news4geeks.net
19May/110

Sony Denies PSN Hack, Confirms PSN Web Exploit

0saves

psn is gong alive backThe PlayStation Network wasn't hacked so much as threatened yesterday when a password exploit accessible through its PSN web page login page came to light, claims Sony.

The PlayStation Network wasn't hacked so much as threatened yesterday when a password exploit accessible through its PSN web page login page came to light, claims Sony.

Sony spokesperson Patrick Seybold confirmed the exploit in an official PlayStation blog dispatch yesterday afternoon.

"We temporarily took down the PSN and Qriocity password reset page," wrote Seybold, quickly adding "Contrary to some reports, there was no hack involved."

The "exploit" involved the PSN web-based password reset page, where


whistleblower Nyleveia claimed anyone could change someone else's password using their PSN account email and date of birth--both details possibly (though not confirmedly) obtained by hackers in the original mid-April PSN breach.

Seybold seemed to confirm this as well: "In the process of resetting of passwords there was a URL exploit that we have subsequently fixed."

"Consumers who haven't reset their passwords for PSN are still encouraged to do so directly on their PS3," said Seybold. "Otherwise, they can continue to do so via the website as soon as we bring that site back up."

The login page was still down Thursday morning.

A hack is technically defined as "use [of] a computer to gain unauthorized access to data in a system," where an exploit isn't formally defined in computer terms, but means to "make full use of and derive benefit from (a resource)." It's splitting hairs to call the PSN password reset issue one or the other, but "hacking" usually involves breaking into something, where "exploiting" involves taking advantage of some preexisting deficiency to gain some advantage from a broken or vulnerable process (as opposed to flat out breaking into a system).

So yes, Sony was hacked. Or exploited. Or both, depending on your stance. All that matters to PlayStation gamers,  the vulnerability was patched quickly: if we go with Nyleveia's version of events, within 15 minutes of notification. That's not such a bad thing as reaction times go, and it's also important to bear in mind Sony's under unprecedented scrutiny levels, so any little slip that might otherwise receive passing notice ends up hyper-magnified.

(Source: idg.no)

 

A trio known for their prowess in hacking Apple's iPhone software indicated on Thursday they may be edging closer to breaking the improved security measures in iOS 6. The ...
READ MORE
The head of Google's Webspam team, Matt Cutts, announced on Twitter that Google has sent out a message to the webmasters of 20,000 sites informing them that their sites ...
READ MORE
Reports that Iranian electronic warfare experts may have succeeded in intercepting and capturing a sophisticated U.S. spy drone was received with some skepticism by security analysts. While it is certainly ...
READ MORE
Hackers exploit Adobe Reader zero-day, may be targeting defense contractors
Adobe today confirmed that an unpatched, or zero-day, vulnerability in Adobe Reader is being exploited by criminals. Those attacks may have been aimed at defense contractors. Adobe promised to patch the ...
READ MORE
AT&T reports attempted customer data hack
AT&T today notified customers that there had been an "organized and systematic" attempt to hack into their personal account information. The company sent out an email to customers informing ...
READ MORE
iPhone hacker dream team edges closer to iOS6
Google warns the operators of thousands of hacked
Analysts wary of Iran’s spy drone hacking claims
Hackers exploit Adobe Reader zero-day, may be targeting
AT&T reports attempted customer data hack

Comments (0) Trackbacks (1)

Leave a comment