Update: fix released for Sony DRM rootkits

GEC: Discuss gaming, computers and electronics and venture into the bizarre world of STGODs.

Moderator: Thanas

User avatar
Lord of the Farce
Jedi Council Member
Posts: 2198
Joined: 2002-08-06 10:49am
Location: Melbourne, Australia
Contact:

Post by Lord of the Farce »

Psycho Smiley wrote:The fix is a direct response to the story being posted on many major tech sites. They probably wanted their asses covered before it hits a major news magazine or something.

EDIT: Slashdot says this may only make the shit visible, not remove it or keep it from hosing your system if you try to delete it. Braedley, have you tried this?
I might just be missing it, but looking at the "Aurora Support" page and both links, I see nothing about it cleaning up DRManure. So personally, I'd be rather suspicious as to what this "Software Update" actually does.
"Intelligent Design" Not Accepted by Most Scientists
Psycho Smiley
Keeper of the Lore
Posts: 833
Joined: 2002-09-08 01:27pm
Location: Soviet Canuckistan

Post by Psycho Smiley »

Rogue 9 wrote:
Psycho Smiley wrote:EDIT: Slashdot says this may only make the shit visible, not remove it or keep it from hosing your system if you try to delete it. Braedley, have you tried this?
Where does /. say this?
In a post here, there is a link:
CNET wrote:The patch that First 4 Internet is providing to antivirus companies will eliminate the rootkit's ability to hide itself and the copy-protection software in a computer's recesses. The patch will be automatically distributed to people who use tools such as Norton Antivirus and other similar programs, Gilliat-Smith said.

The patch that will be distributed through Sony BMG's Web site will work the same way, Gilliat-Smith said. In both cases, the antipiracy software itself will not be removed, only exposed to view.

Consumers who want to remove the copy-protection software altogether from their machine can contact the company's customer support service for instructions, a Sony BMG representative said.
Lord of the Farce wrote:I might just be missing it, but looking at the "Aurora Support" page and both links, I see nothing about it cleaning up DRManure.
The link Sony released requires jumping through at least one more link to get to the patch. I direct linked to the final page. Here is the original link if you prefer.
An Erisian Hymn:
Onward Christian Soldiers, / Onward Buddhist Priests.
Onward, Fruits of Islam, / Fight 'till you're deceased.
Fight your little battles, / Join in thickest fray;
For the Greater Glory / of Dis-cord-i-a!
Yah, yah, yah, / Yah-yah-yah-yah plfffffffft!
User avatar
Braedley
Jedi Council Member
Posts: 1716
Joined: 2005-03-22 03:28pm
Location: Ida Galaxy
Contact:

Post by Braedley »

Ok, so I tried it last night, and by all my accounts, it didn't work. The cause of this could be that Sony doesn't use the exact same software on each album, meaning the disk that I bought isn't supported. I'll do some more testing later.

PS Thanks Psycho Smiley for doing all the hard work for me.
Image
My brother and sister-in-law: "Do you know where milk comes from?"
My niece: "Yeah, from the fridge!"
User avatar
Drooling Iguana
Sith Marauder
Posts: 4975
Joined: 2003-05-13 01:07am
Location: Sector ZZ9 Plural Z Alpha

Post by Drooling Iguana »

Let that be a lesson to all of you: Don't but CDs. Download pirated MP3s instead. It's safer.

Or at least that seems to be the message Sony wants to convey.
Image
"Stop! No one can survive these deadly rays!"
"These deadly rays will be your death!"
- Thor and Akton, Starcrash

"Before man reaches the moon your mail will be delivered within hours from New York to California, to England, to India or to Australia by guided missiles.... We stand on the threshold of rocket mail."
- Arthur Summerfield, US Postmaster General 1953 - 1961
Psycho Smiley
Keeper of the Lore
Posts: 833
Joined: 2002-09-08 01:27pm
Location: Soviet Canuckistan

Post by Psycho Smiley »

Hackers are already making use of this. One example is to use it to circumvent WoW's new anti-cheating software by including $sys$ in the filenames. This hides the hacks from WoW's Warden system.
An Erisian Hymn:
Onward Christian Soldiers, / Onward Buddhist Priests.
Onward, Fruits of Islam, / Fight 'till you're deceased.
Fight your little battles, / Join in thickest fray;
For the Greater Glory / of Dis-cord-i-a!
Yah, yah, yah, / Yah-yah-yah-yah plfffffffft!
User avatar
Faram
Bastard Operator from Hell
Posts: 5271
Joined: 2002-07-04 07:39am
Location: Fighting Polarbears

Post by Faram »

Well this rootkit is even worse!

It is also spyware, who would have guessed?

Sysinternals
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]

"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus


Fear is the mother of all gods.

Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
Psycho Smiley
Keeper of the Lore
Posts: 833
Joined: 2002-09-08 01:27pm
Location: Soviet Canuckistan

Post by Psycho Smiley »

Faram wrote:Well this rootkit is even worse!

It is also spyware, who would have guessed?

Sysinternals
To elaborate, it phones home to Sony every time you play their CDs. Not necessarily malicious, but it isn't advertised, and I'm sure it can be exploited.
An Erisian Hymn:
Onward Christian Soldiers, / Onward Buddhist Priests.
Onward, Fruits of Islam, / Fight 'till you're deceased.
Fight your little battles, / Join in thickest fray;
For the Greater Glory / of Dis-cord-i-a!
Yah, yah, yah, / Yah-yah-yah-yah plfffffffft!
User avatar
Ace Pace
Hardware Lover
Posts: 8456
Joined: 2002-07-07 03:04am
Location: Wasting time instead of money
Contact:

Post by Ace Pace »

So not only is this rootkit bullshit, its also stupid.
The Comments wrote: If you want a more concrete proof, try to rename your favourite ripping software as $sys$whatever.exe and then run it again. You'll notice that the DRM system can no longer detect it, and thus you'll get good copy of the track you try to rip instead of one filled with noise.
Brotherhood of the Bear | HAB | Mess | SDnet archivist |
User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Post by phongn »

F4I's programmers are also incompetent. They're not doing some very basic things that are neccessary in a multithreaded environment.
User avatar
Ace Pace
Hardware Lover
Posts: 8456
Joined: 2002-07-07 03:04am
Location: Wasting time instead of money
Contact:

Post by Ace Pace »

phongn wrote:F4I's programmers are also incompetent. They're not doing some very basic things that are neccessary in a multithreaded environment.
I'm probebly missing something obvious but what exactly?
Brotherhood of the Bear | HAB | Mess | SDnet archivist |
User avatar
Xon
Sith Acolyte
Posts: 6206
Joined: 2002-07-16 06:12am
Location: Western Australia

Post by Xon »

Ace Pace wrote:
phongn wrote:F4I's programmers are also incompetent. They're not doing some very basic things that are neccessary in a multithreaded environment.
I'm probebly missing something obvious but what exactly?
They patch the system jump table (that provides the entrypoints from user-land to kernel-land) and also provide the ability to unload themselves.

The problem with this is the system jump table is static, trying to "unpatch" it is just asking for trouble since every bit of software and it's pet monkey uses it.

For example, consider these events;
  1. Random app gets an entry in the system jumptable
  2. rootkit unloads & unpatches system jumptable
  3. Random app actualls calls that location pointing to the rootkit(which is no unload)
  4. Computer blue screens due to the kernel trying to execute memory which is unallocated
"Okay, I'll have the truth with a side order of clarity." ~ Dr. Daniel Jackson.
"Reality has a well-known liberal bias." ~ Stephen Colbert
"One Drive, One Partition, the One True Path" ~ ars technica forums - warrens - on hhd partitioning schemes.
Post Reply