Update on Sony Rootkit

November 9, 2005 by Tom

First of all…our next meeting is Thursday, Nov. 10, 2005 at 8:00pm on the 7th floor of Kimmel. We (well, I can’t be there, but everyone else) will be discussing the impending lecture, our next demonstration, our newly allocated budget, and the Google Print debate happening on the 17th. Inga is also supposed to talk about how awesome Computer Advocacy is. (c:=

Secondly, there has been a lot of follow-up to the Sony DRM Rootkit stuff I spoke and posted about last week. Basically, Sony (or more specifically First4Internet) has released a “patch” that removes the cloaking, but it does so in an unsafe way. It has also been determined that the software phones home, and that you have to jump through a large number of hurdles to get an uninstaller. Some vendors are considering this spyware…according to Mark Russinovich, some spyware is easier to uninstall than this rootkit (though much is right on par). This recent post on Mark Russinovich’s Sysinternals blog is, of course, the best summary:

Sony: You don’t reeeeaaaally want to uninstall, do you?

Also, third parties have already found a good use for the Sony Rootkit. World of Warcraft, an online game, uses a controversial program called Warden to detect cheat programs. But by leveraging the Sony Rootkit (by preceding the cheat programs’s name with “$sys$”), the cheat program goes undetected.

World of Warcraft hackers using Sony BMG rootkit

-Tom

One Response to “Update on Sony Rootkit”

  1. Laura Says:

    so remember how we were looking for something to tell people at the demonstration if they ask “well, then, how do i get this off my computer?” … i think this is supposed to work:

    http://securityresponse.symantec.com/avcenter/venc/data/securityrisk.first4drm.html

Leave a Reply

You must be logged in to post a comment.