originalkitten opened this issue on Nov 11, 2005 ยท 17 posts
originalkitten posted Fri, 11 November 2005 at 5:46 PM
http://securityresponse.symantec.com/avcenter/venc/data/securityrisk.aries.html
"I didn't lose my mind, it was mine to give away"
pakled posted Fri, 11 November 2005 at 7:03 PM
hmm..good to know..thanks..
I wish I'd said that.. The Staircase Wit
anahl nathrak uth vas betude doth yel dyenvey..;)
lesbentley posted Fri, 11 November 2005 at 7:09 PM
Thanks for the heads up!
nerd posted Fri, 11 November 2005 at 7:32 PM Forum Moderator
That'll start some stink. Sony CDs are officially a virus. Now IT types that had to weed it out of corporate systems can sue Sony for damage.
CL learned how folks feel about being called thievs. The security scheme form P5 was rapidly removed. P6 just uses the old fashioned serial number. That's enough to keep the honest folks honest. Sony should know that those who are intent to copy the CD will copy it no matter what virus the infuse the disk with. If they want to keep people from doing a disk copy just put a bad track in there. That will keep the honest honest and won't cause havock in peoples computers.
Message edited on: 11/11/2005 19:32
kuroyume0161 posted Fri, 11 November 2005 at 9:01 PM
Kewl... ;) Yes, I had mentioned the P5 fiasco. Well, think about this. This wasn't a quick 1-2 decision and away we go. They had to consider how to enforce CMP, how to add it, in what form, where, what kind, who would provide it, and so on. There were meetings about this, meetings with First 4 Internet, probably meetings with other prospective CMP providers. There was lengthy discussion about how to employ the CMP, how to secure it. It needed to be part of the development and design for the Audio CDs. It needed to added to the commercial products, tested, validated. Succinctly, this was something in planning and execution stages for at least six months, a year, or more. This was a deliberate action (albeit not very well thought out). A very deliberate action. And who did it protect? Since this thing only works on Windows, any cracker (or wannabee) could easily circumvent the CMP just by using a different OS. Wow, a cracker using a Unix-based OS, who woulda thunk it? ....
C makes it easy to shoot yourself in the
foot. C++ makes it harder, but when you do, you blow your whole leg
off.
-- Bjarne
Stroustrup
Contact Me | Kuroyume's DevelopmentZone
Silly_Sue_1 posted Sat, 12 November 2005 at 12:53 AM
http://www.eweek.com/article2/0,1895,1885334,00.asp?kc=ewnws111105dtx1k0000599 http://www.eweek.com/category2/0,1874,1258734,00.asp?kc=ewnws111105dtx1k0000599 This may help some regarding this issue as well. If this is not allowable here on this board, please feel free to delete it. Thanks
kuroyume0161 posted Sat, 12 November 2005 at 1:22 AM
Thanks for the article link, Silly_Sue_1. I should mention that I'm using CMP (Content Media Protection) instead of DRM (Digital Rights Management). These are basically synonymous. If you have recently purchased any Sony BMG Audio CDs, I'd recommend returning them - for your safety if nothing else!
C makes it easy to shoot yourself in the
foot. C++ makes it harder, but when you do, you blow your whole leg
off.
-- Bjarne
Stroustrup
Contact Me | Kuroyume's DevelopmentZone
kawecki posted Sat, 12 November 2005 at 1:37 AM
Before returning it, send me a copy of aries.sys. I want to know what it does!
Stupidity also evolves!
maclean posted Sat, 12 November 2005 at 10:00 AM
'This was a deliberate action (albeit not very well thought out). A very deliberate action' It could also be considered a desperate action. This year, Sony will be posting their first yearly loss in 11 years. Last quarter's sales were down 46.5%. They've lost a ton of money making crap movies that bomb at the box-office. That, plus a general slowdown in plasma screens, digital cameras, etc, means they're losing money hand over fist. Am I glad? After this idiotic rootkit stunt, you bet I'm glad! mac
steerpike posted Sat, 12 November 2005 at 10:03 AM
By the way - anybody seen the latest item in freestuff?
originalkitten posted Sat, 12 November 2005 at 10:04 AM
who by?
"I didn't lose my mind, it was mine to give away"
layingback posted Sat, 12 November 2005 at 11:41 AM
Attached Link: http://www.sysinternals.com/blog/2005/11/more-on-sony-dangerous-decloaking.html
Actually CA did same as Symantec - classing it as a virus - much earlier this week. And CA's tool removes it *and* prevents re-infection. BTW, there is no way to remove Sony BMG/F4I's rootkit manually. Even their own uninstall routine, if you manage to get hold of it (and accept their confidentiality requirement), runs the risk of permanently trashing your Windows OS. Symantec's action is probably in light of media pressure - to save face - seems that Symantec was the primary technical consultant behind F4I's development of this rootkit in the first place. But then Symantec have a reputation of backing both sides in the virus arms race. (Historically the bulk of the early virus development was down to Symantec with their asinine $100 bounty for all viruses submitted regardless of source, i.e. whether it had ever been released to the wild. For a few thousand handouts Symantec created the virus market it needed to compete with McAfee. Ever wondered why to this day the percentage of unreleased viruses that Symantec claims to protect against is a huge percentage of the total population count?) And the primary reason this rootkit is so bad is limited programming expertise on the part of F4I - the programmer developing it asked for help from the FOSS community during it's development. Frighteningly basic questions apparently for someone attempting something as mindblowingly complex as a kernel-level hook into Windows that needed to be FORWARD-compatible with Windows future releases. I've attached to link to Mark Russinovich's - the person who discovered it - blog.kawecki posted Sat, 12 November 2005 at 1:43 PM
"BTW, there is no way to remove Sony BMG/F4I's rootkit manually. Even their own uninstall routine, if you manage to get hold of it (and accept their confidentiality requirement), runs the risk of permanently trashing your Windows OS."
You can easily remove it manually, just delete aries.sys and anything in the folder $sys$....
You can't do it from Windows because Windows will don't allow you to do it, so boot with DOS or Linux and delete the files.
Next time that Windows will start will complain for missing files, so run regedit, search for the deleted files and delete all the keys that makes refernce to those files.
Sony uninstall doesn't work because it doesn't remove the DRM, only install it in another way and who knows what else does.
Message edited on: 11/12/2005 13:45
Stupidity also evolves!
layingback posted Sat, 12 November 2005 at 4:18 PM
Agreed, I should have said "... from within Windows". But not all Windows users know how to make/acquire a DOS boot disk, or run Knoppix... The problem with the Sony install or manually deleting from within Windows is that the F4I hook is done poorly, so removing while Windows is running - as the Sony Uninstall does - can have disastrous consequences if something else has hooked in since the Sony F4I installation. Details in the link I provided above.
mamba-negra posted Sun, 13 November 2005 at 12:22 AM
The answer? Consider Sony the criminal they really are and boycott all products they produce! It's the only way to let these jerks realize they can't play these kind of games.... eric
steerpike posted Sun, 13 November 2005 at 3:28 AM
From originalkitten: "who by?" JimFarris - at the time I wrote post #10, his Sony radio was the newest freestuff item.
originalkitten posted Mon, 14 November 2005 at 3:45 AM
lmao.....thanks
"I didn't lose my mind, it was mine to give away"