|
|
Log in / Subscribe / Register

Security

Sony, rootkits, and the escalation of the DRM war

As most readers are likely to have seen by now, a Windows developer recently discovered that a rootkit on his system had been installed by the DRM ("digital restrictions management," to use Richard Stallman's apt term) code from a copy-protected CD. This CD (Van Zant's appropriately named "Get Right With The Man") was issued by SonyBMG. It happily installed software on the system, overrode a couple of system calls, and proceeded to hide itself from casual view. This is not the sort of experience that CD purchases are normally looking for. SonyBMG should - and will - take a fair amount of grief from this bit of silliness.

Just how silly is just becoming clear: consider this weblog entry which suggests that SonyBMG's DRM activities don't really even have anything to do with copy protection. Instead, SonyBMG is simply trying to make life more difficult for iPod users as a way of trying to muscle in on Apple's turf. It is increasingly clear that DRM is being used as a way of excluding competition, rather than for its stated purpose. With luck, some politicians might begin to understand this, and the tone of the debate in various national capitols may change a bit.

Meanwhile, it is also clear that DRM is increasingly a security issue. We have music discs which install malware, the entertainment industry trying to poison bittorrent streams, and legislators who would like to legalize overt attacks against those who are deemed to be pirates. There will certainly be many computers - including those in companies - which have been infected with the DRM code shipped by SonyBMG, and the full capabilities of that code remain unclear. The next security compromise carried out in the name of piracy prevention may be even worse.

There are some obvious conclusions to be drawn from this episode. The most obvious of all being that automatically running code from an arbitrary CD is a stunningly bad idea. Beyond that, avoiding Windows helps, for now. Even Macintosh systems are unaffected by SonyBMG's DRM. And it has been made clear that security threats can come from unexpected directions. SonyBMG is not a bunch of script kiddies in a basement somewhere; it's a high-profile corporation which, one might expect, would not be in the business of attacking its customers' computers. This is unlikely to be the last episode of this kind we will see.

Comments (11 posted)

New vulnerabilities

gallery: privilege escalation

Package(s):gallery CVE #(s):CVE-2005-2596
Created:November 2, 2005 Updated:November 2, 2005
Description: The gallery system has a bug which can allow all PostNuke users full access to the gallery.
Alerts:
Debian DSA-879-1 gallery 2005-11-02

Comments (none posted)

gnump3d: cross-site scripting, directory traversal

Package(s):gnump3d CVE #(s):CVE-2005-3122 CVE-2005-3123
Created:October 28, 2005 Updated:November 7, 2005
Description: Steve Kemp discovered two vulnerabilities in gnump3d, a streaming server for MP3 and OGG files.
Alerts:
Gentoo 200511-05 gnump3d 2005-11-06
Debian DSA-877-1 gnump3d 2005-10-28

Comments (none posted)

Mantis: multiple vulnerabilities

Package(s):mantisbt CVE #(s):CVE-2005-3091 CVE-2005-3335 CVE-2005-3336 CVE-2005-3338 CVE-2005-3339
Created:October 28, 2005 Updated:December 22, 2005
Description: Mantis contains several vulnerabilities, including a remote file inclusion vulnerability, an SQL injection vulnerability, multiple cross site scripting vulnerabilities and multiple information disclosure vulnerabilities.
Alerts:
Gentoo 200512-12 mantisbt 2005-12-22
Debian DSA-905-1 mantis 2005-11-22
Gentoo 200510-24 mantisbt 2005-10-28

Comments (none posted)

openvpn: format string vulnerability

Package(s):openvpn CVE #(s):CVE-2005-3393 CVE-2005-3409
Created:November 2, 2005 Updated:December 12, 2005
Description: OpenVPN 2.0.x contains a format string vulnerability which can be exploited by a hostile server; see this advisory for details.
Alerts:
Mandriva MDKSA-2005:206-1 openvpn 2005-12-09
Mandriva MDKSA-2005:206 openvpn 2005-11-08
Debian DSA-885-1 openvpn 2005-11-07
Gentoo 200511-07 openvpn 2005-11-06
SuSE SUSE-SR:2005:025 multi 2005-11-04
OpenPKG OpenPKG-SA-2005.023 openvpn 2005-11-02

Comments (none posted)

Squirrelmail: preference modification

Package(s):squirrelmail CVE #(s):CAN-2005-2095
Created:November 2, 2005 Updated:November 2, 2005
Description: Versions of Squirrelmail prior to 1.4.5 have an error in how the $_POST variable is handled. As a result, a user's preferences can be viewed and modified.
Alerts:
Mandriva MDKSA-2005:202 squirrelmail 2005-11-01

Comments (1 posted)

TikiWiki: XSS vulnerability

Package(s):tikiwiki CVE #(s):
Created:October 28, 2005 Updated:November 2, 2005
Description: Due to improper input validation, TikiWiki can be exploited to perform cross-site scripting attacks. A remote attacker could exploit this to inject and execute malicious script code or to steal cookie-based authentication credentials, potentially compromising the victim's browser.
Alerts:
Gentoo 200510-23 tikiwiki 2005-10-28

Comments (none posted)

Resources

mwcollect v3.0.0 released

The Honeynet Project has announced the release of mwcollect v3.0.0. This tool, intended to be run from a Linux system, simulates a number of known vulnerabilities then harvests malware payloads from the resulting exploit attempts. In this way, researchers can attract their own collection of nasty code and see what the crackers are trying to do. Click below for the announcement, or see mwcollect.org for more information.

Full Story (comments: none)

Page editor: Jonathan Corbet
Next page: Kernel development>>


Copyright © 2005, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds