Register - Login
Views: 99803166
Main - Memberlist - Active users - Calendar - Wiki - IRC Chat - Online users
Ranks - Rules/FAQ - Stats - Latest Posts - Color Chart - Smilies
05-03-22 07:18:00 AM
Jul - News - Sony, hackers, SQL injection, 1 million passwords in plaintext New poll - New thread - New reply
Pages: 1 2 3Next newer thread | Next older thread
FieryIce

Luigi
Level: 119


Posts: 2671/4161
EXP: 18758273
For next: 171018

Since: 12-18-08

From: Chicago

Since last post: 188 days
Last activity: 2 days

Posted on 06-02-11 09:03:55 PM (last edited by FieryIce at 06-02-11 06:05 PM) Link | Quote
Today, Sony finally put all its services back online after getting hacked over a month ago.

Today also, Sony gets hacked again:


Lulz Security said it broke into servers which run SonyPictures.com.

It said it had hacked into a database that included unencrypted passwords as well as names, addresses and dates of birth of Sony customers.

In April, hackers broke into Sony's PlayStation Network and stole data from more than 77 million accounts.


There's not much information about this yet, this is breaking news.


Lulzsec, the hacking group that made headlines recently for injecting itself onto the PBS front page and pronouncing Tupac Shakur to be alive and in hiding, has announced that it has “compromised over 1,000,000 users’ personal information,” which reportedly included unencrypted passwords and lots of personal information. Lulzsec claims to have used “a very simple SQL injection” in its attack.

Unlike the PlayStation Network breach, however, Lulzsec has released samples of its findings. That includes about 39,000 email / password combinations and 12,500 more with email, password, homes addresses, and dates of birth. About 600 usernames, emails, and passwords were also nabbed from Sony BMG Netherlands. We’re still going through those files, but so far it doesn’t look good. We’ve reached out to Sony Pictures for comment.

We’ve actually called several of the numbers listed in published files, and so far they line up with the associated names and addresses.


http://thisismynext.com/2011/06/02/sony-pictures-security-breach-lulzsec/
CB

Flippitty Flip
Level: 90


Posts: 1955/2280
EXP: 6978766
For next: 209843

Since: 02-01-11

From: Canadaland

Since last post: 10.5 years
Last activity: 10.4 years

Posted on 06-02-11 09:09:05 PM Link | Quote
Are you fucking kidding me?

These fucking hackers aren't even smart enough to understand that Sony Pictures isn't even part of Sony Entertainment. Fuck it all.

____________________
Protip, never copy the entire page source code into your post header. Ever.
Danika
6230
Level: 141


Posts: 5944/6235
EXP: 33298156
For next: 821858

Since: 10-23-09


Since last post: 1.2 years
Last activity: 1.2 years

Posted on 06-02-11 09:10:23 PM Link | Quote
This isn't looking good for Sony I'd have to say... they've been hacked what now, 4 times?

____________________
devin

Yoshi
i'm mima irl
Level: 112


Posts: 2156/3519
EXP: 14931966
For next: 406239

Since: 04-29-08

Pronouns: any
From: FL

Since last post: 306 days
Last activity: 3 days

Posted on 06-02-11 09:12:44 PM Link | Quote
Originally posted by CB
Are you fucking kidding me?

These fucking hackers aren't even smart enough to understand that Sony Pictures isn't even part of Sony Entertainment. Fuck it all.

There is no such company as "Sony Entertainment". SCE and Sony Pictures are two divisions of the same company.

____________________

Photo by Luc Viatour
Nicole

Disk-kun
Level: 146


Posts: 4076/6469
EXP: 38284810
For next: 228484

Since: 07-07-07

Pronouns: she/her
From: Boston, MA

Since last post: 78 days
Last activity: 1 day

Posted on 06-02-11 09:17:43 PM Link | Quote
I'm surprised SonyPictures.com would have 1,000,000 accounts, really...

____________________
CB

Flippitty Flip
Level: 90


Posts: 1956/2280
EXP: 6978766
For next: 209843

Since: 02-01-11

From: Canadaland

Since last post: 10.5 years
Last activity: 10.4 years

Posted on 06-02-11 09:18:10 PM Link | Quote
Originally posted by Cool Timpani
Originally posted by CB
Are you fucking kidding me?

These fucking hackers aren't even smart enough to understand that Sony Pictures isn't even part of Sony Entertainment. Fuck it all.

There is no such company as "Sony Entertainment". SCE and Sony Pictures are two divisions of the same company.


Sorry, Yes I forgot the word, 'Computers' in between Sony and Entertainment. But still, Sony Pictures isn't the same as Sony Computers Entertainment. It's sort of like Hacking the Powerade company to get revenge on Coca-Cola.

____________________
Protip, never copy the entire page source code into your post header. Ever.
devin

Yoshi
i'm mima irl
Level: 112


Posts: 2157/3519
EXP: 14931966
For next: 406239

Since: 04-29-08

Pronouns: any
From: FL

Since last post: 306 days
Last activity: 3 days

Posted on 06-02-11 09:21:33 PM Link | Quote
Originally posted by CB
Originally posted by Cool Timpani
Originally posted by CB
Are you fucking kidding me?

These fucking hackers aren't even smart enough to understand that Sony Pictures isn't even part of Sony Entertainment. Fuck it all.

There is no such company as "Sony Entertainment". SCE and Sony Pictures are two divisions of the same company.


Sorry, Yes I forgot the word, 'Computers' in between Sony and Entertainment. But still, Sony Pictures isn't the same as Sony Computers Entertainment. It's sort of like Hacking the Powerade company to get revenge on Coca-Cola.

If your first reaction to this is "THEY HACKED THE WRONG BRANCH OF SONY!!! IDIOTS!!" then you missed the point big time.

Also, Coca-Cola is the Powerade company.

____________________

Photo by Luc Viatour
CB

Flippitty Flip
Level: 90


Posts: 1958/2280
EXP: 6978766
For next: 209843

Since: 02-01-11

From: Canadaland

Since last post: 10.5 years
Last activity: 10.4 years

Posted on 06-02-11 09:22:51 PM Link | Quote
Originally posted by Cool Timpani
Also, Coca-Cola is the Powerade company.


Exactly my point.

____________________
Protip, never copy the entire page source code into your post header. Ever.
devin

Yoshi
i'm mima irl
Level: 112


Posts: 2158/3519
EXP: 14931966
For next: 406239

Since: 04-29-08

Pronouns: any
From: FL

Since last post: 306 days
Last activity: 3 days

Posted on 06-02-11 09:25:00 PM Link | Quote
Originally posted by CB
Originally posted by Cool Timpani
Also, Coca-Cola is the Powerade company.


Exactly my point.

What?

"But still, Sony Pictures isn't the same as Sony Computers Entertainment. It's sort of like Hacking Coca-Cola to get revenge on Coca-Cola."

____________________

Photo by Luc Viatour
CB

Flippitty Flip
Level: 90


Posts: 1959/2280
EXP: 6978766
For next: 209843

Since: 02-01-11

From: Canadaland

Since last post: 10.5 years
Last activity: 10.4 years

Posted on 06-02-11 09:26:59 PM Link | Quote
Originally posted by Cool Timpani
Originally posted by CB
Originally posted by Cool Timpani
Also, Coca-Cola is the Powerade company.


Exactly my point.

What?

"But still, Sony Pictures isn't the same as Sony Computers Entertainment. It's sort of like Hacking Coca-Cola to get revenge on Coca-Cola."


Sub-branches, Run by different people with different ideas and different jobs. Attacking SPE is still a blow to sony as a whole, but it is hurting more people than what they needed too.

____________________
Protip, never copy the entire page source code into your post header. Ever.
devin

Yoshi
i'm mima irl
Level: 112


Posts: 2159/3519
EXP: 14931966
For next: 406239

Since: 04-29-08

Pronouns: any
From: FL

Since last post: 306 days
Last activity: 3 days

Posted on 06-02-11 09:41:29 PM Link | Quote
Originally posted by CB
Sub-branches, Run by different people with different ideas and different jobs.

There's no "sub-branch" of Coca-Cola responsible for manufacturing Powerade. That's like saying that the Sony Computer Entertainment that created the Playstation 2 is somehow a different company than the Sony Computer Entertainment that created the Playstation 3.

Originally posted by CB
Attacking SPE is still a blow to sony as a whole

That was the entire point. The fact that they (successfully) targeted a completely different part of Sony does much more to expose serious problems with their large-scale corporate practices. Hitting the Playstation Network a second time would have done nothing but piss off PSN users even more.

Originally posted by CB
but it is hurting more people than what they needed too.

Hacks don't hurt people, poor security does.

____________________

Photo by Luc Viatour
FPzero
9590



Post 9351/9597
Active
5.5 years ago
Posted on 06-02-11 10:33:05 PM Link | Quote

macro time

____________________
ParaLax
510
Level: 47


Posts: 309/513
EXP: 735102
For next: 31101

Since: 05-18-11


Since last post: 9.9 years
Last activity: 8.2 years

Posted on 06-03-11 12:22:15 AM Link | Quote
Wow, you'd think that after the first hack they'd change and upgrade all their sites. The hackers are like vultures coming down to put Sony's internet finances to ruin.

SQL injection is so simple that I first learned about it in sixth or seventh grade, silly for them not to hash the passwords as well
Lyskar
12210
-The Chaos within trumps the Chaos without-
Level: 192


Posts: 9182/12211
EXP: 99321219
For next: 552352

Since: 07-03-07

From: 52-2-88-7

Since last post: 7.4 years
Last activity: 7.3 years

Posted on 06-03-11 01:45:06 AM Link | Quote
Stats
Time/Date
06-02-11 07:45:06 PM
Posts
9182
Days Here
1430
Level
140
Metal_Man88's Post
Even Acmlmboards hash their passwords, weak as the old versions are.

Sony's just lazy. And cheap. And this is what you get when that happens.

____________________

Eisnaught - SSQ² - Mobius Roleplay - SSS
Nicole

Disk-kun
Level: 146


Posts: 4085/6469
EXP: 38284810
For next: 228484

Since: 07-07-07

Pronouns: she/her
From: Boston, MA

Since last post: 78 days
Last activity: 1 day

Posted on 06-03-11 01:45:51 AM Link | Quote
Originally posted by Metal_Man88
Even Acmlmboards hash their passwords, weak as the old versions are.

If I recall correctly, though, that wasn't always the case...

____________________
Lyskar
12210
-The Chaos within trumps the Chaos without-
Level: 192


Posts: 9184/12211
EXP: 99321219
For next: 552352

Since: 07-03-07

From: 52-2-88-7

Since last post: 7.4 years
Last activity: 7.3 years

Posted on 06-03-11 01:46:31 AM Link | Quote
Stats
Time/Date
06-02-11 07:46:31 PM
Posts
9184
Days Here
1430
Level
141
Metal_Man88's Post
Well, 1.0 had its own Sony Hacking situation, causing it to be, er, 'improved.'

____________________

Eisnaught - SSQ² - Mobius Roleplay - SSS
ParaLax
510
Level: 47


Posts: 318/513
EXP: 735102
For next: 31101

Since: 05-18-11


Since last post: 9.9 years
Last activity: 8.2 years

Posted on 06-03-11 02:21:57 AM Link | Quote
Originally posted by Metal_Man88
Well, 1.0 had its own Sony Hacking situation, causing it to be, er, 'improved.'


Wow, lol. Never would think it would be plaintext passwords in an acmlm board. I guess it learned it the hard way. Did everyone have to change their passwords?
Post 1248/1311 (41 days), online 1 day ago
Posted on 06-03-11 05:06:33 AM Link | Quote




#58
AcmlmBoard 1.0 did use some form of password encryption, a really weak one but still (shift each character by an increasing amount then reverse it) And I'm pretty sure I used MD5 as soon as the database was switched from text files to MySQL (at version 1.5), or soon after ...

Then again, there was a way to get others' passwords in plain text by reading the password field (in New Reply) with JavaScript and sending that somewhere, and the login cookie only had a slightly less weak reversible encryption


As for Sony, I already lost count of how many times they got hacked recently

____________________
krutomisi
2480
Level: 94


Posts: 1509/2481
EXP: 8265485
For next: 91172

Since: 02-01-10


Since last post: 241 days
Last activity: 181 days

Posted on 06-03-11 05:30:08 AM (last edited by krutomisi at 06-03-11 02:42 AM) Link | Quote


hey guess who put all the info they stole into a torrent file


that's right lulsec did

anybody could download it right now



I just hope I'm not in there

____________________



1509 / 55 / 486
Rick
M'Lord, there's a knife in your head!
Level: 152


Posts: 4309/7540
EXP: 43721885
For next: 579775

Since: 02-15-10

From: Maine

Since last post: 6 days
Last activity: 6 days

Posted on 06-03-11 10:01:17 AM Link | Quote
I honestly want to say that one of us should download that just to make sure that none of -us- is affected and can change passwords and stuff if need be, but I don't know how effective that would be or if it would be pointless or illegal or something.

____________________
Pages: 1 2 3Next newer thread | Next older thread
Jul - News - Sony, hackers, SQL injection, 1 million passwords in plaintext New poll - New thread - New reply


Rusted Logic

Acmlmboard - commit 47be4dc [2021-08-23]
©2000-2022 Acmlm, Xkeeper, Kaito Sinclaire, et al.

31 database queries, 6 query cache hits.
Query execution time: 0.089319 seconds
Script execution time: 0.036318 seconds
Total render time: 0.125637 seconds