Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Sony has infected over one-half million world wide nets incl U.S. Military
Welcome to Planet Sony ^ | 2005-11-15 09:28 | Dan Kaminsky

Posted on 11/15/2005 1:43:21 PM PST by dickmc

More than one-half million networks infected by Sony including U.S. military and various countries.

Dan Kaminsky, http://www.doxpara.com/ ,is the expert who broke this and did the work. His U.S. and Europe infection maps are shown below and are frightening. Dan did a hell of a good job.

Search Google News for "sony numbers trouble" for more in an excellent article today that is very worth reading.


TOPICS:
KEYWORDS: backdoor; drm; exploit; getamac; lowqualitycrap; microsoft; rootkit; securityflaw; sony; trojan; virus; virusbait; windows; worm
Navigation: use the links below to view more comments.
first 1-2021-4041-6061-80 ... 101-110 next last
Infection US photo.

Image hosted by Photobucket.com
with original at http://www.doxpara.com.nyud.net:8090/planetsony_usa.JPG

and for Europe which was not supposed to have any is at
Image hosted by Photobucket.com
with the original at http://www.doxpara.com.nyud.net:8090/planetsony_europe.JPG

Any one for a fork and some popcorn?

Could those of you from Utah send the 'search yield' article to Orrin Hatch?

1 posted on 11/15/2005 1:43:22 PM PST by dickmc
[ Post Reply | Private Reply | View Replies]

To: dickmc

Sony needs to be raked over the coals for this.


2 posted on 11/15/2005 1:46:54 PM PST by clee1 (We use 43 muscles to frown, 17 to smile, and 2 to pull a trigger. I'm lazy and I'm tired of smiling.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dickmc

Sony is pretty sad.


3 posted on 11/15/2005 1:47:27 PM PST by Echo Talon (http://echotalon.blogspot.com)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dickmc

Sooooo.....uhhhhhh......what's Sony's liability for terrorist exploitation, economic espionage, and business losses due to their induced vulnerabilities?


4 posted on 11/15/2005 1:48:09 PM PST by wvobiwan (Proud Minuteman Project Volunteer - Secure borders, illegals OUT, no 'guest workers'!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dickmc

Maybe someone would like to see the article.

Sony.

Sony has a rootkit.

The rootkit phones home.

Phoning home requires a DNS query.

DNS queries are cached.

Caches are externally testable (great paper, Luis!), provided you have a list of all the name servers out there.

It just so happens I have such a list, from the audits I've been running from http://deluvian.doxpara.com .

So what did I find?

Much, much more than I expected.

It now appears that at least 568,200 nameservers have witnessed DNS queries related to the rootkit. How many hosts does this correspond to? Only Sony (and First4Internet) knows...unsurprisingly, they are not particularly communicative. But at that scale, it doesn't take much to make this a multi-million host, worm-scale Incident. The process of discovering this has led to some significant advances in the art of cache snooping. Here are some of the factors I've dealt with:

Just because you *request* the disabling of recursion, doesn't mean it'll actually happen. A full 353,200 name servers had to be excluded from the final tally because not only would recursive queries emit from them whether or not they were desired, but they'd also notify their neighbors of the results.
Low TTL names exist, and are rather difficult to catch by cache snooping (they expire before you can find proof of life). However, they may be hosted by names that last much longer -- updates.xcp-aurora.com has a lifespan of an hour, but xcp-aurora.com's NS link to resolver1.first4internet.co.uk will last 150,000 seconds.
Some hosts lie -- captive portals, I'm looking at you. Simply filtering TTL's that are divisible by 100 has a way of eliminating most of them; after that, you're left with surprisingly few NS's that lie about IP


5 posted on 11/15/2005 1:51:28 PM PST by js1138 (Great is the power of steady misrepresentation.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dickmc

Oops. Sony's going to be busy. Rootkits suck!


6 posted on 11/15/2005 1:51:53 PM PST by MineralMan (godless atheist)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dickmc

John Connor, the white courtesy phone, please.


7 posted on 11/15/2005 1:53:14 PM PST by Frank_Discussion (May the wings of Liberty never lose a feather!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: MineralMan

On this, you and I agree wholeheartedly, my FRiend!


8 posted on 11/15/2005 1:53:33 PM PST by RebelBanker (If you can't do something smart, do something right.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: clee1
I understand that Sony is pulling the offending CDs from the shelves.
I wouldn't buy any CDs with the SONY logo after the news broke. Ever.

For a company that size this is a pretty stupid example of competence.

9 posted on 11/15/2005 1:53:44 PM PST by Publius6961 (The IQ of California voters is about 420........... .............cumulatively)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Publius6961

"I understand that Sony is pulling the offending CDs from the shelves.
"

Oh, they're going to have to do better than that. The infection's already in place. I forsee much trouble for that company in the future.


10 posted on 11/15/2005 1:55:03 PM PST by MineralMan (godless atheist)
[ Post Reply | Private Reply | To 9 | View Replies]

To: dickmc
xrp = IMMUNE!
11 posted on 11/15/2005 1:55:54 PM PST by xrp (Conservative votes are to Republicans what 90% of black votes are to Democrats (taken for granted))
[ Post Reply | Private Reply | To 1 | View Replies]

To: dickmc

Here's a tool to detect and remove the Sony Rootkit, as well as the first of the hacker viruses designed to ride on it.

http://www.sophos.com/support/disinfection/rkprf.html

I can't vouch for it since I'm not infected, but it is recommended by several trustworthy sources.


12 posted on 11/15/2005 1:56:41 PM PST by Cicero (Marcus Tullius)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Publius6961

Pulling them from the shelves now isn't a whole lot of help. There are still a lot of them still out there, and a lot of infected computers.


13 posted on 11/15/2005 1:58:01 PM PST by MizSterious (Anonymous sources often means "the voices in my head told me.")
[ Post Reply | Private Reply | To 9 | View Replies]

To: Frank_Discussion
John Connor, the white courtesy phone, please.

Who do you think would win, Skynet or Colossus?

-PJ

14 posted on 11/15/2005 1:59:35 PM PST by Political Junkie Too (It's still not safe to vote Democrat.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: rdb3; chance33_98; Calvinist_Dark_Lord; Bush2000; PenguinWry; GodGunsandGuts; CyberCowboy777; ...

15 posted on 11/15/2005 1:59:55 PM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dickmc

I'm not up this stuff. Translation please. What does this mean for the average Joe?


16 posted on 11/15/2005 2:00:08 PM PST by TheRake (Taxed to death in Michigan)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Political Junkie Too

Skynet, hands down. Skynet was like Colossus with guns, and wanted to kill all humans.


17 posted on 11/15/2005 2:01:25 PM PST by Frank_Discussion (May the wings of Liberty never lose a feather!)
[ Post Reply | Private Reply | To 14 | View Replies]

To: dickmc

And some wonder why we complain when Congresscritters and Judges try to make decisions about technological issues.

Most of them have no idea what technology is, nor what it does. Yet they write laws -- based on what lobbyests and benefactors tell them WE need.


18 posted on 11/15/2005 2:02:22 PM PST by TomGuy
[ Post Reply | Private Reply | To 1 | View Replies]

To: Frank_Discussion
True, Colossus wanted to join up with its Soviet counterpart to take care of humanity for their own good, not wipe them out.

-PJ

19 posted on 11/15/2005 2:05:53 PM PST by Political Junkie Too (It's still not safe to vote Democrat.)
[ Post Reply | Private Reply | To 17 | View Replies]

To: Political Junkie Too; Frank_Discussion

Hey...doesn't P1 rate?


20 posted on 11/15/2005 2:09:15 PM PST by 6ppc
[ Post Reply | Private Reply | To 19 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-6061-80 ... 101-110 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson