| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
|
Sony Europe hacked: 150 accounts compromised
|
||||||||||||
|

When it rains for Sony, it pours for Sony. And it seems that Sony is currently caught in a deluge: A hurricane of hacks, if you will. The thirteenth hack on a Sony database has been reported by Sophos' Naked Security blog, allegedly netting a single hacker 120 user names, passwords, mobile phone numbers, work emails, and websites from a user database on Sony Europe's site.
The attacker, dubbed "Idahc," claims to have used a standard SQL injection attack to get his hands on the database, which he promptly released to the world via Pastebin document. The passwords were allegedly stored as plain text within Sony's database, a pretty big no-no as far as the world of enterprise security is concerned.
"If you are a database administrator (especially a Sony one) and want to avoid your sensitive data from ending up in the headlines I recommend you actually test your web applications for SQL vulnerabilities," wrote Sophos' Chester Wisniewski.
The pseudonym "Idahc" might sound familiar. It should: The Lebanese attacker is the same person who recently broke into Sony Ericsson's Canadian e-commerce site. This breach in a Sony site or server–the fifth, for those keeping score at home–was also the result of an SQL injection hack.
Idahc also posted the results of his Sony Ericsson hack to a Pastebin document, which included password hashes, email addresses, and the full names of the users connected to the accounts. Idahc also claimed that he had found additional databases with even more juicy details, including user credit card and telephone numbers, but he did not share these publicly.
But that's not the only silver lining to the recent Sony attacks. If you're a Sony user—specifically, a subscriber to Sony's PlayStation Network during the service's extended outage–you can at least enjoy the news of Sony's ongoing hacker issues alongside your brand-new free games.
Sony's Welcome Back package is now live for the 77 million users affected by the PlayStation Network hacking indecent. Users get two free games for both their PlayStation 3 consoles and PSP handheld systems in addition to 30 free days of PlayStation Plus access. Existing Plus subscribers get 60 free days credited to their account, and all Sony users have the option to sign up for a free year of identity theft monitoring.
Don't dawdle with the free game downloads, however, as Sony will only be offering them until July 3.
For more from David, follow him on Twitter @TheDavidMurphy.
Copyright © 2010 Ziff Davis Publishing Holdings Inc.

Want more? Subscribe to Digit and get the month's most relevant news, feature articles, DVDs with latest softwares and a learning guide called Fast Track.
Related Stories
Latest News
Comments 0comments
activision
android game
nintendo 3ds
ios game
valve
psn
microsoft xbox 360
game review
wii
angry birds space
gaming
playstation 3
amd radeon
playstation
nvidia geforce
ps vita
ubisoft
ea games
games
capcom
ea
gpu
xbox 720
sony ps3
ios app
fps
game
rovio
e3
wii u
xbox 360
microsoft
psp
sony playstation
angry birds
fermi
nintendo wii
xbox
ps3
nvidia
call of duty
kinect
nintendo
playstation network
pc
review
electronic arts
sony
e3 2010
amd
