Rootkits: Sony does it again - gHacks Tech News

Rootkits: Sony does it again

I would have never thought that a company like Sony would not learn from its mistakes especially after the first rootkit debacle which was a major public relations fiasco for Sony. The first rootkit was placed on several audio CDs that were distributed in 2005 and led to a $6 million settle case in the United States. While the rootkit was intended to make it impossible for customers (albeit ineffectively) to copy music from the CDs it was on, it was effectively used by producers of malware, trojans and spyware to hide their code from antivirus software.

The sentence that always reminds me of how amateurish Sony handled the whole affair went something in the line of "People who don't know what rootkits do should not care about them".

It seems Sony did it again. F-Secure is reporting that Sony is now selling an USB stick - the Sony MicroVault - which installs a hidden folder in c:\windows when installing the USB fingerprint software.

So, when enumerating files and subdirectories in the Windows directory, the directory and files inside it are not visible through Windows API. If you know the name of the directory, it is e.g. possible to enter the hidden directory using Command Prompt and it is possible to create new hidden files. There are also ways to run files from this directory. Files in this directory are also hidden from some antivirus scanners (as with the Sony BMG DRM case) — depending on the techniques employed by the antivirus software. It is therefore technically possible for malware to use the hidden directory as a hiding place.

F-Secure suspects that the hidden folder is used to protect the fingerprint authentication and strongly disagrees that this is the correct way to achieve a protection.

Malware writers can use the hidden folder to place part of or all of the malware in that folder to avoid detection by antivirus software and other security software that may be running on the PC.

I think that Sony made a big mistake in using such a technology again even if it was intended to be of good use for the owner.

Advertisement

We need your help

Advertising revenue is falling fast across the Internet, and independently-run sites like Ghacks are hit hardest by it. The advertising model in its current form is coming to an end, and we have to find other ways to continue operating this site.

We are committed to keeping our content free and independent, which means no paywalls, no sponsored posts, no annoying ad formats or subscription fees.

If you like our content, and would like to help, please consider making a contribution:


Previous Post: «
Next Post: »

Comments

  1. Tobey said on August 28, 2007 at 8:48 pm
    Reply

    Oh they obviously screwed up again.

    How many more times… :-\

  2. The Guru said on August 29, 2007 at 5:35 am
    Reply

    Sony is not having a good year…

  3. Benóný said on August 29, 2007 at 1:10 pm
    Reply

    “Guru” Sony hasn’t had a good year since 2004 or 2005 :|

Leave a Reply

Check the box to consent to your data being stored in line with the guidelines set out in our privacy policy

Please note that your comment may not appear immediately after you post it.