Showing posts sorted by date for query PlayStation. Sort by relevance Show all posts
Showing posts sorted by date for query PlayStation. Sort by relevance Show all posts

Sony Hacked Again, 1 Million User Data Compromised


A group of hackers that recently gained notoriety for hacking PBS.org’s home page with an image of NyanCat, announced Thursday that it has stolen data from Sony. It’s yet another in a seemingly endless string of embarrassing security incidents for the company, but what’s shocking is just how exposed the data was to begin with.
In a press release posted to their Web site, LulzSec claims to have broken into SonyPictures.com and “compromised over 1,000,000 users’ personal information, including passwords, email addresses, home addresses, dates of birth, and all Sony opt-in data associated with their accounts.”
The theft included 75,000 “music codes” and 3.5 million “music coupons,” according to the group. LulzSec has posted segments of data they claim to have taken from Sony’s server to serve as proof of their accomplishment.
There are two astonishing twists to this story - one is that LulzSec was apparently able to access the information fairly easily, using what they describe as “a very simple SQL injection, one of the most primitive and common vulnerabilities.” Secondly, “every bit of data we took wasn’t encrypted. Sony stored over 1,000,000 passwords of its customers in plaintext, which means it’s just a matter of taking it. This is disgraceful and insecure: they were asking for it.”
If true, it’s devastating news for Sony, which is just getting back on its feet after shutting down access to its PlayStation Network and Sony Online Entertainment servers after hackers made off with personal information on more than 100 million user accounts.
The PlayStation Network, which controls PlayStation 3 and PlayStation Portable users’ ability to connect to one another to play online games, was down for more than three weeks through the last half of April and first half of May as Sony struggled to secure the system.
And only in the past 24 hours has Sony brought back its PlayStation Store, which serves as a way for PS3 and PSP users to download games and content for their systems.
Sony hasn’t even yet initiated its “Welcome Back” package for consumers affected by the PSN blackout - a collection of about $100 worth of games and content, as well as access to the company’s premium “PlayStation Plus” service.
SonyPictures.com isn’t directly related to the PlayStation 3 or PlayStation Network - it’s Sony’s consumer-facing Internet site for information on their movies, television and home entertainment offerings on Blu-Ray Disc and other formats. But Sony’s many Web sites and servers have been on the receiving end of security probes and hack attacks for some time, exacerbated by the company’s legal proceedings against George “Geohot” Hotz, a programmer who sought to “jailbreak” or enable the PlayStation 3 console to support Linux operating system software - a feature Sony once supported itself, but later removed in a firmware update. Since the widely-publicized outage of the PlayStation Network, hackers have stepped up their attempts to break into Sony’s systems.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Young Hacker been Approached Diplomatically To Avoid Backlash by Microsoft




Sony’s recent nightmarish experiences with hackers has made Microsoft rethink their policies regarding how to engage with hackers. If we are to believe the words of Microsoft Corp.’s Ireland General Manager Paul Rellis, his company has learned a valuable lesson from the recent assault on Sony’s worldwide network, and has decided to approach hackers more diplomatically, TechEye reports. 
Apparently a 14-year-old Irish boy was caught trying to break into the Xbox LIVE network, but instead of prosecuting him, Microsoft has decided to help him become a better coder. Microsoft hopes that by helping the young hacker he will become a productive, white-hat hacker in the future instead of an online trouble-maker, and that they company will earn some respect from the hacker community in the process. 

Sony's problems began when they prosecuted the hacker Geohot for jailbreaking the PlayStation 3. Jailbreaking a device allows users to run their own code and, while it is controversial, its legality is still a matter of dispute.
Sony's harsh reaction to an activity that most online hackers consider relatively harmless brought about the attacks that have cost Sony more than $100 million in damages according to their own reports.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

PSN returns to Asia



The PlayStation Network and Qriocity Services have been restored across Asia, Sony has announced.
The platform was restored in countries including Taiwan, Singapore, Malaysia, Indonesia and Thailand with increased security measures yesterday. In addition to the new safeguards, the platform holder has appointed a chief information security officer at Sony Network Entertainment inc, charged with reinforcing security across the firm's infrastructure, Examiner reports.
Sony president Kaz Harai said: "I'd also like to send my sincere regret to customers in Japan and Asian countries and regions for the inconvenience these events have caused you. We are taking aggressive action including increasing security measures and working with respective authorities to address the concerns that were raised by this incident. "We are making consumer data protection a full-time, company wide commitment so that our customers can rest assured about enjoying their entertainment."
PSN functionality was partially restored in Europe and North America on May 15. The PlayStation Store is expected to return at the end of the month. 

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Sony's website in 13 countries been hit by hackers




Sony Corp bounced from two-month lows after the electronics conglomerate said this year's operating profit would match last year's, easing worries about the impact of the March earthquake. In its first estimate for the year to March 2012, Sony said operating profit would come in around 200 billion yen (USD 2.44 billion), prompting Macquarie to upgrade its rating on the stock to outperform from neutral. Morgan Stanley, Credit Suisse and UBS reiterated their overweight, buy or outperform ratings. Separately, Sony said on Tuesday websites in three countries were hacked and personal information for 8,500 people were leaked from its Greek Sony Music Entertainment website, in the latest of a series of security breaches. The company said all three sites had been taken down and that no credit card information had been registered. Analysts said Sony had provided markets with a realistic view of the impact of the quake and a PlayStation network hacking incident, both of which had weighed on the shares. Sony said it expects the quake and the hacking incident to drag down operating profit by 164 billion yen in the current financial year. In contrast, the decline in Sony's market capitalisation of 264 billion yen since the quake "looks overdone," Macquarie analyst Jeff Loff wrote in a report. "With shares cheap and cost impacts one-time in nature, we expect the stock to reverse its fall." Sony expects to report a net loss of 260 billion yen (USD 3.2 billion) for the year ended March 31, its third straight annual net loss, after writing of tax credits following Japan's earthquake and tsunami.
Many of Sony's rivals, including Panasonic Corp, have yet to issue forecasts for the current year due to uncertainty following the disaster. Shares in Sony, the maker of PlayStation video games and Vaio computers, were up 2.4% by 0340 GMT, outperforming a flat Tokyo electrical machinery subindex . Sony's shares dipped nearly 1% in early trade, to its lowest since the immediate aftermath of the earthquake. Some fund managers however said the shares, down 22% so far this year, might not see sharp gains. "I agree that shares are unlikely to keep sliding, but neither do I see any new catalysts that would bring the share price up. I expect shares to continue meandering back and forth at low levels," said Makoto Kikuchi, chief executive officer at Myojo Asset Management. "It's not just Sony. Panasonic, Sharp -- all Japanese home electronics makers have seen the base of their share price sink. They can't compete in prices, so the only route they have is to create new markets with high added value. Products that would make people pay more." "Sony used to have this ability. But I don't see anything that would make share prices rise this fiscal year." Sony has seen a series of hacking attacks that have exposed more than 100 million accounts on its online gaming network to possible data theft, casting doubt on Sony's bid to reinvent itself through its online business. The company cut its annual net earnings forecast for the year ended March 31 to a loss of 260 billion yen from its previous estimate of a profit of 70 billion yen. Credit Suisse analyst Shunsuke Tsuchiya said shares in Sony were close to bottoming out and Morgan Stanley's Masahiro Ono said the announcement cleared uncertainty and was a positive. Sony has been largely squeezed out of the portable music market by Apple Inc's iPod, while losing market share to Samsung Electronics in flat-screen TVs. Sony, which had developed but scrapped products that could be said to predate both the iPod and iPad, is set to announce its full results on Thursday.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Anonymous is attacking US Chamber of Commerce website






In protest of the "PROTECT IP" bill, hacker group Anonymous plans to attack the US Chamber of Commerce website Monday evening. Hacktivist group Anonymous plans to launch attack the US Chamber of Commerce website today at 8pm EST, according to a flier posted to 4chan.org and Reddit.com, which urges Internet users to join in the fight. The distributed denial of service (DDoS) campaign is an act of protest against a piece of supposed anti-piracy legislation proposed by Sen. Patrick Leahy (D-VT) known as the “Preventing Real Online Threats to Economic Creativity and Theft of Intellectual Property” bill, or “PROTECT IP.” Anonymous, known for its campaigns against both corporations and governments around the world who the group believes stifle the free flow of information, argues that, if passed, PROTECT IP “would allow the US Government to force [Internet service providers] and search engines to censor websites they do not like under the guise of ‘copyright protection.’” The online protest was first announced Sunday in a statement released by the group, which reads:
“As pioneers of this new world, it’s our duty to resist and fight those who attempt to stop us. Whether you’re a journalist or blogger, or a participant of Anonymous, or the activists on the ground who protest against these corporate thugs and oppressive regimes and risk everything for freedom of information and speech, we are all in this battle together and we have a responsibility to protect our civil liberties.
“This attack tomorrow will send yet another message to the pigs that run the state that we will not be another cog in the f****d up clock that these corporate entities attempt to preserve through their political puppets in Washington.
“This is our world now and we will fight for it. Take it or leave it.” 
The PROTECT IP bill, a reiteration of the failed COICA bill, would give the US Justice Department broad powers to shut down access to websites it deems “dedicated to infringing activities.” As Anonymous accurately describes, these powers include forcing ISPs to block access to targeted websites, and even requiring search engines, like Google and Bing, to completely remove the websites from their search indexes. Perhaps even more troubling, the bill would also give private citizens — i.e. copyright holders — the ability to request that the government block a websites’ ability to display advertising, or process payments. Anonymous says that, rather than reduce piracy, the bill simply “endangers the free flow of information,” through the use of “domain seizures, ISP blockades, search engine censorship, and the restriction of funding to accused websites,” says Anonymous. All of this, they say, “takes Internet censorship to the next level.” The hacker’s interpretation of the bill, a summary of which leaked online last week, is echoed by a variety of other privacy advocates, who say the legislation is woefully misguided, and will result in rampant government censorship. “Protecting copyright and trademark are of course important objectives,” writes author and technology expert Larry Downes in an analysis of the bill posted to CNet. “But doing so by trampling due process rights, tinkering dangerously with the mechanics of the Internet, and impressing into police duties an expanding set of Internet service providers, hardly seems the best solution.” Anonymous first came into the world spotlight after launching a series of similar attacks on the corporate websites of PayPal, Master Card and Visa, all of which stopped processing donation payments made to whistle blowing website WikiLeaks. Most recently, members of the group were accused by Sony of initiating (or, at least, facilitating) an attack on its PlayStation Network, which resulted in the theft of nearly 13 million user credit cards, and could cost the company upwards of $170 million in damages. Those who wish to join in the DDoS attack — which simply overloads a website’s servers with an overwhelming amount of traffic, causing it to go offline — can join other Anons in the #OperationPayback IRC channel, where countless supporters have gathered to coordinate the attack. 


Anonymous Message on IP ACT






To read a full summary of PROTECT IP  CLICK HERE

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Phishing site found on Sony’s servers.


Okay, okay. Sony has had a lot to deal with of late, what with its Playstation network being hacked and subsequently being taken offline for quite some time. But we believe that Sony has been hacked yet again, this time its Sony Thailand’s website.
As security firm f-secure reports, Sony Thailand’s hdworld.sony.co.th URL has a phishing site running on it, leading to an Italian credit card company.
SonyThailandHack
As you can see, visiting the site on Google Chrome reveals a blatant warning that the site is in fact a phishing scam:

The phishing site is in fact  a sub-domain of Sony Thailand’s website, and it’s possible the hackers either have access to Sony Thailand’s DNS record or there could be a redirect in place on the servers itself, but we can’t be sure. We’ll update this as more information comes in and once we’ve spoken to a security consultant to learn how this could actually be possible.
Update
Okay, we’ve now spoken with Jobert Abma, an online security consultant from Online24. When asked how common this is, he said:
“It’s not as common as other vulnerabilities such as ‘usual’ web issues like data injection. But, when having mayor issues like file access, the success rate of such an attack becomes much higher.”
When asked how phishers actually carried out these hacks, Abma stated that the hackers simply looked for weaknesses in the application or infrastrucutre:
“It can be done through, for example, having file access. To grant such access, weaknesses in the application or infrastructure need to be found. As application issues, you’d mention database access to write files, including remote scripts, able to execute commands on the server and so on. As for weaknesses in an infrastructure, weak passwords or buffer overflows in software could be used to grant access.”
Following on from our chat with Jobert Abma, we spoke with Mikko H. Hyppönen from f-secure – the firm that found this latest hack. Hyppönen came across the site while investigating potential Playstation phishing scams. After confirming it was definitely a hack, Hyppönen gave his thoughts on how access was gained:
“If you have a large site with lots of legacy apps and mini-sites, it’s not unheard of for something like this to happen. In Sony’s case, it’s likely its a PHP or SQL hole rather than DNS access or  htaccess edit on the server itself.”
Hyppönen also stated that this doesn’t necessarily mean that Sony.co.th or Sony.com got hacked, because the sub-domain in question may run on an external party’s server:
“I believe this particular site might run on some ad agency’s IP address. Nevertheless, it’s under Sony’s name, so technically, it’s Sony’s server.”
But it’s not just Sony that will suffer from this. It’s likely that part of the scam will involve spamming people with .it (Italy) email addresses whilst this phishing site is still live. And the hope for the scammers, of course, is they’ll hit someone who does hold the credit card in question.
So, not a good few weeks for Sony at all.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Sony disables PSN web login system after new exploit is discovered



Sony just can’t seem to stave off negative headlines these days.  Just 5 days after PSN services started to be restored throughout the world another nasty exploit has been uncovered allowing hackers to change your PSN account password.  The exploit was discovered by Nylevia last night and confirmed quickly by NeoGAF.
It was found that the web based password reset system on sites like Playstation.com and Qriocity.com will allow someone to change any account password if they know two simple pieces of information; the email address associated with the account, and the date of birth of the account holder, you know, the information that was stolen in late April when hackers first breached the PSN.  On the plus side you’ll get an email informing you that your password was reset.
Sony responded to these reports by taking down all PSN web based login systems.  Right now Sony has given no estimated time for this issue to be fixed.  The only thing Sony is saying is that PSN services won’t be impacted by this downtime.

“Unfortunately this also means that those who are still trying to change their password via Playstation.com or Qriocity.com will be unable to do so for the time being,” said Sony. “This is due to essential maintenance and at present it is unclear how long this will take. In the meantime you will still be able to sign into PSN via your PlayStation 3 and PSP devices to connect to game services and view Trophy/Friends information.”


While it is positive that these troubles won’t impact PSN services it is uncomfortable, to say the least, that Sony is continuing to have issues with their online security.  This has gotten so bad that Nylevia is recommending to maintain a separate email address specifically for use with PlayStation services.  The very idea of maintaining an email address for one account is absurd but it really seems necessary at this point.
This new issue has effectively killed much of the positive momentum Sony has been building since they started bringing PSN services back online last week.  With the Electronic Entertainment Expo (E3) only a few weeks away, Sony is putting themselves in the position where much of their press conference during the event will have to address these various security issues.  Sony is effectively going into one of the largest industry events of the year in damage control mode instead of creating consumer excitement for future products and games.
Hopefully Sony can address security concerns and strengthen all parts of their network against future attacks. Despite their efforts to improve overall network security they are one company who many will never again trust with their personal and credit card information.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

PSN Network Password Recovery Exploited




Patrick Seybold, Sr. Direct of Corporate Communications and Social Media, has released a statement on the PlayStation.Blog regarding this situation. Seybold clarifies, it was not a “hack”, but a URL exploit that Sony has now fixed. See the full statement (and original article) after the jump.
Here’s the official statement:
We temporarily took down the PSN and Qriocity password reset page. Contrary to some reports, there was no hack involved. In the process of resetting of passwords there was a URL exploit that we have subsequently fixed.
Consumers who haven’t reset their passwords for PSN are still encouraged to do so directly on their PS3. Otherwise, they can continue to do so via the website as soon as we bring that site back up.
[Original Article] The Password Recovery program that has been implemented by Sony since the PSN’s return has been moving along nicely. With such a huge influx of people requesting their information through their secure email connection, as opposed to on a PS3, Sony stated that the process would take a little longer than originally estimated. It may be even longer now. While the hack that shut down the PSN was quite “sophisticated,” a small little exploit seems to have been discovered to change the passwords again.
But if you’re worried that your PS3 will go silent once again, fret not. This password exploit seems to only be affecting various web-based Sony services. An official community moderator on the EU PlayStation forums have indicated that several sites are offline, including PlayStation.com, the forums, the Blog, Qriocity.com, and others. The login functions for these services are currently unavailable. For the time being all PlayStation Network activity is still online for PS3 and PSP users. So you don’t have to worry about that. But what DID happen?
If you wanted to reset your PSN password from your computer, you were sent an email with a unique URL to match your account. The entire process is actually fairly primitive. Note that it won’t work right now, as login services are offline.
The prodecure is as follows:
1) Navigate to : https://store.playstation.com/accounts/reset/resetPassword.action?token (this is normally, via email, https://store.playstation.com/accounts/reset/resetPassword.action?token=YYYYYYYYYYYYYYYYYYYYYYYY with the y’s being a unique token) – do not enter the code at this point.
2) Open a new tab in firefox, and go to fr.playstation.com (other pages will work too most likely), and click Login (Connexion)
3) Click Recover password
4) Enter the email and date of birth of the target account
5) Click continue, then on the confirmation page, click “Reset using E-mail”
6) Switch back to the original tab, and enter the code, then click continue
7) You will now be asked to enter a new password for the target account
Fortunately, if your account WAS compromised, you should have received an email that said something along the lines of “Thank you for changing your password, if you were unaware of this change please contact Sony,” or something to that effect. While this method is as effective as it is simple, it would take a lot of time to physically access any large number of accounts. It sounds like Sony found out about this and shut off its only access point fairly quickly. Only one more question left:
When will it just end?

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Security Expert Believes PSN Should Remain Offline



The PSN has been up for a few days now, in most of the world. However, in Japan, the country where Sony calls home, the network has yet to be restored due to governmental blocks in place before it can be separately verified that the new infrastructure is secure. Now at least one security expert in Australia has taken a similar stance.

Bill Caelli, Senior Research Scientist at the Information Security Institute in the Queensland University of Technology, recently spoke with The Australian, a website for the region. He stated that in his opinion the government should have intervened with the restart of the PlayStation Network, to have its new security tested by an outside party. Mr. Caelli begs the question: “Why is it that in the IT industry enterprises certify themselves?” He claims that the average consumer has “no way of assessing the assurances given by the owners of the system themselves.” Australian Privacy Commissioner Timothy Pilgrim stated that an investigation into the incident is currently in progress, and he was also pondering if the commission should seek out more information from Sony.
Have Sony disclosed enough information, or should governments play a more active role in determining if any corporation’s actions are sufficient following a massive data and privacy leak like the one Sony has just gone through? The PSN service is currently up in Australia, but of course we will update you if and when the situation changes.
Roger Thompson, AVG’s Chief Research Officer also recommended holding off inputting your credit card details straight away in an exclusive interview (Part 1, Part 2) with PlayStation LifeStyle during the PSN downtime. 

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Amazon cloud service blamed for Sony hacking



An anonymous source claims the person who hacked into Sony’s Playstation network did so using Amazon’s cloud computing servers. If true, it would suggest previous warnings of the potential for misuse were very much valid.
An unnamed Bloomberg source says the Sony hacker carried out the attack using Amazon’s EC2 service which, unlike more basic forms of cloud computing that are mainly for storage or document editing, allows users to carry out the data processing of their choice on a pay-per-use basis.
Sensibly enough, the hacker is said to have used a bogus name to set up the EC2 account and has since disabled the account. Amazon — which can probably expect a visit from the FBI if the story is true — does have measures to keep track of who uses its services, such as requiring a valid phone number and credit card. There are ways round both of those checks, though it would require a little more determination.
It’s not just the potential for anonymity that can make cloud computing services attractive, however. Back in January a German security consultant said he’d been able to use EC2 to successfully break a wireless password in 20 minutes and that he believed he could cut that to six minutes. That’s not just an issue of saving time, but also money: with Amazon’s pricing structure, a six-minute attack could cost under $2.
If EC2 was indeed used in the Sony attack, it’s clearly going to have been a slightly more sophisticated technique than a brute force attack on a wireless password (in effect, guessing every possible answer, usually starting with dictionary words.) But the basic principle remains the same: using cloud computing allows access to intensive processing without the hardware costs.
Amazon has previously noted that its acceptable use policy bars customers using EC2 for unauthorized hacking, though it isn’t clear if or how it attempts to stop such behavior.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

IU experts find flaws in US web protection plan


The White House proposed new cybersecurity legislation Thursday that aimed to protect the country against threats to the national infrastructure and the economy, but it was too small a step, according to IU cybersecurity experts.
Fred Cate, a professor in the Maurer School of Law and the director of the Center for Applied Cybersecurity Research, said cybersecurity attacks are a huge problem in today’s society.
“We live in a data-driven society — almost everything we do generates or uses digital data,” Cate said. “Yet as the president and most everyone else recognizes, those data and the systems that transmit and store them are not secure.”
The proposal focuses on the protection of American citizens, critical infrastructure, government systems and privacy and civil liberties. The legislation includes harsher penalties for cybercriminals and requires the Department of Homeland Security to work with companies in the private sector to identify and address vulnerabilities.
Von Welch, the deputy director of the CACR, thinks the new legislation was a positive step, but not a big enough one.
“My concern is that it isn’t keeping up with advances we’re seeing in cybercrime,” he said.
The administration’s cybersecurity efforts have been focused on new technologies, rather than on creating legal and economic incentives for the private sector to invest in better security, Cate said. This approach hasn’t worked, he said.
“During the past two years we have witnessed massive security breaches involving hundreds of millions of Americans, involving Sony PlayStation, the online marketing firm Epsilon, even the security powerhouse RSA,” Cate said. “According to one study, more than 2,500 companies were victims of one sophisticated cyberattack that exfiltrated proprietary corporate data, and there are thousands of other successful attacks against companies and agencies.”
Cate said that U.S. counterintelligence officials report that 140 foreign intelligence organizations are actively engaged in trying to hack into U.S. government and business networks.
“Without appropriate incentives, industry won’t invest sufficiently in good security,” he said. “It is that simple.”
Welch agrees. Much of what the legislation does is formalize practices already happening, he said.
“For example, federalizing breach notification laws have already been put in place by many states, and explicitly allowing collaboration and information exchange that is already taking place by cybersecurity practitioners.”
Cate and Welch agree that there are some positive parts to the plan. Its focus on critical infrastructure, by mandating core critical infrastructure operators, creates a plan for addressing threats. Having those plans evaluated by third parties is a good step given the importance of critical infrastructure to national security, Welch said.
What’s missing from the plan, Welch said, is a similar push for other parts of the Internet.
“As recent high-profile cases such as Sony and Epsilon have shown, and what seem to be constant problems with privacy on social networking sites, there are other companies operating on the Internet that while perhaps not critical to our national security, still impact millions of people,” he said. “There is nothing in the proposed legislation to really incentivize these companies to improve their cybersecurity and, in turn, our privacy as their users.”
Cate explained how the plan could be improved.
“The plan could include legal requirements for good information security, tax incentives, safe harbor provisions for businesses that try to enhance security even if they fail, liability provisions to allow injured consumers to recover from harms caused by bad security and new enforcement powers and resources for the Federal Trade Commission,” he said.
In addition to calling for new privacy protections, he said the President should appoint the members of the Privacy and Civil Liberties Oversight Board, which Congress created, but the administration has yet to fill.
Cate also said the administration’s plan includes no effort to curtail risky behaviors by businesses themselves.
“The recent discoveries that Google and Apple are both collecting location data on smart phone users and storing that data, unencrypted, in unsecured files suggests that some regulation may be appropriate to protect individuals as well as industry,” he said.
The bottom line? Technology is very important in security, but the administration’s focus on it is only one step towards enhancing information security.
“Technologies are like magic bullets for the government — no matter what the problem, we want to believe that technology can solve it,” Cate said. “Technology alone just isn’t enough — for security or anything else.”

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

What the PlayStation Network Hack Teaches Us about Cyber Security??



Cyber security is becoming increasingly important as more everyday transactions take place on the Internet.
Sony Computer Entertainment America (SCEA) announced in April that its PlayStation Network (PSN) had been “hacked” and that an unidentified intruder may now possess every bit of personal data ever uploaded by its clients onto its servers.
The list of information includes names, telephone numbers, birth dates, email addresses, personal and billing addresses, credit card numbers, account passwords, PSN passwords and even purchasing data collated and stored by SCEA.
Somewhere between 70 and 100 million PSN clients have been exposed to the security breach, which SCEA chairman Kazuo Hirai said may have been made by the hacker’s collective known as Anonymous, which the chairman said had been initiating denial of service (DDoS) attacks against SCEA since January.
Anonymous is an organization, but it is also a label used by many independent hackers who participate in “hacktivism” in support of Internet freedom and freedom of speech. The organization, however, has denied any involvement in the hack, challenging that its schemes are benign and intended only to raise awareness.
The seriousness of the attack has put the spotlight on the need for increased commercial cybersecurity, and the US government is insisting on more transparency from Sony about how the attack occurred, its practices and its failure to immediately alert its clients upon learning that their personal information may have been compromised. It has also asked several national and foreign government agencies to investigate, including the FBI.
While Sony’s PSN services are now back, clients are wondering what they should be doing. Cybersecurity and criminal justice experts warn that credit cards must be monitored and passwords must be changed.
The problem, they say, is that many people use the same passwords for most or all of their Internet transactions because it makes them easier to remember as the need for more passwords continues to grow. One previous hack revealed that the majority of passwords collected were either “12345” or “password” and that these were likely used interchangeably with other accounts.
Cybersecurity must evolve, but Internet users must also realize the dangers involved with Internet transactions and practice vigilance as well. Ensuring that websites and businesses are legitimate and have cybersecurity measures in place is the first step; protecting oneself by creating difficult and different passwords and changing them often is the second step, and just as important as the first, as the attack on Sony has proven.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

PlayStation Network Restored and Qriocity Services Begins


Sony Corporation and Sony Computer Entertainment (SCE) announced that Sony Network Entertainment International (SNEI, the company) will today begin a phased restoration by region of PlayStation®Network and Qriocity Services.  The phased restoration will be on a country by country basis beginning in the Americas, Europe, Australia, New Zealand, and Middle East.

The first phase of restored services for these countries and regions will include:
  • Sign-in for PlayStation®Network and Qriocity services, including the resetting of passwords
  • Restoration of online game-play across PS3 and PSP
  • Playback rental video content, if within rental period, of PlayStation Network Video Delivery Service on PS3, PSP and MediaGo
  • Music Unlimited powered by Qriocity, for current subscribers, on PS3 and PC
  • Access to 3rd party services such as Netflix, Hulu, Vudu and MLB.tv
  • 'Friends' category on PS3, including Friends List, Chat Functionality, Trophy Comparison, etc
  • PlayStation Home

Increased Security Measures
As the result of a criminal cyber attack on the company's data-center located in San Diego, California, U.S.A., SNEI shut down the PlayStation Network and Qriocity services on April 20, in order for the company to undergo an investigation and make enhancements to the overall security of the network infrastructure. Working closely with several respected outside security firms, the company has implemented new and additional security measures that strengthen safeguards against unauthorized activity, and provide consumers with greater protection of their personal information.
The company has made considerable enhancements to the data security, including updating and adding advanced security technologies, additional software monitoring and penetration and vulnerability testing, and increased levels of encryption and additional firewalls.  The company also added a variety of other measures to the network infrastructure including an early-warning system for unusual activity patterns that could signal an attempt to compromise the network.
"I'd like to send my sincere regret for the inconvenience this incident has caused you, and want to thank you all for the kind patience you've shown as we worked through the restoration process," said Kazuo Hirai, Executive Deputy President, Sony Corporation.  "I can't thank you enough for your patience and support during this time. We know even the most loyal customers have been frustrated by this process and are anxious to use their Sony products and services again. We are taking aggressive action at all levels to address the concerns that were raised by this incident, and are making consumer data protection a full-time, company wide commitment."
"During the past 18 months, we've seen a dramatic rise in the volume of cyber attacks, their sophistication and their impact on businesses. Thwarting cyber-crime requires an evolutionary approach to security that is well integrated, reduces risk exposure and improves efficiencies," said Francis deSouza, Senior Vice President, Enterprise Security Group, Symantec. "Today's cyber crime attacks are proving to be more covert, more targeted and better organized than those we've seen in years past. In working with Sony on the move of their data-center, it's clear they're implementing measures to reduce security risks moving forward."  
As an additional measure, Fumiaki Sakai, president of Sony Global Solutions Inc. (SGS), has been appointed acting Chief Information Security Officer of SNEI.  In addition to his current role at SGS, Mr. Sakai, in his role at SNEI, will work to further reinforce overall information security across the company's network infrastructure.  Mr. Sakai will lead the recruiting effort in finding a new and permanent CISO for SNEI.  As CISO, Mr. Sakai will report to Tim Schaaff, president, SNEI, as well as to Mr. Shinji Hasejima, CIO, Sony Corporation.  
"While we understand the importance of getting our services back online, we did not rush to do so at the expense of extensively and aggressively testing our enhanced security measures. Our consumers' safety remains our number one priority," Hirai continued. "We want to assure our customers that their personal information is being protected with some of the best security technologies available today, so that everyone can feel comfortable enjoying all that PlayStation Network and Qriocity services have to offer."  
The restoration of the services across the Americas, Europe, Australia, New Zealand, and Middle East are beginning, and consumers will be able to enjoy some of the online functionality provided by both the PlayStation Network and Qriocity services.  Phased restoration in Japan and other Asian countries and regions will be announced in due course.  The company expects to have the services fully restored by the end of May 2011.  
The company will be offering customers a "Welcome Back" package of services and premium content to all registered PlayStation Network and Qriocity account services.  The details of this program will be announced in each region shortly.  
For more information about the PlayStation Network and Qriocity services intrusion and restoration, please visit http://blog.us.playstation.com or http://blog.eu.playstation.com/


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Thousands of E-Mails, Résumés at Risk After Eidos Hacking


Hackers might have accessed up to 25,000 e-mail addresses and 350 résumés during an attack on game developer Eidos Interactive’s websites, parent company Square Enix said Friday.
The security breach, which Square Enix said occurred Wednesday, could have given hackers access to user data for the Deus Ex: Human Revolution website, as well as résumés submitted by job applicants to Eidos.
“Square Enix can confirm a group of hackers gained access to parts of our Eidosmontreal.com websiteas well as two of our product sites,” the company told Joystiq. “We immediately took the sites offline to assess how this had happened and what had been accessed, then took further measures to increase the security of these and all of our websites, before allowing the sites to go live again.”
Square Enix added that it would be contacting all parties that might have been affected by the breach, emphasizing that no credit card information was compromised.
According to a report by former Washington Post writer Brian Krebs, the official Deus Ex: Human Revolution and Eidos websites were inaccessible Thursday morning. During this period, hackers reportedly put up a banner that read “Owned by Chippy1337.”
The hackers, Krebs wrote, said they plan to distribute the stolen information on file sharing networks. His report pegs the volume of information stolen, according to the hackers, to be the personal information of more than 80,000 users and 9,000 ésumés.
A recent Ars Technica report suggests there might be discord among members of hacking collective Anonymous, centering on a 17-year-old British hacker named Ryan. According to a chat log uncovered by Krebs, the Eidos hackers attempted to frame Ryan for the attack.
It’s unclear whether this is related to the crippling hack on Sony’s PlayStation Network several weeks ago that left millions of users’ personal information at risk. Anonymous has disavowed responsibility for that attack.
Neither Square Enix nor Eidos Interactive responded to Wired.com’s requests for comment Friday.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

The End Of Anonymous: Anonymous Attacks Eachother


It now seems that there is an internal war happening in the ranks of leaderless hacker group ‘Annoymous’ in which a rogue admin had taken control of two key sites that the group uses to coordinate their actions online.
In a message to users posted on AnonOps.in, part of Anonymous’s AnonOps network, admins accused a former comrade of organising a “coup d’etat“.
The name that seems to be comng up is ‘Ryan’, who is now being accused of stealing IP addresses and passwords of users of two ‘Anonymous’ sites. AnonOps.net and AnonOps.ru were attacked by first getting the precious information, and then getting Denial of service (DoS) attacks directed against them.
The sites provide communication within the members of the group through IRC channels and have been used to launch several attacks, they were also key in organising Anonymous activity in support of the uprising in Tunisia and Egypt and Siria.
Some messages have been appearing in hacking websites from anonymous:

‘We regret to inform you today that our network has been compromised by a former IRC-operator and fellow helper named “Ryan”. He decided that he didn’t like the leaderless command structure that AnonOps Network Admins use. So he organised a coup d’etat, with his “friends” at skidsr.us . Using the networks service bot “Zalgo” he scavenged the IP’s and passwords of all the network servers (including the hub) and then systematically aimed denial of service attacks at them.’
‘We would STRONGLY ADVISE all users to STAY AWAY from AnonOps.net and AnonOps.ru, and they should be considered COMPROMISED. Using or connecting to any service on those addresses may put your computer, and by extension your person, at risk’.
These latest developments come after Sony had accused the hacker group to be more than likely (however without providing definite evidence) involved in the data leak that caused the loss of personal and financial information of over 70 million users of the Playstation Network. Please let us know what are your thoughts by leaving a comment below.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Anonymous hacked by one of its own


Infamous hacktivist group Anonymous has been hacked by one of its own. In a message posted to the AnonOps.in site, the group claimed a former member organised the attack, taking over its AnonOps.ru and .net communications sites and publishing names and IP addresses of users online.
After receiving media attention worldwide when Sony claimed it was unwittingly involved in hacking the PlayStation Network, it seems Anonymous now has its own crisis to deal with.
"We regret to inform you today that our network has been compromised by a former IRC-operator and fellow helper named 'Ryan'," the group claimed.
The hacker brigade strongly advised users to stay clear of the AnonOps network and added: "He decided that he didn't like the leaderless command structure that AnonOps Network Admins use. So he organised a coup d'etat."
After stealing the IP addresses of hundreds of the message board's users, the mysterious Ryan reportedly launched denial-of-service attacks against AnonOps.ru and AnonOps.net, the platforms that provide communications for the group. It is where hundreds of supporters have collaborated when they brought sites such as PayPal and Bank of America offline, and commanded the cyber attacks in support of WikiLeakslast year.
Anonymous is still under attack. Going to AnonOps.net diverts to a page with the title 'LOL ANONOPS DEAD' followed by some rather unpleasant language.
Despite repeatedly denying responsibility for the hack, Anonymous has been in the spotlight since the Chairman of Sony Computer Entertainment, Kazuo Hirai, wrote to US authorities suggesting the group played a role in Sony's massive data breach.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Hackers plan third attack on Sony


Hackers are planning a third attack on Sony in retaliation for its handling of the PlayStation Network and Online Entertainment services data breaches, according to US reports.
The attack on Sony's website is planned for this weekend, says a CNet report, citing an unnamed observer of the Internet Relay Chat (IRC) channel used by the hackers.
According to the source, the hackers claim to have access to some of Sony's servers and plan to publish information they are able to copy from those servers.
Although Sony has stopped short of blaming the hacker group known as Anonymous for the latest breaches, it said in a letter to a Congressional hearing that it had found a file named "Anonymous" containing a fragment of the group's slogan, "We are Legion".
Anonymous has a history of denial-of-service attacks against Sony websites in retaliation for Sony's legal action against hacker George Hotz, but the group has denied responsibility.
Anonymous has never been known to have engaged in credit card theft, the group said in a statement.
According to the group, whoever broke into Sony's servers to steal the credit card information and left a document blaming Anonymous clearly wanted Anonymous to be blamed.
"No one who is actually associated with our movement would do something that would prompt a massive law enforcement response. On the other hand, a group of standard online thieves would have every reason to frame Anonymous in order to put law enforcement off the track," the statement says.
In an attempt to tackle criticism for its handling of the breach, Sony has issued a letter to customers in which it blames forensic analysis for delays in notifying customers that their personal data may have been stolen.
The company has also promised to help protect customers from identity theft around the world and offer a "Welcome Back" package, including free subscriptions, once its networks are restored.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

LastPass hacking latest in a string of data breaches


News is emerging that yet another online network may have been hacked, and this time, from a service that acts as a safe-deposit box for users other passwords.
Cloud-based password management company LastPass issued a warning to users late Wednesday advising customers to change their passwords as a precaution to what may be a massive data-breach.
"We're going to be paranoid and assume the worst: that the data we stored in the database was somehow accessed," Joe Siegrist, LastPass CEO said.
"We know roughly the amount of data transferred and that it's big enough to have transferred people's email addresses, the server salt and their salted password hashes from the database."
LastPass is one of the largest cloud-based password management tools on the web. The company serves clients in 113 countries.
It said experts are delving deeper into the breach and will release more details as they emerge.
If the hack is proven, it represents the latest in a series of high-profile data-losses in the past few weeks.
Just last month Sony admitted that its only gaming network, the Playstation Network, was hacked, potentially exposing data of nearly 80 million users. The breach, one of the largest in history, also leaked 10 million credit cards, though the company said those were encrypted.
Also today, for the second month in a row, Best Buy has had to inform customers that their e-mail addresses were stolen.
On April 22, the consumer electronics retailer discovered some e-mail addresses had been exposed in a security breach at a third-party vendor.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Sony blames hacktivist group Anonymous for Playstation Network intrusion


File this one under “things not to do when dealing with massive network outages.” Sony has kicked the hornet’s nest today by blaming Anonymous, a massive network of hackers that regularly takes up activist causes, for indirectly causing a breach of security in its PlayStation Network (PSN) online gaming network that led to the attack that brought PSN down.
While the company isn’t blaming Anonymous for the attack itself, it said the hackers that stole gobs of sensitive data about PSN users were able to break into the network while it was defending itself from denial of service attacks orchestrated by Anonymous. Anonymous took on Sony after the company went after famed PS3 hacker George Hotz, who reverse engineered the PlayStation 3 to run unauthorized programs.
When the PlayStation Network crashed on April 21, Anonymous said it was not behind the attack. Instead, the hacktivist group said, “Sony is incompetent.” But an observer of the IRC forum used by members of Anonymous said the attackers behind this current Sony outage appear to have learned their methods from Anonymous’ activities of two weeks ago.
This really is not the time for Sony to start playing with fire. Anonymous doesn’t regularly respond to blame and threats, but because the network of hackers has taken on Sony before, there is no guarantee Sony’s latest accusation won’t spark some kind of retaliation. Anonymous has proven time and again that it is a force to be reckoned with. Sony has to focus on beefing up its network, not trying to shift blame around and incite more attacks against the already feeble network.
Hackers attacked the PSN on April 19, forcing the Japanese company to bring down the network, which has more than 77 million registered users. The nightmare then continued after hackers broke into the company’s Station.com site, which serves as a host for its PC games like Everquest. Hackers were able to steal information from as many as 24.6 million accounts on that site, according to Sony. In all, more than 100 million accounts might have been compromised.
The PSN breach was a massive security gaffe that has caused the U.S. government to get involved and demand answers — such as who attacked the network and what users were affected. Sony has sent warnings to PSN users about the possible credit card theft. The whole ordeal spawned an apology from Sony that lasted more than an hour and a half.
The network has been down for more than a week, denying 77 million registered gamers the ability to play online games, watch movies, listen to music or download other entertainment to their PlayStation 3 consoles and PlayStation Portable handhelds. The PlayStation Network is a critical service that competes with Microsoft’s Xbox Live online gaming service — as well as other online gaming services. There are also 948 games now available in the PlayStation Network store, as well as 4,000 pieces of add-on content for games.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Related Posts Plugin for WordPress, Blogger...