What Was the Sony BMG Rootkit? Copy Protection That Came With a Barcode

He was testing a new build of RootkitRevealer on his own machine. The machine was clean; he would have known otherwise. The tool said there was a hidden directory, a hidden driver, and a set of hidden registry keys, and the driver had hooked the kernel's system call table.

He traced it back to a CD. Get Right with the Man, by Van Zant. He had bought it.

That is how Mark Russinovich spent the last days of October 2005, and on 31 October he wrote it up. The post was titled, with no particular subtlety, Sony, Rootkits and Digital Rights Management Gone Too Far.

What was the Sony BMG rootkit?

A copy-protection system called XCP, Extended Copy Protection, licensed by Sony BMG from a British company called First 4 Internet and pressed onto roughly two million discs across fifty-two titles in 2005. Put one in a Windows machine, and the disc's autorun offered a licence agreement. Accept it, and XCP installed a media player that would play the album and burn it a limited number of times.

It also installed a second thing, which the licence did not mention. A kernel driver that hooked the Windows system call table and hid every file, directory, process and registry key whose name began with $sys$. Not from the disc. From the owner of the machine, from Windows Explorer, from Task Manager, from the registry editor, and from every antivirus product on the market.

That is a rootkit. Not by analogy: by definition. The techniques were the same ones malware authors had been using for years to stay resident on a compromised machine, and the only novel part was that they had arrived with a barcode.

What it did to the machine

The cloaking was the headline, but it was not the only cost. The hidden driver intercepted every system call on the machine to check whether the caller was asking about something named $sys$, which is to say it sat in the path of everything the computer did; Russinovich measured it consuming CPU on an idle system just by existing. The player phoned a Sony server every time a disc was played, sending the album identifier, which is how the scale of the thing was later measured. And because the driver was hidden, it could not be uninstalled through Add or Remove Programs, and trying to remove it by hand left Windows unable to see its own CD drive.

There was no uninstaller. There was no mention of any of it in the licence. The word rootkit did not appear anywhere in Sony's materials because, as far as anyone can tell, nobody at Sony BMG knew what they had bought.

Why hide it at all?

Because the copy protection was trivial to defeat if you could see it. XCP worked by sitting between the disc and the ripping software; find the driver, disable the driver, and the disc is a disc again. Hiding the files was the mechanism that stopped the mechanism from being removed.

Which is the same logic every piece of malware uses, and it produced the same result. A system that cloaks anything named $sys$ cloaks it for everyone. Within days there was malware in the wild that renamed itself with the prefix and got hidden from antivirus for free. Players of World of Warcraft found that the game's anti-cheat scanner, the Warden, could not see a cheat tool once it was renamed $sys$ either. Sony had shipped, on a music CD, a general-purpose hiding place, and the people who found the most immediate use for it were cheating at a video game.

The quote

On 4 November 2005, four days after Russinovich's post, NPR ran a segment on the story. Thomas Hesse, the president of Sony BMG's global digital business, was asked about it.

Most people, I think, don't even know what a rootkit is, so why should they care about it?

It is the sentence this incident is remembered by, and it deserves to be, because it is honest. It is precisely the reasoning that put the driver on the disc. The people who would notice were a rounding error; the people who would not notice were the market.

The people who would notice were, as it turned out, the people who write the tools everyone else runs, and they noticed on the same weekend.

The uninstaller was a second hole

Sony's first response, on 2 November, was a patch that made the hidden files visible. It did not remove the driver. Then it offered an uninstaller, which could only be obtained by filling in a web form with an email address, waiting for a reply, and then visiting a page that installed an ActiveX control to do the removal.

The control was marked safe for scripting and left on the machine afterward. Ed Felten and Alex Halderman at Princeton, and separately Russinovich, showed that any web page could call it. It exposed methods that would download and execute arbitrary code. The fix for the rootkit was a remote code execution vulnerability that stayed behind after the rootkit was gone.

Microsoft eventually shipped a kill bit for it. Microsoft also added XCP's driver to the December 2005 release of the Malicious Software Removal Tool, which is the closest thing there is to an official classification.

The code inside the code

There was one more thing in XCP, found by people reading the binary in the weeks that followed. The player contained code lifted from open-source projects: the LAME MP3 encoder, mpg123, and, most pointedly, DRMS, the FairPlay-stripping code from the VideoLAN project. A copy-protection system built to stop people copying music had itself been assembled, in part, from other people's copyrighted code, under licences it did not comply with. The LAME developers published an open letter about it.

How many machines?

Nobody knows exactly, and the figure that gets quoted is worth understanding rather than repeating. Dan Kaminsky did not count infected computers; he counted DNS. XCP's player phoned home to a Sony domain every time a disc was played, and the lookups sat in the caches of resolvers around the world. Kaminsky queried resolvers for the cached name and found it on more than 500,000 of them.

Each resolver serves anywhere from one machine to a whole ISP, so the number is a floor on networks, not a count of computers. It could mean millions. It could not mean fewer than half a million networks that had at least one machine playing a Sony disc with the rootkit installed. That is the honest reading, and it is bad enough without inflating it.

The recall, the lawsuits, the settlement

  • 11 November 2005 — Sony BMG said it would suspend manufacture of XCP discs.
  • 15 November 2005 — the recall. Unsold discs pulled, and an exchange programme for consumers who already had one.
  • 18 November 2005 — the full list of fifty-two affected titles, published only after the EFF had pieced together most of it from readers.
  • 21 November 2005 — the State of Texas sued under its Consumer Protection Against Computer Spyware Act, the first use of the statute. The Electronic Frontier Foundation filed a class action the same day.
  • January 2007 — the Federal Trade Commission settlement. Sony BMG was barred from installing software without clear disclosure, required to provide an uninstaller, and required to reimburse consumers up to $150 for damage done getting the thing off their machines.

The other copy-protection system on Sony discs at the time, SunnComm's MediaMax, was on around twenty million more discs and installed itself before the licence agreement was shown, whether or not you accepted it. It got less attention because it was not a rootkit, only spyware. That was the standard the year had set.

What it was for

Copy protection on a compact disc does not survive contact with a Mac, a Linux box, a standalone CD player with a line-out, or a Windows machine with autorun turned off. XCP protected the album from exactly one thing: a Windows user who accepted the defaults. It did not stop the music from reaching file-sharing networks, where every one of the fifty-two titles was available within days of release, ripped from somewhere XCP could not reach.

What it did do was install a kernel-mode driver, hidden from the owner, on every machine that played the disc as intended. The protection did not stop copying. It stopped the disc from being a disc.

Further reading

  • Mark Russinovich — Sony, Rootkits and Digital Rights Management Gone Too Far, Sysinternals blog, 31 October 2005.
  • J. Alex Halderman and Edward W. Felten — Lessons from the Sony CD DRM Episode, USENIX Security 2006.
  • Electronic Frontier Foundation — Sony BMG Litigation Info, including the full XCP title list.
  • Federal Trade Commission — Sony BMG Music Entertainment consent order, January 2007.
  • Bruce Schneier — Real Story of the Rogue Rootkit, Wired, 17 November 2005.

EXHIBIT 0026 — SONY BMG ROOTKIT

We put it on a shirt. A compact disc in an open jewel case, drawn as an engraving, the disc half lifted from its tray, the booklet in the lid. On the disc, one small label: $sys$.

Callouts: IT HID ANYTHING NAMED $sys$. 52 TITLES, TWO MILLION DISCS. THE UNINSTALLER OPENED A SECOND HOLE. FOUND BY A MAN TESTING HIS OWN TOOL.

And the kicker is the quote, because nothing anyone could write about this incident is as damning as what its own executive said about it on the radio.

That's the whole idea.

View the Sony BMG Rootkit shirt — EXHIBIT 0026

Back to blog

Leave a comment

Please note, comments need to be approved before they are published.