Showing posts with label Sony PlayStation Network hacked again. Show all posts
Showing posts with label Sony PlayStation Network hacked again. Show all posts

Tuesday, July 5, 2011

Anonymous suspects arrested in Italian police raids


Italian police are the latest to make arrests in connection to hacking collective Anonymous, according to reports from the country today.
anonymous
32 dawn raids were carried out, including one across the border in the Swiss region of Ticino. Following the raids, three people including one minor were arrested.
The raids follow police action in Spain last month, which saw another three suspects arrested in connection with the hack which brought down Sony’s Playstation Network for several weeks. It’s unclear if the Italian arrests relate to the same incident or not, but police are reportedly claiming to have grabbed an alleged “ringleader” going by the nickname of Frey – an Italian 26 year-old living in Switzerland.
TechEye reports a statement from Italian police, which downplays Anonymous’ hacking skills.
Out of all of the current hacker groups, Anonymous is the largest, but is also populated by the least technical people. Some of its members carry out attacks using software downloaded from the Internet and do not carry out the most basic attempts to secure their IP address.
We’re expecting more details of the arrests to emerge throughout the day and we’ll update this story as and when we hear more.

Source: The Next Web

Tuesday, May 24, 2011

Sony hacked again as attackers target Sony Music Japan

Sony hacked again as attackers target Sony Music Japan. This is getting tiresome.

Just when you couldn’t imagine it getting any worse for Sony, a new wave of attacks have been levelled on the Sony Music Japan website, exposing databases using SQL injection techniques.

NakedSecurity reports that the highlighted databases do not contain sensitive information, with no names, passwords or personally identifiable information thought to have been exposed in the attacks.

However, the attackers, who mock Sony with a note stating “This isn’t a 1337 h4x0r, we just want to embarass Sony some more”, do note that two other databases on the site are vulnerable but it is not known whether they contain sensitive information. Lulz Security takes claim for the breach, the same hackers that targeted Fox.com earlier in the month.

It’s been a tough month for Sony, which first saw its PlayStation Network brought down for weeks after hackers stole sensitive information hosted on the platform. Soon after that, it emerged that a phishing site was found on Sony’s Thailand portal before it attackers managed to breach the company’s Greek website using a similar SQL injection attack.

Sony is reported to have lost $171 million as a result of attacks on its gaming platform, but its reputation could suffer more than its bank balance if events continue to play out as they currently are.


Source: The Next Web

Wednesday, May 18, 2011

Sony PlayStation Network hacked again, user passwords compromised !

With Sony's PlayStation Network freshly back online, attackers have once again breached the system, this time going for a vulnerability with the system's password reset.

This is getting (more) ridiculous. Not even two days after Sony restored its embattled PlayStation Network for most users worldwide, cyber criminals have once again launched an attack, this time going after the PSN’s password reset system. In order for users to reconnect to the PSN, they were required to reset their passwords. You know, for security reasons…

undefined


News of this third, most recent attack were originally reported on Nyleveia.com, which warned PSN users that “accounts are still not safe.”

“I want to make this clear to ALL PSN users. Despite the methods currently employed to force a password change when you first reconnect to the PlayStation network, your accounts still remain unsafe,” writes Nyleveia. “A new hack is currently doing the rounds in dark corners of the internet that allows the attacker the ability to change your password using only your account’s email and date of birth. It has been proven to me through direct demonstration on a test account, so I am without any shadow of a doubt that this is real.”

Following the Nyleveia post there was, in fact, some doubt that this was real. But further tests by Eurogamer proved that the breach was real, which caused prompt action from Sony. In response, the company has blocked PSN login access to a number of its site, and the PSN password reset site has also been taken offline.

Sony responded to the new attack, saying: “Unfortunately this also means that those who are still trying to change their password via Playstation.com or Qriocity.com will be unable to do so for the time being.”

“This is due to essential maintenance and at present it is unclear how long this will take,” Sony added. “In the meantime you will still be able to sign into PSN via your PlayStation 3 and PSP devices to connect to game services and view Trophy/Friends information.”

Fortunately, this round of breaches isn’t actually a “hack” in the true sense of the word — at least not if you want to be a stickler about it. The previous attacks on the PSN were true hacks in that someone broke into Sony’s network, and stole nearly 13 million credit cards, and the personal data of about 100 million people. This time, they just used some of the data that was already stolen to break into people’s accounts. Big difference, we know.

Still, this proven vulnerability is sure to give Sony more grief. Just yesterday, Sony CEO Howard Stringer defended his company’s handling of the April attacks, which resulted in the being turned off for a week before users were alerted to the data theft.

On Monday, Sony released the details of its user “Welcome Back” program, which includes free games, like ModNation Racers and Killzone Liberation, and free movie rentals. Perhaps this most recent breach will prompt them to toss in a few more options, just to keep users happy. Just a suggestion.

Source: The Hacker News