Showing posts with label Sony. Show all posts
Showing posts with label Sony. Show all posts

Tuesday, July 5, 2011

Anonymous suspects arrested in Italian police raids


Italian police are the latest to make arrests in connection to hacking collective Anonymous, according to reports from the country today.
anonymous
32 dawn raids were carried out, including one across the border in the Swiss region of Ticino. Following the raids, three people including one minor were arrested.
The raids follow police action in Spain last month, which saw another three suspects arrested in connection with the hack which brought down Sony’s Playstation Network for several weeks. It’s unclear if the Italian arrests relate to the same incident or not, but police are reportedly claiming to have grabbed an alleged “ringleader” going by the nickname of Frey – an Italian 26 year-old living in Switzerland.
TechEye reports a statement from Italian police, which downplays Anonymous’ hacking skills.
Out of all of the current hacker groups, Anonymous is the largest, but is also populated by the least technical people. Some of its members carry out attacks using software downloaded from the Internet and do not carry out the most basic attempts to secure their IP address.
We’re expecting more details of the arrests to emerge throughout the day and we’ll update this story as and when we hear more.

Source: The Next Web

Sony seemingly hacked yet again, Irish music site vandalized


Sony appears to have fallen victim to yet another hack, with its Irish music website bearing the brunt this time.
The Sony Music Ireland site was this morning displaying three news stories claiming that; two members of band The Script had died, Rebecca Black had married R Kelly and that scientists had proven X-Factor contestants were stupid. The prank follows on from a spate of hacks the Japan-based electronics and media giant has suffered in the past three months.
The website URL is currently redirecting to Sony Music Ireland’s Facebook page, although Google’s cache still holds the rogue version of the site.  The Irish Times reports that Sony Music Ireland is refusing to comment on the incident, except to say that the stories published were false. No-one has yet claimed responsibility for this latest attack, which feasibly could alternatively have been an ‘inside job’ by a disgruntled employee.
It comes just a day after a Fox News Twitter account was hijacked to falsely report the death of the US president.

Source: The Next Web

Tuesday, May 24, 2011

Sony hacked again as attackers target Sony Music Japan

Sony hacked again as attackers target Sony Music Japan. This is getting tiresome.

Just when you couldn’t imagine it getting any worse for Sony, a new wave of attacks have been levelled on the Sony Music Japan website, exposing databases using SQL injection techniques.

NakedSecurity reports that the highlighted databases do not contain sensitive information, with no names, passwords or personally identifiable information thought to have been exposed in the attacks.

However, the attackers, who mock Sony with a note stating “This isn’t a 1337 h4x0r, we just want to embarass Sony some more”, do note that two other databases on the site are vulnerable but it is not known whether they contain sensitive information. Lulz Security takes claim for the breach, the same hackers that targeted Fox.com earlier in the month.

It’s been a tough month for Sony, which first saw its PlayStation Network brought down for weeks after hackers stole sensitive information hosted on the platform. Soon after that, it emerged that a phishing site was found on Sony’s Thailand portal before it attackers managed to breach the company’s Greek website using a similar SQL injection attack.

Sony is reported to have lost $171 million as a result of attacks on its gaming platform, but its reputation could suffer more than its bank balance if events continue to play out as they currently are.


Source: The Next Web

Wednesday, May 18, 2011

Sony PlayStation Network hacked again, user passwords compromised !

With Sony's PlayStation Network freshly back online, attackers have once again breached the system, this time going for a vulnerability with the system's password reset.

This is getting (more) ridiculous. Not even two days after Sony restored its embattled PlayStation Network for most users worldwide, cyber criminals have once again launched an attack, this time going after the PSN’s password reset system. In order for users to reconnect to the PSN, they were required to reset their passwords. You know, for security reasons…

undefined


News of this third, most recent attack were originally reported on Nyleveia.com, which warned PSN users that “accounts are still not safe.”

“I want to make this clear to ALL PSN users. Despite the methods currently employed to force a password change when you first reconnect to the PlayStation network, your accounts still remain unsafe,” writes Nyleveia. “A new hack is currently doing the rounds in dark corners of the internet that allows the attacker the ability to change your password using only your account’s email and date of birth. It has been proven to me through direct demonstration on a test account, so I am without any shadow of a doubt that this is real.”

Following the Nyleveia post there was, in fact, some doubt that this was real. But further tests by Eurogamer proved that the breach was real, which caused prompt action from Sony. In response, the company has blocked PSN login access to a number of its site, and the PSN password reset site has also been taken offline.

Sony responded to the new attack, saying: “Unfortunately this also means that those who are still trying to change their password via Playstation.com or Qriocity.com will be unable to do so for the time being.”

“This is due to essential maintenance and at present it is unclear how long this will take,” Sony added. “In the meantime you will still be able to sign into PSN via your PlayStation 3 and PSP devices to connect to game services and view Trophy/Friends information.”

Fortunately, this round of breaches isn’t actually a “hack” in the true sense of the word — at least not if you want to be a stickler about it. The previous attacks on the PSN were true hacks in that someone broke into Sony’s network, and stole nearly 13 million credit cards, and the personal data of about 100 million people. This time, they just used some of the data that was already stolen to break into people’s accounts. Big difference, we know.

Still, this proven vulnerability is sure to give Sony more grief. Just yesterday, Sony CEO Howard Stringer defended his company’s handling of the April attacks, which resulted in the being turned off for a week before users were alerted to the data theft.

On Monday, Sony released the details of its user “Welcome Back” program, which includes free games, like ModNation Racers and Killzone Liberation, and free movie rentals. Perhaps this most recent breach will prompt them to toss in a few more options, just to keep users happy. Just a suggestion.

Source: The Hacker News

Sunday, May 1, 2011

Sony to Resume PlayStation Network Services, Says “No Evidence” Credit Card Info Stolen

Sony will resume some PlayStation Network services and beef up its security nearly two weeks after a hacker attack forced Sony to shut it down.
undefinedThe company made the announcements during a press conference in Tokyo. Kaz Hirai, Sony’s executive deputy president and the likely successor to CEO Howard Stringer, started by offering “our deepest and sincerest apologies” for the outage of the PlayStation network, as well as apologizing to customers whose personal information has been compromised. Hirai and two other Sony executives bowed deeply, a Japanese custom for apologizing.

Hirai confirmed that lots of users account information was stolen as the result of a hacker attack that has forced Sony to shut down PSN and Qriocity services for the last two weeks. Sony says that it was first alerted to the attack on April 20 and has been working with authorities and two security firms to investigate.

“This criminal act against our network had a significant impact not only on our consumers but our entire industry,” Hirai said. “These illegal attacks obviously highlight the widespread problem with cyber-security.”

The big question though is whether or not credit card data was stolen, a possibility that has raised questions from the U.S. Congress. Hirai and two other Sony executives repeatedly asserted that they have found “no evidence” that credit card data or billing information has been stolen. Hirai wouldn’t rule out the possibility, however, which likely explains why Sony is asking customers to check their credit card statements just in case.

To prevent an attack like this one from happening again, Sony says it has moved PSN and Qrioicity services to a new data center and implemented new security measures, including additional firewalls, enhanced encryption and automated software monitoring. The company has also created a new position: Chief Information Security Officer, a senior executive who will report to Sony Chief Information Officer Shinji Hasejima. In addition, Sony will require all users to change their passwords, but with additional security measures to verify identity.

Sony says it will resume some PlayStation Network services in the next week as a result. This includes restoration of online gameplay, Qriocity music services, friend lists, chat functionality and movie rental services. It is also launching a “Welcome Back” campaign as an apology to users for what has transpired. Sony is offering affected users a 30-day subscription to PlayStation Plus and some free software downloads. Qriocity customers will be receiving 30 additional days of service for free.

Source: mashable

Sunday, April 3, 2011

Anonymous takes down Sony Pictures US and UK sites !

Anonymous successfully taken down http://www.sonypictures.com/ and http://www.sonypictures.co.uk


The Sony PS3 console was "hacked" or more appropriately, jail broken, by iPhone hacker, Geohot. Anonymous managed to reverse engineer his own PlayStation 3 to run home brew applications on it.And then later released the method to the public, through his site, geohot.com



Sony hit Anonymous with a lawsuit and demanded social media sites, including YouTube to hand over IP addresses of people who visited Geohot's social pages/videos.Pay pal have granted access to Sony for them to view Geohot's Pay Pal account. The judge of the case has given permission to Sony to view the IP addresses of everyone who visited geohot.com Sony are also after another group of hackers for the same case.

The PS3 hack which GeoHot released can be compared to the "unlocking" of a phone. i.e. Once you purchase the phone, it's yours, you can do whatever it is you want with it.