FAQ: Sony's 'rootkit' CDs

By John Borland, Special to ZDNet
14 November 2005 10:09 AM
Tags: sony, virus, protection, cd, copy, rootkits, cds, viruses
Can I uninstall it?
Even if you could find the hidden copy protection components yourself, computer experts warn against trying to uninstall it without help. Trying to do remove it without official instructions could damage the computer, rendering the CD drive inoperable.

Sony's Web site has a downloadable patch which will remove the ability of the copy protection software to hide from view, but will not uninstall it.

To uninstall the software completely, a user must fill out a separate customer service form on Sony's Web site, asking for instructions on how to uninstall the rootkit software.

How do the new Trojan horses piggyback on Sony's software?
The Sony software hides itself very well on a computer, but allows other software to use the same technique. Essentially it establishes a new rule at the level of the operating system that says any software that starts with the string of characters "$sys$" should be hidden from view.

Virus writers quickly took pre-existing malicious software and put those characters at the beginning of the relevant code, making their work invisible on any computer that had the Sony copy protection installed.

What do the new viruses do?
So far, the ones that have emerged hide themselves, then open a channel to the IRC chat network. An attacker could use that back door to control the computer completely, using it to send out spam, launch attacks on other computers, or many other nefarious tasks.

Will antivirus software stop this?
The problem with rootkits is that they can hide themselves even from antivirus software. However, most of the big antivirus companies are working with First 4 Internet and Sony to break through the rootkit's invisibility and identify anything hidden by the Sony software. That means most antivirus protection will be able to identify and remove the Trojans.

As always, it's important to keep antivirus software updated, or it won't be able to find these new problems.

Do all copy-protected CDs have this problem?
No, the majority does not. Most of Sony's copy-protected CDs use a different technology from a company called Sunncomm, which does not present the rootkit security issues. In other countries, many copy-protected CDs use technology from Macrovision, which also uses a different technique.

Which CDs are dangerous, then?
The Electronic Frontier Foundation is keeping a list of CDs that seem to have the First 4 Internet software included.

If you're buying a CD, look on the back for a little box labelled "Compatible with." If that includes the Web address "cp.sonybmg.com/xcp", then it probably has the rootkit software included.

Is what Sony did legal?
Copy-protection software by itself is perfectly legal. However, at least one class-action lawsuit has already been filed against Sony in California, asserting that it violated state and federal statutes against computer tampering, trespass, fraud and false advertising. Several other lawsuits are expected. Italian consumer groups have also called for criminal investigation and potential legal action, although the discs were primarily distributed in the United States.

Advertisement

Talkback 7 comments

    How Do I Know If I Have It? Anonymous -- 16/11/05 (in reply to #120123365)

    Okay, so I have one of the "culprit" CDs and I have burned it to my PC (Windows). How do I know if my machine has created the vulnerability?

    According to this report (http://www.eff.org/deeplinks/archives/004144.php), at least one of the CDs is "labeled as XCP, but, oddly, our disc had no protection," I find myself wondering how in the world I check my machine to see if it's there!?

    Any suggestions are appreciated!

    How Do I Know If I Have It? Anonymous -- 16/11/05

    Okay, so I have one of the "culprit" CDs and I have burned it to my PC (Windows). How do I know if my machine has created the vulnerability?

    According to this report (http://www.eff.org/deeplinks/archives/004144.php), at least one of the CDs is "labeled as XCP, but, oddly, our disc had no protection," I find myself wondering how in the world I check my machine to see if it's there!?

    Any suggestions are appreciated!

    Might help Adam -- 18/11/05 (in reply to #120123367)

    In internet explorer, this website will attempt to use the ActiveX control that Sony / F4I require you to install to remove the DRM cloaking.

    http://www.cs.princeton.edu/~jhalderm/xcp/detect.html

    A proof of concept really, they could take other actions like reboot the system etc, at the moment it just uses the IsAdministrator call.

    Easy way to avoid this.... use Linux Tom Sugar -- 20/11/05

    Well well well

    I'm glad that I use Linux.... in the unlikely event I buy a Sony CD their rootkit would be completely ineffective against my computer.

    SONY rootkits... Anonymous -- 21/11/05 (in reply to #120123543)

    Well, Linux may be impervious to the rootkits, but what are the chances you won't be able to play your purchased CD at all?

    A better solution; don't buy Sony music CDs.

    Maybe..but.. Mr brown -- 29/11/05 (in reply to #120123570)

    Whiloe I agree with your comment that the most effective way to protest this awful action on the part of Sony is to vote with your wallet and not buy their CD's I would also say that Linux plays EVERYTHING....

    It's even trivial to get around the iTunes Apple protection systems...allegedly ;)

    With Linux you can play/rip/copy everything on the planet..

    cheers!

    easier way to avoid this Anonymous -- 22/11/05

    Don't buy cds. It puts you at the mercy of those companies. This is just the tip of the iceberg....
    Just imagine what the next piece of malware will do.

Add your opinion

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • Array Is wholesale-only backhaul just a pipedream?
    The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
  • More blogs »

Tags

Back to top

Featured