Showing posts sorted by date for query Sony. Sort by relevance Show all posts
Showing posts sorted by date for query Sony. Sort by relevance Show all posts

PBS Hacked Again



The affected website was for the program "Becoming American." Bentley says a "very small number" of administrative user names and encrypted passwords were stolen.PBS spokeswoman Anne Bentley says one section of a website in the PBS collection of sites was defaced Friday. PBS says its website has been hacked for at least the second time in a month - the latest in a string of intrusions into such sites as Sony, Lockheed Martin, Nintendo and others.  At the end of May, hackers broke into the PBS website and posted a phony story claiming the late rapper Tupac Shakur was alive. A group that claimed responsibility complained about a recent "Frontline" investigation on Wikileaks.Arlington, Va.-based PBS says it has seen an increasing number of intrusion attempts recently. 


Apparently retaliating for a recent Frontline program about WikiLeaks, the group, which calls itself @LulzSec or The Lulz Boat, also disclosed passwords and e-mail addresses held by PBS on the public bulletin board Pastebin.com.Shakur died in a shooting in Las Vegas in 1996. Smalls, whose real name was Christopher George Latore Wallace, was gunned down the following year in a Los Angeles drive-by shooting.By Monday morning, the fake story, which had appeared on The RunDown under the byline PBS WebTech, was gone. But a cached version remains available:"Prominent rapper Tupac has been found alive and well in a small resort in New Zealand, locals report. The small town - unnamed due to security risks - allegedly housed Tupac and Biggie Smalls (another rapper) for several years. One local, David File, recently passed away, leaving evidence and reports of Tupac's visit in a diary, which he requested be shipped to his family in the United States."A hacker group posted a bogus report on the PBS website on Saturday evening that claim slain rappers Tupac Shakur and Biggie Smalls were actually alive and residing in New Zealand.  
According to the Australian publication Secure Business Intelligence, LulzSec had earlier targeted Fox News and the X-Factor television show.
In explaining its motivation, "LulzSec" put out a statement:
"Greetings, Internets. We just finished watching WikiSecrets and were less than impressed. We decided to sail our Lulz Boat over to the PBS servers for further... perusing. As you should know by now, not even that fancy-ass fortress from the third shitty Pirates of the Caribbean movie (first one was better!) can withhold our barrage of chaos and lulz. Anyway, unnecessary sequels aside... wait, actually: second and third Matrix movies sucked too! Anyway, say hello to the insides of the PBS servers, folks. They best watch where they're sailing next time."

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Obama Proposes Anti-Hacking Laws



Hackers will face tougher penalties in the U.S. if the Obama administration's proposed cyber-security measures become law, in an attempt to deter attacks on critical online infrastructure.Under the new law, hackers would face 20 years in prison for endangering national security, 10 years for stealing data and three years for accessing a government computer.
The proposal doubles the penalties from current laws in nearly every category, responding with force to the spate of hacks that have made headlines this last month.The Obama administration first suggested the law last month, before the hacking group LulzSec broke into FBI, CIA and U.S. Senate websites. If prosecuted under the new law, its members could face hefty prison terms for flaunting national security.Compared to the anonymous hacks against Lockheed Martin and the International Monetary Fund, however, LulzSec's distributed denials-of-service, or DDoS, attacks against government websites were merely an annoyance.
Groups like LulzSec, who hack for the fun of it, may face the same sentences as serious data thieves under the cyber-security plan.
Either way, the trouble lies in catching computer hackers who use botnets and server mis-location to cover their tracks. Months after Sony's disastrous data breach left 100 million users' information exposed, Sony and the FBI still haven't found those responsible for the attack.
Tracking down "smoking keyboards" is not impossible, however, as Spain and Turkey proved by arresting members of the Anonymous hacking group. Spain's authorities captured three men accused of intending to publish "sensitive data" about Spanish politicians and policemen. Turkey nabbed 32 Anonymous hackers that had coordinated DDoS attacks against the Turkish government after the country announced plans to restrict Internet services starting this August.
Arresting hackers may deter some from attempting further exploits, but in Anonymous' case the group's loose-knit organization means hundreds of new hackers can rise to fill one member's shoes.
Furthermore, some hackers may have government backing, as IMF officials believe was the case in their hack and as Google alleges happened to them in China.If governments are indeed involved in some of the major recent hacks, things could get sticky, as the Pentagon is set to publish a policy to use physical force against online crime. As one official warned, "If you shut down our power grid, maybe we will put a missile down one of your smokestacks."
The difficulties of catching and prosecuting hackers seem nearly insurmountable. But the new law in the U.S. could encourage a reduction in cybercrimes if it makes an example of even a few.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

19 Years Old Guy get Busted by London Police in Sony Hacking Case


A teenager has been arrested near London in connection with the hacking of Sony, London's Metropolitan Police said Tuesday. The 19-year-old is suspected of hacking into systems and mounting denial of service attacks against "a number of international businesses and intelligence agencies," police said. Naming suspects who have been arrested in Britain is illegal. Sony's PlayStation Network went down on April 20 after what Sony said was a massive data breach. It had more than 70 million subscribers at the time. It began coming back on line in mid-May. The PlayStation Store did not reopen until June 2.

The company estimated the cost of that attack will total $171 million. Hackers later broke into Sony Pictures website, compromising the accounts of over 1 million users, and the gaming company SEGA, stealing nearly 1.3 million users' details via a British subsidiary of the Japanese company. SEGA makes games for PlayStation and other gaming systems. The suspect's computer "will now be examined for ties to any potential group, including LulzSec," a police spokesman told CNN, declining to be named in line with custom. "This link has not been established yet as it is still early days," the spokesman said. The hacker group LulzSec claimed recently to have attacked the CIA website, and took credit for hacking into the website of the American public broadcaster PBS and posting a fake story saying the rapper Tupac Shakur was still alive. He was killed nearly 15 years ago. It's unclear whether LulzSec members played a role in the Sony PlayStation Network breach. But they have posted on their website what they claim is proprietary information from Sony Pictures and other Sony properties' websites. On Friday, on the occasion of their 1,000th tweet, the group posted a manifesto of sorts in which they said people, including their targets and advocates of Internet freedom, should be thankful. "The main anti-LulzSec argument suggests that ... our actions are causing clowns with pens to write new rules for you," the group wrote. "But what if we just hadn't released anything? What if we were silent? That would mean we would be secretly inside FBI affiliates right now, inside PBS, inside Sony... watching... abusing... ."
They seemed to suggest that by making their attacks public, they'll push websites to increase security. They said they're sitting on account information for 200,000 players of the online game Brink, but moments later said that releasing people's information is worth doing sometimes because it's fun. 
"Yes, yes, there's always the argument that releasing everything in full is just as evil, what with accounts being stolen and abused, but welcome to 2011," they wrote. "This is the lulz lizard era, where we do things just because we find it entertaining."
Analysts said the group appears to be some sort of spin-off of "Anonymous," the loose coalition of hackers that grew to prominence through their support of the whistle-blower site WikiLeaks.
But while Anonymous has its own set of moral codes and is largely politically motivated, LulzSec seems to be random.
For every hack like the one on PBS, which the group said came out of anger over a documentary about WikiLeaks, there's the cracking of porn site pron.com -- and a subsequent public list of members' e-mail addresses and passwords.
LulzSec has not yet posted a comment on the arrest of the teen in Essex, outside London, which police said was "intelligence-led."
The suspect was arrested Monday night and police are now examining a "significant amount of material," they said.


The Suspect Details:- 
Name: Mr Ryan Cleary
Alias: viraL
Age: 18-19
Address: 10 South Beech Avenue Wickford SS11 8AH
Phone Number: +447510557265
-NEWS SOURCE (CNN)

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

LulzSec said: "Hack Attacks Will Continue Until Group Caught"



In a catch-me-if-you-can explanation of why it has targeted the likes of Sony, the U.S. Senate, an FBI affiliate, and online porn sites, the LulzSec hacking group says it plans to keep having fun until it gets caught. A statement the group has posted says going public with user personal details after a hack attack is better than keeping exploits private. It gives users a chance to change their passwords, the group says. Such public releases are also arguably good for websites too. After the group published 26,000 emails and passwords stolen from porn sites last week, Facebook automatically locked every account linked to the email addresses, stopping the kind of unauthorized access LulzSec discusses. LulzSec says its hack attacks will continue until "we're brought to justice, which we might well be." The group's statement amounts to a manifesto and is surprisingly more erudite than might be expected. "We're attracted to fast-changing scenarios, we can't stand repetitiveness," the group says. "Nobody is truly causing the Internet to slip one way or the other, it's an inevitable outcome for us humans." And not everything the group has done has appeared malicious. Although ithacked into the British health system computers, it declined to cause damage or publish details, instead warning admins that the system was insecure.
The group denies it's locked in a hacker war with similar group Anonymous. This had been suggested after LulzSec targeted the 4Chan website with a denial of service attack following attempts by 4Chan users to expose members of LulzSec.
LulzSec members were considered righteous vigilantes by some sectors of the Internet after their repeated attacks against Sony, which were carried out in response to Sony's hounding of PS3 hardware hacker George Hotz. However, support has been waning after the group targeted non-Sony game servers this week. Perhaps surprisingly, in the statement the group attempts to distance itself from these attacks, pointing out they were done "by the request of callers [to its telephone request line], not by our own choice".  

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Microsoft gave comment about LulzSec



Microsoft has commented on LulzSec's posting of emails and addresses, some of which may be associated with Xbox Live accounts. Microsoft has sent us this comment on the data, which is an info dump and not a hack.
"This group appears to have posted a list of thousands of potential email addresses and passwords, and encouraged users to try them across various online sites like Xbox LIVE in the event one of the users happens to use the same password and email address combination.  At this time we do not have any evidence Xbox LIVE has been compromised. However we take the security of our service seriously and work on an ongoing basis to improve it against evolving threats."
The group dumped a list of 62,000 emails and passwords on a file sharing site (the list has been taken down multiple times) for accounts of sites and services like Xbox Live, PayPal, WOW, and much more (confirmed on LulzSec's Twitter, even). We've also had one poor reader tell us the credit card attached to his Xbox Live account has already been hit for $100 and the account's password changed.Just to clarify: LulzSec hasn't hacked Xbox Live, they've simply released people's emails and passwords that may pertain to an Xbox Live or PayPal or WOW, etc. account.  Hacker group LulzSec has released emails and passwords for some people's Xbox Live account info, among other sites and services. LulzSec has also been involved in attacks on Nintendo, Minecraft, EVE Online, and (of course) Sony, among others. And for those of you keeping score out there, hactivists Anonymous deal more in denial of service attacks, while exposing user info is one of LulzSec's deals. Whatever the method or rationale, though, it's annoying. 

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

SEGA Hacked



SEGA took the SEGA Pass system offline Thursday. Friday morning, it sent an email to Pass members alerting them that an unauthorized and unidentified third party had gained access to the SEGA Pass database. SEGA Pass, the gaming company’s member database and online network, has been hacked. Members’ email addresses, birth dates and encrypted passwords were obtained in the attack, according to the company. SEGA is also telling members that it has reset their passwords, that all access to SEGA Pass has been temporarily suspended and that Pass users should consider changing their passwords on other sites. No party has stepped up to claim responsibility as of yet, though hacker group LulzSec tweeted at SEGA Friday morning:


 “We want to help you destroy the hackers that attacked you. We love the Dreamcast, these people are going down.” Meanwhile, LulzSec recently claimed responsibility for hacking Sony’s and Nintendo’s servers, taking down the CIA’s website and hacking the U.S. Senate.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

LulzSec Security opens 'request line'



After claiming responsibility for attacking several sites, including the US Central Intelligence Agency, hacker group LulzSec opened its lines to accept hack requests.
Last Tuesday, the group posted a phone number on its Twitter account, as well as ports for online chats, inviting the public to "join the party."

"Call us: 614-LULZSEC (now accepting calls) |


 Join the party: irc.lulzco.org (port 6697 for SSL 


 channel #LulzSec or http://t.co/Sm5wHjd)," 





LulzSec had claimed it hacked the Public Broadcasting Service, an affiliate of the Federal Bureau of Investigation, and Sony. An article on PC World said the group disrupted websites during its "Titanic Takeover Tuesday." 
The PC World article said group's activities Tuesday disrupted the websites for The Escapist and the IT security company Finfisher, as well as the login servers for EVE Online, Minecraft and League of Legends. It said the group claimed to have received 5,000 missed calls and 2,500 voicemails. While the 614 area code represents Columbus, Ohio, "only an irresponsible gambler would wager that that will help authorities locate members of LulzSec in the slightest," "LulzSec is begging to get busted, but also, in a perverse way, 'giving back' to a community that enjoys seeing the flaws of big companies exposed. The ironic twist is that these big companies are made big by the average public whose private information is being revealed in the hacks,"


-News Source PCWorld

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

CITI Group Said that more than 36000 Citi cards was Hacked





Citigroup Inc. has revealed the extent of the recent security breach it faced after hackers got access to hundreds of thousands of its credit card customers’ information in North America. Management affirmed that around 360,083 North America Citi-branded credit cards were hacked and only accounts issued in the U.S. were impacted.
Citi came to know about this unauthorized access during a routine check up. Customers' account information such as name, account number and contact information, including email addresses were leaked. However, chances of fraud are perhaps less as more critical data remained unscathed. Such data include customers' social security number, date of birth, card expiration date and card security code (CVV).
Yet, customers remain susceptible to other problems. The extent of client information that has been hacked could be used to procure further financial information through illicit ways.


Measures by Citi:-
The affected customers are being contacted by the company and measures have been taken to avoid any such event again in the future. Around 217,657 accounts were reissued credit cards along with a notification letter by Citi.
Other customers were not re-issued credit cards because either their accounts were closed or they already received new credit cards as a result of other card replacement practices. Citi is significantly monitoring these accounts for suspicious activity.


Companies Under Attack:-
Besides Citi, the other companies that suffered cyber attacks in recent times include some big names like Google Inc. (GOOG -Analyst Report), Lockheed Martin Corp. (LMT - Analyst Report), and Sony Corp. (SNE - Snapshot Report). The most notable was that of the security breach at EMC Corp.’s (EMC - Analyst Report) RSA unit, which makes SecurID used by banks for corporate networks’ to secure log in. Such a situation raises concern about the level of protection these companies are providing to their customers.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

LulzSec hacked porm sites, then next target is Onile Gamming (Brink & Bethesda)



Hacking collective Lulz Securtiy (LulzSec) has made headlines most recently with high profile intrusions  and data compromising on websites owned by PBS, Sony, FOX and Unveilance a whitehat security company that specializes in data breaches and botnets. With each successful breach LulzSec posts a press release on it’s website listing it’s spoils of war, usernames, passwords, email address, etc. LulzSec, like hacktivist group Anonymous is made of an unknown amount of individuals located from around the world. They operate in a similar manner in which communication is made in an IRC chat room(s) and the assumption is that there is no clear leadership or structure, though that remains to be seen. There has been recent IRC Chat logs and other data mining that suggests the two groups have ties to one another, an assumption LulzSec denies.
This past Friday afternoon the group announced that it had stolen and posted administrative emails and passwords for 50+ porn sites, along with 26,000 emails and passwords for users of the adult content website Pron.com.
Hi! We like porn (sometimes), so these are email/password
combinations from pron.com which we plundered for the lulz
Check out these government and military email
addresses that signed up to the porn site…
They are too busy fapping to defend their country
The group was quick to point out that six of the 26,000 email addresses stolen from Pron.com contained those who signed up for the site using their government or military (.gov and .mil) email accounts.
LulzSec, called on its followers over Twitter to try and use the credentials to log into Facebook, and to post on the compromised accounts to show their propensity for Internet porn. Facebook quickly responded to by matching up the leaked email addresses against its own database and resetting those users passwords.
In an unexpected twist though, LulzSec has now turned it’s reticule on Bethesda and its online FPS game Brink. It started on Sunday (June 12th) with tweets from their LulzSec twitter account:
“We were going to keep this little treasure chest to ourselves, but it appears the hand has been bitten. Say your prayers, Brink users >:]”
Followed by:
“Big lulz coming up in the near future. Time to show these bitches how it’s done. #Brink #Bethesda #ZeniMax.”
The group later tweeted again that it would have carried out the attack yesterday but that it looked forward to releasing ‘it” in 24hrs.
“We’d release right now, but we’re missing one vital ingredient to complete our victory soup. No ETA, but we’re hoping in the next 24 hours.”
The news only gets more bleak with the tweet “Snap your minds into a new realm, my friends. We did it because they couldn’t stop us – and did it we did, as you’ll see. We always deliver.” almost indicating that the hack has been completed, whatever “it” may be. There hasn’t been any word from Bethesda on the matter as of this write up but it appears that the Bethesda Store is currently unavailable and has been since 3pm yesterday which was around the time the first LulzSec tweet was posted in regards to Bethesda. If you or anyone you know has a Bethesda account I encourage you to at least change your password as soon as possible and as a general rule of thumb if you use the same password on multiple sites/services change those as well. Since we don’t know the full reach and exposure of what LulzSec has accomplished be on the look out of any personal information of yours that may be associated with Bethesda so that you are aware of just what information of yours must be watched closely or altered in the near future.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

After #opTurky, 32 Anonymous get busted by Turky Police



After hacker group Anonymous' apparently successful Operation Turkey to protest Internet censorship, the country's authorities have detained 32 people in connection with the attack on Turkish government Web sites.
After Friday's attack, Turkey's telecommunications authorities investigated and took the people into custody, according to a report today by Turkey's state news agency. Eight of those detained were under 18 years old, the report said.
The arrests come just days after Spain said Friday it arrested three Anonymous hackers in connection with attacks on Sony's PlayStation Network, governments, banks, and others. Retribution followed quickly, with an Anonymous attack that reportedly took a Spanish police off the Net.
The attacks take the form of a distributed denial of service (DDoS), which involves a coordinated flooding of a Web site with traffic with specially crafted network tools.
Security firm Sophos, though, said the Turkish attackers apparently used an attack tool called LOIC (Low Orbit Ion Cannon) that isn't terribly anonymous.
"LOIC...doesn't do a very good job of covering your tracks--making it potentially easy for computer crime authorities to track those behind the attacks," said Sophos' Graham Cluley.
A loose group of angry hacktivists is only one force spotlighting the Net's vulnerabilities today. The International Monetary Fund suffered what was reported over the weekend to be a major network breach. Google said it disrupted a plan the company said originated from China to break into Gmail accounts. It's open season for hackers.
One person's illicit hacker might be another person's sanctioned military authority, though. The United States and United Kingdom increasingly talk of cyberwar as just a facet of ordinary war.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

The International Monetary Fund get Hacked.


The International Monetary Fund, which manages the money of many a nation around the world, was recently the victim of what has been described as a "large and sophisticated" attack on its systems. It isn't yet clear how bad the damage is.
The breach certainly comes at a bad time, as the fund was only just rocked by the sexual assault charges against its former director Dominique Strauss-Kahn last month. However, the attack might have taken place even before said charges, though an official statement has yet to be made. The hackers responsible could, then, have had access to very serious information for some time:-
Because the fund has been at the center of economic bailout programs for Portugal, Greece and Ireland - and possesses sensitive data on other countries that may be on the brink of crisis - its database contains potentially market-moving information. It also includes communications with national leaders as they negotiate, often behind the scenes, on the terms of international bailouts. Those agreements are, in the words of one fund official, "political dynamite in many countries." It was unclear what information the attackers were able to access.
The attack was apparently so serious that the World Bank cut the connection that allows the two organizations to share data.
The IMF is only the most recent example of a large corporate entity being made vulnerable by cyber mischief. Both Sony and Lockheed Martin have fallen victim to wayward hackers in recent months. The fund has denied, however, any connection to the RSA SecurID break-in that compromised Lockheed back in March.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

3 Anonymous suspects get busted in Spain


Police in Spain have arrested three cyber criminals who are suspected to be members of the online ‘hactivist’ group, Anonymous. The group has been in the news recently with their attack on the Sony PlayStation Network, the Indian army website as well as the Indian government website - NIC.According to the Spanish police Twitter feed, the hackers were arrested in Spanish cities of Barcelona, Alicante and Almeria and a server hosted in Gijon was seized, as well. They also claim that they have dismantled the Anonymous hacker group in Spain who were responsible for attacking the PlayStation Store. The police said that these individuals have the capacity to make decisions and direct attacks. They also claim that the group has the ability to coordinate DDoS attacks to collapse Web sites around the world and are considered a threat by NATO.
According to a report, these arrests were made after investigation which began in October 2010. The Spanish police say that the arrests were made after going through millions of lines of chat logs to discover who was behind the group’s activity. The report goes on to say that some of the attacks made by the group’s members used a web based tool called Loic to fill the targeted sites with the required data.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

FBI is ramping Up Cyber-Attack Defense



The FBI has been called to investigate cyber attacks at Google and Sony in the past week, incidents that shed light on "the ever-present danger from sophisticated Internet attack," FBI Director Robert Mueller said intestimony Wednesday before the Senate Judiciary Committee."Along with countless other cyber incidents, these attacks threaten to undermine the integrity of the Internet and to victimize the businesses and people who rely on it," he said.The hearing, a video of which is available online, was focused on President Obama's request to extend Mueller's term as director until 2013. The director gave an opening statement on threats facing the intelligence organization and how it's working to combat them, and then fielded questions from the committee.
Mueller cited cyber attacks as one of the FBI's top challenges in the next 10 years, and said the agency needs to step up efforts to combat them, something it's currently working on."The increase of cyber as a mechanism for conducting all sorts of crimes--and also it being a highway to extracting our most sensitive secrets or extracting IP from our commerce" is a key concern, he said. "We as an organization need to continue to grow the capability of addressing that arena in the future."In addition to addressing growing cybersecurity needs, Mueller cited other technology-focused priorities of the organization during his testimony. One is the use of the Internet for terrorist cells to communicate, organize, and radicalize new terrorists, something the FBI is aimed at stifling, he said."In the age of the Internet, these radicalizing figures no longer need to meet or speak personally with those they seek to influence," Mueller said. "Instead, they conduct their media campaigns from remote regions of the world, intent on fostering terrorism by lone actors here in the United States."Another concern Mueller said he will continue to work on is his quest for the intelligence agency to expand its wiretapping capability to avoid a problem known as "going dark." The term refers to situations in which the agency has legal authorization to obtain Internet communications but cannot do so in a timely fashion due to a company's lack of technology to get the information quickly and efficiently.
An increase in high-profile and sophisticated cyber attacks in the United States is pushing the FBI to bolster its ability to fight cybercrime and foster stronger cybersecurity, its director told Congress this week.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Why does Sony getting hacked for multiple times (full report)


Since the April Play Station Network breach that exposed over 100 million user accounts, Sony has been hacked more than 10 times. Sony Pictures,Sony Europe, Sony BMG Greece, Sony Thailand,Sony Music Japan, Sony Ericcson Canada, and others, have all been the target of attacks. Sony has had to contend with intense scrutiny from media, disgruntled users and lawmakers, with everyone asking the company how it could let such a breach happen. Sony has apologized repeatedly and said that the original attack was a highly professional, criminal cyber attack aimed at stealing credit card numbers. Other experts have said that Sony simply didn't have its security act together and that the attack was likely far simpler. Now, critics are wondering what exactly the motivation might be behind the continued hacks. While the initial PlayStation Network breach was the largest of the hacks to date, Sony's cyber attack problem has continued due to both inconsistent security across Sony's systems and the rise of new groups of hackers interested less in punishing Sony than in showing off their ability to breach the company's defenses, experts say.

Some analysts say Sony's security woes started when the company pressed charges against 20 year-old hacker, George Hotz, who reverse-engineered Sony’s PlayStation 3 so that it could run unapproved third-party applications. Sony responded by suing Hotz, a move that reportedly infuriated many in the hacker community. Many experts say the attack on the PlayStation Network in April could have been an act of vilgilante justice resulting directly or indirectly from Sony's lawsuit against Hotz.

"Sony's perceived abuse of the legal system in targeting reverse-engineer George Hotz infuriated hacker groups," said Randy Abrams, director of technical education at ESET, an IT security firm. Abrams also noted that even before the Hotz incident, Sony had drummed up "significant antipathy" as the result of a 2005 scandal involving Sony CDs that automatically installed a rootkit that made users' computers vulnerable to attack.
The PlayStation Network attack appears to have set off an avalanche of follow-ups.

"Other hackers and hacking groups realized they could jump on the bandwagon and break into other Sony properties and get in the news," said Richard Wang, manager of Sophos Labs, a security vendor. "Really anything that has the Sony brand on it has become a target for someone trying to make a name for themselves or trying to prove they can break into the website."

Fred Cate, director of the Center for Applied Security Research at the University of Indiana, said the first PlayStation Network breach may have tempted hackers by revealing Sony as open to attack. "There's sort of a pile-on effect," Cate said. "Once you hear that there's a vulnerable network out there, other folks start trying. Sony's now a new target of interest."
Other hackers seem to have joined up for reasons other than political or monetary gain. Sites like has sonybeen hacked this week.com demonstrate a curious mixture of genuine curiosity and weary cultural saturation.

"Prior to the PSN hack, the loosely organized Anonymous group had waged war against Sony, reflecting the opinion of a significant share of netizens who got infuriated by Sony's corporate attitude," said Guillaume Lovet, a senior manager of the threat response team at Fortinet. "But now, from being a target for opinion reasons only, it also became a target 'just for the lulz,' for [hacker group] lulzsecurity and others."
"The outcome," Lovet said, "is more attackers, thus more successful hacks."

Some critics have questioned whether Sony's security efforts both before and after the initial breaches have been adequate. Sony has since promised to boost its security systems and review existing procedures. Still, according to experts, many of the attacks used to breach Sony's sites are fairly basic hacks that the company could easily have protected against.

"They seemingly have an almost anarchistic approach to global network security, with no visible coordination of security practices across Internet properties," said Abrams. "Some properties, such as Sony Pictures, seem to have been ignoring basic security best practices."

Part of the problem is Sony’s huge international web presence. Experts say its highly unlikely that the company's multiple divisions, from movies to gaming, are following any coordinated set of security protocols.

"Sony has disclosed many breaches, including different servers in Indonesia and Thailand. I highly doubt that the same developers who developed these websites are the same developers who worked on the Playstation Network, Sony Pictures, etc.,” said Derek Manky, a senior security strategist at Fortinet. "Quite simply, there is a tradeoff: Security dwindles as you add convenience and complexity."

While the novelty of hacking Sony may continue to diminish as other cybersecurity stories hit the news, it's clear Sony must get its act together or risk more attacks, a loss of customer faith and money and possible government intervention. 

"Sony needs time to get their security house in order," Jeremiah Grossman, the CTO of WhiteHat Security wrote in an email. "As an organization, Sony could see this as an opportunity. A year or more from now, they could be an example of how security SHOULD be done across the entire industry."

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Nintendo Servers Hacked, Next target XBOX


Nintendo reports that a Web server for its U.S. unit was hacked. The attack on Nintendo shows that this new era of hacking isn't going to end any time soon, and should serve as a wakeup call for other companies that were hoping this was purely a Sony issue. To be fair, the Nintendo incident is nothing compared to the Sony debacle. It's like comparing the United States "invasion" of Grenada, with the United States bombing Hiroshima and Nagasaki. While Sony has been hacked repeatedly for the past month--compromising sensitive information from more than 100 million user accounts in the process, the Nintendo hack appears to have yielded a simple server configuration file, and not exposed any sensitive data.
Hackers continue to take down networks for hacktivism bragging rights. The current plague of hacks and network takedowns is not limited to game console vendors, nor is it limited to one hacking collective. LulzSec is dominating headlines right now after attacking PBS, the FBI, hacker magazine 2600, and now Nintendo, but there are other groups out there as well--like the notorious Anonymous.
2600 seems to have nailed it on the head when it tweeted, "Hacked websites, corporate infiltration/scandal, IRC wars, new hacker groups making global headlines - the 1990s are back!"
Yes. That seems to sum things up. Granted, the vast majority of these attacks are driven by "hacktivism"--a pseudo-noble attempt to stand up for an issue and make a statement. But, there is a fine, fine line between that "Robin Hood complex" vigilantism, and just being a cyber thug.
The problem with hacktivism is that there are hackers representing both sides. While hacker groups battle it out online for bragging rights, innocent users are caught in the crossfire. I can sympathize with some of the hacktivist causes, but regardless of my opinion of Sony, or any other organization, I can't condone or support exposing sensitive information of users, or even interrupting services that those users have paid for and enjoy using.
While malware has evolved from script kiddies in search of bragging rights to organized crime in search of money, hacktivism is bringing back the "Wild West" days of the Internet. The thing is, hacktivism is just hacking--it's easy to rationalize by making it about trying to stand up for an issue or make some sort of statement, but really the only statement it makes is "look how great I am--I got in to your network."
The days of "All Your Base Are Belong to Us" are back. Watch your back Xbox Live, you're probably next as some group attempts to "outdo" LulzSec.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Sony Hackers LulzSec Strike FBI Affiliate InfraGard


LulzSec, the hacking group that has been identified as being behind the latest attack on Sony, has struck again—this time targeting a private-sector FBI affiliate called InfraGard.
InfraGard is a non-profit organization that connects the business community with law enforcement. It has about 42,000 members, including FBI agents, according to its website, and has an FBI special agent coordinator at each the bureau's field offices who recruits interested civilians nearby to form local InfraGard chapters. The InfraGard hack was part of a LulzSec action it called "Fuck FBI Friday" and culminated in the anonymous hacking group's publication of InfraGard e-mails, passwords and personal contact information for about 180 members on Friday. One LulzSec tweet late Friday promised "700MB in emails" via a link to a torrent file. LulzSec also defaced the InfraGard Atlanta website with a YouTube video challenging its target to "LET IT FLOW YOU STUPID FBI BATTLESHIPS," according to reports.
The hack of InfraGard that netted all the data published Friday seems to have occurred about a week or more ago. One InfraGard member told CNET Friday that he was contacted by a hacker group via email on May 26.
Karim Hijazi, CEO of botnet-tracking company Unveillance, said the hackers threatened to publish information about him found on InfraGard if he didn't give them sensitive security information about botnets. Botnets are networks of personal computers used by hackers and spammers who have slaved those PCs to the botnet either from volunteers, as is the case with the Anonymous hacking group's botnet, or from unsuspected PC users through a computer virus. Hijazi said that about a week before the first email came from "unveillance.owned@husmail.com," his company had detected attempts to crack the Unveillance corporate network with iPredator, a VPN tunneling tool. He also told CNET that he believed an unknown person had listened in on a company conference call. In a later IRC chat with his tormenters, the LulzSec hackers threatened to post a recording of a company call they said they had listened in on. "They had me under the gun for a little over a week with threats and extortion," Hijazi told CNET. "The very nature of having to contend with someone who is holding something ransom is not pleasant."


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

NATO Vs. Anonymous Hackers


The Anonymous hacking group has joined Al Qaeda, the Taliban and North Korea on the list of threats the world’s most powerful military alliance, NATO. 
According to a report written by NATO Parliamentary Assembly General Rapporteur Lord Jopling, the Anonymous hacking group now poses a hazard that needs to be taken seriously. The views are his own, but will strike a chord with the anxieties of others within and around European governments. “Observers note that Anonymous is becoming more and more sophisticated and could potentially hack into sensitive government, military, and corporate files,” Jopling said in the draft general report’s section on ‘hacktivism’. “Today, the ad hoc international group of hackers and activists is said to have thousands of operatives and has no set rules or membership. It remains to be seen how much time Anonymous has for pursuing such paths.” The report notes the various targets Anonymous has hit at will in the last year, and its vague political aspirations, including support for the US pursuit of Wikileaks’ founder, Julian Assange. Part of Jopling’s concern was simply the difficulty of defining cybersecurity for an organisation that takes in 28 countries with various cyberdefence capacities. The organisation was also struggling to define what its founding principle - that of mutual self-defence - might mean when applied to cyberspace, a realm where the origin and purpose of attacks is not always easy to decipher. Lacking a central leadership and organisation, Anonymous encapsulates the vague nature of many such cyber-threats. It has become notorious for self-styled campaigning attacks on ‘enemies’ as diverse as MasterCard, PayPal, Amazon, security company HBGary, various music companies including Sony, and even rock musician, Gene Simmons and the Church of Scientology. Its targets, then, are as diverse as its supporter’s interests. “The longer these attacks persist the more likely countermeasures will be developed, implemented, the groups will be infiltrated and perpetrators persecuted,” predicted Jopling.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Sony Hacked Again, 1 Million User Data Compromised


A group of hackers that recently gained notoriety for hacking PBS.org’s home page with an image of NyanCat, announced Thursday that it has stolen data from Sony. It’s yet another in a seemingly endless string of embarrassing security incidents for the company, but what’s shocking is just how exposed the data was to begin with.
In a press release posted to their Web site, LulzSec claims to have broken into SonyPictures.com and “compromised over 1,000,000 users’ personal information, including passwords, email addresses, home addresses, dates of birth, and all Sony opt-in data associated with their accounts.”
The theft included 75,000 “music codes” and 3.5 million “music coupons,” according to the group. LulzSec has posted segments of data they claim to have taken from Sony’s server to serve as proof of their accomplishment.
There are two astonishing twists to this story - one is that LulzSec was apparently able to access the information fairly easily, using what they describe as “a very simple SQL injection, one of the most primitive and common vulnerabilities.” Secondly, “every bit of data we took wasn’t encrypted. Sony stored over 1,000,000 passwords of its customers in plaintext, which means it’s just a matter of taking it. This is disgraceful and insecure: they were asking for it.”
If true, it’s devastating news for Sony, which is just getting back on its feet after shutting down access to its PlayStation Network and Sony Online Entertainment servers after hackers made off with personal information on more than 100 million user accounts.
The PlayStation Network, which controls PlayStation 3 and PlayStation Portable users’ ability to connect to one another to play online games, was down for more than three weeks through the last half of April and first half of May as Sony struggled to secure the system.
And only in the past 24 hours has Sony brought back its PlayStation Store, which serves as a way for PS3 and PSP users to download games and content for their systems.
Sony hasn’t even yet initiated its “Welcome Back” package for consumers affected by the PSN blackout - a collection of about $100 worth of games and content, as well as access to the company’s premium “PlayStation Plus” service.
SonyPictures.com isn’t directly related to the PlayStation 3 or PlayStation Network - it’s Sony’s consumer-facing Internet site for information on their movies, television and home entertainment offerings on Blu-Ray Disc and other formats. But Sony’s many Web sites and servers have been on the receiving end of security probes and hack attacks for some time, exacerbated by the company’s legal proceedings against George “Geohot” Hotz, a programmer who sought to “jailbreak” or enable the PlayStation 3 console to support Linux operating system software - a feature Sony once supported itself, but later removed in a firmware update. Since the widely-publicized outage of the PlayStation Network, hackers have stepped up their attempts to break into Sony’s systems.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

After the PSN Phenomena Microsoft decides to be nice to hackers



Software giant, Microsoft has decided that Sony's get tough plans with hackers did not work and probably resulted in getting the Japanese outfit into more hot water. Instead, the cuddly Vole has decided that nurturing hackers, so that they love Microsoft, is a much better plan. Microsoft's General Manager in Ireland Paul Rellis revealed that the company had learned from Sony's heavy-handed response to the PS3 hacking and the subsequent network-wide outages that followed. Instead of doing a Sony and taking a 14-year old boy from Dublin, who attempted to break into the Xbox LIVE network, to the cleaners it is going to nuture his talents instead. The boy was responsible for an alert when Microsoft detected the intrusion and feared that personal information may have been compromised. Rellis revealed  that the Microsoft was working with the teenager to develop his talent and help him use his skills for legitimate purposes. This is more likely to get a positive response from the hacker community than Sony's public attempts to shut down and prosecute hackers like GeoHot and the Fail0verflow group for their part in bypassing the PS3's security measures.
Unfortunately, Rellis did not indicate what Vole was doing with the boy from Tallaght, or what they plan to do with him once his training is finished. A cynic would wonder if the boy has been sent to the Volehill never to be seen again.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Young Hacker been Approached Diplomatically To Avoid Backlash by Microsoft




Sony’s recent nightmarish experiences with hackers has made Microsoft rethink their policies regarding how to engage with hackers. If we are to believe the words of Microsoft Corp.’s Ireland General Manager Paul Rellis, his company has learned a valuable lesson from the recent assault on Sony’s worldwide network, and has decided to approach hackers more diplomatically, TechEye reports. 
Apparently a 14-year-old Irish boy was caught trying to break into the Xbox LIVE network, but instead of prosecuting him, Microsoft has decided to help him become a better coder. Microsoft hopes that by helping the young hacker he will become a productive, white-hat hacker in the future instead of an online trouble-maker, and that they company will earn some respect from the hacker community in the process. 

Sony's problems began when they prosecuted the hacker Geohot for jailbreaking the PlayStation 3. Jailbreaking a device allows users to run their own code and, while it is controversial, its legality is still a matter of dispute.
Sony's harsh reaction to an activity that most online hackers consider relatively harmless brought about the attacks that have cost Sony more than $100 million in damages according to their own reports.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Related Posts Plugin for WordPress, Blogger...