January 6, 2012
Sony website defaced by second hacker
A defacer affiliated with Anonymous vandalised Sony's online front door this week over the corporate behemoth's support of SOPA, a hated anti-piracy law proposed in the US.
The Sony Picture's website was defaced and clearly unauthorised comments were posted on the media giant's Facebook page. The digital graffiti was scribbled by a hacker who uses the Twitter handle s3rver_exe. Both acts of vandalism were rapidly purged, while the YouTube video illustrating the hack was quickly pulled.
Neither cyber-assault was significant as the perp readily concedes. Even so, the latest security breach doesn't reflect well on Sony's much vaunted efforts to bolster its electronic defences following last year's PlayStation Network hack, which forced Sony to take down its gaming platform for weeks.
In an ironic twist, the Twitter account of @s3rver_exe was hacked on Friday in the wake of the #OpSony pawnage.
The Sony Picture's website was defaced and clearly unauthorised comments were posted on the media giant's Facebook page. The digital graffiti was scribbled by a hacker who uses the Twitter handle s3rver_exe. Both acts of vandalism were rapidly purged, while the YouTube video illustrating the hack was quickly pulled.
Neither cyber-assault was significant as the perp readily concedes. Even so, the latest security breach doesn't reflect well on Sony's much vaunted efforts to bolster its electronic defences following last year's PlayStation Network hack, which forced Sony to take down its gaming platform for weeks.
In an ironic twist, the Twitter account of @s3rver_exe was hacked on Friday in the wake of the #OpSony pawnage.
"Sony was hacked because the admin panel was not encrypted ROFL. And I have got my account back," s3rver_exe said. "I don't know why the hacker hacked me. I think he did it for the lulz."
"The hack wasn't big but still the servers were vulnerable and I got access to the admin too," he later added.
Author: dfgdfg,
Categories:
Anonymous,
Defacement,
Sony
October 12, 2011
Sony: 93,000 PlayStation, SOE gamers' accounts cracked

Intruders "using very large sets of sign-in IDs and passwords" had brief access to 60,000 accounts on the PlayStation Network and Sony Entertainment Network and another 33,000 accounts on Sony Online Entertainment's servers, Sony said.
The attacks occurred from Friday through Monday and affected "less than one-tenth of 1 percent" of PSN, SEN, and SOE consumers, Sony said in a statement. Hackers succeeded in verifying sign-in IDs and passwords, but Sony said credit card information was "not at risk" during the attack. Sony locked the accounts after confirming the attempts were unauthorized.
The compromised accounts also "showed additional activity prior to being locked," but that information has not been detailed. "We are continuing to investigate the extent of unauthorized activity on any of these accounts," Sony said.
"In this case, given that the data tested against our network consisted of sign-in ID-password pairs, and that the overwhelming majority of the pairs resulted in failed matching attempts, it is likely the data came from another source and not from our Networks," Sony Chief Information Security Officer Philip Reitinger said on the PlayStation blog.
Reitinger somewhat hinted at what the "additional activity" could be: "We will work with any users whom we confirm have had unauthorized purchases made to restore amounts in the PSN/SEN or SOE wallet."
Sony is actively sending e-mails to affected consumers who have locked accounts and is requiring them to perform a secure password reset.
PSN hacking is a sensitive subject for many following a month of outages earlier this year that were ultimately pegged to cyberbattacks.
The sheer scope of the recent hacking scandal, which compromised the personal information of millions of gamers--was a huge smudge on the public perception of the gaming network. In the damage-control department, Sony issued multiple apologies and the promise of a strengthened network, along with giving affected users a $1 million identity theft insurance policy and free games. It also gave all PSN members affected by the outage access to PlayStation Plus for a month.
Author: dfgdfg,
Categories:
Brute Force Attack,
Password Security,
PlayStation,
Sony
September 25, 2011
LulzSec Hackers betrayed by HideMyAss.com
It was last week, Cody Kretsinger, a 23 years old from Phoenix, Arizona that was allegedly involved in hacking Sony Pictures, got arrested and I was having a battle of the mind on how and what possible means that Feds used to track this guy down.
Well it now seems that what we should believe to be hiding our ass is now exposing our ass. HideMyAss.com allows you to surf anonymously online in complete privacy.
The indictment against Kretsinger says he used a proxy server to hide his identity while carrying out the attack. But it emerged that the site he allegedly used to disguise his identity cooperated with the Feds to track him down.
The details of how it all happened is not yet public, but Hidemyass blog said they had to cooperate with the police when a leaked IRC chat logs that was released, exposed the participants of using various VPN service which their's were among.
Full indictment is below:
Cody Andrew Kretsinger Indictment
Well it now seems that what we should believe to be hiding our ass is now exposing our ass. HideMyAss.com allows you to surf anonymously online in complete privacy.
The indictment against Kretsinger says he used a proxy server to hide his identity while carrying out the attack. But it emerged that the site he allegedly used to disguise his identity cooperated with the Feds to track him down.
The details of how it all happened is not yet public, but Hidemyass blog said they had to cooperate with the police when a leaked IRC chat logs that was released, exposed the participants of using various VPN service which their's were among.
It first came to our attention when leaked IRC chat logs were released, in these logs participants discussed about various VPN services they use, and it became apparent that some members were using our service. No action was taken, after all there was no evidence to suggest wrongdoing and nothing to identify which accounts with us they were using. At a later date it came as no surprise to have received a court order asking for information relating to an account associated with some or all of the above cases. As stated in our terms of service and privacy policy our service is not to be used for illegal activity, and as a legitimate company we will cooperate with law enforcement if we receive a court order (equivalent of a subpoena in the US).You can be sure that HideMyAss is not the only provider to be hit with subpoenas and essentially being forced to hand over user data. It’s likely the FBI and other officials are digging deep and requesting similar information from other VPN providers and online services such as Pastebin, Twitter, and other tools and web services commonly used by hackers.
Full indictment is below:
Cody Andrew Kretsinger Indictment
Author: dfgdfg,
Categories:
Kretsinger Jailed,
LulzSec,
Sony
September 23, 2011
Alleged LulzSec, Anonymous hackers arrested

Cody Andrew Kretsinger, 23, of Phoenix was indicted September 2 by a federal grand jury on charges of conspiracy and unauthorized impairment of a protected computer, the FBI said in a statement. Kretsinger could not be reached for comment.
Separately, 47-year-old Christopher Doyon of Mountain View, Calif., was arrested and appeared before Magistrate Judge Howard Lloyd in U.S. District Court for the Northern District of California in San Jose, according to a U.S. Department of Justice statement released this afternoon. Lloyd ordered that a bail study be done and set a court appearance for September 29 at 1:30 p.m. PT.
Doyon, who allegedly uses the alias "Commander X," and Joshua John Covelli, 26, of Fairborn, Ohio, were indicted on charges of conspiracy to cause intentional damage to a protected computer, causing intentional damage to a protected computer, and aiding and abetting by participating in a distributed DoS attack on Santa Cruz County servers December 16, 2010, shutting down the Web site. A criminal summons was issued to Covelli, aka "Absolem" or "Toxic," to appear before Magistrate Paul Grewal in San Jose on November 1.
In the Sony case, Kretsinger is accused of using proxy services via the hidemyass.com site, designed to offer anonymous Internet access, to probe Sony Pictures Entertainment's computer systems in May, according to the indictment, which was unsealed in U.S. District Court in Los Angeles today.
He and other co-conspirators looked for vulnerabilities and exploited them by means of a SQL injection attack between May 27 and June 2, the indictment says. They then allegedly compromised the Sony system, making "tens of thousands of requests for confidential data," and released the information from Sony on a public Web site and on Twitter.
Kretsinger permanently erased the hard drive of the computer he used to conduct the attack, the indictment alleges. He is due to make an initial appearance in federal court in Phoenix today. The U.S. government will request that he be transferred to Los Angeles to face prosecution. He faces up to 15 years in prison if convicted.
He is alleged to have used the hacker handle "recursion" and is believed to be a member of the LulzSec hacker group.
The LulzSec group, believed to be a spinoff of the Anonymous group of online activists, had bragged about breaking into Sony Pictures' system, posting a statement on Pastebin on June 2 and proof of their attack. "We recently broke into SonyPictures.com and compromised over 1,000,000 users' personal information, including passwords, email addresses, home addresses, dates of birth, and all Sony opt-in data associated with their accounts," the statement said. "Among other things, we also compromised all admin details of Sony Pictures (including passwords) along with 75,000 'music codes' and 3.5 million 'music coupons.'"
A week later, Sony said that actually personally identifiable information of 37,500 customers had been exposed in the breach. The breach was one of a series of attacks targeting Sony and its affiliate sites globally that started in May following a legal spat Sony had with a hacker who had modified his Sony PlayStation 3.
In the San Jose cases, the indictments allege that the attack on Santa Cruz County servers was orchestrated by the People's Liberation Front (PLF), which is associated with the Anonymous group. After the city enacted a law restricting camping in city limits, protesters occupied the courthouse premises and several were charged with misdemeanors, the Justice Department said. In retaliation, the PLF organized the DoS attack, the statement alleges.
Covelli is also separately under indictment in U.S. District Court for the Northern District for allegedly participating in a distributed DoS attack on PayPal in December 2010. His next court appearance in that case is set for November 1 at 9 a.m. PT before Judge Lowell D. Jensen in San Jose. Neither Doyon nor Covelli could immediately be reached for comment this afternoon.
The Justice Department and FBI said they could not comment on the San Jose cases beyond the indictments and statements, so it is unclear exactly where Doyon was arrested. Earlier today, Fox News reported that a hacker who is believed to be homeless was arrested in San Francisco on charges of participating in attacks allegedly carried out by activist group Anonymous on Santa Cruz County government Web sites, and that search warrants were being executed in New Jersey, Minnesota, and Montana. An FBI spokesman said that the agency does not typically comment on search warrants.
Author: dfgdfg,
June 11, 2011
Lulz Security Gives Sony a Break Today and Takes Down Terrorist Website
The execs at Sony HQ can wipe the sweat off the brow for the next 30 minutes, because the hacker crew of the SS Lulz is claiming responsibility for AlJahad.com's (temporary) demise. The Islamist extremism site is sunk.
The site was nuked by rival (?) hacker The Jester in March, prompting Lulz Sec to boast of their coup: "ujelly?"
The Jester is likely somewhat jelly. Enjoy your lulz, boys! Nice of you to scrape away something other than vulnerable Sony customer accounts. [via LulzSec]
Subscribe to get the latest news about Anonymous hacking group directly into your inbox.
Author: dfgdfg,
Spanish Police Arrest Suspected Hackers Linked To Anonymous: AnonOps vows revenge
Three people suspected of being involved in attacks against websites belonging to Sony, Spanish banks BBVA and Bankia, Italian energy company Enel, and the governments of Egypt, Algeria, Libya, Iran, Chile, Colombia, and New Zealand have been arrested in Spain. All three were claimed to be the leadership of hacktivist organization Anonymous in Spain.
The individuals are accused of performing and organizing large distributed denial of service (DDoS) attacks that took their victims' Web servers offline. The detainees were also claimed to have attacked the websites of Spain's Central Electoral Board on May 18, and later the sites of the Catalan police and the UGT trade union.
The arrests were made after investigation work by the Brigada de Investigación Tecnológica (BIT), the cybercrime division of Spain's civilian police force. With these arrests, Spain joins the UK, US, and Netherlands in having taken police action against Anonymous members. During the investigation, more than 2,000,000 lines of IRC logs were examined to track down the people involved.
The three were arrested in Almeria, Barcelona, and Valencia. One of those arrested was said to have set up an IRC server in their home, and this server was used by all three to coordinate their various hack attacks. Those attacks were DDoS attacks, performed using Anonymous' preferred LOIC tool; LOIC has an automatic mode that uses IRC for command and control. Also found were malware creation tools and WiFi cracking software; two of the people arrested apparently had no Internet connection themselves, instead depending on the WiFi connections of others.
Though Sony was one of the organizations victimized by the hacktivists, the official statement issued by the police did not indicate any suspicion of involvement in the hacks that forced Sony to take Playstation Network offline for weeks, nor the subsequent hacks made on Sony Web properties by LulzSec. Rather, the three hackers appear to have been involved with the denial of service attacks of early April. Vocal Anonymous faction AnonOps has long denied that Anonymous had any involvement with the broader, more serious attack against Playstation Network.
When news of the arrests became public, AnonOps was swift to issue a warning to the Spanish authorities: Expect us.
Subscribe to get the latest news about Anonymous hacking group directly into your inbox.
The individuals are accused of performing and organizing large distributed denial of service (DDoS) attacks that took their victims' Web servers offline. The detainees were also claimed to have attacked the websites of Spain's Central Electoral Board on May 18, and later the sites of the Catalan police and the UGT trade union.
The arrests were made after investigation work by the Brigada de Investigación Tecnológica (BIT), the cybercrime division of Spain's civilian police force. With these arrests, Spain joins the UK, US, and Netherlands in having taken police action against Anonymous members. During the investigation, more than 2,000,000 lines of IRC logs were examined to track down the people involved.
The three were arrested in Almeria, Barcelona, and Valencia. One of those arrested was said to have set up an IRC server in their home, and this server was used by all three to coordinate their various hack attacks. Those attacks were DDoS attacks, performed using Anonymous' preferred LOIC tool; LOIC has an automatic mode that uses IRC for command and control. Also found were malware creation tools and WiFi cracking software; two of the people arrested apparently had no Internet connection themselves, instead depending on the WiFi connections of others.
Though Sony was one of the organizations victimized by the hacktivists, the official statement issued by the police did not indicate any suspicion of involvement in the hacks that forced Sony to take Playstation Network offline for weeks, nor the subsequent hacks made on Sony Web properties by LulzSec. Rather, the three hackers appear to have been involved with the denial of service attacks of early April. Vocal Anonymous faction AnonOps has long denied that Anonymous had any involvement with the broader, more serious attack against Playstation Network.
When news of the arrests became public, AnonOps was swift to issue a warning to the Spanish authorities: Expect us.
Subscribe to get the latest news about Anonymous hacking group directly into your inbox.
Author: dfgdfg,
Categories:
AnonOps,
Anonymous,
DDos Attack,
Hacking,
Sony
June 10, 2011
Hacker reveals further Sony flaws in Portugal
Sony's hack of the day has been claimed by a Lebanese hacker who says he has breached the company's Portuguese site.
Sony has been under almost daily attack for weeks from various hacking groups, which have targeted the company after an attack took out its PlayStation Network.
The hacker, who calls himself Idahc and also targeted Sony Europe last week, claimed to have found three weaknesses on the Portuguese site.
“I found three flaws on the www.sonymusic.pt - sql injection, XSS, and Iframe Injection,” he said in a posting on Pastebin.
Claiming that he was “not a black hat", he won't be dumping the database into the public domain, but instead posted a list of harvested email addresses as proof of his exploits.
Kick off your day with Prohackingtrick's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.
Author: dfgdfg,
Categories:
Hacking,
PlayStation,
Sony
June 6, 2011
LulzSec Hacking Group Activities Over the Weekend
LulzSec is certainly going to make a name for themselves at the rate they are going. The hacker group claims responsibility for the recent major attacks against Sony and PBS’s websites as we have written about, compromising well over an incredible number of user’s security information and exposing the poor security of both companies.
Despite having successfully orchestrated a major hack on Sony just a few days ago, they announced Friday that they had successfully infiltrated the Atlanta chapter of Infragard. For those not in the know, Infragard is an FBI affiliate. The hackers then uploaded Infragard’s user database to the internet, compromising security for the company and its affiliates. An associated company’s use of botnets was exposed as well, claims the group, and they are claiming that the documents they exposed also reveal an attempt by someone involved to pay LulzSec not to expose the breach.
LulzSec actually took complete control of Infragard’s Atlanta Chapter website, defacing it. One of their main reports was that while there were not many logins (around 180), all of them were affiliated with the FBI in one way or another.
Ironically, Infragard is a private-public partnership between the FBI and US businesses. Their business is “designed to protect IT systems from hacker attacks and other intrusions.” It would appear they are going to have to rethink their security protocols.
LulzSec really seems to be driving home the intense need for appropriate security measures to be taken by companies who are holding extremely valuable personal information for clients. One “weak link” can expose literally thousands of networks to a security breach, as was well demonstrated by their exposure of Karim Hijaz’s indiscretions when it came to his password. It must be understood that reusing passwords in several different places is frowned upon by both the FBI and Infragard handbooks and, indeed, by any person or organization concerned about security.
The attack on Infragard exposed Hijazi’s repeated use of his Infragard password in other places, including accounts of his personal business as well as his personal e-mail. Hacking one system gave them access to all of the major information Hijazi was privy to, compromising not only his own security, but that of the FBI, Infragard, his personal business, all of this clients as well as his personal activities. Particularly interesting to note is the fact that Hijazi’s personal business, “Unveillance” is a whitehat company that specializes in data breaches and botnets. LulzSec reported on their website that Karim was contacted personally by them and told all that they had done and that he purportedly offered them money in exchange for eliminating his competitors by illegal hacking means and for their silence. Supposedly they even discussed plans for him to give them insider information regarding his botnet information.
Hijazi issued a public statement shortly thereafter and is quoted here:
Over the last two weeks, my company, Unveillance, has been the target of a sophisticated group of hackers now identified as “LulzSec.” During this two week period, I was personally contacted by several members of this group who made threats against me and my company to try to obtain money as well as to force me into revealing sensitive data about my botnet intelligence that would have put many other businesses, government agencies and individuals at risk of massive Distributed Denial of Service (DDoS) attacks.While this author cannot vouch one way or the other for the truth of Hijazi’s or LulzSec’ claims, she can provide the last response LulzSec regarding Hijazi’s claims:
In spite of these threats, I refused to pay off LulzSec or to supply them with access to this sensitive botnet information. Had we agreed to provide this data to them, LulzSec would have been able to grow the size and scope of their DDoS attack and fraud capabilities.
Karim compromised his entire company and the personal lives of his colleagues, then attempted to silence us with promises of financial gain and mutual benefits … [he] used the same password for all of his online accounts and all accounts linked to a company he owns. Then he tried to bargain with hackers so his company wouldn’t crumble.Regardless of whose claims are the complete truth, one thing is for certain: LulzSec is not playing around. Companies holding vitally sensitive information
would do well to make sure their security protocols are truly secure, for their own sakes as well as the sakes of the clients who trust them.
As a side note, as this article was being written, it has come out that Lulzsec has hacked Nintendo as well, though Nintendo claims that no user information has been compromised. We will update this article as more information becomes available.
Author: dfgdfg,
May 28, 2011
Sony's PlayStation Network to reopen in Asia
Sony's PlayStation Network online gaming service will reopen for millions of gamers across Asia on Saturday, more than five weeks after it was taken offline following a cyber attack.
Sony pulled the plug on the PlayStation Network and the companion Qriocity audio and video streaming service on April 20, a day after detecting what it later called a "very sophisticated" intrusion.
When service resumes on Saturday in Japan, Taiwan, Singapore, Malaysia, Indonesia and Thailand, there will only be two more countries where service is still offline: South Korea and Hong Kong. Sony is still in discussions with authorities in those markets and can't name a date for the resumption of services in the two countries.
"It's going to take a little while longer," said Satoshi Fukuoka, a spokesman for Sony Computer Entertainment in Tokyo.
Gamers in Asia were kept waiting while Sony briefed authorities in several countries on the hack and its response, but service returned for users in North America, Europe, the Middle East, Australia and New Zealand on May 14 and 15.
The incident began when an unknown hacker or hackers penetrated three firewalls to get inside Sony's system and steal data on all 77 million registered accounts.
The stolen data included user names, e-mail addresses, login IDs and passwords. It was originally feared that millions of credit card numbers had also been leaked, but a subsequent computer forensics investigation failed to find any evidence that the credit card database had been accessed by the attacker, said Sony.
PlayStation users are required to download a firmware update for the console before they can reconnect to the network. Then, as a security measure, users must change their password upon login.
Sony has initially resumed a subset of the full PlayStation Network and Qriocity services. Back online are: online gaming, playback of already rented video, "Music Unlimited" online audio streaming, access to third-party services like Netflix and Hulu, PlayStation Home and friends features such as chat.
Full service is expected to resume in all markets, except South Korea and Hong Kong, by the end of May.
The attack and Sony's response to it will cost the company around ¥14 billion (US$170 million) this financial year, it said Monday. That includes the cost of calling in several computer security companies, a rebuild of its security system, identity theft monitoring for users in some countries and the offering of several free games to users.
Sony pulled the plug on the PlayStation Network and the companion Qriocity audio and video streaming service on April 20, a day after detecting what it later called a "very sophisticated" intrusion.
When service resumes on Saturday in Japan, Taiwan, Singapore, Malaysia, Indonesia and Thailand, there will only be two more countries where service is still offline: South Korea and Hong Kong. Sony is still in discussions with authorities in those markets and can't name a date for the resumption of services in the two countries.
"It's going to take a little while longer," said Satoshi Fukuoka, a spokesman for Sony Computer Entertainment in Tokyo.
Gamers in Asia were kept waiting while Sony briefed authorities in several countries on the hack and its response, but service returned for users in North America, Europe, the Middle East, Australia and New Zealand on May 14 and 15.
The incident began when an unknown hacker or hackers penetrated three firewalls to get inside Sony's system and steal data on all 77 million registered accounts.
The stolen data included user names, e-mail addresses, login IDs and passwords. It was originally feared that millions of credit card numbers had also been leaked, but a subsequent computer forensics investigation failed to find any evidence that the credit card database had been accessed by the attacker, said Sony.
PlayStation users are required to download a firmware update for the console before they can reconnect to the network. Then, as a security measure, users must change their password upon login.
Sony has initially resumed a subset of the full PlayStation Network and Qriocity services. Back online are: online gaming, playback of already rented video, "Music Unlimited" online audio streaming, access to third-party services like Netflix and Hulu, PlayStation Home and friends features such as chat.
Full service is expected to resume in all markets, except South Korea and Hong Kong, by the end of May.
The attack and Sony's response to it will cost the company around ¥14 billion (US$170 million) this financial year, it said Monday. That includes the cost of calling in several computer security companies, a rebuild of its security system, identity theft monitoring for users in some countries and the offering of several free games to users.
Author: dfgdfg,
Categories:
Hacking Tricks,
PlayStation,
Sony
May 3, 2011
PlayStation Network: hackers claim to have 2.2m credit cards
Discussions in hacker forums point to huge numbers of credit card details stolen from Sony's PlayStation Network, while some owners see fraud – but is it just coincidence?
Hackers in underground online forums are claiming to have access to credit card details stolen from Sony's PlayStation Network in mid-April, though security researchers say it is not possible to verify the claims.
The online discussions centre around a haul of 2.2m Sony customer credit card numbers that are claimed to have been copied during the attack, which led Sony to shut down the network for more than a week after it happened between 17 and 19 April.
At the same time some of the 77 million PSN users have begun to report discovering new fraudulent charges on their credit cards, though the timing could be coincidence and not linked directly to the breach. Any sufficiently large number of credit card owners is certain to include some who have recently been defrauded by other methods.
The claims of fraud include the equivalent of $1,500 spent in a German grocery store on an American credit card, and dozens of people reporting charges on items such as German airline tickets and Japanese stores.
Kevin Stevens, a security analyst with Trend Micro, said in a tweet that "the hackers that hacked PSN are selling off the DB [database]. They reportedly have 2.2m credit cards with CVVs" - the latter being the three-figure number required for "card not present" transactions.
But Stevens added that he couldn't be sure the claim was true. The hackers were also claiming to have offered to sell the database back to Sony, but that the company declined it. Sony spokesman Patrick Seybold said that as far as he knew there was no truth in that claim.
Speculation is growing that the hackers who carried out the attack could be European, based on the names being used in forums, though no further details have emerged so far.
One reader of Venturebeat said he had been contacted by Sony and told that his card might have been compromised, and discovered two new charges totalling $400 he hadn't made.
Sony insisted in a blog post that the credit card data it stored was encrypted: "While all credit card information stored in our systems is encrypted and there is no evidence at this time that credit card data was taken, we cannot rule out the possibility.
"If you have provided your credit card data through PlayStation Network or Qriocity, out of an abundance of caution we are advising you that your credit card number (excluding security code) and expiration date may have been obtained. Keep in mind, however, that your credit card security code (sometimes called a CVC or CSC number) has not been obtained because we never requested it from anyone who has joined the PlayStation Network or Qriocity, and is therefore not stored anywhere in our system."
Hackers in underground online forums are claiming to have access to credit card details stolen from Sony's PlayStation Network in mid-April, though security researchers say it is not possible to verify the claims.
The online discussions centre around a haul of 2.2m Sony customer credit card numbers that are claimed to have been copied during the attack, which led Sony to shut down the network for more than a week after it happened between 17 and 19 April.
At the same time some of the 77 million PSN users have begun to report discovering new fraudulent charges on their credit cards, though the timing could be coincidence and not linked directly to the breach. Any sufficiently large number of credit card owners is certain to include some who have recently been defrauded by other methods.
The claims of fraud include the equivalent of $1,500 spent in a German grocery store on an American credit card, and dozens of people reporting charges on items such as German airline tickets and Japanese stores.
Kevin Stevens, a security analyst with Trend Micro, said in a tweet that "the hackers that hacked PSN are selling off the DB [database]. They reportedly have 2.2m credit cards with CVVs" - the latter being the three-figure number required for "card not present" transactions.
But Stevens added that he couldn't be sure the claim was true. The hackers were also claiming to have offered to sell the database back to Sony, but that the company declined it. Sony spokesman Patrick Seybold said that as far as he knew there was no truth in that claim.
Speculation is growing that the hackers who carried out the attack could be European, based on the names being used in forums, though no further details have emerged so far.
One reader of Venturebeat said he had been contacted by Sony and told that his card might have been compromised, and discovered two new charges totalling $400 he hadn't made.
Sony insisted in a blog post that the credit card data it stored was encrypted: "While all credit card information stored in our systems is encrypted and there is no evidence at this time that credit card data was taken, we cannot rule out the possibility.
"If you have provided your credit card data through PlayStation Network or Qriocity, out of an abundance of caution we are advising you that your credit card number (excluding security code) and expiration date may have been obtained. Keep in mind, however, that your credit card security code (sometimes called a CVC or CSC number) has not been obtained because we never requested it from anyone who has joined the PlayStation Network or Qriocity, and is therefore not stored anywhere in our system."
Author: dfgdfg,
Categories:
PlayStation,
Sony
PlayStation Network users fear identity theft after major data leak
Sony issues worldwide alert after personal details of 77 million PlayStation users, including 3 million Britons, stolen by hackers
Up to 3 million Britons are believed to be among the 77 million users of Sony's PlayStation Network, which has been hacked into by criminals who have stolen users' personal information, possibly including credit card details.
Reeling from one of the worst such security breaches in history, Sony warned all users of the PSN network – used to play games online and download content including films – that they should be alert for fraudulent activity on their credit cards. Users have been warned to be wary of "phishing" emails pretending to be updates or security information, and to urgently change the passwords on any sites or services that use the same password as their PSN username.
The firm conducted a "forensic security" examination and discovered a hacker, or hackers, had accessed the internal corporate computer systems that hold the details. The UK's information commissioner said he would ask Sony to explain the circumstances of the data leak, which might constitute a breach of the Data Protection Act.
The details of the users of the worldwide PlayStation Network – used by owners of Sony Playstation 3s and PlayStation Portables – include names, addresses, dates of birth, email addresses, and passwords to the network. They are a treasure trove potentially worth more than £100m to those who have stolen them if sold through online black markets, where the data required for an individual identity theft can cost up to $10, and a million unverified email addresses cost just $8.
Sony confirmed late on Tuesday that it had suffered an "intrusion" into its system on Wednesday 20 April, and that it had shut down the PSN and its Qriocity music streaming services as soon as the incident was discovered.
The PSN system was still down late on Wednesday. As well as costing Sony money the closure will be affecting a new generation of games companies that had hoped to use the system as a new means of selling games solely through downloads.
The admission will be a huge blow to Sony, which has been struggling to regain its once iconic status after years of missteps, and will increase pressure on its chief executive, Sir Howard Stringer.
Sony has not said how the hackers broke in. But Rik Ferguson, a computer security consultant at Trend Micro, said: "This has all the hallmarks of commercial criminal activity going for a saleable commodity. It doesn't look as though they would have broken in directly through the PlayStation Network. Far more likely is that they breached the corporate systems and then moved through them to access this valuable data."
The breach is one of the biggest ever, and in terms of the value of the data contained may be the most valuable to the hackers. In January 2009 a US payment card processor, Heartland Payment Systems, was hacked, affecting up to 100m cards; in March 2007 the systems of the store chain TK Maxx were hacked, leading to the theft of 46m credit card details.
However the PSN break-in is potentially more valuable because of the quality and breadth of data involved, as it could be used to construct an entire identity.
Security experts are wondering whether Microsoft's rival XBox Live service, which provides a similar function to Sony's PSN, could be targeted, though experts said it was a more closed system.
Dave Whitelegg, a data security blogger, said: "Microsoft's approach to [running a gaming network] is a bit more guarded than Sony's. The PSN is a much more open system. It's a whole different philosophy. A classic example is, on Xbox Live you do not get a web browser – the reason for that is security; it's a possible attack vector and could get you into their network. But the PlayStation 3 has one."
Ferguson said highly targeted commercial hacking attacks had increased recently, with large online repositories of information being targeted. The activism group Anonymous took the unusual step of insisting it was not behind the breach. It had previously attacked Sony over the company's legal complaints about gamers who tried to hack software that would let PS3s play any game.
"For once we didn't do it," the organisation, which describes itself as fighting for internet freedom, wrote on its blog. "AnonOps was not related to this incident and does not take responsibility for whatever has happened."
Sony has been criticised for the fact that the hackers have apparently been able to copy the data directly, implying it was not encrypted.
Almost every commercial site scrambles a user's password before storing it; when the user tries to log in, the password they provide is scrambled in the same way and then compared with the stored one, meaning the "plaintext" password is not available. It does not appear that Sony has done this.
Ian Shepherd, chief executive of video-games retailer Game Group, told Reuters: "The issue, the experience that Sony are having … is a really serious one. It's one we're staying very close to. I think there are lessons for the whole industry from the experience that Sony are having."
Many gamers expressed anger. On the PS3news.com online forum, PSN member Jarvis wrote: "Stop purchasing anything remotely related to Sony. Let companies who deal with Sony know that you can't support them if they continue to work with Sony."
But Ferguson said such threats were unlikely to amount to anything. "That's just frustration. There would be a real hardware cost in doing that. In fact, it's likely to be more like what happens after a terrorist attack: security is stepped up and everyone is much safer for some time afterwards."
Since Stinger's appointment in March 2005 he has struggled to break the company out of its "silo" organisation that has prevented co-ordination between different divisions.
But revenue and profits have both remained flat, while the company has struggled to make an impact in new areas. The PlayStation 3, launched in 2006 in Japan and 2007 elsewhere, is widely seen as third-placed behind Microsoft's Xbox and Nintendo's Wii, and has dragged down profits.
A series of other problems such as battery fires and spyware embedded on music CDs have not helped its reputation either, and Stringer is now widely seen as being vulnerable if the company's performance does not improve.
Meanwhile the first lawsuit resulting from the security breach has been filed.
It was filed on behalf of Kristopher Johns, 36, of Alabama. Johns accuses Sony of not taking "reasonable care to protect, encrypt, and secure the private and sensitive data of its users."
Author: dfgdfg,
Categories:
PlayStation,
Sony
May 2, 2011
PlayStation hack: will you think twice about sharing personal data online?
Sony has warned that information about 77 million people with accounts on its PlayStation Network has been stolen. Will this make you think twice about sharing personal data online?
Sony's PlayStation Network has suffered a massive breach, allowing the theft of names, addresses and possibly credit card data.
Will you now think twice about sharing personal data online?
Author: dfgdfg,
Categories:
PlayStation,
Sony
PlayStation Network hack: what every user needs to know
Comprehensive guide to what's happened and what all PlayStation Network users need to do
Sony's PlayStation Network – the infrastructure that allows PS3 owners to play online games, as well as buy movies and other downloadable content – has been infiltrated by an unknown hacker, and the customer details of up to 77 million users have been compromised.
But how worried should we be, and what can PSN users do to protect themselves? Here are a few of the answers we have so far ...
What has happened?
Between 17 April and 19 April, Sony realised there had been an "unauthorised intrusion" on the PlayStation Network and Qriocity services. The company shut the services down and undertook an investigation. It claims that the full extent of the security breach was only understood yesterday.
How has this happened?
Good question – and one that Sony should be required to answer as soon as possible. Indeed, US senator Richard Blumenthal has written to SCEA president Jack Tretton demanding an explanation. It seems, though, that there have been recurrent weaknesses in the PSN security infrastructure. In January, the PS3 system root key, which authorises software running on the machine, was hacked, potentially allowing pirated games and unauthorised software to run on "jailbroken" PS3s. There are now numerous coding sites offering custom firmware, allowing PlayStation owners to run their own apps and operating systems on the machine. This is not unique to Sony's console however: both the Wii and Xbox 360 can be "hacked" to run pirated software – however, the accounts and personal details of other console customers have not been involved on this scale.
What have the hackers obtained?
It seems that any personal information you have entered into the PSN service is vulnerable. That means your name, address (including postcode), country, email address, birthdate, PlayStation Network/Qriocity password, login, password security answers, and your PSN online ID. Sony says that it is also possible that your profile data may have been obtained, "including purchase history and billing address". If you have used your credit card to buy downloadable content via PSN or Qriocity, your credit card details, excluding your security number (usually the three-digit number on the reverse of the card, on the signature panel) may have been obtained. Sony is stressing that all of this is a possibility; it doesn't know for definite that the hacker has acquired all of this information.
What should I do about my PSN account now?
While the network is down, there's not much you can do. Sony won't say when the service is going back online, but when it does, you should immediately change your PSN password.
What other precautions should I take?
If you use the same password elsewhere online, change every instance. Ideally, you should employ different passwords on every secure site you use. From now on, try to make your passwords as un-guessable as possible. Use numbers, capitals and symbols. When the Gawker network was hacked last year it was discovered that the most popular password among users was "12345"; the second was "password". That's not a good idea if you have credit card information to protect. If you use a Google Mail account to access secure sites, consider employing two-factor authentication.
Also, be aware that phishing scams will now be in operation: if you receive emails claiming to be from Sony and asking for account information or personal details, do not reply. Sony has stated that it will not email PSN users requesting details.
How will I know if my account has been compromised?
You probably won't know if someone holds your data until they attempt to use it. Keep a close eye on your credit card statements – look out for any unusual transactions and inform your bank or credit card company immediately if you see anything suspicious. If you are worried, you can pay for a credit card report from one of the three UK agencies: Experian, Equifax and Call Credit. They also run subscription services that monitor your account and alert you to suspicious activities. Senator Blumenthal has urged Sony to provide PSN users with free access to credit reporting services for two years. This is unlikely to happen. In its online FAQ, Sony has broached the subject of refunds, stating: "When the full services are restored and the length of the outage is known, we will assess the correct course of action."
When PSN is back online will it be safe?
Sony has said that it is rebuilding the service. The company has also bought in third-party security experts to trace the source of the hack. It's worth pointing out, however, that data security is an issue facing every site where customers hand over personal and financial details. There are question marks over whether online data systems can ever be 100% safe.
Author: dfgdfg,
Categories:
PlayStation,
Sony
PlayStation Network hackers access data of 77 million users
Sony says hackers have accessed personal information, but says there is no evidence of credit card details theft.
Sony has warned that the names, addresses and other personal data of about 77 million people with accounts on its PlayStation Network (PSN) have been stolen.
Gamers have been locked out of the network for a week, but the company has revealed that the system has been suspended since it was hacked last Wednesday.
Sony said it discovered that between 17 and 19 April an "illegal and unauthorised person" got access to people's names, addresses, email address, birthdates, usernames, passwords, logins, security questions and more.
Children with accounts established by their parents also may have had their data exposed, according to Sony, which put the warning on its US PlayStation blog – although the warning about the compromise might not be immediately visible to passing readers. The company is also emailing people who might be affected.
The intrusion is potentially one of the biggest ever into a store of credit cards. Sony's PSN is one of the world's biggest holders of credit cards, though not as large as Amazon, eBay, PayPal or Apple's iTunes, which each hold more than 100m accounts.
The previous largest hacking attacks were on Heartland Payment Systems in January 2009, when up to 100m US credit and debit card details were stolen, and TK Maxx in March 2007, when up to 46m credit card details were stolen.
The company said that it saw no evidence that credit card numbers were stolen, but it added: "Out of an abundance of caution, we are advising you that your credit card number (excluding security code) and expiration date may have been obtained,"
The online marketplace launched in autumn 2006 and allows users to purchase and play video games, music and films on their PlayStation consoles.
The hack attack has put it out of action and it says that it may be up to a week before it is operational again.
Sony said it had hired an outside security firm to investigate what happened and has taken steps to rebuild its system to provide greater protection for personal information.
PlayStation members are required to submit credit card and personal details to play online games and download software, films and music.
Warning users of the network to be on the look out for telephone and email scams, Sony said: "To protect against possible identity theft or other financial loss, we encourage you to remain vigilant to review your account statements and to monitor your credit or similar types of reports."
PlayStation Network posted an apology to users through the Sony website saying it would email those who are suspected to be victims of the hacking.
It said: "We don't have an exact date to share at this moment as to when we will have the services turned on, but are working day and night to ensure it is as quickly as possible.
"Please note that we are as upset as you are regarding this attack and are going to proceed aggressively to track down those that are responsible."
Graham Cluley, senior technology consultant at security firm Sophos, said that the theft of so much detailed customer information would be seen as a "public relations disaster".
Author: dfgdfg,
Categories:
PlayStation,
Sony
Hackers keep PlayStation Network offline for fifth day
Sony says it is working to get internet-based retail service back online quickly after an 'external intrusion'
Hackers have kept Sony's lucrative PlayStation Network offline for a fifth day while engineers scramble to overhaul the system and make it more secure.
Sony's equivalent of Apple's iTunes Store, PlayStation Network is the internet-based retail service that allows users of its PlayStation 3 and PlayStation Portable devices to buy games, films, music and game add-ons, and to chat with one another.
Sony confirmed on Friday that the service had been attacked by hackers, describing it on the official PlayStation blog as an "external intrusion". Patrick Seybold, senior director of corporate communications, wrote that Sony planned "a thorough investigation … to verify the smooth and secure operation of our network services".
In an update on Monday, Seybold wrote: "This is a time intensive process and we're working to get them back online quickly."
Staff have not been given any details about the problem, which first resulted in PSN going offline last Wednesday. A weekly internal progress email mentioned the "external intrusion" but did not give any indication how long the service would remain offline.
Sony's troubles began when it removed the "Other OS" option from all PS3 consoles in March last year, which meant users could no longer choose to install and run the Linux operating system. Sony cited security concerns, but the move triggered some users to hack the PS3 so that they could still run Linux.
Sony then moved to sue a group of hackers that included 21-year-old George Hotz – who had already earned a reputation after jailbreaking the iPhone – who had allegedly published a root key for the PS3 that meant any content, such as films and music, could be played on a jailbroken device.
The high-profile Hotz case, which was settled out of court this month, attracted attention from the Anonymous hacking network, which pledged to target Sony. A post on the Anonymous blog on 4 April said the action against Hotz and fellow hacker Graf_Chokolo was "wholly unforgivable".
"You have victimised your own customers for merely possessing and sharing information … Your corrupt business practices are indicative of a corporate philosophy that would deny consumers the right to use products they have paid for, and rightfully own, in the manner of their choosing," it said.
Despite the threats, a later post on the blog stated "for once we didn't do it" and said Sony could be "taking advantage of Anonymous' previous ill-will towards the company to distract users from the fact the outage is actually an internal problem with the company's servers".
Patrick Garrett, on the games industry blog VG24/7, said the PSN crisis could have dire consequence for Sony if it did not adopt a more sophisticated strategy for dealing with hackers. "PlayStation's entire 2011 so far has been marred by a single issue: hacking," he wrote. "Sony has now allowed the issue to affect its entire audience: it has been forced to deny millions of PSN users a key PlayStation feature over a global holiday."
Garrett referred to speculation that hackers might have compromised personal information for Sony to have taken the serious step of closing PSN for five days. PSN has an estimated 75 million users worldwide, many of whom have credit card information registered with the service.
"Sony's escalation of its war on hacking could potentially threaten not only Sony's ability to cut content deals, but, in a nightmare scenario, may compromise personal information of its millions of users. Sony must demonstrate it is capable of dealing with this situation right now. If these episodes become regular in any way, PSN's users, core or not, will lose faith in its brand and gravitate elsewhere."
Author: dfgdfg,
Categories:
PlayStation,
Sony
Subscribe to:
Posts (Atom)











