On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

By Alorie Gilbert
Posted on ZDNet News: Nov 16, 2005 11:52:00 PM

Sony BMG took another blow Wednesday, when a security company said it has found malicious attacks based on software designed to defuse the record label's "rootkit" problems.

Websense's security labs reported that it has discovered several Web sites designed to exploit security flaws in a rootkit uninstaller program issued by Sony BMG Music Entertainment. As reported earlier, some Sony CDs deposit rootkit-like code onto people's computers that leave them open to attacks.

Websense has uncovered only a couple of Web sites set up to attack flaws in the initial uninstall program, and the damage they cause appears to be minimal so far. One of them, hosted in the United States, simply restarts infected computers.

Reader response
What should Sony do?
Debate how the debacle will
affect the label's policies.

"It's someone trying to make a point," said Dan Hubbard, senior director of security and technology research at Websense. "They could have done a lot worse."

Sony became embroiled in controversy earlier this month after the record label was discovered to be distributing secret code similar to a rootkit with certain music CDs as a copy-protection mechanism. Sony BMG recalled millions of these CDs on Tuesday, after viruses exploiting flaws in the rootkits began to appear.

The company also released programs to uninstall the rootkits, but the initial Web-based version has its own set of flaws, Princeton University computer science professor Ed Felten wrote in his blog Tuesday.

Web site attack page

In the case of the U.S.-hosted malicious site, the attacker may have compromised the site without the owner's knowledge, Websense's Hubbard said. The site appears to be associated with Canada's version of the American Idol TV show. Websense also found the following message in the site's malicious code: "Sony DRM Christmas Gift." DRM stands for digital rights management, a type of copy-protection technology.

"Any user who has downloaded and run the Sony uninstaller program is susceptible to this attack," Websense said in a statement.

A Sony BMG representative did not immediately respond to inquiries about the alert.

However, in response to concerns about the security of its uninstall software, Sony has removed the program from its Web site, and promised to release another version soon.

"We currently are working on a new tool to uninstall First4Internet XCP software," the Sony site now reads. "In the meantime, we have temporarily suspended distribution of the existing uninstall tool for this software. We encourage you to return to this site over the next few days."

The flaw in Sony's uninstall software was based on an ActiveX progam installed on hard drives, which allowed Web sites to run malicious code automatically in the Internet Explorer Web browser. Some security experts are advising people who think they might have used Sony's uninstall tool to use the Firefox Web browser, which does not support automatic ActiveX controls.

Princeton computer science professor Ed Felten and researcher Alex Haldeman have created a page that tests whether a computer might be at risk as a result of running the uninstall tool.

CNET News reporter John Borland contributed to this story.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 25 Talkback(s)
Microsoft Needs to Take Action
I've already commented on this Sony thing elsewhere here on ZDnet...but there is ONE thing that does need doing.

Microsoft needs to immediately make it impossible for anyone to install a root-k... (Read the rest)
Posted by: jimc52@... Posted on: 12/07/05 You are currently: a Guest | | Terms of Use
Class Action Law Suits  IT-sys | 11/16/05
Message has been deleted.  Valis Keogh | 11/16/05
Just Ordered Mine  itanalyst | 11/17/05
Too late, once again  Jack-Booted EULA | 11/17/05
There Was NOTHING Wrong With That Post  itanalyst | 11/17/05
Well, I think what happened was this  James T. Kirk | 11/17/05
Oops...  James T. Kirk | 11/17/05
Class Action Law Suits  IT-sys | 11/16/05
Even Worse Than This  Edward Meyers | 11/16/05
Only legit customers were hurt  jtwillia | 11/16/05
That's what I've been saying all along  jinko | 11/16/05
Recording companies have  ebrke | 11/17/05
Sony is evil AND incompetent  llaitner | 11/16/05
Actually  James T. Kirk | 11/17/05
Safer to download than to purchase?  Breakthrough Bruce | 11/17/05
No Sonys under the tree this year  Boot_Agnostic | 11/17/05
Ho, Ho, NO!  Doc Farmer | 11/17/05
Malpractice  bony tryan | 11/17/05
Boycott Sony! Sign the petition!  CommSoft | 11/17/05
Sony dosen't care who you are  RIAAsucks | 11/17/05
That sir....  James T. Kirk | 11/17/05
Double OOPS  Update victim | 11/17/05
This Just Gets Better and Better- DVD John's Illegal Code Is Included i  Edward Meyers | 11/17/05
A good idea gone bad  johni123 | 11/20/05
Microsoft Needs to Take Action  jimc52@... | 12/07/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here