Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Trojan horse exploits Sony DRM copy protection vulnerability
SOPHOS ^ | 11/10/05

Posted on 11/11/2005 10:12:11 AM PST by savedbygrace

10 November 2005

Trojan horse exploits Sony DRM copy protection vulnerability

Sophos issues tool to detect and disable "cloaking" flaw exploited by Trojans

Music CD
The Trojan horse exploits a vulnerability introduced by Sony's CD copy protection software.

Experts at SophosLabs™, Sophos's global network of virus and spam analysis centres, have detected a new Trojan horse that exploits the controversial Sony DRM (Digital Rights Management) copy protection included on some of the music giant's CDs.

The Troj/Stinx-E Trojan horse appears to have been deliberately spammed out to email addresses, posing as a message from a British business magazine.

Typical emails look as follows:

Subject: Photo Approval Deadline

Message body:

Hello,
Your photograph was forwarded to us as part of an article we are publishing for our December edition of Total Business Monthly. Can you check over the format and get back to us with your approval or any changes? If the picture is not to your liking then please send a preferred one. We have attached the photo with the article here.

If the attached program is run, the Trojan horse copies itself to a file called $sys$drv.exe. Any file with $sys$ in its name is automatically cloaked by Sony's copy-protection code, making it invisible on computers which have used CDs carrying Sony's copy protection.

"Despite its good intentions in stopping music piracy, Sony's DRM copy protection has opened up a vulnerability which hackers and virus writers are now exploiting," said Graham Cluley, senior technology consultant for Sophos. "We wouldn't be surprised if more malware authors try and take advantage of this security hole, and consumers and businesses alike would be sensible to protect themselves at the earliest opportunity."

Detect and disable "cloaking flaw" in Sony's DRM copy-protection

Have your say

Is Sony's DRM copy protection

a fair way to fight music pirates?

a security threat?

Sophos has issued a tool which will detect the existence of Sony's DRM copy-protection on Windows computers, disable its "cloaking" function, and prevent that functionality from re-installing. The tool also detects versions of the Troj/Stinx Trojan horse which exploit the Sony vulnerability.

"Sophos is acting on customers' concern that the software on Sony's CDs is introducing a vulnerability which hackers and virus writers are able to exploit," explained Cluley. "We will give customers the ability to determine if their computers suffer from the vulnerability and remove it if necessary."

Sophos recommends that businesses ensure their computers are kept automatically up-to-date with the very latest anti-virus software.


TOPICS: Miscellaneous; Technical
KEYWORDS:
I did an FR Search and this didn't show up.
1 posted on 11/11/2005 10:12:12 AM PST by savedbygrace
[ Post Reply | Private Reply | View Replies]

To: rdb3; chance33_98; Calvinist_Dark_Lord; Bush2000; PenguinWry; GodGunsandGuts; CyberCowboy777; ...

2 posted on 11/11/2005 10:48:32 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: savedbygrace

Here's how you can protect yourself:

Step 1: Disable the preview pane in Outlook and/or Outlook Express.

Step 2: Don't use Outlook and/or Outlook Express.

That should cover all of the bases, but as a precaution I would recommend deleting spam without reading it. Your body parts are fine just like they are.


3 posted on 11/11/2005 12:01:10 PM PST by KarinG1 (Some of us are trying to engage in philosophical discourse. Please don't allow us to interrupt you.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: KarinG1
Your body parts are fine just like they are.
Really?   : )

 

4 posted on 11/11/2005 12:05:23 PM PST by counterpunch (~ Let O'Connor Go Home! ~)
[ Post Reply | Private Reply | To 3 | View Replies]

To: KarinG1

That's just silly - Outlook and OE haven't autorun scripts or executables since Office 97.


5 posted on 11/11/2005 12:11:45 PM PST by Senator Bedfellow
[ Post Reply | Private Reply | To 3 | View Replies]

To: savedbygrace

Trojan.... protection.....


6 posted on 11/11/2005 12:31:04 PM PST by WasDougsLamb (Just my opinion.Go easy on me........)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Senator Bedfellow

Maybe I am silly. In fact I'm pretty sure that I am, but my computers work.


7 posted on 11/11/2005 12:46:15 PM PST by KarinG1 (Some of us are trying to engage in philosophical discourse. Please don't allow us to interrupt you.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: KarinG1

That's exactly why I wave a dead chicken over my machines every morning - it may be silly, but my computers work ;)


8 posted on 11/11/2005 12:47:55 PM PST by Senator Bedfellow
[ Post Reply | Private Reply | To 7 | View Replies]

To: Senator Bedfellow

I use live chickens. That's just a cultural difference and it doesn't mean that either of us is wrong. At least our computers work.


9 posted on 11/11/2005 1:44:48 PM PST by KarinG1 (Some of us are trying to engage in philosophical discourse. Please don't allow us to interrupt you.)
[ Post Reply | Private Reply | To 8 | View Replies]

To: KarinG1

Fair enough :)


10 posted on 11/11/2005 1:46:02 PM PST by Senator Bedfellow
[ Post Reply | Private Reply | To 9 | View Replies]

To: Senator Bedfellow

I thought you had to kill them and let the blood drain on the keyboard. I've been had.


11 posted on 11/11/2005 1:47:36 PM PST by js1138 (Great is the power of steady misrepresentation.)
[ Post Reply | Private Reply | To 8 | View Replies]

To: js1138

You must go through a lot of keyboards. I just wait until they die and then pour a 40 ouncer over them...


12 posted on 11/11/2005 1:49:59 PM PST by Senator Bedfellow
[ Post Reply | Private Reply | To 11 | View Replies]

To: savedbygrace
If you run sony DRM your crazy, the darned thing has a rootkit in it.

The good thing is sony will help you remove it. :)

Sure I'm brainless enough to let the party who installed a rootkit on my machine remove it.
sony folks found some real good dope.
13 posted on 11/11/2005 1:58:59 PM PST by JamminJAY (This space for rent)
[ Post Reply | Private Reply | To 1 | View Replies]

To: JamminJAY

LOL.


14 posted on 11/11/2005 3:44:56 PM PST by savedbygrace
[ Post Reply | Private Reply | To 13 | View Replies]

To: WasDougsLamb

Confusing, ain't it?


15 posted on 11/11/2005 3:45:25 PM PST by savedbygrace
[ Post Reply | Private Reply | To 6 | View Replies]

To: KarinG1

How about just not buying any more Sony CDs with their attached malware. MS-hating twit.


16 posted on 11/11/2005 5:54:06 PM PST by RJS1950 (The rats are the "enemies foreign and domestic" cited in the federal oath)
[ Post Reply | Private Reply | To 3 | View Replies]

To: RJS1950

I don't hate Microsoft and I'm not a twit, but you are very mean spirited. Fortunately I'm used to it. I get more hate mail before daylight than most people get all day long.


17 posted on 11/11/2005 6:50:22 PM PST by KarinG1 (Some of us are trying to engage in philosophical discourse. Please don't allow us to interrupt you.)
[ Post Reply | Private Reply | To 16 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson