. (No, the US impeachment procedure doesn't count. The current Congress wouldn't impeach Bush if he was caught red-handed in an act of treason, and the population at large has no impeachment rights. The UK's vote of no co

    --
    It's a small world and it smells funny; I'd buy another if it wasn't for the money; Take back what I paid (SoM)
  32. Sony Rootkit News Absent From CNN by Esion+Modnar · · Score: 5, Insightful

    So far, I haven't seen any mention on the mainstream news about this. Maybe because it's too technical, but I think it's because CNN is a company of Time-Warner, and Time-Warner and Sony are fellow MPAA (and/or RIAA?) members. They (CNN) are great about covering the fluff. Count on them to down-play the stuff that hurts their business sleaze.

    --

    They say the first thing to go is your penis. Well, it's either that or your brain. I forget which...
  33. $sys$ now Sony's fnord? by Esion+Modnar · · Score: 2, Insightful

    I've tried mentioning this story to some of my non-geek friends, and their eyes just glaze over. I even try phrasing it like, "Sony put something on these CD's that just takes over your computer." They can't get it. The phone rings. The baby cries. Something interesting comes on TV. It's like their brain can't stay focused on the statement that a giant media conglomerate is trying to fuck with their computer, trying to fuck with them. I hate to say it, but these companies will eventually win, because the vast majority of people are so fucking clueless about this stuff, and firmly try to stay clueless. Fucking sheeple.

    --

    They say the first thing to go is your penis. Well, it's either that or your brain. I forget which...
    1. Re:$sys$ now Sony's fnord? by olympus_coder · · Score: 2, Insightful

      Let me phase it for you. This worked on the people I support. I actually got a decent reaction.

      "Newer Sony CDs install a type of virus on your computer called a root kit."

      The word virus is the key. If the president of Sony doesn't have a clue what a root kit is, then lets cut the BS and use the right word. It is a VIRUS in the since that the only term most normal people really "get" (I know, it isn't a virus as security people define it).

      --
      Spell check? Why bother. That is what grammer/spelling Nazi freaks who waiste band width posting "spell right" are for.
  34. Re:wake up, this is Bush's Amerifka! by cbreaker · · Score: 2, Insightful

    It's 2.5 kids dammit! I like to say that because it sounds trendy!

    But seriously, I aggree with you 100%, but I also agree that you could get into some bad luck, get stuck with big bills because you couldn't find good work no matter how hard you tried, and up to this point you've tried to live your life in a fairly moral manner.

    Even as a 26 year old with a pretty good paying job in IT, I wouldn't exactly just up and quit my job because of something like this. I would, however, raise serious objections that would probably get me put on the shit list eventually. But I wouldn't quit.

    If the company were developing a way to secretly kill babies, I'd quit in a moment. But in the case of a rootkit for the purpose of copy-protecting a music CD? Well, I can live with that I suppose.

    --
    - It's not the Macs I hate. It's Digg users. -
  35. ALL GAMESITES SHOULD DROP SONY COVERAGE by artifex2004 · · Score: 2, Insightful

    Boycott Sony by refusing to cover the PS3, and encourage other websites to do the same. If they are denied all the prelaunch coverage they need to create a groundswell of demand, it will have real consequences for them, and they will pay attention.

  36. Computer Associates Removes Sony DRM by inverselimit · · Score: 2, Informative

    CA antivirus is now removing the DRM. I think this is a violation of the DMCA, right? 5 years in prison and a big fine? Let the fireworks begin. story

  37. Definition of "Natrual Rights" by radtea · · Score: 2, Interesting

    Here is a useful definition of "natural right" that might help people understand the natural rights perspective:

          natural right(n): A political condition required for the life of a morally autonomous being.

    A natural right, in this view, is to political or social life what the requrirement for food, water or air is to physical life. I cannot say, "I relenquish my need for food" in any meaningful sense, because it is my nature to need food to live.

    Likewise, for a being whose mode of life involves making and acting on its own value judgements, certain political conditions are required. The need for these political conditions cannot be relenquished.

    "Tyranny" is a political condition, as is "republic", "police state", etc. Not all of these political conditions allow morally autonomous beings to live as such.

    Note that I do not believe that natural rights theory is sufficient to construct a theory of society. Nor do I believe that protection of natural rights is a sufficient basis for a just society. Humans are more than rights-bearing creatures, and our social needs are far more complex than the needs described by natural rights. A natural-rights-only society is the bread-and-water diet of social theory: sufficient to sustain some kind of existence, but not sufficient for genuine health and happiness.

    --
    Blasphemy is a human right. Blasphemophobia kills.
  38. Anyone know... by KIondike · · Score: 2, Insightful

    Where I can find a copy of the email and attachment for this trojan? For some reason my level of spam has dropped through the floor recently, and I would love to take a look at this thing and start picking it apart. Any help is much appreciated.