Sony DRM Rootkit — it’s worse



I did this as updates to an earlier post, but it probably deserves it’s own post now. The morning brought us the news of SERIOUS flaws in the Uninstaller ActiveX control for Sony’s DRM, then came news of ANOTHER flaw, this one a privilige escalation “attacker can take control of PC” vulnerability in the DRM rootkit (XCP) itself. The other bit of news to come has been the extent of the install base of XCP.


It seems that over 560,000 networks have the Sony DRM rootkit. Basically, Dan Kaminsky has analyzed DNS servers around the world and 560,000 +++ have cached DNS lookups for the site that the XCP rootkit “Phone’s home to”. These are DNS servers, so the scope of this could easily be millions of PC’s and could be 10′s of millions. Apparently there are few countries not represented in the list.

So, the DRM Rootkit (aka XCP) from Sony has major security flaws, it can hide other malicious software with it’s designed feature of hiding all files with $SYS$ in front of the name, the uninstaller was reported as buggy and requires an ActiveX control which is marked safe for scripting, remains on the system after uninstall. Some methods of uninstalling will wreck your ability to use the cd drive, the ActiveX control has multiple remote vulnerabilities and it’s on AT the VERY LEAST 560,000 PC’s and a reasonable estimate is that it could be millions. THANK YOU SONY.

I think I can hear the shouts of glee from malicious crackers EVERYWHERE.

At this point, Sony has said they’re stopping sale of affected discs and will be providing recall/swap details soon. I think they need to start getting out some information. How many of these cds were sold, how many have contacted the “Phone home servers” (to give a reasonable guess at the number of affected PC’s), I can’t believe they didn’t track that information. Further to help clean up from the UNINSTALLER, they need to start putting out numbers of how many downloads the ActiveX control has had. For much of this Sony/First4Internet are the only ones that will be able to truly give an idea of how widespread this is, but it is obviously VERY widespread. For once in this whole mess, Sony needs to stand up, take responsibility and proactively try to help people clean up this mess, get the word out to customers, etc….

Until that happens, the December update of Microsoft’s Malicious software removal tool may be the best bet for most users.

Related Posts

Blog Traffic Exchange Related Posts
  • Sony BMG is still having a bad week.... Unfortunately a LOT of people that have bought Sony-BMG cds (or borrowed, whatever...) are going to have some headaches too. By stock in Tylenol or Aleve or something.... anyway... here's todays roundup of Sony Rootkit news. Including a virus borrowing the gift of SONY... First up is some "backstory" that......
  • Sony's OTHER DRM software uninstaller will be pulled According to zdnet.com, Sony and SunnComm are pulling the OTHER DRM uninstaller from the web and it will be replaced with a safer version of the uninstaller. Researchers blogging at freedom-to-tinker.com had detailed serious vulnerabilities in the uninstaller for the DRM software made by SunnComm (called MediaMax). The companies say......
  • More on the MediaMax DRM software The OTHER Sony-BMG DRM (Digital Rights Management) software is in the news again today. freedom-to-tinker which did great research into the security flaws that the UNINSTALL process for both XCP and MediaMax had is back to give more disturbing news. What's interesting here is that even declining the EULA for......
Blog Traffic Exchange Related Websites
  • How to Install a Home Security System: Most Common Pitfalls Installing a home security system might seem easy. To be sure, it’s a lot easier to install one today than it was just a decade ago. Inexpensive consumer electronics components combined with robust wireless technology means that even an amateur can put in a decent system. Just because it’s easy,......
  • Prevent and Remove Registry Errors at Instant Registry Fixes A healthy windows registry is equivalent to a healthy PC. Only one registry error is needed to make your system spiral down until it cannot be used any more. That is why you must keep your computer in tiptop shape for optimum performance. Regularly scan your PC for viruses and......
  • Race for Sony Ericsson Championships Continues Doha 2009 has finally come to an end, and Jelena Jankovic has qualified, becoming the eighth and the final player to be qualifying for this championship during the singles competition. Jelena Jankovic is going to be joining Venus Williams, Victoria Azarenka, Elena Dementieva, Caroline Wozniacki, Svetlana Kuznetsova, Serena Williams and......
en.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site