On MovieTome: See images from the CHUN-LI movie!
BNET Business Network:
BNET
TechRepublic
ZDNet

By John Borland
Posted on ZDNet News: Nov 15, 2005 11:03:00 PM

Record label Sony BMG Music Entertainment said Tuesday that it will recall millions of CDs that, if played in a consumer's PC disc drive, will expose the computer to serious security risks.

Anyone who has purchased one of the CDs, which include southern rockers Van Zant, Neil Diamond's latest album, and more than 18 others, can exchange the purchase, Sony said. The company added that it would release details of its CD exchange program "shortly."

Sony reported that over the past eight months it shipped more than 4.7 million CDs with the so-called XCP copy protection. More than 2.1 million of those discs have been sold.

Reader response
What should Sony do?
Debate how the debacle will
affect the label's policies.

"We share the concerns of consumers regarding discs with XCP content-protected software, and, for this reason, we are instituting a consumer exchange program and removing all unsold CDs with this software from retail outlets," the company said in a statement. "We deeply regret any inconvenience this may cause our customers."

The company made the announcement--its second public apology since the CDs' risks came to light last week--just as security researchers found several other potentially dangerous flaws in the software.

Princeton University computer science professor Ed Felten wrote on his blog Tuesday that he and a fellow researcher had confirmed that Sony's initial Web-based uninstall tool--designed to uninstall the copy-protection software deposited by Sony's CDs--actually exposed a critical vulnerability on computers.

The tool downloaded a program that causes a user's hard drive to accept instructions from Web sites. But the program remained active on the user's hard drive after it had been instructed to uninstall the Sony software. The program could then be triggered by almost any code from any Web site, including malicious instructions, the Princeton researchers said.

"Any Web page can seize control of your computer; then it can do anything it likes," Felton and fellow researcher J. Alex Halderman wrote on their blog. "That's about as serious as a security flaw can get."

Sony later replaced that Web-based uninstall tool with one that downloads a program with its own instructions, as opposed to one that accepts instructions from Web sites. The researchers said the new program appeared to be safe.

For anyone who did use the earlier tool, the researchers' blog has instructions for removing the Sony component.

Separately on Tuesday, security company Internet Security Systems released its own new advisory on Sony's software. It warned that flaws in the copy-protection software--not just in the early uninstall tool--could allow an attacker to take control of a user's machine.

Related story
FAQ: Sony's 'rootkit' CDs
The basics everyone should know about Sony's copy-protection technology.

Previously, security researchers had spotlighted the online release of several Trojan horse viruses that piggybacked on the Sony software to hide their presence on hard drives.

The Trojan horse software, once installed, automatically connects to an Internet chat network and allows an attacker to take remote control of an infected computer.

Half a million people at risk?
Although more than 2 million of the Sony discs have been sold, it's still unclear how many of those were actually played in a Windows-based computer, thus triggering the security risks. Sony notes that the copy-protection software is not activated on an ordinary CD or DVD player, or on a Macintosh computer.

Security researcher Dan Kaminsky said he estimated that at least 500,000 computers had installed the Sony software.

Once installed, the Sony software can relay data, which indicates what CDs are being played, to an outside server. To relay the information, the software has to find its destination by contacting the Internet's domain name system address servers, where a publicly available record of that request is left behind.

Kaminsky said he counted more than 568,000 separate requests. The method counts any request coming from the same network, but only once. So it might not include repeated requests coming from offices or schools, where numerous computers use the same network, he said.

"The thing that's proved here is not the upper bound," Kaminsky said. "This is a lower bound. This is a pandemic."

Sony's copy-protection software was created by British company First 4 Internet. The software is installed on a computer's hard drive when certain Sony compact discs are put in the CD player and the listener accepts a license agreement.

The software then hides itself using a controversial programming tool called a "rootkit," which takes over high-level access to some computing functions. The rootkit blocks all but the most technically savvy users from being able to detect its presence.

Sony has worked with antivirus companies to help their products pierce this veil of invisibility, and has posted a patch on its Web site that will uncloak the hidden software. It also said it would temporarily stop manufacturing discs using the First 4 Internet tools.

Lawsuits have been filed against the record label in California and New York, and others are expected.

  • Talkback
  • Most Recent of 35 Talkback(s)
Which artists' CDs are infected?
I've yet to read the names of the CDs containing the rookit files. How would I know if they're in my possession if I'm currently playing them only on CD players?

Hey Sony-BMG whatever your name is this year - name the infected CDs.... (Read the rest)
Posted by: dstaubel@aol.com Posted on: 11/23/05 You are currently: Logged In as: a Guest  | Login | Terms of Use
ROOTS!  osreinstall | 11/15/05
Complete list of affected discs?  geobeck | 11/15/05
MORE than 20 CDs! see URL for list  ChazzMatt | 11/16/05
MORE than 20 CDs! see URL for list  ChazzMatt | 11/16/05
Sony didn't lie  BrewMan01 | 11/19/05
Impossible to say!  gafisher@... | 11/16/05
Sony is too slow  Ken_z | 11/15/05
Where do we return?  IT-sys | 11/15/05
Thy Kernel Crumbles  HALAPI | 11/15/05
boycott sony  gsweely | 11/15/05
Rationally?? You ask too much....  shawkins | 11/15/05
It's the stupidity that bugs me  ebrke | 11/16/05
Rationally?? You ask too much....  shawkins | 11/15/05
Again, the double post..... what's up with ZDnet??  shawkins | 11/15/05
That is why Sony and First 4 Internet must be  Mectron | 11/15/05
boycott sony  gsweely | 11/15/05
Sony Hypocrites!!!  jhoman22@... | 11/15/05
This is what happens when...  lawryll@... | 11/15/05
Programming is entry level work bites back!!!  Too Old For IT | 11/16/05
Time for a taste of their own medicine  jstme123 | 11/15/05
Taste of their own medicine  jstme123 | 11/15/05
Don't blame the artists!  gafisher@... | 11/16/05
Just what Sony is counting on.  enduser_z | 11/16/05
Sony no isolated case, this is the scary future.  kraterz | 11/16/05
RE: Sony no isolated case, this is the scary future. by kraterz  btljooz | 11/16/05
Idiotessimo  Roger Ramjet | 11/16/05
Sony Trojans  tdbriz@... | 11/16/05
Who Else?!?!  pilaar39 | 11/16/05
Bad Sony  rastaub | 11/16/05
It may not be just the CDs  NobodyHome | 11/16/05
Yeah, just in time for the PS3  Boot_Agnostic | 11/16/05
I just bet...  BitTwiddler | 11/16/05
Sony  ArthurDent | 11/16/05
Just on name alone  Boot_Agnostic | 11/17/05
Which artists' CDs are infected?  dstaubel@... | 11/23/05

What do you think?

advertisement
advertisement

CIO Sessions

advertisement
Click Here