Advertisement
Promo

Security threats Toolkit

Sony rootkit victims 'in every US state'

Ingrid Marson ZDNet.co.uk

Published: 17 Jan 2006 17:40 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A security researcher has revealed that computers in every US state have been affected by copy-restriction software produced by Sony BMG.

Security researcher Dan Kaminsky released the information at the Shmoocon 2006 hacker conference in Washington last week. Florida seems to have the highest number, with 12,588 networks detected that are hosting computers with the DRM installed, according to figures posted by The Washington Post. California and Massachusetts also exhibit high rates of infection, although the numbers are only an estimate as each network could host any number of computers with the Sony software installed.

The digital rights management (DRM) software is automatically installed by some Sony BMG music CDs and is hidden using a rootkit, which can be exploited by a particular type of Trojan horse and hence constitutes a significant security risk.

Kaminsky worked out the locations of machines with the Sony rootkit installed by collating information on communication between the rootkit and Sony — the software contacts Sony each time the CD is played.

"Sony has a rootkit. The rootkit phones home. Phoning home requires a DNS query. DNS queries are cached. Caches are externally testable provided you have a list of all the name servers out there," explains Kaminsky in his blog.

In December, Kaminsky reported that around 560,000 name servers had "witnessed DNS queries related to the rootkit", which he claimed was "much, much more" than he expected.

The problems with Sony's DRM are not limited to US customers, with Kaminsky's research showing that infected PCs can be found in many countries across the world, including many European countries.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
90 out of 161 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters