Oops -- New Sony DRM Patch Insecure
By Nate Mook | Published December 8, 2005, 11:40 AM
Just one day after jointly announcing a patch to correct a security flaw in the SunnComm MediaMax copy protection included on 27 CDs, Sony BMG and the Electronic Frontier Foundation are urging users not to install it. The update includes a vulnerability similar to the one it attempted to fix.
SunnComm's MediaMax version 5 software does not properly protect a directory it installs, opening the door for a privilege escalation attack. Thus, a restricted user account could replace the executables within the MediaMax directory with malicious code, which would then be executed by an administrator upon inserting a CD.
Sony said it would notify customers of the SunnComm problem through an advertising banner within the MediaMax software, and via an online ad campaign. It also began distributing an update on the Sony BMG Web site and to security vendors.
But despite claims that "independent software security firm NGS Software have determined that the security vulnerability is fully addressed by the update," Princeton researcher Alex Halderman has found otherwise.
"It turns out that there is a way an adversary can booby-trap the MediaMax files so that hostile software is run automatically when you install and run the MediaMax patch," Princeton professor Edward Felten explained. "The previously released MediaMax uninstaller is also insecure in the same way."
Halderman and Felten also discovered that even if a user declines the MediaMax license agreement, the vulnerable software is still installed on their computer. However, those users will not see the advertising banner Sony is using to notify customers.
"The consequences of this problem are just as bad as those of the XCP rootkit whose discovery by Mark Russinovich started SonyBMG's woes," added Felten. "This problem, like the rootkit, allows any program on the system to launch a serious security attack that would normally be available only to fully trusted programs."
This isn't the first time Sony's fix for vulnerable DRM has done more harm than good. Last month, Felten reported that the Web based uninstaller for the XCP copy protection contained a security flaw that could enable malicious software to be automatically installed on a PC.
Sony has recalled all CDs with XCP due to the furor surrounding the software's rootkit, but much to the chagrin of security experts, it is not following suit with SunnComm.
"Every disc sitting on somebody’s shelf, or in a record-store bin, is just waiting to install the vulnerable software on the next PC it is inserted into. The only sure way to address this risk is take the discs out of circulation," warns Felten. "The time has come for SonyBMG to recall all MediaMax CDs."
I acctually laughed out loud when i read the title
Score: 0
|It's just one more reason to boycott SONY products. First it was the damned rootkits and now another DRM product which damages our computers. It's time to "outlaw" these schemes as a rip-of of the consumer. Time to amend the coputer hacking laws and enforce them!
When does the government prosecute this crooked record company? Wanna bet that millions of illegal CDs are made with SONY's blank disks and hardware? This doesn't sound like a fascist corporation really worried about piracy...
Score: 0
|More of a reason to BOYCOTT all Sony products.
To think a few years ago the name Sony stood for quality.
Wow what a difference a few years make, now I won't buy anything with the Sony name.
Score: 0
|Anybody who don't know what a "rootkit" is doesn't need to worry whether they have one.
We should all trust Sony to do what's best for us.
Remeber: Having your personal computer destroyed represents a small price in the War Against Copyright Infringement !
The Computer Rodent
Score: 0
|There is more than 1 way to skin a cat....maybe if they thought about what the people wanted and not about what their wallets wanted things would have not gotten this bad.
Score: 0
|Dishonesty always meets ridicule at one time or another. One day, it just get stucked in it.
Score: 0
|http://boycottsony.us
Score: 0
|this rootkit thing just proves how deperate and how far the record comanies are willing to go to stop music piracy. too bad it all for nothing!!!
Score: 0
|Googun, you just gave Sony their greatest idea ever!
I think Sony would like nothing better than to *not* distribute their product in the traditional sense. All music, video, games, and creative works will, in the future, be housed at one gigantic Sony hubstation. Any consumer that wants to listen to a song (or watch a movie or play a videogame or view a piece of art) must allow Sony to penetrate every orifice of his home and body with RFID tags. When the consumer wants to hear a song, he must bend over and slide his @ss across a Sony branded scanner, insert a dongle into his ear, and agree to pay whatever arbitrary amount Sony deems appropriate at the time for the one time use of their product.
Consumer overspray of said product will be eliminated due to the nature of the delivery; the product will be beamed directly from the hubstation to the uniquely identified neurons of the paying consumer only. Any non-paying consumers caught tampering with or sampling from a paying consumer's RFID tags or dongles will be immediately shot by government appointed SWAT teams. All physical and intellectual property of these dead *pirates* will be immediately turned over to Sony in compensation for the revenue they would have earned if they had not been victimized.
Score: 0
|Kill da bas****s. Don't buy anything from Sony anymore.
Score: 0
|LMAO ok fearless leader
Score: 0
|http://boycottsony.us/
Score: 0
|You know... I remember my posts a year or so back talking about what an "ungrateful monster" the music industry is and how they're going to "get what they asked for" when the consumer decides to fight back. I guess I'm right, although I suggested that a massive boycott of music could occur.
So I guess I could say that my sympathy glands are dry for them and that it serves them right that they want to treat their customers like criminals. Speaking of criminals, did you know that murders will get a lower fine than file sharers?
Score: 0
|Hmm I wonder. Has anyone bought a VIAO lately? I wonder if it comes prepackaged with a Rootkit and some SunComm goodness.
Score: 0
|i bet allthese brand name computer come with loads of spyware preinstalled on them makes me want to go into a store and run ad-aware on one of the HP or VIAO copmputer just to see how much I find
Score: 0
|Among other brands of PCs (and printers), I sadley support Sony VAIO systems. While no evidence of rootkits (one user had rootkit revealer showed nada), it does come with the Sony 'bloatware' and adware. Argueably WildTangeant (forgive my spelling, I don't make habits of learning to spell spyware companies correctly) is spyware too, but every major PC vendor bundles that now. Sony comes with some extra crap that other vendor PC's don't, though.
Score: 0
|See me comment above. BTW out of box VAIO Laptop customer complained that Adaware found 12 critical items. Not sure if he had already connected to the web or not so that may not be accurate.
Score: 0
|People have always copied music. Even 100 years ago when guys were selling sheet music in the streets, copying was a problem. The music industry has never in all that time really grasped the idea that copying will always be with us. If you can hear music or retrieve it, by whatever means, then you can record it. Simple as that.
Copy-protecting their product will only ever stall the copying for as long as it takes to overcome its protection method. It is exactly the same as the situation with encryption software: It slows the process down. The only way to end copying is to not distribute the product, which of course would be the end of Sony music. That's not to say that copying is okay, but to point out that treating all customers like criminals in case one of them IS a criminal, is ultimately pointless. It does not end copying nor hurt the criminal; it justs upsets the customers.
Score: 0
|They are well aware it'll always be with us. They have an extremely profitable business, they have money rolling in, hand over fist, with margins that most companies would kill for. They obviously want to protect this profit and this business, and if they scare x people out of copying and into buying, then they have done their job.
They are still making gobs of money, but on some level I think they know they are losing this battle.
Score: 0
|i EL OH EL at sony.
Score: 0
|Haha... yeah. LMAO ROFL copter
Score: 0
|It looks like the DRM security softwares are going to cause more problems than the p2p file sharing networks caused.
Score: 0
|This is so true...Good comment! :-)
Score: 0
|Ummm... sure...
Score: 0
|Oy Veh...
Score: 0
|A dude I know at work installed the sony software on his home PC. I gave him this alarming look like, have you wiped your machine yet? and he seemed unphased, even a little offended that I would even suggest such a thing, even though he was somewhat aware of the rootkit fiasco.
It just reconfirms my belief that the majority of people in this world are morons and just don't care about security. BTW, this guy is a PHD and makes 6 figures a year, owns 3 houses. meh.
Score: 0
|Well....Sony has officially turned into a Japanese version of Microsoft. I suppose they were just so envious of Microsoft they had to go and copy them just like everything else in America.
Score: 0
|Hey man, IE is bad, but this is just ridiculous!
I guess it's up to the user whether they want a hidden vulnerable exploit-filled browser, or something hilarious to laugh at every week. :D
Score: 0
|ridiculous. R *I* D.
As in: We need to get rid of all those who ridicule others for spelling errors because it is patently ridiculous to do so.
Sorry. I hate that mistake. Nothing personal.
Call me a spelling nazi in 3...2...
Score: 0
|Pfft, you call yourself a spelling nazi? You missed two other words spelled wrong in that same post!
Score: 0
|Bwahahahahaha
Classic :)
Score: 0
|Hehe...
It had been a long day. ;)
Score: 0
|Yay for Sony.
Score: 0
|how can a company screw up so much and fail so bad yet can still succeed. I'm just at awe.
Score: 0
|It's an evil Japanese monopoly, that's how.
Score: 0
|Come back Walter Yetnikoff and save these fools from themselves.
Score: 0
|If we don't see a massive exodus of artists from the Sony label (and all of it's affiliates) soon, I will be utterly shocked. Anybody that continues to fly the Sony flag after this disaster flat out deserves what they get.
Merry Christmas, Sony! You still suck!
Score: 0
|Unfortunately for artists, invasive DRM software, shockingly stupid statements, and overall bad publicity aren't among the reasons for them to abandon their contracts. :P
Score: 0
|No-one expects the Sony signed artists to leave!!
Our chief reason to abandon our contracts is invasive DRM software...invasive DRM software and shockingly stupid statements...shockingly stupid statements and invasive DRM software....
Our *two* reasons are shockingly stupid statements and invasive DRM software...and overall bad publicity....
Our *three* reasons are shockingly stupid statements, invasive DRM software, and overall bad publicity...and an almost fanatical devotion to the Almighty Dollar....
Our *four*...no...
*Amongst* our reasons....
*Amongst* our reasonings...are such elements as shockingly stupid statements, invasive DRM software....
I'll come in again.
Sorry....had to be done. Or not. But I couldn't resist.
Score: 0
|These people could cross thread a mason fruit jar lid!
Score: 0
|I have to post again cause I am still in awe at this.
Is this the same company that revolutionized Home Entertainment with the PlayStation? What kind of idiots do they have working there now?
How can a company knowing FULL WELL that the entire tech community is looking at them with a microscope for any mistake on the drm front, do something like this?
Score: 0
|The PS was hardware, this is software. They would have to designed their own firmware for the PS, not code for windows(which they're apparently very bad at).
Score: 0
|They should just give up! They just can't write programs.
Seriously fire your programmers, hang your head in shame, and give up on copy protection software (and copy protection software patches & copy protection removal)
** I would say "find a better way" but this is Sony we're talking about!!! **
Score: 0
|This is better than a soap.
Move over Fox Primetime, the Sony DRM Saga goes on!
Score: 0
|Lmao! :D
Score: 0
|OK, NOW they are going to piss off some people, I tried to defend them, but they are completely on their own now. They are just being retarded and lame now..
That lawsuit, just got a whole lot bigger.
Score: 0
|Welcome to teh Sony BMG hater's Guild.
Enjoy your stay.
Score: 0
|"By PC_Tool
posted Dec 8, 2005 - 4:40 PM
ridiculous. R *I* D.
As in: We need to get rid of all those who ridicule others for spelling errors because it is patently ridiculous to do so.
Sorry. I hate that mistake. Nothing personal.
Call me a spelling nazi in 3...2...
By PC_Tool
posted Dec 8, 2005 - 2:18 PM
Welcome to teh Sony BMG hater's Guild.
Enjoy your stay.
;)"
Did you mean THE? LOL Had too, I couldn't resist.
Score: 0
|He likely did that for emphasis. Unfortunately, it's the Sony BMG haters' Guild.
Score: 0
|No he mistyped the word 'the" and I was being an ass. He knows that he is muh dude and that I have no ill for him...LOL ummm I mean that I am not being hateful. I saw that on South Parks so had to say it.
Score: 0
|No the "teh" was intentional, but I did screw the pooch on the apostrophe.
My bad.
10 whacks with a ruler, for me.
Score: 0
|lmao.
Shaddup Cartman.
Score: 0
|This is just too funny. They absolutely, completely, and without fear. jump right in and shoot themselves in the foot again....and again...and...again.
They have *got* to be running a little low on toes by now.
Score: 0
|Hmm....well, they're down like 4 now, right? So that's 6 left?
Score: 0
|Almost makes you feel sorry for them...NOT
Score: 0
|Sony, seriously... give up on the DRM... it's not helping you.
Score: 0
|They did! THey're just trying to Fix the existing lol
Score: 0
|LoL. this is just hilarious. What an incompetent bunch of idiots. Seriously, dont ppl do Q&A anymore? Dont they seek help from GOOD security firms?
Score: 0
|No way, that would be responsible and we all know that big companies like Sony know nothing of responsibility (just look at all the retractions that were made by Sony during the first week of this...).
Good software development has been tossed completly out the window in liu of just getting a product out the door... damn the bugs! We have a deadline to meet!!!
Just my 2.5 cents ;-)
Score: 0
|Jesus, Sony can't get a break can they? The more they try the more they screw up!
Score: 0
|Why should they get a break? They are incompetent with these software fixes. They are blatantly irresponsible for not telling the "customers" about these DRM software and then "down-playing" the problems!
Score: 0
|http://boycottsony.us
Score: 0
|Good thing the EFF bent over. Once again, they are the Jesse Jackson of the tech world...
Score: 0
|just more fuel in the fire
Score: 0
|QA obviously does not stand for Quality Assurance in Sony.
Score: 0
|I agree
Score: 0
|