|
|
This topic comprises 6 pages: 1 2 3 4 5 6
|
|
Author
|
Topic: Sony puts malware on its music CDs.
|
|
|
|
|
|
|
Daryl C. W. O'Shea
Film God

Posts: 3977
From: Midland Ontario Canada (where Panavision & IMAX lenses come from)
Registered: Jun 2002
|
posted 11-16-2005 06:23 PM
This non-media article demonstrates the scale of Sony's infections, which rival some worm's infection rates. With images showing infections across the globe! Interestingly, the infections are only significant in North America.
quote: http://www.doxpara.com/?q=sony Welcome To Planet Sony Submitted by Dan Kaminsky on Tue, 2005-11-15 09:28.
Sony.
Sony has a rootkit.
The rootkit phones home.
Phoning home requires a DNS query.
DNS queries are cached.
Caches are externally testable (great paper, Luis!), provided you have a list of all the name servers out there.
It just so happens I have such a list, from the audits I've been running from http://deluvian.doxpara.com.
So what did I find?
Much, much more than I expected.
It now appears that at least 568,200 nameservers have witnessed DNS queries related to the rootkit. How many hosts does this correspond to? Only Sony (and First4Internet) knows...unsurprisingly, they are not particularly communicative. But at that scale, it doesn't take much to make this a multi-million host, worm-scale Incident. The process of discovering this has led to some significant advances in the art of cache snooping. Here are some of the factors I've dealt with:
* Just because you *request* the disabling of recursion, doesn't mean it'll actually happen. A full 353,200 name servers had to be excluded from the final tally because not only would recursive queries emit from them whether or not they were desired, but they'd also notify their neighbors of the results. * Low TTL names exist, and are rather difficult to catch by cache snooping (they expire before you can find proof of life). However, they may be hosted by names that last much longer -- updates.xcp-aurora.com has a lifespan of an hour, but xcp-aurora.com's NS link to resolver1.first4internet.co.uk will last 150,000 seconds. * Some hosts lie -- captive portals, I'm looking at you. Simply filtering TTL's that are divisible by 100 has a way of eliminating most of them; after that, you're left with surprisingly few NS's that lie about IP.
I also have an IP->Geographic data, courtesy of Mike Schiffman's libipgeo and the fine folks at IP2Location, who have a very impressive database. So, the first thing I did was geolocate the data. After dispensing with the raw stats gather...
What can I say? Pretty pictures. Ugly data, but pretty pictures!
* USA * Asia * Europe
And the tool used to make this? Welcome To Planet Sony! (based on Partiview in general and the always awesome PlanetLab's work in particular)
| IP: Logged
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Paul Mayer
Oh get out of it Melvin, before it pulls you under!

Posts: 3836
From: Albuquerque, NM
Registered: Feb 2000
|
posted 11-21-2005 05:08 PM
I love it. The State of Texas is suing Sony for violations of the new Texas Anti-Spyware Law:
quote: Texas Sues Sony Under Anti-Spyware Law Texas Sues Sony BMG Music Entertainment Under Its New Anti-Spyware Law
The Associated Press
AUSTIN, Texas Nov 21, 2005 — The state sued Sony BMG Music Entertainment on Monday under its new anti-spyware law, saying anti-piracy technology the company slipped into music CDs leaves huge security holes on consumers' computers.
The lawsuit is over the so-called XCP technology that Sony had added to more than 50 CDs to restrict to three the number of times a single disc could be copied.
After a storm of criticism, Sony recalled the discs last week.
To enforce the restrictions, the CD automatically installed the copy-protection program when discs were put into a PC a necessary step for transferring music to iPods and other portable music players.
Attorney General Greg Abbott accused Sony BMG of surreptitiously installing "spyware" in the form of files that mask other files Sony installed as part of XCP.
This "cloaking" component can leave computers vulnerable to viruses and other security problems, said Abbot, echoing the findings of computer security researchers.
"Sony has engaged in a technological version of cloak-and-dagger deceit against consumers by hiding secret files on their computers," Abbott said in a statement.
The term "spyware" has been used broadly to cover programs that are installed without users' full knowledge and consent, whether or not they actually spy on a user's activities.
A Sony BMG spokesman didn't immediately return a call Monday morning.
Sony BMG initially rejected the uproar over XCP as technobabble.
But after security experts discovered that XCP opened gaping security holes in users' computers as did the method Sony BMG offered for removing XCP Sony BMG agreed last week to recall the discs.
Some 4.7 million had been made and 2.1 million sold. CDs that had XCP included releases by Van Zant, The Bad Plus, Neil Diamond and Celine Dion.
Abbott said some CDs remained in Texas stores as of Monday morning.
The Texas spyware law allows the state to recover damages of up to $100,000 in damages for each violation.
Abbott said there were thousands of violations, and that any money would go to the state.
| IP: Logged
|
|
|
|
|
|
Monte L Fullmer
Film God

Posts: 8367
From: Nampa, Idaho, USA
Registered: Nov 2004
|
posted 11-22-2005 02:46 AM
Let's try it again: - Monte
CNET page
quote: It was a grand experiment that failed miserably: As a means of copy-protecting its music, Sony employed a piece of software from First4Internet. But the technology, as used by Sony, did two bad things: First, it hid itself on computers by using root-kit technology; and second, it opened a remote access connection that called out to Sony (or one of its agencies). This exposed users' computers to worms that took advantage of the stealth technology.
Sony has agreed not to put root-kit technology on future music CDs as a means of protecting its copyrights. But this story is far from over. There are at least two lawsuits pending. There are also viruses poised to take advantage of already-infected PCs worldwide, the number of which may be much higher than anyone previously thought. Worse, Sony's fix for the problem may not be any more secure than the original root kit.
In case you missed it Here's how users get stuck with the Sony root kit: When they first inserted certain CD titles from Sony BMG onto a desktop or laptop PC, a brief End User License Agreement flashed on the screen before they could listen to the music. Most people just agreed to the EULA so that they could get to the music. But by agreeing, they also consented to having additional software installed on their computer. That software, produced by First4Internet, hid itself and opened the remote connections.
The problem with root kits is that they are well known to criminal hackers (crackers), and they are all but invisible to most off-the-shelf antivirus apps available today. By definition, that's a root kit. The problem with root kits is that they are well known to criminal hackers (crackers), and they are all but invisible to most off-the-shelf antivirus apps available today. The infected Sony CDs have been out in the world since last spring, but researchers such as Mark Russinovich at SysInternals and more recently, antivirus vendor F-Secure began wondering whether virus writers would soon exploit this in some fashion.
Exploited They did. Word of the Sony root kit surfaced in the first week of November, and starting on November 10, several viruses began to appear. Breplibot.c is one of several that attempted to go undercover using the Sony root kit. While a serious threat nonetheless, coding errors (perhaps because the criminal hackers worked in great haste) prevented the malicious part of the code from activating.
There is now hard data available Now that Sony has agreed to stop producing CDs with a stealthlike DRM software embedded, one would think the threat would go away. It won't. Security Researcher Dan Kaminsky, a frequent speaker at Black Hat, has done some fascinating research into Domain Name Service servers and the related security threats potential to them. Recently, Kaminsky posted what the Sony root kit might mean in terms of sheer numbers of people infected. The data isn't good from a security standpoint.
Kaminsky started with a very basic premise: Sony has a root kit; all root kits phone home; phoning home requires a DNS query; DNS queries are cached. From this simple theory, Kaminsky was able to query roughly 3 million Domain Name Service servers to find traces or signatures of Sony root kits calling from their desktop and laptop PC clients back home to Sony (or some other agency) host servers. He didn't find a few thousand, nor a hundred thousand. Kaminsky found roughly 568,200 DNS servers that have signatures of the Sony root kit calling home. He states that from this figure, he can't conclusively determine how many hosts that translates into--only Sony and First4Internet know that number.
"0wned" by Sony Kaminisky has translated his data into a satellite image of Earth; here's a graphic of Sony-owned North American PCs. As mentioned, Sony has stopped production of music CDS and has offered to replace CDs already purchased with CDs sans DRM software, but the company has yet to state how it proposes to remove the remote-access Trojans from the roughly half-million infected PCs.
Also, the patch, offered by Sony, apparently causes more harm than good. Finnish security researcher Muzzy reported that in removing the First4Internet root kit, new ActiveX code is installed. The new code, called CodeSupport, doesn't restrict itself to Sony or First4Internet; instead, someone could write an exploit for CodeSupport that directs new traffic to a cracker's domain. First4Internet is apparently aware of this and may soon offer a fix to its patch.
But wait, there's more While First4Internet's root kit has enjoyed the lion's share of media, there's a secondary software package used by Sony to protect its assets, SunComm's MediaMax. The site Free to Tinker has reported that MediaMax uses spywarelike behavior, although it does not hide itself the way the First4Internet software does. And security company ISS is reporting new vulnerabilities for those still infected with the original Sony root kit.
Perhaps someday vendors will understand that my PC is a temple, and I (and only I) decide what should be running on it. Looking ahead, what would happen if rival companies started installing root kits on consumer's PCs--say, you buy one CD from Sony and another from Warner. According to F-Secure's blog site, in order for any root kit to hide itself, it must interface with the operating system kernel on a very low level, one that leaves no room for error. But what happens if you buy CDs from two competing manufacturers? Installing one root kit on top of another could lead to a very unstable situation. I say could, because this is all theoretical at this point. News.com has collected a variety of "what this might mean" stories regarding the Sony root-kit fiasco here.
I suspect we'll see more exposure of business practices like this in the near future. Antivirus companies are getting better at finding and exposing root kits, and brand-name vendors may find themselves, like Sony, having to answer for their past actions. Perhaps someday vendors will understand that my PC is a temple, and I (and only I) decide what should be running on it.
By Robert Vamosi Senior editor, CNET Reviews November 18, 2005
| IP: Logged
|
|
|
|
|
|
All times are Central (GMT -6:00)
|
This topic comprises 6 pages: 1 2 3 4 5 6
|
Powered by Infopop Corporation
UBB.classicTM
6.3.1.2
The Film-Tech Forums are designed for various members related to the cinema industry to express their opinions, viewpoints and testimonials on various products, services and events based upon speculation, personal knowledge and factual information through use, therefore all views represented here allow no liability upon the publishers of this web site and the owners of said views assume no liability for any ill will resulting from these postings. The posts made here are for educational as well as entertainment purposes and as such anyone viewing this portion of the website must accept these views as statements of the author of that opinion
and agrees to release the authors from any and all liability.
|