Mark Russinovich: Sysinternals, Sony's Rootkit and Azure
On Halloween 2005, Mark Russinovich published a blog post about a music CD, and by the time the dust settled a record label had been hauled in front of the Federal Trade Commission and the whole world knew the word "rootkit."
He was already famous in a narrower circle. Sysinternals, the free toolkit he built with Bryce Cogswell, was how Windows administrators found out what their machines were really doing, and he had a habit of discovering things Microsoft would rather he hadn't.
Then Microsoft bought the company and made him a Technical Fellow. Today he's the chief technology officer of Azure, the cloud that runs a large slice of the world. The outsider who embarrassed Windows became the insider who builds it.
Mark Russinovich at a Glance
- Russinovich was born in Salamanca, Spain, and raised in Birmingham, Alabama, and Pittsburgh. He earned computer engineering degrees from Carnegie Mellon and Rensselaer and a PhD from Carnegie Mellon in 1994.
- In 1996 he and Bryce Cogswell founded Winternals Software and the Sysinternals website in Austin, Texas, home of Filemon, Regmon, Process Explorer and Autoruns.
- That September his research showed that Windows NT Workstation and the far pricier NT Server were nearly the same code, separated by registry settings.
- On October 31, 2005, he revealed that a Sony BMG CD had installed a rootkit on his PC. Sony settled with the FTC in January 2007.
- Microsoft acquired Winternals on July 18, 2006, and Russinovich joined as a Technical Fellow.
- He co-authors the Windows Internals books and wrote three cyberthrillers: Zero Day (2011), Trojan Horse (2012) and Rogue Code (2014).
- He became Azure's founding CTO and is now CTO, Deputy CISO and Technical Fellow for Microsoft Azure, with a sideline in AI security research.
The Life of Mark Russinovich
Russinovich's Early Years
Mark Russinovich was born in Salamanca, Spain, and grew up in Birmingham, Alabama, and then Pittsburgh. He studied computer engineering at Carnegie Mellon and Rensselaer Polytechnic Institute, and returned to Carnegie Mellon for a PhD, finishing in 1994 with a dissertation on "application-transparent fault management," the art of keeping software running when things break underneath it.
Windows NT was new, and Russinovich wanted to know how it worked. Microsoft wasn't telling, so he took it apart.
NTInternals
By 1996 he was a consulting associate at Open Systems Resources, a New Hampshire driver shop, and had co-written a stack of NT utilities: a registry monitor, a file monitor, even an NTFS driver for DOS. That year he and Bryce Cogswell founded Winternals Software and a website called NTInternals, soon renamed Sysinternals, "with the goal of developing advanced technologies for Windows."
The first bombshell came in September 1996. An O'Reilly report built on his research showed that Windows NT Workstation and Windows NT Server, separated by an $800 price difference and legal limits on using the cheaper one as a web server, had "identical kernels."
NT was "a single operating system with two modes," and "only two registry settings" switched between them in NT 4.0. Microsoft wasn't pleased. Administrators were delighted.
Over the next decade the free tools kept coming: Filemon and Regmon showed every file and registry access; Process Explorer replaced Task Manager for anyone serious; Autoruns listed everything that started with Windows; RootkitRevealer compared what Windows reported with what was actually on disk and flagged the differences. By 2006 the site was drawing about a million visitors a month, and "millions of people" were using the tools every day.
The Halloween Post
In October 2005 Russinovich was testing a new version of RootkitRevealer, a Sysinternals tool for finding software that hides itself, when he "ran a scan on one of my systems and was shocked to see evidence of a rootkit."
He dug in. A hidden directory, a driver called Aries.sys that patched the Windows kernel, and cloaking code that hid "any file, directory, Registry key or process whose name begins with '$sys$'." To prove it, he renamed a copy of Notepad to $sys$notepad.exe, and it vanished from view.
The files claimed to belong to "Essential System Tools" from a company called First 4 Internet, which sold a copy-protection technology called XCP. Then he found the source: "Sony BMG's Get Right with the Man (the name is ironic under the circumstances) CD by the Van Zant brothers," bought on Amazon and played once on his PC.
On October 31 he posted the whole investigation under the title "Sony, Rootkits and Digital Rights Management Gone Too Far." The code, he noted, showed "a lack of sophistication on the part of the programmer." Within days it was international news.
Fallout
The post set off weeks of bad news for Sony, and the legal consequences took longer. On January 30, 2007, Sony BMG settled with the FTC, which found the discs had installed software without adequate disclosure, limited playback, monitored listening habits and "created security vulnerabilities."
"Installations of secret software that create security risks are intrusive and unlawful," said FTC chairman Deborah Platt Majoras. Sony agreed to disclose restrictions on future CDs, stop installing software without consent, exchange the discs, provide uninstall tools and patches for two years, and reimburse consumers up to $150 for damage done removing the software.
One blog post by one engineer with his own tool had done all of that.
On His Way to Microsoft
On July 18, 2006, Russinovich wrote a post titled "On My Way to Microsoft!" Microsoft had bought Winternals and Sysinternals. He joined the Platforms and Services Division as a Technical Fellow, Cogswell joined the Windows team as a software architect, and the Sysinternals tools stayed free, which they remain today.
He kept writing. The Windows Internals books became the definitive account of how the operating system works, joined later by the Windows Sysinternals Administrator's Reference and Troubleshooting with the Windows Sysinternals Tools.
His "The Case of the..." blog posts turned troubleshooting into detective stories: the notepad that wouldn't run, the delayed file-open dialogs, each solved with his own tools and a screenshot.
Zero Day
In 2011 the detective stories became fiction. Zero Day, his first novel, imagined a coordinated cyberattack that sends an airliner down and nearly melts a reactor, with a security consultant named Jeff Aiken racing to stop it. Trojan Horse followed in 2012 and Rogue Code in 2014, a thriller about hackers inside the stock exchange that the Wall Street Journal noted was the first novel about high-frequency trading.
The appeal was obvious: the author knew exactly how the attacks would work, because he'd spent his life taking apart the systems they targeted.
Building Azure
Russinovich became the founding CTO of Microsoft Azure, responsible for the technical architecture of its compute, storage, networking and datacenter infrastructure as the cloud grew from a side project into one of the largest computing platforms ever built.
His title today is CTO, Deputy CISO and Technical Fellow for Azure. His recent research is on AI security: jailbreaks and red-teaming, agent security, and what he calls planet-scale infrastructure. He also co-hosts "Scott & Mark Learn To," a podcast with Scott Hanselman, which is where the man who once reverse-engineered Windows now explains it.
Mark Russinovich: The Case of the Trusted Insider
Russinovich made his name by refusing to take a vendor's word for what its software did, and he kept the habit after he became the vendor.
The tools he built in 1996 are still the first thing a Windows administrator downloads, and the Sony post is still the reason record labels don't put rootkits on CDs.
The $sys$notepad.exe experiment showed how easily the rootkit could hide a file. Russinovich made sure the rootkit itself didn't stay hidden.
QUOTE:
"Amateurs hack systems, professionals hack people."