On TV.com: Is COMMUNITY or MODERN FAMILY better?
BNET Business Network:
BNET
TechRepublic
ZDNet

August 27th, 2007

Rootkit-like behavior found on Sony fingerprint reader

Posted by Ryan Naraine @ 1:38 pm

Categories: Botnets, Browsers, Data theft, Digital rights management, Exploit code, Hackers, Metasploit, Passwords, Patch Watch, Pen testing, Responsible disclosure, Rootkits, Viruses and Worms, Vulnerability research, Zero-day attacks

Tags: Technique, Sony Corp., Directory, F-Secure Corp., Rootkit, Fingerprint Reader, Ryan Naraine

Rootkit-like behavior found on Sony fingerprint readerFinnish anti-virus vendor F-Secure has found rootkit-like features in a plug-and-play fingerprint reader marketed by Sony.

The discovery was made when F-Secure’s BlackLight scanner picked up hidden files on a system with the Sony Microvault USM-F fingerprint reader software.

F-Secure Mika Stahlberg explains:

The Sony MicroVault USM-F fingerprint reader software that comes with the USB stick installs a driver that is hiding a directory under “c:\windows\”. So, when enumerating files and subdirectories in the Windows directory, the directory and files inside it are not visible through Windows API. If you know the name of the directory, it is e.g. possible to enter the hidden directory using Command Prompt and it is possible to create new hidden files. There are also ways to run files from this directory. Files in this directory are also hidden from some antivirus scanners (as with the Sony BMG DRM case) — depending on the techniques employed by the antivirus software. It is therefore technically possible for malware to use the hidden directory as a hiding place.

In addition to the software that was packaged with the USB stick, F-Secure also tested the latest software version available from Sony and found the same hiding functionality.
“[We] feel that rootkit-like cloaking techniques are not the right way to go here,” Pehkonen said.

He said Sony did not respond to F-Secure’s attempt at notification.

This comes almost two years after the Sony BMG copy protection scandal, where rootkit techniques were used in a DRM (digital rights management) scheme.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 43 Talkback(s)
RE: Rootkit-like behavior found on Sony fingerprint reader
Here we go again...
This is why I no longer buy anything from SONY or any of its subsidiaries (can we say BMG?).
This is also the reason why a lot of people would rather illegally download p... (Read the rest)
Posted by: craig-wilson@... Posted on: 09/20/07 You are currently: a Guest | | Terms of Use
Once a Crook Always a Crook  Mectron | 08/27/07
do they care?  patibulo | 08/28/07
Most Don't Know  bmgoodman | 08/28/07
Ha !  bruceslog | 08/29/07
Here we go again!  propagandhi | 08/27/07
Here we go again!  davolente@... | 08/28/07
Citation  CosmoAgain | 08/29/07
Looks like $ony found something to do with all those unused rootkits.  Mr. Roboto | 08/27/07
hei  mano.n.s75@... | 08/30/07
Did they think nobody would notice  zmud | 08/27/07
Why do we keep giving Sony another chance?  BitTwiddler | 08/28/07
I Don't !  bruceslog | 08/29/07
Sony  cast7776@... | 08/28/07
Wow....  James T. Kirk | 08/28/07
that begs the question...  Linux Geek | 08/28/07
Since you don't have a C:\Windows folder  JLHenry | 08/28/07
Should I even reply to that?  Logics | 08/28/07
This is why you leave UAC enabled  CobraA1 | 08/28/07
Still doesn't help though  voska | 08/28/07
UAC is not protect you against driver instllations  ericsami | 08/28/07
Why does the OS make this possible?  wkulecz | 08/28/07
There is no way to prevent it  ericsami | 08/28/07
Only questioning the need to make it invisible!  wkulecz | 08/28/07
I can think of clean way to do it  ericsami | 08/28/07
Wrong of OS to allow it!  wkulecz | 08/29/07
I beg to disagree  ericsami | 08/29/07
It's NOT the OS doing this...  bmerc | 08/30/07
Windows  endersjane@... | 08/29/07
Another clueless one heard from...  3D0G | 08/28/07
DOH!!!  3D0G | 08/28/07
Clue for ya!  wkulecz | 08/28/07
Sony=Scum  wizardb@... | 08/29/07
Name an OS Where This Isn't Possible  rkuhn040172@... | 08/29/07
Unix/Linux  wkulecz | 08/29/07
And how does that help?  bmerc | 08/30/07
Collecting fingerprints for ?  bruceslog | 08/29/07
Tin-foil hat territory  wkulecz | 08/29/07
But Why ?  bruceslog | 08/29/07
Buy Sony...FAT CHANCE  jcole@... | 08/29/07
Sony  ITdaized | 08/29/07
Yes to that...  unistar@... | 08/29/07
Bye Sony  GrumpyOldMan | 08/29/07
RE: Rootkit-like behavior found on Sony fingerprint reader  craig-wilson@... | 09/20/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads