BugTraq
Sony: The Return Of The Rootkit Aug 29 2007 09:34PM
Quark IT - Hilton Travis (Hilton QuarkIT com au) (1 replies)
Re: Sony: The Return Of The Rootkit Aug 30 2007 04:10PM
Paul Sebastian Ziegler (psz observed de) (2 replies)
Re: Sony: The Return Of The Rootkit Aug 31 2007 09:45PM
Jason Brooke (jason qgl org) (1 replies)
Paul Sebastian Ziegler wrote:
> Have another one:
> http://observed.de/?entnum=101
>
> Now I was outraged by Sony's Copyprotection Rootkit - but this is simply
> something different.
>
> Many Greetings
> Paul

I can't see anything in your article that adds anything to your email,
why did you want him to read it?

Also, the article by f-secure that you're having a go at, says "This USB
stick with rootkit-like behavior" and openly acknowledges that the
purpose of hiding files by the device is probably to try and prevent
tampering with the fingerprint authentication. Their main point is that:

"The Sony MicroVault USM-F fingerprint reader software that comes with
the USB stick installs a driver that is hiding a directory under
"c:\windows\". So, when enumerating files and subdirectories in the
Windows directory, the directory and files inside it are not visible
through Windows API. If you know the name of the directory, it is e.g.
possible to enter the hidden directory using Command Prompt and it is
possible to create new hidden files. There are also ways to run files
from this directory. Files in this directory are also hidden from some
antivirus scanners (as with the Sony BMG DRM case) ? depending on the
techniques employed by the antivirus software. It is therefore
technically possible for malware to use the hidden directory as a hiding
place."

[ reply ]
Re: Sony: The Return Of The Rootkit Aug 31 2007 10:48PM
Paul Sebastian Ziegler (psz observed de) (2 replies)
Re: Sony: The Return Of The Rootkit Sep 01 2007 04:16PM
John Hammond (josephhammond hotmail com)
Re: Sony: The Return Of The Rootkit Sep 01 2007 04:01PM
Tyler Reguly (ht computerdefense org)
Re: Sony: The Return Of The Rootkit Aug 31 2007 07:03PM
Chad Perrin (perrin apotheon com)


 

Privacy Statement
Copyright 2010, SecurityFocus