You almost want to bury your head in the sand at this point if you’re Sony…. Freedom-to-tinker has some details. The last couple weeks the XCP copy protection that Sony uses has been the center of a Firestorm for rootkit capabilities and massive security problems. Well, it seems the OTHER Digital Rights Management (DRM) software they use ( SunnComm MediaMax ) has some serious flaws too.
The big security flaw is in the ActiveX uninstaller component, much like the security flaws in the XCP uninstaller….
From Felten’s post: “When you visit the SunnComm uninstaller web page, you are prompted to accept a small software component — an ActiveX control called AxWebRemoveCtrl created by SunnComm. This control has a design flaw that allows any Web site to cause it to download and execute code from an arbitrary URL.
“If you’ve used the SunnComm uninstaller, the vulnerable AxWebRemoveCtrl component is still on your computer, and if you later visit an evil Web site, the site can use the flawed control to silently download, install and run any software code it likes on your computer. The evil site could use this ability to cause severe damage, such as adding your PC to a botnet or erasing your hard disk.”
Also, there is a tool to block this component at the Freedom-to-tinker link above and it comes with this warning.
“Unfortunately, if you use our tool to block the control, you won’t be able to use SunnComm’s current uninstaller to remove their software. It’s up to them to replace the flawed uninstaller with a safe one as soon as possible, and to contact those who have already used the vulnerable uninstaller with instructions for closing the hole.”
The flaw in this uninstaller is easier to exploit than that of the previous according to freedom-to-tinker.com and they EMPHASIZE that the problem (security flaw) is with the UNINSTALLER for the SunnComm MediaMax software. To get the uninstaller link required a couple of emails to support “pestering” for a way to get rid of the software. So if you have the MediaMax software installed and have never uninstalled it previously you should be safe (as far as is known. In other words, there are no other KNOWN problems with the MediaMax DRM.)
So, the world now waits for Sony and SunnComm’s reactions to this and hopefully a fix that can clear up the MASSIVE security holes they’ve left on machines around the world. Once again… thanks Sony.
Brian Krebs at the SecurityFix is also soliciting for a list of CDs protected by THIS DRM management software (the SunnComm MediaMax tool.) And says that he was skeptical at the beginning that this would be a deathknell for DRM software, but he’s starting to wonder.
Personally, in a time when computer security is such an issue, having unknown software from multiple sources can really raise a machines risk. It really makes me wonder what liabity these companies could find themselves in for poorly designed software. (And how enforcable a EULA is if there isn’t a reasonably easy way to decline.)
Beyond that it’s a reminder that should be WELL known by now. ActiveX controls can be VERY unsafe.
–update 11/17 – 8PM EST –
The Electronic Freedom Foundation has lists of titles affected by either DRM software. Also, it seems that some titles may be on the list and NOT have copy protection, you essentially need to use the “spotting guide” at the EFF link above to determine if you have a DRM’ed disc or not.
Related PostsRelated Posts
- The virus arms race? is locking down systems the key? The securityfix has a post on the "dirty little secret" about antivirus. Eugene Kaspersky of Kaspersky antivirus has posted an introspective article on the antivirus industry and it's current problems. The biggest problem with antivirus is that it's always one step behind the virus writers. Antivirus software only can prevent......
- Sneaky TorrentSpy bundling... Sunbeltblog is talking about torrentspy, which has licensed their own version of Rufus, a bittorrent client. All well and good, but... they've decided to bundle WhenU SaveNow *(adware) with THEIR version of Rufus. This has ticked off the writers of Rufus among others. What's more, they haven't disclosed the bundling......
- More on the MediaMax DRM software The OTHER Sony-BMG DRM (Digital Rights Management) software is in the news again today. freedom-to-tinker which did great research into the security flaws that the UNINSTALL process for both XCP and MediaMax had is back to give more disturbing news. What's interesting here is that even declining the EULA for......
- Antivirus Software Vs. Internet Security Software Lots of individuals believe that antivirus software and internet security software are same. While they protect your PC and avoid it from being attacked and infected by threats, they have exact roles in terms of defense and safety for your PC. Antivirus software can be installed on your personal computer......
- Comparison Between Free Of Charge And Paid Web Comparison between free of charge and paid Web security software has turn into a main subject of discussion amongst probably the most of all computer users recently. Numerous people who have employed both free of charge as well as paid Web security software place their strong opinions. Although many people......
- Magic Banner Bot Every once in a while you come across a piece of software that is worth writting about. Such is the case with Magic Banner Bot. A fantastic piece of software that gives you the ability to link to any site on the internet and then have your own banners linking......
- Sunncomm/MediaMax software fix released
- Sony’s OTHER DRM software uninstaller will be pulled
- Today’s Sony DRM rootkit stories….
- Sunncomm/Mediamax software fix FLAWED
- The best way to get rid of the Sony DRM rootkit