Showing posts sorted by relevance for query Sony. Sort by date Show all posts
Showing posts sorted by relevance for query Sony. Sort by date Show all posts

Amazon cloud service blamed for Sony hacking



An anonymous source claims the person who hacked into Sony’s Playstation network did so using Amazon’s cloud computing servers. If true, it would suggest previous warnings of the potential for misuse were very much valid.
An unnamed Bloomberg source says the Sony hacker carried out the attack using Amazon’s EC2 service which, unlike more basic forms of cloud computing that are mainly for storage or document editing, allows users to carry out the data processing of their choice on a pay-per-use basis.
Sensibly enough, the hacker is said to have used a bogus name to set up the EC2 account and has since disabled the account. Amazon — which can probably expect a visit from the FBI if the story is true — does have measures to keep track of who uses its services, such as requiring a valid phone number and credit card. There are ways round both of those checks, though it would require a little more determination.
It’s not just the potential for anonymity that can make cloud computing services attractive, however. Back in January a German security consultant said he’d been able to use EC2 to successfully break a wireless password in 20 minutes and that he believed he could cut that to six minutes. That’s not just an issue of saving time, but also money: with Amazon’s pricing structure, a six-minute attack could cost under $2.
If EC2 was indeed used in the Sony attack, it’s clearly going to have been a slightly more sophisticated technique than a brute force attack on a wireless password (in effect, guessing every possible answer, usually starting with dictionary words.) But the basic principle remains the same: using cloud computing allows access to intensive processing without the hardware costs.
Amazon has previously noted that its acceptable use policy bars customers using EC2 for unauthorized hacking, though it isn’t clear if or how it attempts to stop such behavior.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Three million PS3 users in danger of fraud


Gaming giant Sony has confirmed subscribers’ card details have been stolen in the world’s biggest online hacking.
Following the revelation that 77 million subscriber accounts on Sony’s PS3 network had been hacked into, three million Brits are now vulnerable to being victims of identity fraud scams.
Customers should keep a close eye on their account for any unusual activity
The data stolen by the hackers includes names, postal addresses (including postcode, city and country), dates of birth, online IDs, email addresses, online passwords and other log-in details.
Sony has confirmed that all credit card data on its systems was stored in encrypted form, which should limit its usefulness for financial fraud.
However, other user data, such as passwords and address details, was stored in plain text, and will be open to use by “phishers” and spammers.
Although it took Sony a week to admit the colossal breach of online security, bank industry body Financial Fraud Action UK (FFA UK) has issued an urgent alert to victims.
“There’s no need for customers to contact their bank or card company at this stage,” said a FFA UK spokesman.
“However, customers should continue to do what they should normally be doing: checking their statement and keeping a close eye on their account for any unusual activity. If they spot any, they should contact their bank or card company.”
One of the major worries for UK PS3 subscribers is that many customers use the same passwords for their PlayStation account as they do for other financial accounts. FFA UK recommends they should change these passwords as soon as possible.
Victims of hacking have also been warned to watch out for spam emails - “phishing” attacks - which are targeted attempts to acquire confidential information.
Phishers send out emails that look like a genuine communication from the recipient’s credit card company or bank, with the request they fill in an online form with personal information.
This information can then be used to open accounts in the victim's name, such as mobile phone contracts or utility services, or used to apply for credit cards and loans.
Fraudsters can also open bank accounts, apply for state benefits, order goods in someone else's name and obtain genuine legal documents such as passports, driving licences and birth, marriage and death certificates. 

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Security Expert Believes PSN Should Remain Offline



The PSN has been up for a few days now, in most of the world. However, in Japan, the country where Sony calls home, the network has yet to be restored due to governmental blocks in place before it can be separately verified that the new infrastructure is secure. Now at least one security expert in Australia has taken a similar stance.

Bill Caelli, Senior Research Scientist at the Information Security Institute in the Queensland University of Technology, recently spoke with The Australian, a website for the region. He stated that in his opinion the government should have intervened with the restart of the PlayStation Network, to have its new security tested by an outside party. Mr. Caelli begs the question: “Why is it that in the IT industry enterprises certify themselves?” He claims that the average consumer has “no way of assessing the assurances given by the owners of the system themselves.” Australian Privacy Commissioner Timothy Pilgrim stated that an investigation into the incident is currently in progress, and he was also pondering if the commission should seek out more information from Sony.
Have Sony disclosed enough information, or should governments play a more active role in determining if any corporation’s actions are sufficient following a massive data and privacy leak like the one Sony has just gone through? The PSN service is currently up in Australia, but of course we will update you if and when the situation changes.
Roger Thompson, AVG’s Chief Research Officer also recommended holding off inputting your credit card details straight away in an exclusive interview (Part 1, Part 2) with PlayStation LifeStyle during the PSN downtime. 

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

What the PlayStation Network Hack Teaches Us about Cyber Security??



Cyber security is becoming increasingly important as more everyday transactions take place on the Internet.
Sony Computer Entertainment America (SCEA) announced in April that its PlayStation Network (PSN) had been “hacked” and that an unidentified intruder may now possess every bit of personal data ever uploaded by its clients onto its servers.
The list of information includes names, telephone numbers, birth dates, email addresses, personal and billing addresses, credit card numbers, account passwords, PSN passwords and even purchasing data collated and stored by SCEA.
Somewhere between 70 and 100 million PSN clients have been exposed to the security breach, which SCEA chairman Kazuo Hirai said may have been made by the hacker’s collective known as Anonymous, which the chairman said had been initiating denial of service (DDoS) attacks against SCEA since January.
Anonymous is an organization, but it is also a label used by many independent hackers who participate in “hacktivism” in support of Internet freedom and freedom of speech. The organization, however, has denied any involvement in the hack, challenging that its schemes are benign and intended only to raise awareness.
The seriousness of the attack has put the spotlight on the need for increased commercial cybersecurity, and the US government is insisting on more transparency from Sony about how the attack occurred, its practices and its failure to immediately alert its clients upon learning that their personal information may have been compromised. It has also asked several national and foreign government agencies to investigate, including the FBI.
While Sony’s PSN services are now back, clients are wondering what they should be doing. Cybersecurity and criminal justice experts warn that credit cards must be monitored and passwords must be changed.
The problem, they say, is that many people use the same passwords for most or all of their Internet transactions because it makes them easier to remember as the need for more passwords continues to grow. One previous hack revealed that the majority of passwords collected were either “12345” or “password” and that these were likely used interchangeably with other accounts.
Cybersecurity must evolve, but Internet users must also realize the dangers involved with Internet transactions and practice vigilance as well. Ensuring that websites and businesses are legitimate and have cybersecurity measures in place is the first step; protecting oneself by creating difficult and different passwords and changing them often is the second step, and just as important as the first, as the attack on Sony has proven.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

LulzSec said: "Hack Attacks Will Continue Until Group Caught"



In a catch-me-if-you-can explanation of why it has targeted the likes of Sony, the U.S. Senate, an FBI affiliate, and online porn sites, the LulzSec hacking group says it plans to keep having fun until it gets caught. A statement the group has posted says going public with user personal details after a hack attack is better than keeping exploits private. It gives users a chance to change their passwords, the group says. Such public releases are also arguably good for websites too. After the group published 26,000 emails and passwords stolen from porn sites last week, Facebook automatically locked every account linked to the email addresses, stopping the kind of unauthorized access LulzSec discusses. LulzSec says its hack attacks will continue until "we're brought to justice, which we might well be." The group's statement amounts to a manifesto and is surprisingly more erudite than might be expected. "We're attracted to fast-changing scenarios, we can't stand repetitiveness," the group says. "Nobody is truly causing the Internet to slip one way or the other, it's an inevitable outcome for us humans." And not everything the group has done has appeared malicious. Although ithacked into the British health system computers, it declined to cause damage or publish details, instead warning admins that the system was insecure.
The group denies it's locked in a hacker war with similar group Anonymous. This had been suggested after LulzSec targeted the 4Chan website with a denial of service attack following attempts by 4Chan users to expose members of LulzSec.
LulzSec members were considered righteous vigilantes by some sectors of the Internet after their repeated attacks against Sony, which were carried out in response to Sony's hounding of PS3 hardware hacker George Hotz. However, support has been waning after the group targeted non-Sony game servers this week. Perhaps surprisingly, in the statement the group attempts to distance itself from these attacks, pointing out they were done "by the request of callers [to its telephone request line], not by our own choice".  

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Lulzsec Member Recursion Might Have to Face 15 Years of Imprisonment

The FBI has arrested a member of the LulzSec hacking group over its attacks on Sony Pictures earlier this year. Cody Kretsinger, who goes by the name ‘Recursion', was arrested during a raid on his home in home in Arizona. Kretsinger has been charged with conspiracy and the unauthorized impairment of a protected computer, and faces a statutory maximum sentence of 15 years in prison.
An FBI statement alleges that Kretsinger was involved in the hack on Sony Pictures, and the distribution of information stolen from the company. The statement said that he posted the stolen information on the LulzSec site, and announced the attack via Twitter. He is also alleged to have erased the hard drive of the computer used to attack Sony, in a bid to avoid detection. Four other raids were conducted looking for members of Anonymous, which has loose affiliations with LulzSec.
LulzSec embarked on a string of high profile attacks between May and July this year, targeting the US Senate, the CIA, the NHS, and Sony, but the group claimed to have disbanded.


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Microsoft Said, Our Security is Stronger than Sony & RSA, also We are not Vulnerable to DDoS


Microsoft's John Howie claims Microsoft security is stronger than Sony and RSA which were hacked due to "rookie mistakes." The software giant also released Volume 10 of its Security Intelligence Report.

Uh-oh. There's nothing quite like throwing down the gauntlet and virtually taunting hackers to prove a proud boast is false. In what some attackers might consider a dare,  John Howie, Microsoft's senior director in the Online Services Security & Compliance (OSSC) team, basically claimed that Microsoft sites are unhackable and can't be DDoSed.
According to Microsoft, "rookie mistakes" by Sony and security firm RSA caused the corporations to be brought down by hackers. Howie told Computing News that Sony was coded badly and failed to patch its servers. "These are rookie mistakes," Howie said.  In regards to the breach at RSA, Howie stated, "RSA got hacked because someone got socially engineered and opened a dodgy email attachment. A rookie mistake."
Howie added, "At Microsoft we have robust mechanisms to ensure we don't have unpatched servers. We have training for staff so they know how to be secure and be wise to social engineering. We have massively overbuilt our internet capacity, this protects us against DoS attacks. We won't notice until the data column gets to 2GB/s, and even then we won't sweat until it reaches 5GB/s. Even then we have edge protection to shun addresses that we suspect of being malicious."
In other Microsoft security news, after analyzing 600 million computers worldwide, Microsoft released Volume 10 of its Security Intelligence Report. It  focuses on malware, software vulnerability disclosures, vulnerability exploits, and related trends. The majority of all vulnerabilities in 2010 were vulnerabilities in applications versus operating systems or web browsers. Exploiting Java vulnerabilities topped the list of exploitation categories over generic HTML/scripting exploits, operating system exploits, and document exploits. Adobe Acrobat and Reader accounted for the highest number of document format exploits. Windows 7 and Windows Server 2008 R2 had the lowest operating system infection rate for both client and server platforms. 64-bit versions of Windows 7 which "appeal to a more technically savvy audience than their 32-bit counterparts" have the lowest infection rates.
In regard to malicious websites, phishers targeted gaming sites in the first half of 2010 but then targeted social networks. Yet the "number of active sites targeting gaming sites remained relatively high during the second half of the year, which suggests that more campaigns may be coming."
According to the SIR [PDF] Global Threat Assessment graph below, in the 4th quarter of 2010, the most common threat in the USA  was miscellaneous Trojans which affected 38.6% of all cleaned computers. This was down from 43.8% in the 3rd quarter. The second most common threat was Adware which affected 28.3% of all cleaned computers and was up from 23% in the third quarter. "Miscellaneous Potentially Unwanted Software" was the third most common threat in the U.S. and affected 24.6% of cleaned computers. The MSRT detected malware on 11.6 of every 1,000 computers scanned in U.S. in 4Q10 giving the States "a CCM score of 11.6, compared to the 4Q10 average worldwide CCM of 8.7."

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

FBI says it is "reviewing" PSN security breach


FBI says it is "reviewing" PSN security breach
The Federal Bureau of Investigation (FBI) is currently "reviewing" a recent security breach that compromised user data and downed the PlayStation Network (PSN) for over a week.
"The FBI is aware of the reports concerning the alleged intrusion into the Sony on line game server and we have been in contact with Sony concerning this matter," special agent Darrell Foxworth told Kotaku.
"We are presently reviewing the available information in an effort to determine the facts and circumstances concerning this alleged criminal activity."
Meanwhile, at least two dozen state AG's have kicked off their own investigation of the incident, with the FTC confirming it could theoretically claim jurisdiction in a case that involved loss of customer data via a securitybreach. 


"The fact that sensitive information was apparently accessed without authorization makes me especially concerned about the possibility of financial fraud and targeted phishing scams," Connecticut Attorney General George Jepsen wrote in an official letter to SCE CEO Jack Tretton.
"What is more troubling is Sony's apparent failure to promptly and adequately notify affected individuals of this large-scale breach."
As expected, a number of other countries aside from the United States have expressed concern over the embarrassing and damaging security lapse.
For example, the city of Taipei (Taiwan) is apparently demanding that Sony provide satisfactory details about the leak within 10 days or face heavy fines for alleged breaches of local consumer protection laws. 
"Manufacturers and service providers should take responsibility for their customers' reasonable expectations of security, including personal information security," Taiwan capital's Law and Regulation Commission said in a letter obtained by PC World.
"This incident [is said to] involve leaks of consumer names, e-mails, birth dates and even credit card information."


Indeed, security researchers say stolen credit card information may already be up for sale on various Internet forums.
"The hackers that hacked PSN are selling off the DB. They reportedly have 2.2 million credits cards with CVVs," Trend Micro security expert Kevin Stevens claimed in a tweet.
"Supposedly the hackers selling the DB says it has: fname, lnam, address, zip, country, phone, email, password, dob, ccnum, CVV2, exp date... It is not a rumor, it was a conversation on a criminal forum. [Still], I never saw the DB so I can't verify if it is real."

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Nintendo Servers Hacked, Next target XBOX


Nintendo reports that a Web server for its U.S. unit was hacked. The attack on Nintendo shows that this new era of hacking isn't going to end any time soon, and should serve as a wakeup call for other companies that were hoping this was purely a Sony issue. To be fair, the Nintendo incident is nothing compared to the Sony debacle. It's like comparing the United States "invasion" of Grenada, with the United States bombing Hiroshima and Nagasaki. While Sony has been hacked repeatedly for the past month--compromising sensitive information from more than 100 million user accounts in the process, the Nintendo hack appears to have yielded a simple server configuration file, and not exposed any sensitive data.
Hackers continue to take down networks for hacktivism bragging rights. The current plague of hacks and network takedowns is not limited to game console vendors, nor is it limited to one hacking collective. LulzSec is dominating headlines right now after attacking PBS, the FBI, hacker magazine 2600, and now Nintendo, but there are other groups out there as well--like the notorious Anonymous.
2600 seems to have nailed it on the head when it tweeted, "Hacked websites, corporate infiltration/scandal, IRC wars, new hacker groups making global headlines - the 1990s are back!"
Yes. That seems to sum things up. Granted, the vast majority of these attacks are driven by "hacktivism"--a pseudo-noble attempt to stand up for an issue and make a statement. But, there is a fine, fine line between that "Robin Hood complex" vigilantism, and just being a cyber thug.
The problem with hacktivism is that there are hackers representing both sides. While hacker groups battle it out online for bragging rights, innocent users are caught in the crossfire. I can sympathize with some of the hacktivist causes, but regardless of my opinion of Sony, or any other organization, I can't condone or support exposing sensitive information of users, or even interrupting services that those users have paid for and enjoy using.
While malware has evolved from script kiddies in search of bragging rights to organized crime in search of money, hacktivism is bringing back the "Wild West" days of the Internet. The thing is, hacktivism is just hacking--it's easy to rationalize by making it about trying to stand up for an issue or make some sort of statement, but really the only statement it makes is "look how great I am--I got in to your network."
The days of "All Your Base Are Belong to Us" are back. Watch your back Xbox Live, you're probably next as some group attempts to "outdo" LulzSec.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

After the PSN Phenomena Microsoft decides to be nice to hackers



Software giant, Microsoft has decided that Sony's get tough plans with hackers did not work and probably resulted in getting the Japanese outfit into more hot water. Instead, the cuddly Vole has decided that nurturing hackers, so that they love Microsoft, is a much better plan. Microsoft's General Manager in Ireland Paul Rellis revealed that the company had learned from Sony's heavy-handed response to the PS3 hacking and the subsequent network-wide outages that followed. Instead of doing a Sony and taking a 14-year old boy from Dublin, who attempted to break into the Xbox LIVE network, to the cleaners it is going to nuture his talents instead. The boy was responsible for an alert when Microsoft detected the intrusion and feared that personal information may have been compromised. Rellis revealed  that the Microsoft was working with the teenager to develop his talent and help him use his skills for legitimate purposes. This is more likely to get a positive response from the hacker community than Sony's public attempts to shut down and prosecute hackers like GeoHot and the Fail0verflow group for their part in bypassing the PS3's security measures.
Unfortunately, Rellis did not indicate what Vole was doing with the boy from Tallaght, or what they plan to do with him once his training is finished. A cynic would wonder if the boy has been sent to the Volehill never to be seen again.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Top 5 DDoS Attacks of 2011, Exclusive Report By Corero Network Security

Corero Network Security (cns:LN), the leader in on-premises Distributed Denial of Service (DDoS) Defense Systems for enterprises, data centers and hosting providers, named its list of 2011's Top 5 DDoS attacks. Corero's findings show an increase in newer, intelligent application-layer DDoS attacks that are extremely difficult to identify "in the cloud," and often go undetected until it is too late. Corero also found an uptick in attacks against corporations by "hactivists" DDoS-ing sites for political and ideological motives, rather than financial gain. Attacks against Mastercard, Visa, Sony, PayPal and the CIA top Corero's list.
"The cat-and-mouse game between IT administrators, criminals and hactivists has intensified in 2011 as the number of application-layer DDoS attacks has exploded. Coupled with an increase in political and ideological hactivism, companies have to be extremely diligent in identifying and combating attempts to disable their websites, steal proprietary information and to deface their web applications, " said Mike Paquette, chief strategy officer, Corero Network Security.

Corero's 2011 Top 5 DDoS Attacks:-

1. Anonymous DDoS Attacks on WikiLeaks "Censors" Visa, MasterCard and PayPal. The most significant DDoS attack so far this year, the WikiLeaks-related DDoS attacks on Visa, MasterCard and PayPal were both Anonymous' "coming out" party, and the first widespread example of what has been dubbed "cyber rioting" on the Internet, with virtual passersby joining in the attack voluntarily.

2. Sony PlayStation Network DDoS. A shocking wake-up call for many gamers, customers and investors, the Sony Playstation Network DDoS attack began a series of cyber attacks and data breaches that damaged Sony financially and hurt its reputation.

3. CIA and SOCA Hit by LulzSec DDoS Attacks. The appearance of LulzSec on the cyber attack scene, highlighted by bold DDoS attacks on the CIA and the U.K. Serious Organised Crime Agency (SOCA), made us wonder if anyone was safe on the Internet.

4. WordPress DDoS. A massive DDoS attack disrupted one of the world's largest blog hosts--some 18 million websites. The huge attack hit the company's data centers with tens of millions of packets per second.

5. Hong Kong Stock Exchange. This DDoS attack had a major impact on the financial world, disrupting stock market trading in Hong Kong. This was a highly leveraged DDoS attack, potentially affecting hundreds of companies and individuals through a single target.

For all the pain and suffering DDoS attacks have caused, there are a number of best practices that companies can implement to reduce their risk. The most effective defense against DDoS attacks requires expert preparation of defensive resources, ongoing vigilance and a rapid, organized response.

-News Source (Corero Network Security)


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Sony Pakistan Hacked By Optik Fiber (Team Openfire)


Sony Pakistan Hacked By Optik Fiber of Team Openfire also known as Indian Cyber Force. The hacker group hacked the Database of Sony Pakistan and exposed  admin credentials and so on.
Websites:-
http://sonycenter.com.pk/

Here are some exposure submitted by Team Openfire:-

INFECTED FILE : CATEGORY.PHP
ADMIN USERNAME :- admin                                       
PASSWORD :- pa$$word

For More Information Click Here



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Kaz Hirai said Anonymous not behind current PSN outage

Kaz Hirai
Yesterday at PSN news conference Sony’s deputy president Kaz Hirai confirmed that infamous hacker group "Anonymous" are not behind the current PSN outage.

At a press conference a Japanese reported quizzed Hirai if there were any links between PSN outage and Anonymous, to this Hirai replied that the group known for targetting Sony was not at all responsible for current attack.


In the past Anonymous also confirmed that they are not behind the current PSN outage issue faced by PS3 owners, this means that their planned attack on Sony is still on.
But now the question is if it's not Anonymous then Who?

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Sony database has been compromised by lionaneesh



Sony database has been compromised by lionaneesh


link : http://www.sony.com2.us






DB Version :  MySQL>=5
Data Base:      avtest_db01
Tables :        member , admin etc..


Some of the hacked Accounts :-
uname           passw                           question                                answer
jame    f891bab5f1816a5bb288e705c40c5504        What is your favorite food?
            yourfather
adminope        2b792dabb4328a140caef066322c49ff        What is your birthday?          15
mam_avvalue     e10adc3949ba59abbe56e057f20f883e        What is your favorite
food?    walkman
mravvalue       699fbafe7fd7000fd84e443d5748bca8        What is your birthday?          120411


ryuchroplast    06372f0aa7f1659445861cf2085e0e9e        What is your birthday?          310584

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Australia is Planning new Law on PSN hacking



The Australian government is planning a law in the wake of Sony's PSN hacking disaster. The new ruling is designed to force companies to disclose any privacy breaches to the public. 1,560,791 Australian accounts were caught in the mess, and officials in the country are pissed. 
Privacy minister Brendan O'Connor has publicly criticized Sony, saying it was "very concerned" about the way in which the situation was handled. However, he added that other companies have been doing a bad job of protecting customer data, and everybody needs to tighten their security. 
Sony insists it didn't know that details were compromised before it made the problem public, but that hasn't stopped politicians from getting pissed. Clearly, a lot of people still want answers. 

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Anonymous hacked by one of its own


Infamous hacktivist group Anonymous has been hacked by one of its own. In a message posted to the AnonOps.in site, the group claimed a former member organised the attack, taking over its AnonOps.ru and .net communications sites and publishing names and IP addresses of users online.
After receiving media attention worldwide when Sony claimed it was unwittingly involved in hacking the PlayStation Network, it seems Anonymous now has its own crisis to deal with.
"We regret to inform you today that our network has been compromised by a former IRC-operator and fellow helper named 'Ryan'," the group claimed.
The hacker brigade strongly advised users to stay clear of the AnonOps network and added: "He decided that he didn't like the leaderless command structure that AnonOps Network Admins use. So he organised a coup d'etat."
After stealing the IP addresses of hundreds of the message board's users, the mysterious Ryan reportedly launched denial-of-service attacks against AnonOps.ru and AnonOps.net, the platforms that provide communications for the group. It is where hundreds of supporters have collaborated when they brought sites such as PayPal and Bank of America offline, and commanded the cyber attacks in support of WikiLeakslast year.
Anonymous is still under attack. Going to AnonOps.net diverts to a page with the title 'LOL ANONOPS DEAD' followed by some rather unpleasant language.
Despite repeatedly denying responsibility for the hack, Anonymous has been in the spotlight since the Chairman of Sony Computer Entertainment, Kazuo Hirai, wrote to US authorities suggesting the group played a role in Sony's massive data breach.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

NASA, Sony, Adidas, SPIKE TV & Few Other Govt Websites Are Vulnerable - Said "TeamHav0k"

NASA, Sony, Adidas, SPIKE TV & Few Other Govt Websites Are Vulnerable - Said "TeamHav0k"
Newly formed hacker group named "TeamHav0k" continues their Operation XSS #OPXSS. Like earlier they have found cross site scripting vulnerability in many high profile websites. This time NASA, adidas Official Store, SPIKE TV Official Site, Brighton& Hove City council,  Air Accident Investigation Branch [Govt of UK], Portal and Information Services of Tocantins [Govt of Brazil] became the victim. In a pastebin release the hacker group claimed that using the vulnerabilities an attacker can perform cookie stealing, XSS & XSSF Tunneling and such nasty things. Which indeed can create serious harm for those vulnerable sites. They have also found redirection vulnerability on the official website of Sony Global Headquarters later it was patched. 
Earlier TeamHav0k figure out XSS vulnerability in the official site Huffingtonpost, EA, IGN, NYTimes & many other. 




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

PSN returns to Asia



The PlayStation Network and Qriocity Services have been restored across Asia, Sony has announced.
The platform was restored in countries including Taiwan, Singapore, Malaysia, Indonesia and Thailand with increased security measures yesterday. In addition to the new safeguards, the platform holder has appointed a chief information security officer at Sony Network Entertainment inc, charged with reinforcing security across the firm's infrastructure, Examiner reports.
Sony president Kaz Harai said: "I'd also like to send my sincere regret to customers in Japan and Asian countries and regions for the inconvenience these events have caused you. We are taking aggressive action including increasing security measures and working with respective authorities to address the concerns that were raised by this incident. "We are making consumer data protection a full-time, company wide commitment so that our customers can rest assured about enjoying their entertainment."
PSN functionality was partially restored in Europe and North America on May 15. The PlayStation Store is expected to return at the end of the month. 

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Full Story of Hacking Anonymous IRC Server





War rages between competing factions within the hacker collective Anonymous after this weekend's drama-filled takeover of the main Anonymous IRC server network. That network, used by Anons to plan and conduct attacks, was taken over by one of its own, an IRC moderator known as "Ryan."
His attack has sparked a debate over the "leadership" of Anonymous.

Hacking the hackers:-

The main Internet chat servers used by Anonymous have been run by a group called "AnonOps," which provides communications platforms for the group. Pointing IRC clients at anonops.ru or anonops.net would connect anyone to the servers, where they could then join channels like "#OpSony" and participate in various Anon activities.
Though Anonymous is often described as leaderless, factions like AnonOps by necessity have a loose structure; servers must be paid for, domain names must be registered, chat channels must have at least some moderation. Ryan was one of those IRC mods, and this weekend he proceeded with an attack that seized control of the AnonOps servers away from the small cabal of leaders who ran it.
Those leaders include people with handles like "shitstorm," "Nerdo," "blergh," "Power2All," and "Owen"—and if you're paying attention, you'll remember that HBGary Federal's Aaron Barr had fingered Owen as one of three "leaders" of all Anons.
The most popular channel on the old IRC servers now says simply, "anonops dead go home." Ryan also put up a set of chat logs showing Owen and others reacting to the weekend's massive denial of service attacks against AnonOps that culminated in the server takeover. (In the transcript below, "doom" is one of the AnonOps servers.)

Owen -> SmilingDevil: we lost a numbe rof servers last night
SmilingDevil -> owen: :P we need some more security.
t forcved level3 to stop anno
Owen -> SmilingDevil: dude Owen -> SmilingDevil: iuning a /24 Owen -> SmilingDevil: it was in the gbps range
vil -> owen: gigabit or gigabyte? Owen -> Smili
Owen -> SmilingDevil: doom alone got hit with 1 gb SmilingD engDevil: all leafs went down Owen -> SmilingDevil: add it all up Owen -> SmilingDevil: yeah huge
ly they know about Owen -> SmilingDevil: um thats called the hub Owe
SmilingDevil -> owen: :P we need a hidden irc server for the admins. SmilingDevil -> owen: that o nn -> SmilingDevil: :) SmilingDevil -> owen: did they take that too? Owen -> SmilingDevil: but anyhow
Owen -> SmilingDevil: we suffered alot of damage
The "old" leaders released a statement this morning explaining what happened over the weekend and why IRC remained down:
We regret to inform you today that our network has been compromised by a former IRC-operator and fellow helper named "Ryan". He decided that he didn't like the leaderless command structure that AnonOps Network Admins use. So he organized a coup d'etat, with his "friends" at skidsr.us . Using the networks service bot "Zalgo" he scavenged the IP's and passwords of all the network servers (including the hub) and then systematically aimed denial of service attacks at them (which is why the network has been unstable for the past week). Unfortunately he has control of the domain names AnonOps.ru (and possibly AnonOps.net, we don't know at this stage) so we are unable to continue using them.
Not everyone buys the explanation. One Anon pointed out that the Zalgo bot in question is controlled by a user named "E," not by Ryan.
Second, Zalgo can only see chan msgs and msgs to zalgo. The net staff is saying (pretty much) Ryan used Zalgo to steal server passwords (false, I know server protocol) which were tranfered in channels in plain text for the to see (true).
Third: Take everything AnonOps says with a grain of salt. They're putting out lies and not telling the whole story.
Others pointed out that E and Ryan are friends and that E was actually recommended as an op by Ryan.
However it happened, the end result was that Ryan redirected some of the AnonOps domain names he had control over, he led an attack on the IRC servers with denial of service data floods, and he grabbed (and then published) the non-obfuscated IP addresses of everyone connected to the IRC servers. Ryan apparently also gained root access to the Zalgo network services bot, which is presumably how he harvested the non-obfuscated IP addresses, though it's not clear exactly what Zalgo did or how much access it provided Ryan.

Clashing factions

Ryan is associated with 808chan, a 4chan splinter site and apparent home of the recent denial of service attacks on AnonOps. Ryan is "DDoSing everything that he doesn't own with his band of raiders from 808chan," says one Anon.
The 808 brigade apparently valued big botnets, and made users prove their abilities before letting them participate. AnonOps had a more democratic ethos; anyone could show up, configure the Low Orbit Ion Cannon attack tool, and start firing at Sony or others.
"It's an open network where everyone, mostly newfags can join and not have to prove they're able to wield a botnet and can just join a channel of their choosing, fire up LOIC and hit some organization for reasons they believe are right," said one Anon.
Ryan's control of AnonOps extends to some of the actual domain names, including AnonOps.ru. This wasn't a hack; he was actually given administrative control over the domains some time ago by AnonOps leaders.
One Anon explained the reason for this, saying: "As for the domains, they were transferred to Ryan after some of us got vanned so he can keep the network up. What he did certainly wasn't the plan." (Getting "vanned" refers to getting picked up by the police.)
According to another Anon, the current fight was precipitated when Ryan's IRC credential were revoked. "You morons don't realize Ryan IS LEGALLY THE OWNER OF DOMAINS," he wrote. "Nerdo and Owen removed Ryan's oper, Ryan took domains."

Smoky back rooms?

Among Anons arguing over what happened this weekend, the key debate involves the issue of leaders. Anonymous also said it was leaderless and memberless, but is it? The AnonOps statement above claims that Ryan was angry at the "leaderless" structure of the group and wanted to set himself up as king; again, though, not everyone is so sure.
Owen, for instance, helps to shape the conversation and planning in IRC. One Anon complained privately to me that Owen has booted him from the IRC servers—and thus from the place where all the real work against Sony was taking place several weeks ago. "Owen has not only told me that he doesn't really give a shit about freedom of speech, he's also moderately against the action that's being taken on Sony," this Anon said.
Owen and others conduct some of their work in private, invite-only channels, which leads some Anons to suspect that the really important operations and hack attempts are only discussed in a virtual back room. As one Anon put it yesterday:
"Have you ever been in one of their invite-only chats? This is no bullshit. EVERYTHING is decided on them, the eventual course of the operation, the hivemind's target, the channel's topic, everything. Why all this secrecy? These invite-only chats have NO reason to exist. You want to keep out trolls? Turn on mute, and give voice to a few. At least we can see what is being written."
Others were even angrier. A former AnonOps member wrote:
From the fucking beginning (during the hack at Aiplex which started Operation Payback) there has been an secret club, an aristocracy in AnonOps, deciding how operations will play out in invite-only channels.
It's obvious, for they control the topic, the hivemind, the guides, every single thing behind the scenes.
I don't know if the Owen's current bureaucracy is to be trusted, or Ryan's new delegation (from 808chan!) is.
What I do know is that AnonOps no longer has a good reason to exist. The insane amount of power the channel operators wield, and the reputations gained by their NAMES, causes them to become dictator-like, as "power corrupts".
Why did we leave the comforts of the womb of anonymous imageboards, and end up in name-fagging circlejerks controlled only by a few? Why?
Anonymous, this is bullshit. Neither side, neither Ryan's coalition of hackers nor Owen's bureaucracy can be trusted.
Others argued against this equivalence. "Ryan was the dictator, not the one who decided to solve the dictator problem," said one. Another responded, "Lol, how do you know? For all you know, Owen and Ryan are just the classic generals duking out to take over."
For his part, Ryan told the UK's Thinq today that he shared the concerns over private decision making. Owen and the other leaders "crossed the barrier, involving themselves in a leadership role," Ryan said. "There is a hierarchy. All the power, all the DDoS—it's in that [private] channel."
But among those who backed AnonOps, one thing was clear: Ryan needs to get got. Anons quickly embarked on a mission to find Ryan "dox," and quickly unearthed what they said was his full name, his home address (in Wickford, Essex, UK), his phone number, his Skype handle, and his age (17).
On Twitter, some Anons began spreading the word that Ryan had "betrayed" Anonymous, and that he had done so "to mess up all after having stolen PSN credit cards." No evidence for this last assertion was provided.
As the old AnonOps team attempted to get a handle on what had happened—and after they switched to an Indian domain name—they expressed irritation with early media mentions ("fail reporting") of the attack.
"Some 'mainstream' media is calling this the 'insider threat,'" they wrote, "which isn't really a fair representation, AnonOps doesn't have any corporate secrets, its run by the people for the people on a basis of mutual trust. Drama happens almost 24/7, occasionally drama overspills the network.
"Also we must remind the press AnonOps DOES NOT EQUAL Anonymous, saying they are one and/or the same thing in a blog/article just makes you look stupid. AnonOps is just a IRC network and a few other services that ANYONE can use, its not the only place Anonymous gather, and unlikely to be the *last* (see Streisand effect)."
But will the AnonOps leaders ever gather on a forum they don't control? Ryan took great delight in posting the following alleged comment from Owen to another AnonOps leader: "yo odnt honestly think we're goign to some other irc where we have no control do you?"
Of course, Anonymous has always been about drama and "the lulz," so the current confusion may not even bother them that much; this is just par for the course. But it's certainly amusing to others.
"Lmao. You fucking twits can't even keep your shit safe," wrote someone watching the debacle. "This literally made me laugh out loud. Not lol, but laugh. You all are so stupid."
Click here To see the Dump of Anon Ops Chat 

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Related Posts Plugin for WordPress, Blogger...