Journal xtracto's Journal: Sony Rootkit CD providers! 44
Update, November 17:
Sony has made available an official list of the CD's that contain the XCP copy protection. The list can be read HERE.
As stated on the story: Sony DRM Installs a Rootkit, it seems that some of Sony's disks install a rootkit on your system after you try to listen them on your PC.
Why does it matter?
A rootkit is A type of Trojan that keeps itself, other files, registry keys and network connections hidden from detection. It runs at the lowest level of the machine and typically intercepts common API calls."
It is dangerous because hackers and virus writers can use it to help the attacker [hacker] to maintain his or her access to the system and use it for malicious purposes
On this page one of the developers at SysInternals explains what and how is the rootkit installed WITHOUT ASKING YOU when you insert any of the affected AUDIO CD's to play them on your computer running WINDOWS
Which CD's?
I have made a list of the CD's that are "Enhanced" and "Copy Protected" from sony with the XCP copy protection that provides a Rootkit.
It is easy to get an "up to date" list with
this google query.
The list of CD's so far are:
Nothing Is Sound. Switchfoot
Unwritten [CONTENT/COPY-PROTECTED CD] [ENHANCED]
Natasha Bedingfield
Ride [CONTENT/COPY-PROTECTED CD] [CONTENT/COPY-PROTECTED CD]
Shelly Fairchild
12 Songs [CONTENT/COPY-PROTECTED CD]
Neil Diamond
Touch [CONTENT/COPY-PROTECTED CD] [CONTENT/COPY-PROTECTED CD]
Amerie
Bloom Remix Album [CONTENT/COPY-PROTECTED CD] [ENHANCED]
Sarah McLachlan
Kasabian [CONTENT/COPY-PROTECTED CD]
Kasabian
The Essential Pete Seeger [CONTENT/COPY-PROTECTED CD] [CONTENT/COPY-PROTECTED CD] [ORIGINAL RECORDING REMASTERED]
Pete Seeger
Jeru [CONTENT/COPY-PROTECTED CD] [ENHANCED] [ORIGINAL RECORDING REMASTERED]
Gerry Mulligan
Times Like These [CONTENT/COPY-PROTECTED CD] [CONTENT/COPY-PROTECTED CD]
Buddy Jewell,
Bob Brookmeyer & Friends [CONTENT/COPY-PROTECTED CD] [ORIGINAL RECORDING REMASTERED]
Bob Brookmeyer
Healthy In Paranoid Times [CONTENT/COPY-PROTECTED CD] [ENHANCED]
Our Lady Peace
Cautivo [CONTENT/COPY-PROTECTED CD] [DUALDISC]
Chayanne
The Invisible Invasion [CONTENT/COPY-PROTECTED CD]
Coral, The Coral
Defined [CONTENT/COPY-PROTECTED CD] [CONTENT/COPY-PROTECTED CD]
Amici Forever
Suspicious Activity [CONTENT/COPY-PROTECTED CD] [ENHANCED]
The Bad Plus
Manhattan Symphonie [CONTENT/COPY-PROTECTED CD] [ORIGINAL RECORDING REMASTERED]
Dexter Gordon
Phantoms [CONTENT/COPY-PROTECTED CD] [CONTENT/COPY-PROTECTED CD]
Acceptance
On Ne Change Pas [CONTENT/COPY-PROTECTED CD]
Celine Dion
Get Right with the Man [CONTENT/COPY-PROTECTED CD]
Van Zant
To Love Again [CONTENT/COPY-PROTECTED CD] [ENHANCED]
Chris Botti
Life [CONTENT/COPY-PROTECTED CD] [DUALDISC]
Ricky Martin
The Essential Dion [CONTENT/COPY-PROTECTED CD] [CONTENT/COPY-PROTECTED CD] [ENHANCED] [ORIGINAL RECORDING REMASTERED]
Dion
Faso Latido [CONTENT/COPY-PROTECTED CD] [CONTENT/COPY-PROTECTED CD]
A Static Lullaby
Change It All [CONTENT/COPY-PROTECTED CD]
Goapele
Susie Suh [CONTENT/COPY-PROTECTED CD]
Susie Suh
My Very Special Guests [CONTENT/COPY-PROTECTED CD] [CONTENT/COPY-PROTECTED CD] [ORIGINAL RECORDING REMASTERED]
George Jones
Broken Valley [CONTENT/COPY-PROTECTED CD]
Life of Agony
Silver's Blue [CONTENT/COPY-PROTECTED CD] [ENHANCED] [ORIGINAL RECORDING REMASTERED]
Horace Silver
Z [CONTENT/COPY-PROTECTED CD] [ENHANCED]
My Morning Jacket
The 60s [CONTENT/COPY-PROTECTED CD]
The Dead 60s
What Can I do?
It is important to note that if you have tried to listen any of the above mentioned CD's your computer may have the rootkit installed. Hence, your system may be in danger of being hacked.
If you feel outraged because of this, you can write to the artists and complain about the problem. Tell them that their CD breaks your system as it opens a security hole.
If you think that there are other CD's which should be on this list please feel free to list them in a comment, also if you think any of the listed CD's DOES NOT actually have this problem please also state it in a comment.
Thank you!.
UPDATE:
November, 07. 2005
Mark Russinovich has posted a new entry on his blog showing some quite interesting and not less nasty behaviours of the fix "patch" provided by sony.
I found very interesting some of the comment posts in response of its blog entry. Specifically the one made by an author named xcp support who presumably represent the company behind the XCP technology.
On that post she states the following:
Blog: He claims that the patch itself could cause a blue-screen, although he says the risk is small.
Answer: This is pure conjecture. F4I is using standard Windows commands (net stop) to stop their driver. Nothing more.
There, she is trying to discredit the information provided by Russinovich's work. Stating that the program uses "standard windows commands". While that is certainly true, Russinovich shown on his post the specific state of the system that would cause the system failure.
Now, more interesting is a post from another user, Matt Nikki:
So, that means that if someone wanted to make illegal copies of the CD's listed before, they just needed to rename one file!. Thus, at the very end it is Sony's technology who is providing the means to bypass its own copy protection technology.
People won't need to disassemble or hack/crack and or reverse engineer anything. Just rename a simple file.
Ironic no?
List Update
Anyway, here is an update of the list as of today.
For those who asked, no the links above aren't any kind of referral links. This means I will not get any money if anyone clicks those links and/or buy those CDs.
To make this list I am only making a google search as I stated before and then manually parsing the entries.
Life In Slow Motion David Gray
Elizabethtown [SOUNDTRACK] Various Artists
Golden Elkland
Aha Shake Heartbreak Kings of Leon
Unfabulous And More: Emma Roberts [ENHANCED] Emma Roberts
Vivian Vivian Green
Dreamin' My Dreams [ENHANCED] Patty Loveless
Mary Mary [ENHANCED] Mary Mary
Never Gone Backstreet Boys
Aha Shake Heartbreak Kings of Leon
Friendship [ORIGINAL RECORDING REMASTERED] Ray Charles
Juego De Amor [Copy Protected CD] ~ Antony Santos
On Your Shore Charlotte Martin
Brown Sugar Various Artists
Blue Skies Diana DeGarmo
I'm a Hustla [EXPLICIT LYRICS] Cassidy
Hero Kirk Franklin
All That I Am Santana
List last updated:
November, 09. 2005 (13:08 GMT)
(The most up to date list can be found HERE)
thanks (Score:2)
typos discredit your cause (Score:2, Insightful)
Re:typos discredit your cause (Score:1)
Re:typos discredit your cause (Score:3, Funny)
Unforunately for the grammar Nazi inside you, English is not my native language.
Mas sería interezante ver que tanto dominas otro lenguaje que no sea Inglés.
Re:typos discredit your cause (Score:1)
How about "Sería interesante ver cuánto dominas un lenguaje que no sea inglés"?
Oh well... I've become one of those> .
Re:typos discredit your cause (Score:2)
Time? I don't think anyone who points out grammatical and spelling errors has to read the passage slowly or multiple times. These things stick out like purple giraffes to many people and are noticed on the first read only. Thus, if you read the passage, you spent the same amount of time noticing mistakes as the grammar nazi who pointed it out... he just did a better job
The artists have little to no say in the matter (Score:2, Interesting)
Re:The artists have little to no say in the matter (Score:2)
Please (Score:2)
Re:Please (Score:1)
Re:are those referral links? (Score:1)
http://www.amazon.com/exec/obidos/ASIN/B0009XT8Y2/ giftlistusa-20 [amazon.com]
His links look like this:
http://www.amazon.com/exec/obidos/tg/detail/-/B000 9XT8Y2/102-5413961-8783357?v=glance [amazon.com]
or this:
http://www.amazon.com/exec/obidos/ASIN/B0009XT8Y2 [amazon.com]
Notice the lack of an associate ID (afaik, they always end in -20, but even so, it's obviously missing)?
Possible Rootkit CD (Score:1)
Re:Possible Rootkit CD (Score:1)
Oh no! My ears! (Score:2)
Uh oh. That's the same company that recently denied they were planning on developing a DRM kit that would shatter the eardrums [theregister.co.uk] of those evil P2P downloaders. Hope they're telling the truth . . . ;-)
Something else you can do (Score:2)
The Above List (Score:2, Interesting)
Sony and others don't care - they wish CD died (Score:3, Insightful)
Perhaps many of the music labels wish the music CD format would die and be replaced with something else - embedding "trojans" is definitely speeding up the music CDs demise
And in the longrun that will hurt the labels - even now with all the on-line music options, many people still buy music CDs because they are simple to buy, familiar, easy of use, etc
Ron
Similar Search (Score:1)
ADVERTISEMENT: Sony Class Action Lawsuit (Score:4, Interesting)
Don't forget about Sony's BMG label too! (Score:1)
Re:Don't forget about Sony's BMG label too! (Score:1)
Re:Has anyone spelunked SONY DVDs for more RKs? (Score:2)
I'll try to remember to keep track of who's doing it in the future.
You... (Score:1)
There's a Slashdot article linking to it, posted in the Mysterius Future.
Re:Foo Fighters album DOES NOT use rootkit (Score:2)
Add to the list: (Score:1)
Re:Add to the list: (Score:2)
I bet Montgomery and Gentry aren't too proud of this. Oh the irony. Van Zant's "Get Right with the Man" is pretty ironic too, although they are talking about God as the Man, not Big Brother.
Re:Add to the list: (Score:1)
Re:Add to the list: (Score:2)
Re:Add to the list: (Score:1)
Heads up (Score:1)
another artist and cd to add (Score:1)