ASE Labs
Welcome Guest. Please register or log in now. There are 115 people online (0 Friends).
  • Home
  • Articles
  • News
  • Forum
  • Register/Login

COMPUTER BILD Exclusive: PlayStation Server Scan Logfiles Uncover True Scope of Sony's Sloppy Data Security

Poster: SySAdmin
Posted on May 17, 2011 at 8:07:01 AM
COMPUTER BILD Exclusive: PlayStation Server Scan Logfiles Uncover True Scope of Sony's Sloppy Data Security

Scan Logs Show That Sony Servers Were Running Extremely Dated Programs and Web Services - Vulnerabilities of Obsolete Software Known for Years on the Internet

HAMBURG, Germany, May 17, 2011/PRNewswire/ --     It was the largest data theft ever: on the 19th of April, hackers broke
into Sony servers and stole the personal information of more than 100 million
customers. Highly sensitive information available to the German magazine
COMPUTER BILD now reveals that the servers had massive security issues.

    Internet activists of Anonymous, a worldwide secret organization,
provided COMPUTER BILD with logs of scans that they had performed on Sony
servers already before the data theft. Anonymous had launched distributed
denial-of-services (DDoS) attacks on the Sony servers as a "stress test" to
bring down the conglomerate's online services. To this end, they scanned the
servers for vulnerabilities. Logs of the scans revealed glaring security
holes.

    The logs indicate that Sony was using outdated, and thus insecure,
software versions, the weaknesses of which had been documented on the
Internet for years. For example, Sony used the OpenSSH 4.4 service to encrypt
data communication - a version that permits unauthorized access by attackers.
The current version, in which those holes have been closed, is 5.7.
Furthermore, some Sony servers were running the obsolete Apache version
2.2.10. The vulnerabilities in that version - which were eliminated in 2008 -
permit DDoS and other attacks. The current version is 2.2.17.

    Anonymous claims that it has nothing to do with the theft of personal
information of millions of users. But whoever stole the data, they did not
have to overcome any major obstacles in light of the glaring security holes.

    A number of PlayStation Network servers in Europe have been back online
since Sunday. Sony promises significantly higher security standards,
hopefully with the latest software this time.

    For all the facts and documents, as well as tips on what PlayStation
Network users need to do now, please visit
http://www.computerbild.de/go/sony-ps3-details.

   
    Contact:

    Olaf Pursche
    opu@computerbild.de
    +49-40-34960266

    COMPUTER BILD
    Axel-Springer-Platz 1
    D-20350 Hamburg
    Germany

Source: COMPUTER BILD

.
 
Print This Entry
Tags PR Press Release
Related Articles
  • Huntkey Has Launched Its New Power Strips with USB Chargers on Amazon US
  • Inspur Releases TensorFlow-Supported FPGA Compute Acceleration Engine TF2
  • Hot Pepper Introduces Spicy New Smartphones in US Markets
  • Sharp Introduces New Desktop Printers For The Advanced Office
  • DJI Introduces Mavic 2 Pro And Mavic 2 Zoom: A New Era For Camera Drones
Login
Welcome Guest. Please register or log in now.
Forgot your password?
Navigation
  • Home
  • Articles
  • News
  • Register/Login
  • Shopping
  • ASE Forums
  • Anime Threads
  • HardwareLogic
  • ASE Adnet
Latest News
  • Kingston HyperX Cloud 2 Pro Gaming Headset Unboxing
  • Synology DS415+ Unboxing
  • D-Link DCS-5020L Wireless IP Pan/Tilt IP Camera
  • Actiontec WiFi Powerline Network Extender Kit Unboxing
  • Durovis Dive Unboxing
  • Bass Egg Verb Unboxing
  • Welcome to the new server
  • Gmail Gets Optional Preview Pane
  • HBO Go on Consoles
  • HP Touchpad Update
Latest Articles
  • D-Link Exo AC2600 Smart Mesh Wi-Fi Router DIR-2660-US
  • HyperX Double Shot PBT Keys
  • Avantree ANC032 Wireless Active Noise Cancelling Headphones
  • ScharkSpark Beginner Drones
  • HyperX Alloy FPS RGB Mechanical Gaming Keyboard
  • D-Link DCS-8300LH Full HD 2-Way Audio Camera
  • Contour Unimouse Wireless Ergonomic Mouse
  • HyperX Cloud Alpha Pro Gaming Headset
  • Linksys Wemo Smart Home Suite
  • Fully Jarvis Adjustable Standing Desk
Latest Topics
  • Hello
  • Welcome to the new server at ASE Labs
  • Evercool Royal NP-901 Notebook Cooler at ASE Labs
  • HyperX Double Shot PBT Keys at ASE Labs
  • Avantree ANC032 Wireless Active Noise Cancelling Headphones at ASE Labs
  • ScharkSpark Beginner Drones at ASE Labs
  • HyperX Alloy FPS RGB Mechanical Gaming Keyboard at ASE Labs
  • D-Link DCS-8300LH Full HD 2-Way Audio Camera at ASE Labs
  • Kingston SDX10V/128GB SDXC Memory at ASE Labs
  • What are you listening to now?
  • Antec Six Hundred v2 Gaming Case at HardwareLogic
  • Sans Digital TR5UTP 5-Bay RAID Tower at HardwareLogic
  • Crucial Ballistix Smart Tracer 6GB PC3-12800 BL3KIT25664ST1608OB at HardwareLogic
  • Cooler Master Storm Enforcer Mid-Tower Gaming Case at HardwareLogic
  • Arctic M571-L Gaming Laser Mouse at ASE Labs
  • Contour Unimouse Wireless Ergonomic Mouse at ASE Labs
Advertisement
Advertisement
Press Release
  • Huntkey Has Launched Its New Power Strips with USB Chargers on Amazon US
  • Inspur Releases TensorFlow-Supported FPGA Compute Acceleration Engine TF2
  • Hot Pepper Introduces Spicy New Smartphones in US Markets
  • Sharp Introduces New Desktop Printers For The Advanced Office
  • DJI Introduces Mavic 2 Pro And Mavic 2 Zoom: A New Era For Camera Drones
  • DJI Introduces Mavic 2 Pro And Mavic 2 Zoom: A New Era For Camera Drones
  • Fujifilm launches "instax SQUARE SQ6 Taylor Swift Edition", designed by instax global partner Taylor Swift
  • Huawei nova 3 With Best-in-class AI Capabilities Goes on Sale Today
  • Rand McNally Introduces Its Most Advanced Dashboard Camera
  • =?UTF-8?Q?My_Size_to_Showcase_Its_MySizeId=E2=84=A2_Mobil?= =?UTF-8?Q?e_Measurement_Technology_at_CurvyCon_NYC?=
Home - ASE Publishing - About Us
© 2010 Aron Schatz (ASE Publishing) [Queries: 18 (8 Cached)] [Rows: 314 Fetched: 57] [Page Generation time: 0.011327981948853]