Update on Sony Rootkit
November 9, 2005 by TomFirst of all…our next meeting is Thursday, Nov. 10, 2005 at 8:00pm on the 7th floor of Kimmel. We (well, I can’t be there, but everyone else) will be discussing the impending lecture, our next demonstration, our newly allocated budget, and the Google Print debate happening on the 17th. Inga is also supposed to talk about how awesome Computer Advocacy is. (c:=
Secondly, there has been a lot of follow-up to the Sony DRM Rootkit stuff I spoke and posted about last week. Basically, Sony (or more specifically First4Internet) has released a “patch” that removes the cloaking, but it does so in an unsafe way. It has also been determined that the software phones home, and that you have to jump through a large number of hurdles to get an uninstaller. Some vendors are considering this spyware…according to Mark Russinovich, some spyware is easier to uninstall than this rootkit (though much is right on par). This recent post on Mark Russinovich’s Sysinternals blog is, of course, the best summary:
Sony: You don’t reeeeaaaally want to uninstall, do you?
Also, third parties have already found a good use for the Sony Rootkit. World of Warcraft, an online game, uses a controversial program called Warden to detect cheat programs. But by leveraging the Sony Rootkit (by preceding the cheat programs’s name with “$sys$”), the cheat program goes undetected.
World of Warcraft hackers using Sony BMG rootkit
-Tom
November 13th, 2005 at 11:19 am
so remember how we were looking for something to tell people at the demonstration if they ask “well, then, how do i get this off my computer?” … i think this is supposed to work:
http://securityresponse.symantec.com/avcenter/venc/data/securityrisk.first4drm.html