Showing posts with label hacking of sony site. Show all posts
Showing posts with label hacking of sony site. Show all posts

Thursday, 9 June 2011

Sony Pictures Security Hole Hits 37,500 Users





Blammo. Sony has just confirmed that 37,500 Sony Pictures visitors have had their passwords, emails, and other potentially identifying details stolen from the Sony Pictures website. There is little financial effect in this hack as it simply exposed logins and passwords although users should probably change their important passwords if they suspect they have been affected.
Sony writes:
We are continuing to investigate the details of this cyberattack; however, we believe that one or more unauthorized persons may have obtained some or all of the following information that you may have provided to us in connection with certain promotions or sweepstakes: name, address, email address, telephone number, gender, date of birth, and website password and user name.

Sunday, 5 June 2011

Sony and the Rise of the Hacker Hordes

It's becoming difficult to count the exact number of times various Sony systems have been attacked and hacked over the last couple of months. Malicious hackers targeting corporations isn't a new phenomenon, but what's unusual about Sony's case is the repetitive nature of the attacks. Hackers are ganging up and concentrating their efforts, and it's becoming harder for Sony to regain focus between punches.







Sony's (NYSE: SNE) security nightmare just won't end.
Earlier this week, malicious hackers released a bundle of personal information on thousands of Sony customers that was stolen -- quite easily, according to the infiltrators -- from Sony's IT systems.
That was only the latest in a long series of cyberattacks the company's been suffering since mid-April, which forced Sony to shut down its PlayStation Network for several weeks.
There's speculation that these attacks are being launched in retaliation for Sony's actions against hacker George Hotz, whom Sony sued for jailbreaking the PlayStation 3 and publishing the tools and techniques he used to do so on the Web.
As part of the settlement of the case, Hotz consented to a permanent injunction, but he severely criticized Sony.
The case had angered the hacker community, which vowed revenge.
Hacker activity against major corporations is nothing new, but what's perhaps unusual about the blows Sony's been enduring is their frequency and repetition. Typically when an organization is successfully targeted, the attack is limited to a single breach -- sometimes large, sometimes small. With Sony, however, hackers from all corners appear to be ganging up on the consumer electronics giant, launching attacks that range from irritating pranks to large-scale theft of customer Reach More Customers with Live Chat - Free Whitepaper information.
Could Sony's saga indicate the rise of the socio-political hacker, one who strides the Web like a god of vengeance, striking out at any organization that angers the techie community?
"This is less of a 'let's just grab some credit cards for our personal benefit or grab some emails to make them look bad'" sort of incident, Chris Lytle, a senior researcher at Veracode, told TechNewsWorld. "It's a concerted brand and image attack just because people don't like them."
More such attacks may surface in the future.
"We live in a persistent state of cyber-insecurity due to the lack of efficacy of traditional defenses against advanced cyberattacks," Ashar Aziz, founder and CEO of FireEye, commented.

The Blitzkrieg Against Sony

The Japanese entertainment giant is reeling under wave after wave of attacks of varying sizes and impact.
"Sony have probably had somewhere in the neighborhood of 20 security incidents in the past few months," Lytle said.
"Previous breaches have been a one-and-done thing; this has been a concerted group of attacks," he stated.
Few of the attacks share the same attack vector, and the hackers are targeting different business units within Sony, Lytle said. In addition to the Playstation Network, the hackers hit Sony BMG Greece, an unmaintained Sony sweepstakes site, Sony's Thailand site, and the company's Indonesian website, he added.
The hackers are "targeting Sony as a monolithic organization," and some of the breaches are "rather small," Lytle said.
Take, for example, the attack on Sony's Indonesian website on May 21. "That wasn't a high-impact attack; it was a simple website defacement, of which dozens occur every day," Lytle remarked.
At the same time, though, there were other, more serious attacks launched that had more impact on Sony, such as the theft of credit card numbers from its databases, Lytle said.
Sony did not respond to requests for comment by press time.

Is Sony's IT Infrastructure Flawed?

Perhaps Sony should share part of the blame -- companies do have the responsibility to protect data their customers share with them. However, FireEye's Aziz contends that all enterprises are vulnerable to cyberattacks to some degree.
"There are systemic vulnerabilities in every organization, and hackers have figured out how to exploit them," Aziz told TechNewsWorld.
Those vulnerabilities are the legacy approach to attack detection, and they rely on reactive techniques such as signatures for defensive purposes, Aziz said.
Apple (Nasdaq: AAPL) found that out in short order after releasing a defense against the MacGuard malware package this week; hackers circumvented that defense within hours, and the vendor is now playing cat-and-mouse with cyberattackers.
"No organization, no matter how well-run it is, is well-protected against this kind of attacks, because the new threat landscape has effectively obsoleted traditional enterprise security defenses," Aziz sad.

LulzSec Laughs While Sony Weeps

The hacker group Lulz Security claimed responsibility for the most recent Sony attack.
On Friday, it claimed to have compromised the personal information of 1 million users on the SonyPictures.com website.
Lulz has posted some of the data taken from the databases of various Sony companies.

What's Lulz Got to Do With It?

The word "lulz" is defined as laughter at someone else's expense. To attack a site "for the lulz" suggests the motive lies in personal amusement, pulling a prank or making a social or political statement, rather than personal monetary gain. Regardless of the motive, though, an attack can have serious consequences.
"There have been a lot of security breaches across a lot of companies," Veracode's Lytle said. "We are seeing a lot more cybercrime, but that acts as a distractor for social- or political-based hacking."
For example, the theft of credit cards from Sony's databases has kept it from dealing with all the other attacks against it.
"Sony's too busy dealing with the fact that 77 million cards have been stolen to deal with the other hacks," Lytle said. "The different hacker groups are kicking them while they're down."
Waves of attacks could be launched at other targets, Lytle warned, if they have a wide enough presence that they can be attacked easily -- and if they have angered a group of savvy Internet users.

Saturday, 4 June 2011

Hacker group steals details of a million Sony users


                                                Sony's headquarters in Tokyo, Japan
Sony has suffered another massive data breach, with a hacker group known as Lulz Security, or LulzSec, claiming to have stolen details about one million users from SonyPictures.com.
In a statement, LulzSec say they are not attempting to come across as "master hackers", but instead wish to highlight Sony's lax security. They say:
Every bit of data we took wasn't encrypted. Sony stored over 1,000,000 passwords of its customers in plaintext, which means it's just a matter of taking it.
The group says the data stolen includes users' passwords, email addresses, home addresses and dates of birth, and has placed samples online for others to verify their claim.
LulzSec say they accessed SonyPictures.com with an SQL injection, in which attackers exploit vulnerabilities in a website and force it to run unauthorised code. The group calls this "one of the most primitive and common vulnerabilities", and asks: "Why do you put such faith in a company that allows itself to become open to these simple attacks?"
Sony says it is aware of LulzSec's statement and is investigating the issue. "We are looking into these claims," Jim Kennedy, executive vice president of global communications for Sony Pictures Entertainment, told the Associated Press.
AP also called a number listed by LulzSec and verified that it belonged to a woman in Minnesota, who confirmed the rest of her details.
This latest attack comes as Sony recovers from a previous hacking incident, with its PlayStation Network only just fully restored after a month-long outage.
It is also the latest in a string of security breaches carried out by LulzSec, who last weekend hacked into and defaced the website of PBS, the US public broadcasting organisation, and previously stole data from the Fox broadcasting company.
Meanwhile, infamous hacktivist group Anonymous today said it has stolen 10,000 emails from Iran's Ministry of Foreign Affairs as part of its latest endeavour, OpIran.
Anonymous carried out its attacks as a response to Iranian crackdowns on anti-government protests, with one member telling The Epoch Times they aimed to damage the image of Iran "both in cyber space and the real world." The emails were taken from the Iranian Passport and Visa Office, and appear to be mostly visa applications.

(Mashable) -- Sony is not having a good year. As the company scrambles to get the PlayStation Network and Qriocity music serviceback online, it's suffering from yet another security breach.
This time it's a hacker attack on various websites associated withSony Pictures.
A team of individuals going by the name LulzSec, who recently managed to deface PBS.org's homepage, announced that they have broken into SonyPictures.com and compromised more than 1 million user accounts. An additional 75,000 music codes and 3.5 million coupons were also uncovered.
The attack, part of a campaign known as Sownage, was announced on Twitter and on the LulzSec website.
LulzSec said that it didn't have enough resources to copy all the data that it was able to access. But the group did manage to grab a collection of databases that contain thousands of usernames.
The accounts, presumably associated with any sort of registered activity on SonyPictures.com (or its subsidiaries or partners), contain information like passwords, email addresses, dates of birth and other Sony opt-in data.
This certainly isn't as dangerous as the information that was exposed during the PSN hack, but it could still be used to gather access to more important accounts elsewhere.
The scariest part of this attack isn't what was taken, but how easy it was for the LulzSec members to take it. According to the groups ownpress release, access to the main Sony Pictures website was gained using a very basic tactic called a SQL injection.
We haven't had a chance to examine the released files to see what this injection was, but it's likely that an out-of-date software stack and relatively unprotected web server made passing the injection trivial.
LulzSec says that all of the information it took was unencrypted.
"Sony stored over 1,000,000 passwords of its customers in plaintext," says the hackers' press release, "which means it's just a matter of taking it. "
Seeing as this is the second security breach of a major Sony-branded website in just outside of a week, we have to ask: Is anyone at Sony employed to handle web security?
Sure, managing a large number of brands and properties that are often connected in name only has to be a challenge, not to mention the logistical and administrative challenges of managing websites that can store millions of user profiles. Still, that doesn't make up for what by all appearances is an abysmal security record.
LulzSec has been on a tear, infiltrating the websites and databases for the UK television program, "The X Factor," parts of Fox.com, Sonymusic.co.jp and many parts of PBS.org in the past three weeks alone.
The attacks, while often juvenile in nature and execution (the Lulzsecurity.com website plays the theme from "The Love Boat"), underscore just how important it is for brands to keep their web servers updated, hardened and monitored. In the age of simple publishing tools like WordPress, it's easy for managers to underestimate the importance of having someone on contract or on staff to keep data encrypted and protected.
We can only hope the most recent cyber attacks convince executives to think seriously about investing in online security