On GameSpot: $299 PS3 Slim and price cut announced!
BNET Business Network:
BNET
TechRepublic
ZDNet

By John Borland
Posted on ZDNet News: Nov 11, 2005 7:55:00 PM

On Thursday, a wave of malicious software appeared in the wild that piggybacked on copy-protection technology installed on hard drives by Sony BMG Music Entertainment CDs.

Computer security companies had been predicting such exploit code in the wild for weeks, since an independent developer had exposed the presence of a "rootkit" tool on the Sony CDs. The rootkit technology hid the copy protection from view, but also left open a hole that could hide other software.

Virus writers quickly took advantage of that hole, modifying an old Trojan horse to take advantage of the powerful inadvertent shielding provided by the Sony software.

On Friday, Sony responded to the furor and announced that it will suspend production of CDs that contain this particular copy-protection technology and take a second look at its digital rights management strategy.

Antivirus companies are now offering a range of advice, and confusion remains about exactly what the software does and how dangerous it can be to a PC. Here are the basics that everyone should know about this potentially dangerous issue:

What is on the Sony CDs?

The CDs involved are loaded with a relatively new kind of content protection created by British company First 4 Internet. When a listener puts the album into a computer's CD drive, it pops up a license agreement. If the listener accepts, it installs the copy protection rootkit onto the hard drive.

The rootkit element of the software is used to hide virtually all traces of the copy protection software's presence on a PC, so that an ordinary computer user would have no way to find it. The software acts to limit the number of copies that can be made of the CD and prevents a computer user from making unprotected MP3s from the music.

What is a rootkit? Isn't that something that virus writers use?

A rootkit is a powerful piece of software that takes over control of a computer at the most fundamental level. In computer terms, it establishes "root" access, which is similar to administrative access, instead of access for just an ordinary user. It can potentially prevent a computer user from detecting its presence or from performing certain tasks on their own PC.

Like most computing tools, this is not intrinsically a bad thing, but can be abused. Virus writers use these tools to help take over computers and hide the presence of their work.

Is Sony's software a virus or a Trojan horse?

Some aggrieved users may see little difference. Computer security companies do make a distinction between Sony's software and a virus, noting that this was distributed by a legitimate company with a legitimate business interest (even if many people disagree with that business interest).

However, they are deeply critical of Sony's techniques and say that the amount of information given to users about what the software would do to a computer was wholly inadequate, and the lack of an uninstall tool was bad policy.

Computer Associates has labeled the software "spyware," because it also sends back some information about what CDs are being played.

Can I uninstall it?

Even if you could find the hidden copy protection components yourself, computer experts warn against trying to uninstall it without help. Trying to do remove it without official instructions could damage the computer, rendering the CD drive inoperable.

Sony's Web site has a downloadable patch which will remove the ability of the copy protection software to hide from view, but will not uninstall it.

To uninstall the software completely, a user must fill out a separate customer service form on Sony's Web site, asking for instructions on how to uninstall the rootkit software.

How do the new Trojan horses piggyback on Sony's software?

The Sony software hides itself very well on a computer, but allows other software to use the same technique. Essentially it establishes a new rule at the level of the operating system that says any software that starts with the string of characters "$sys$" should be hidden from view.

Virus writers quickly took pre-existing malicious software and put those characters at the beginning of the relevant code, making their work invisible on any computer that had the Sony copy protection installed.

What do the new viruses do?

So far, the ones that have emerged hide themselves, then open a channel to the IRC chat network. An attacker could use that back door to control the computer completely, using it to send out spam, launch attacks on other computers, or many other nefarious tasks.

Will antivirus software stop this?

The problem with rootkits is that they can hide themselves even from antivirus software. However, most of the big antivirus companies are working with First 4 Internet and Sony to break through the rootkit's invisibility and identify anything hidden by the Sony software. That means most antivirus protection will be able to identify and remove the Trojans.

As always, it's important to keep antivirus software updated, or it won't be able to find these new problems.

Do all copy-protected CDs have this problem?

No, the majority does not. Most of Sony's copy-protected CDs use a different technology from a company called Sunncomm, which does not present the rootkit security issues. In other countries, many copy-protected CDs use technology from Macrovision, which also uses a different technique.

Which CDs are dangerous, then?

The Electronic Frontier Foundation is keeping a list of CDs that seem to have the First 4 Internet software included.

If you're buying a CD, look on the back for a little box labeled "Compatible with." If that includes the Web address "cp.sonybmg.com/xcp", then it probably has the rootkit software included.

Is what Sony did legal?

Copy-protection software by itself is perfectly legal. However, at least one class-action lawsuit has already been filed against Sony in California, asserting that it violated state and federal statutes against computer tampering, trespass, fraud and false advertising. Several other lawsuits are expected. Italian consumer groups have also called for criminal investigation and potential legal action, although the discs were primarily distributed in the United States.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 28 Talkback(s)
Guilt?
Regarding the issue of guilt - when someone breaks a window and gets into my house, I wonder who is guilty, the glass maker? Or the trespasser?

Just a thought ...... (Read the rest)
Posted by: lmenningen Posted on: 12/13/05 You are currently: a Guest | | Terms of Use
? why no talkbacks?  Valis Keogh | 11/11/05
Because...  DarbyOhara | 11/12/05
mr. bush's only mistake  alandee4 | 11/12/05
sony cd`s  graszhopper1938 | 11/12/05
Are you a patholigical liar?  Immanuel Tranz-Mischen | 11/13/05
Message has been deleted.  Update victim | 11/14/05
What did Clinton lie about?  Immanuel Tranz-Mischen | 11/14/05
Under oath, "banging an intern", and then we have  Update victim | 11/15/05
mr. bush's many triumphs  chris1752@... | 11/14/05
Right on, null  sykandtyed | 11/14/05
Political Affiliation Test  dfgu ;aZSdkfjg | 11/15/05
I hope that was a joke.....  JoeMama_z | 11/15/05
Funny....  bchesmer | 11/16/05
Funny....  bchesmer | 11/16/05
sleep in day for some  alandee4 | 11/12/05
DEATH TO DRACONIAN DRM  Valis Keogh | 11/11/05
They should state what their CD's carry...  thetargos | 11/12/05
`rootkit`  graszhopper1938 | 11/12/05
Won't be buying anymore sony cd's  bandaid69 | 11/14/05
This article probably doesn't reach as many affected users who copy CD's  BrookStone5 | 11/14/05
It's about the money - - -  Not*A*Clue | 11/15/05
Boycott Sony!  zaphod@... | 11/15/05
Should have sent paper  mobrien_12@... | 11/15/05
Microsoft ? not Sony are guilty.  Ianko | 11/15/05
Guilt?  lmenningen | 12/13/05
Where's my music? licenses, Media Player after reinstall  Kendahsi | 11/15/05
Your solution  plumnilly | 11/15/05
Theft  LordNyghthawk@... | 11/16/05

What do you think?

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More