The display of security incompetence Sony
Corp. (6758) is
astonishing. Weeks after losing the contents of its two largest databases
PlayStation Network (PSN) database and the Sony
Online Entertainment (SOE) database -- the company appears to have
lost yet more information after
experiencing an attack almost identical to one just days prior.
I. Sony Fails to Block Identical Attack
On Sunday, The Hacker News revealed
that Sony BMG Greece (the Greek unit of the company's music branch) was hacked
using an SQL injection attack and lost 8,000+ customer records.
It now appears that just days
later a group called LulzSecurity -- known for formerly hacking FOX.com's
login database -- has used an injection attack to compromise
databases on Sony BMG Japan.
Astonishingly, Sony appears to have done little to
nothing in the way of escaping or parameterization to protect its databases,
even in the wake of the SQL injection breach of its Greek property.
The hackers accessed an on-site tablet that did
not appear to contain any personally identifiable information. They
openly mocked Sony, posting to
Twitter, "LOL @Sony, Nice Japanese website dumbasses (sic)."
They later posted, "This isn't a l337 h4x0r,
we just want to embarrass Sony some more. Can this be hack number 8? 7
and a half?!"
While the hack itself was obviously just designed
to target Sony and not hurt its customers, the hackers did post publicly that
there was two other databases on the site that they did not look at, but should
be accessible using the injection attack.
This message was likely up for hours -- at least
-- before Sony heard about it and shut down access to its servers. In the
meantime it's very feasible that other users -- including outright malicious
ones -- could have stolen information from these tables. As tables on the
Sony BMG Greece website contained users' names, passwords, etc. it's quite
possible that one of these tables held similar information, and you can almost
guarantee that there would be many more records than in the Greece table, as
Japan is Sony's home nation.
II. Sony Intrusion Send Clear Message to
Customers -- You Can't Trust Sony
Sophos Security researcher Chester Wisniewski , who yesterday took a gentler tone when covering the Greece intrusion, this time firmly admonished Sony, writing:
While there is an enormous target on Sony's back as a result of these very public attacks it is unclear why this is happening. Is Sony taking security seriously or are there simply so many flaws from the past that exist in their public facing sites that it will take them a long time to patch them all?I hope this is the last time I have to report on a flaw at Sony. Sony has announced they are working with several professional organizations to get their security house in order and for their sake I hope this happens sooner rather than later.
While there is an enormous target on Sony's back as a result of these very public attacks it is unclear why this is happening. Is Sony taking security seriously or are there simply so many flaws from the past that exist in their public facing sites that it will take them a long time to patch them all?
I hope this is the last time I have to report on a flaw at Sony. Sony has announced they are working with several professional organizations to get their security house in order and for their sake I hope this happens sooner rather than later.
quote: The sad thing is that probably a lot of these fortune 500 companies have just as bad security practices or possibly worse. Are they using this as a wake up call to fix their security. Its doubtful.
quote: Just days later it now appears that just days later a group called LulzSecurity
quote: It'd be hard enough to track down a couple hackers attacking your firm -- good luck if the entire hacking community decides to rain fire down upon you.
quote: Game over.
quote: after all the people bought and paid for the consoles so there should be no restrictions on what software can be used on there.
quote: It's a console. If you want to run ANYTHING on it you want with no restrictions, get a PC. Sony's only obligation is to make sure you have a fully working console. You make it seem like they told people they could no longer play games on it or something or broke key functionality.
quote: Oh please. Firmware updates routinely break functionality in devices. Hell my first Intel SSD was broken because of the TRIM firmware.If every company who made buggy firmware deserved to be hacked and shut down, we wouldn't have many tech companies left.
quote: When Sony tried to lock its most tech-savvy customers out of legitimately using products
quote: He writes: props to fail0verflow for the asymmetric half no donate link, just use this info wisely i do not condone piracy if you want your next console to be secure, get in touch with me. any of you 3. it'd be fun to be on the other side....and this is a real self, hello world although it's not NPDRM, so it won't run off the hard drive shouts to the guys who did PSL1GHT without you, I couldn't release this
quote: The Xbox 360's DRM protections were cracked some time ago. Microsoft has worked to ban modded consoles from online play, though, so don't be surprise if SCEI resorts to similar measures.
quote: Sorry...stupid should hurt. And Sony is a stupid as they come.
quote: Maybe now people will start to understand the price of hacking and why the only good hacker is very dead?
quote: Bill Gates, Steve Jobs and other tech visionaries got their start in the hacking scene of their day.
quote: They openly mocked Sony, openly,