News: 1639144931

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Revealed: Remember the Sony rootkit rumpus? It was almost oh so much worse

(2021/12/10)


Retired Microsoft engineer, Dave Plummer, [1]offered a blast from the past last week with a look back at the infamous Sony Windows "rootkit" scandal.

What was the Sony rootkit scandal?

Picture it: it was 2005. Kanye West's Late Registration , Green Day's American Idiot and Eminem's Encore were topping the album charts. Fearful of perfect copies being made of its audio compact discs (remember those?), Sony included in its CDs a feature that silently deployed its Digital Rights Management (DRM) software when one of its music discs, equipped with the code, was inserted.

Sysinternal's (and now Microsoft's) Mark Russinovich [2]uncovered the nefarious code in late October, 2005, and branded it a "root kit," because – like certain malware – it found its way onto systems uninvited; and once there, endeavored to remain undetected. The removal of that code, it transpired, could severely upset Windows, meaning "ordinary users with Windows systems [were] unable to play CDs."

And goodness, [3]how the lawsuits flew . Sony ultimately settled the case in December 2005.

In his latest video, [4]Tempest obsessive and [5]author Plummer confessed to having once been the owner of Windows components such as Calculator and CD Autorun.

Calculator is, bar the odd edge case or two, and the infamous [6]Pentium FDIV , not the most controversial of tools.

Nonetheless, said Plummer: "Trust me... being the name on the code review line can have a certain amount of 'pucker factor' because the stakes involved are really high, and the press would be really bad if you did make a mistake."

CD Autorun was, on the other hand, "that boring, staid old component that nobody loved and a few people hated."

[7]

It would also become somewhat controversial.

[8]

[9]

The thing about it was that it could silently run code on an inserted disc – perhaps a setup program. Perhaps a game. Or perhaps install a rootkit (see sidebar) in a misguided attempt to fight off perceived threats from pirates...

A self-confessed Sony fanboy (and possessed of lots of branded kit), Plummer recounted the tale.

[10]

As Plummer pointed out, the discovery of the Sony DRM issue occurred in 2005, and the man had long left Microsoft by then. AutoRun had a longer history that dated back to Windows 95.

It also had a sibling by the name of AutoPlay.

Plummer told us a story that took place in the 1990s. An AutoPlay developer took a look at what was possible (thanks to the somewhat laissez-faire approach taken to security at the time) while the component was being first put together and came away alarmed.

[11]

You see, the internal development version of the code was very media-agnostic. It didn't matter if the media was a CD or not. It could be one of those new-fangled USB things. It could even be a network drive. Windows simply didn't care – the shell showed the user nothing. Instead it was up to the autoplay title to throw up a user interface.

So, any time a volume turned up (say, a network drive,) the original development code would look for autorun.inf and do what it was told before the user had a chance to intervene.

What could possibly go wrong?

The reaction of the higher-ups to the security concerns belied a different Microsoft in those days. A clunky shell pop-up was deemed something that might yank the user out of an otherwise magical Windows experience. Filtering so only some drive types worked might have made the feature feel unpredictable.

The shipment of what could only be described as Rookitting for Dummies drew ever closer, and our hero apparently resorted to alternative means by which to get his point across.

[12]Sony 'rootkit' settlement clamps down on DRM

[13]Removing Sony's CD 'rootkit' kills Windows

[14]Sony's CD rootkit infringes DVD Jon's copyright

[15]Sony digital boss - rootkit ignorance is bliss

He wrote a little autoplay app, one that would harmlessly change the user's desktop wallpaper (on reboot), hid it as system files on file server locations frequently used by the team, and waited.

Copious patience was not required. Before long, the amusing desktop bitmap was being reported throughout the team and heads were being scratched. It was eventually a kernel developer that tumbled the mystery. A net use created an unusually large spike in disk I/O, and watching what was actually happening using a debugger showed the hidden code in action.

The result was that the big cheeses were sufficiently alarmed to pop in some restrictions on eligible media. Testing? Stick everyone's favourite inbox app, notepad.exe, onto a CD to see how the shell handled paths.

Alas, Microsoft hadn't reckoned with the "good guys" – aka Sony – shipping CDs with a hybrid ISO and Red Book format. Sure, apps duking it out for top billing on the Start Menu was par for the course. But a silently installed rootkit? Who would do such a thing?

Hindsight is a wonderful thing. The delightfully naive "CD-ROM = OK" assumption turned out, as Plummer explained, Sony exploited and Russinovich discovered, to have flaws of its own. ®

Get our [16]Tech Resources



[1] https://youtu.be/PqWjq2SdzpI

[2] https://www.theregister.com/2005/11/01/sony_rootkit_drm

[3] https://www.theregister.com/2005/12/29/sony_settles_rootkit/

[4] https://youtu.be/dqO03_q9UCA

[5] https://www.amazon.co.uk/Secrets-Autistic-Millionaire-Everything-Aspergers-ebook/dp/B09KGF6685/

[6] https://www.theregister.com/1999/12/09/oh_no_its_intel_fdiv/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YbOHyAiqtT6zYRDPqmS4egAAAAc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YbOHyAiqtT6zYRDPqmS4egAAAAc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YbOHyAiqtT6zYRDPqmS4egAAAAc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YbOHyAiqtT6zYRDPqmS4egAAAAc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YbOHyAiqtT6zYRDPqmS4egAAAAc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[12] https://www.theregister.com/2005/12/29/sony_settles_rootkit/

[13] https://www.theregister.com/2005/11/01/sony_rootkit_drm/

[14] https://www.theregister.com/2005/11/18/sony_copyright_infringement/

[15] https://www.theregister.com/2005/11/09/sony_drm_who_cares/

[16] https://whitepapers.theregister.com/



Skiron

Didn't outlook (or whatever it was called then) email client auto-run executable file attachments too around the same time?

Yet Another Anonymous coward

And an image file format that let you put batch commands in the header and it would run them before it displayed the file

Nick Ryan

It was called [1]Outlook Express and it may as well have been specifically designed to be a virus propagation platform.

It didn't auto-run executables, however it was a trivial process to cause it to execute pretty much anything. Usually without letting the user know. Combine this with Microsoft's brain dead insistence that nobody really needed to know what the real file extension of a file is (hiding file extensions is one Microsoft's most stupid general UI things to date) and you could have a safe looking file which was an .exe which presented the icon of an image (extracted from the file itself) which was really "xmas.jpg.exe" but shown to the user as "xmas.jpg" with an image icon.

It was replaced by Windows Mail which really wasn't much better in many ways (an absolute horror to use and failed to work with many SMTP implementations until they were hacked up to "support" Windows Mail's broken interpretation of standards and special Microsoft extras. It also feels like some of the really crap rendering and editing code from Outlook Express was moved into Outlook...

[1] https://en.wikipedia.org/wiki/Outlook_Express

You have to wonder

Yet Another Anonymous coward

If you scattered pills outside MSFT HQ with a note saying "eat me" how many wouldn't?

Re: You have to wonder

Our Lord and Savior Rahl

I mean I have no association with Microsoft and I would - how would I know that they hadn't been left by the forerunners to elevate one of us to global dominion - all you have to be is brave enough to try.

Re: You have to wonder

Pascal Monett

Go ahead and scatter USB sticks anywhere with "FREE" marked on them and watch the mayhem unfold.

Re: You have to wonder

Nick Ryan

The mayhem would really depend on what the USB devices actually were... USB storage devices containing unpleasant or unwanted content or USB killer devices that would discharge a huge burst of electricity into the USB port?

Re: You have to wonder

nematoad

" USB killer devices that would discharge a huge burst of electricity into the USB port?"

No need for that.

I remember working one day when I got an anguished call from an Australian manager of the company where I worked. Remember, he was Australian and I was then working in the Republic of Ireland, so how did I get the call?

It turns out he was over in Ireland sorting out some plans to move operations from there to here, or something like that, it was a long time ago. Anyway, to cut a long story short, he had apparently mistaken the land line 'phone socket for an RJ45 and plugged his laptop into the telephone circuit.

Now the voltage on that circuit is about 48 volts so did the poor NIC and laptop no good at all. In the end I had to 'phone his network manager in Australia and try and sort out the mess. This was at about 11:30 AM our time so the manager was not amused to be disturbed at home in the evening and let me know of his displeasure.

In the end we got his account details and set up a temporary replacement for him and that was the last we heard of the affair.

You can't plan for stupid.

Never done any business with Sony since and never will

Graham Cobb

Sony ultimately settled the case in December 2005.

Sony may have "settled" (who with? not with me!). But I (and, I hope, many others) have never done business with Sony, in any form, ever since. And will not. They tried to hack my computer. They didn't apologise. They didn't change to remove DRM and build a business model based on freedom and respect. I have even written into my "living will" that my carers are not allowed to do business with Sony or any Sony-owned company as part of my care!

@Graham Cobb - Re: Never done any business with Sony since and never will

Anonymous Coward

Same for me. That was the day I stopped buying anything even remotely related to Sony.

Re: Never done any business with Sony since and never will

Gene Cash

Same here. I get funny looks from Best Buy, Staples, etc employees when I say "no Sony stuff, thanks"

Re: Never done any business with Sony since and never will

usbac

Same here. I still won't buy a Blu ray drive or player because Sony might get some kind of royalty payment.

Re: Never done any business with Sony since and never will

Graham Cobb

By the way, this decision was a couple of years after I decided I would not do business with Adobe (no loss - I wasn't doing any business with them anyway) and HP. HP was much more serious: they made some great products but I have not bought any HP product since 2002.

In both cases this was over them leading the misapplication of the US DMCA to software. The DMCA was (still is) an appalling piece of legislation (as is the UK equivalent) - preventing many legitimate uses of electronics on spurious grounds of copyright (particularly format shifting and ownership - which are basic concepts which should have been protected). In particular, the Sklyarov and Snosoft cases (see https://www.theregister.com/2002/08/02/hp_withdraws_dmca_threat if you weren't there).

I still believe that without the actions of these two companies, other companies would not have been brave enough to mis-extend a law intended to protect entertainment media into the world of denying people the right to use the software they have bought in whatever ways they choose. That later led, of course, to things like preventing interoperability of interfaces or protocols, and even reverse engineering, maintenance and substitution of manufacturers components (print cartridges, etc) on spurious DMCA grounds. None of that would have happened without HP leading the way in showing how to abuse DMCA.

So, I have never bought anything from Adobe, or from HP (since 2002), and even avoided them where possible in my professional capacity.

About Sony...

Old Used Programmer

I have mixed feelings. Everything said above about Sony resonates, and I agree. On the other hand, I use a fair number of Raspberry Pis and many of them are made in the Sony contract manufacturing plant in Wales...

Re: About Sony...

Version 1.0

Sony were just using a Windows "feature" ... it was dumb on both sides, not just Sony.

Re: About Sony...

Graham Cobb

No, they weren't "just using a Windows feature". Yes, it was a stupid feature but Sony used it to hack into and damage computers owned by other people without permission! The company should have been taken apart and people should have spent time in jail.

First off - Quake is simply incredible. It lets you repeatedly kill your
boss in the office without being arrested. :)
-- Signal 11, in a slashdot comment