• PS3 Hacks, PSN , 01.05.2011

    Wondering how many users per region were affecting by the PSN attack/data compromise? Mark MacDonald has tweeted a chart outlining just that (click to enlarge):

    This chart was handed out to people attending the Sony press conference on May 1st regarding the PSN attacks.

    Sony also handed out how the hackers manage to attack PSN, diagram of that below:

    Thanks to jaRRed for news tip.

    Tags: ,

    Discuss in Forums (36)


  • 36 Comments

    1. Mystt
      05-01-2011
      03:03 PM
      1

      I'd say that's pretty bad *after subtracting dupe accounts and so forth*. Thanks for the post.

    2. GregoryRasputin
      05-01-2011
      03:33 PM
      2

      I think the PSN account information is wrong.

      Russian Federation, which is the largest single country in the world with a population of 142,905,200, only has just under 445,000 PSN accounts.

      Where as a tiny island like Ireland with a small population of 6,197,100, has almost 437,000 PSN accounts.

      Austria has a population of 8,032,926 and has almost 413,000 PSN accounts.

      So how can a country with close to 143 million people have around the same amount of PSN accounts as a country with only 8 million.

    3. darkfroggy
      05-01-2011
      03:51 PM
      3

      Bastards u left Aruba out!!!!!
      We have ps3 too u know??!!!!

    4. OoZic
      05-01-2011
      04:15 PM
      4

      I did read somewhere before their PSN servers were running an old Linux version and reading the diagram that is correct. it looks like the hackers used vulnerabilities in outdated libs or something. Now explain me one thing: how is it possible they where running an outdated Linux version on their servers? By stopping OtherOS they stopped updating their own servers? Their servers run on PS3 clusters?

      Again an Epic Fail to my opinion... Fire all those people who are responsible for keeping their network updated and didn't do it

    5. Mystt
      05-01-2011
      04:18 PM
      5

      Again an Epic Fail to my opinion... Fire all those people who are responsible for keeping their network updated and didn't do it
      I pretty sure there was some kind of inside corporate accountability and shuffle done and that some employees were let go.

    6. tryp
      05-01-2011
      04:27 PM
      6

      Their servers run on PS3 clusters?


      That would make sense, as I'm sure it's cheaper for those tightwads to use something they manufacture instead of buying proper servers.

    7. alexandxela
      05-01-2011
      04:30 PM
      7

      Hmmm
      I' am not a super expert but i' am quite an expert in various fields including security and crypto designs. So the basic question raised here is
      1. The Credit card numbers are supposed to be to stored in anyone's individual machine,
      and just verified at the time of transaction.
      2. If Sony corporation makes a CreditCardNumber storage just after one trasnaction that sounds illegal to me. This kind of storage is permitted only to corporations like PAYPAL which have quite a bit non just electronic verification system.
      3. If this is the case, we are not facing a PSN mamboo jamboo hack but a plain "man in the middle attack" , and "the man in the middle" is SONY.
      Why this obvious observation does not catch the eyes of a lawyer!!!!!!!!!!!

    8. AgentFortyS3v3n
      05-01-2011
      04:36 PM
      8

      UK with 9 million accounts yeah right. More Fony lies. I dont see the UK having as much as that, plus there is probably more 360 users in the UK than PS3.

    9. Mattr92
      05-01-2011
      04:41 PM
      9

      Consider how many people have multiple accounts, I my self have 4 alone

    10. panzearon
      05-01-2011
      04:49 PM
      10

      Originally Posted by darkfroggy View Post
      Bastards u left Aruba out!!!!!
      We have ps3 too u know??!!!!
      I find it hard to believe that anyone gives a damn.

    11. OoZic
      05-01-2011
      05:16 PM
      11

      Originally Posted by darkfroggy View Post
      Bastards u left Aruba out!!!!!
      We have ps3 too u know??!!!!
      The Kingdom of the Netherlands excist out 4 countries, to know Aruba, Curacao, Sint Maarten and the Netherlands .....

      (dutch: )
      Het Koninkrijk der Nederlanden bestaat nu uit vier landen: Aruba, Curaçao, Sint Maarten en Nederland.

      You also have dutch voting rights. So look under The Netherlands
      ************* [ - Post Merged - ] *************
      Originally Posted by tryp View Post
      Their servers run on PS3 clusters?


      That would make sense, as I'm sure it's cheaper for those tightwads to use something they manufacture instead of buying proper servers.
      Their PS3 cluster computers are very good because linux/unix is the best for servers, only problem is updating the OS on 2200 PS3's in one cluster, takes some time and employees. But do-able for something important like PSN. That is if you take your customers serious...

      I don't like updating Windows because all of their crap but I always install their latest security patches. And for one reason: By publishing the vulnerabilities the leaks are known by everyone who wants to misuse security holes.

      [user12] I also know that the server that does the x-i-5 tickets is a bit more tight about the ciphers than any other system in sonyland
      [user12] if sony is watching this channel they should know that running an older version of apache on a redhat server with known vulnerabilities is not wise, especially when that server freely reports its version and its the auth server
      [user2] its not old version, they just didnt update the banner
      [user12] I consider apache 2.2.15 old
      [user2] which server
      [user12] it also has known vulnerabilities
      [user12] auth.np.ac.playstation.net
      [user2] ya the displayed version u see via banner is not the real version
      [user12] unless they updated it in the last couple weeks
      [user12] I doubt that since its not trivial to change that
      [user12] its a bit more invasive than just setting it to Prod like they do on their other servers
      [user11] you know, watching this conversation makes me think about whether it was a good idea after all to buy a couple of games from psn using a visa card
      [user2] its just backported security patches
      [user11] i did remove all my info after downloading the games though
      [user12] that is just psn not the store
      [user12] they are running linux 2.6.9-2.6.24 on that box too
      [user12] that too is old
      [user2] lol @ buying on store
      [user11] yes, but their general attitude towards security just seems…ugh
      [user2] sony wont misuse the info i bet xD
      [user2] but just prevent using cfw’s of unknown ppl
      [user2] even better from ALL ppl
      [user2] make ur own lol
      [user12] so I doubt that they are spoofing the network stack on that box as well
      [user12] my guess is that it really is undermaintained “it works why change anything”
      [user2] could be
      [user12] sony really should update that stuff to something more current
      [user2] ya
      [user2] but imagine
      [user2] psn == 45 environments
      [user2] and for example
      [user2] every env has 50 subdomains
      [user2] to external machines
      [user2] its rly rly huge
      [user2] who wants to do this xD
      [user2] ppl r lazy
      [user2] wont change

    12. boblob
      05-01-2011
      05:48 PM
      12

      Interesting, the UK has had 4m PS3 sales according to vgchartz, yet 9m+ accounts - that is a lot of dupes.

      Furthermore - the diagram - how did they plant the 'tool' onto the app server when the app server, according to the diagram has no internet traffic route to it, only internal traffic back and forth from the web server when the vuln was on the app server?

    13. jorgebus
      05-01-2011
      06:01 PM
      13

      I've expected to see more firewalls in that diagram : /

      Looks unprotected even in the map.

    14. OPTIMUSCRIM
      05-01-2011
      06:27 PM
      14

      So its just like last weeks Southpark. "In store credit then?"

    15. 1rottie1
      05-01-2011
      06:59 PM
      15

      i still cant believe theres 31million accounts in the US...... thats insane...... they better offer more then just ps+..... if my cc # gets out sony gonna be talking to a big time lawyer..... they gonna go from to to

    16. jcasas392
      05-01-2011
      07:18 PM
      16

      i think it's time for sony to take their finger out their asses and stop acting like this guy YouTube - Never (While You ****)

    17. tman420
      05-01-2011
      07:26 PM
      17

      I already changed my cards and got new ones I hope someone tries to use my old numbers
      i have a feeling $ony is really screwed this time

    18. mightykhan
      05-01-2011
      07:49 PM
      18

      Originally Posted by agentfortyseven
      UK with 9 million accounts yeah right. More Fony lies. I dont see the UK having as much as that, plus there is probably more 360 users in the UK than PS3.
      UK is the natural Euro account spot for Americans. Unless you speak German, or French, or Russki, or Español, and don't mind researching up some fake info in those languages.

      We could use Ireland, but most of the Irish are already in America, so they aren't the first Euro country we think of. Otherwise there would be millions of Ireland accounts.

      many of the 9 million Japanese accounts are really Americans too.

    19. Pockets69
      05-01-2011
      07:58 PM
      19

      so you got access to the logs too ozic?

    20. bobshi
      05-01-2011
      08:08 PM
      20

      Originally Posted by jorgebus View Post
      I've expected to see more firewalls in that diagram : /

      Looks unprotected even in the map.
      More? There is one between every layer. The lazy-mans infrastructure would just say well these two layers only communicate internally, we'll just shove one on the internet-facing end.

      The infrastructure layout is fine, they just obviously failed to keep it up to date. Which is the trouble with high availability services, you cannot afford to take them out of service to update, not to mention if you know something is running stable on a particular version you will be reluctant to update in case of breakage.

      That said they have had maintenance periods, so what were they doing during those? That is when they should have taken the time to update their servers.

    21. Wolfie708
      05-01-2011
      08:10 PM
      21

      Originally Posted by mightykhan View Post
      UK is the natural Euro account spot for Americans. Unless you speak German, or French, or Russki, or Español, and don't mind researching up some fake info in those languages.

      We could use Ireland, but most of the Irish are already in America, so they aren't the first Euro country we think of. Otherwise there would be millions of Ireland accounts.

      many of the 9 million Japanese accounts are really Americans too.
      Ok, I may be being dumb here, but that makes zero sense to me???

      I'm English and I live in England. If I move to Sweden, I am still English but I live in Sweden so therfore I would have a Swedish account.

      Are you just talking of fake details, as in someone just picks a country etc?

    22. Pockets69
      05-01-2011
      08:36 PM
      22

      yup! when on 1.50 firmware long long ago i had 3 psn accounts all with fake ids streets zip codes, etc, one being european, another being american and the other japanese! and i am portuguese! now i can't even remember any of the passwords or usernames LOL, i don't care about psn

    23. jfeddd
      05-01-2011
      09:11 PM
      23

      Originally Posted by GregoryRasputin View Post
      I think the PSN account information is wrong.

      Russian Federation, which is the largest single country in the world with a population of 142,905,200, only has just under 445,000 PSN accounts.

      Where as a tiny island like Ireland with a small population of 6,197,100, has almost 437,000 PSN accounts.

      Austria has a population of 8,032,926 and has almost 413,000 PSN accounts.

      So how can a country with close to 143 million people have around the same amount of PSN accounts as a country with only 8 million.
      its duh moneyz as you can see all these country's consume a lot more then Russia. Not sure why but these charts show it.

    24. Wolfie708
      05-01-2011
      09:14 PM
      24

      My buttons buggered off again, but thanks Pockets lol

    25. bobshi
      05-01-2011
      09:19 PM
      25

      Originally Posted by Wolfie708 View Post
      Ok, I may be being dumb here, but that makes zero sense to me???

      I'm English and I live in England. If I move to Sweden, I am still English but I live in Sweden so therfore I would have a Swedish account.

      Are you just talking of fake details, as in someone just picks a country etc?
      I think he might mean that Americans wanting an account in another country would pick the UK? Though usually any exclusives go to the US first don't they, so whilst we might register ourselves a US PSN account to get stuff early, not so sure many would do it the other way around?

    26. Wolfie708
      05-01-2011
      09:22 PM
      26

      Thanks to Bobshi as well.............. I want my Thank You button back!!! *Stamps feet in tantrum!*

    27. KillerBug
      05-01-2011
      10:19 PM
      27

      Originally Posted by bobshi View Post
      More? There is one between every layer. The lazy-mans infrastructure would just say well these two layers only communicate internally, we'll just shove one on the internet-facing end.

      The infrastructure layout is fine, they just obviously failed to keep it up to date. Which is the trouble with high availability services, you cannot afford to take them out of service to update, not to mention if you know something is running stable on a particular version you will be reluctant to update in case of breakage.

      That said they have had maintenance periods, so what were they doing during those? That is when they should have taken the time to update their servers.
      They were releasing system updates & a new TOS every week just to f**k with their loyal users.

    28. tman420
      05-01-2011
      11:39 PM
      28

      this diagram is explaining an inside job or the hacker had direct access to the ps3 main database to insert the communication tool if im not mistaken, If that is the case ROTFLMFAO

    29. davidbb
      05-02-2011
      03:36 AM
      29

      Originally Posted by Pockets69 View Post
      yup! when on 1.50 firmware long long ago i had 3 psn accounts all with fake ids streets zip codes, etc, one being european, another being american and the other japanese! and i am portuguese! now i can't even remember any of the passwords or usernames LOL, i don't care about psn
      Did you purchase anything with these accounts, if so then it shows how poor Sony's security is as good security usually needs a genuine billing address to verify credit cards even if the delivery address is different.

      On another note I now going to start a conspiracy theory that the US government carried out the PSN hack, they clearly knew Bin laden owned a PS3 :D

    30. OoZic
      05-02-2011
      03:41 AM
      30

      Originally Posted by Pockets69 View Post
      so you got access to the logs too ozic?
      I do my research when something affects me

      Would Sony understand they were reverse engineering to find their Epic Fail no.2
      Oh, I remember again..... only normal people are not allowed to reverse engineer according to Sony. Sony = GOD so Sony has all rights to forbid something they are allowed to do themselves.....

    31. bagster
      05-02-2011
      06:02 AM
      31

      Strange figures there. I agree with above surelly there would be more russian users on psn. Or did the 'hackers' purposly not target that area

    32. mightykhan
      05-02-2011
      06:09 AM
      32

      Originally Posted by bobshi
      Originally Posted by "wolfie708
      Ok, I may be being dumb here, but that makes zero sense to me???

      I'm English and I live in England. If I move to Sweden, I am still English but I live in Sweden so therfore I would have a Swedish account.

      Are you just talking of fake details, as in someone just picks a country etc?
      I think he might mean that Americans wanting an account in another country would pick the UK? Though usually any exclusives go to the US first don't they, so whilst we might register ourselves a US PSN account to get stuff early, not so sure many would do it the other way around?
      Yeah, that's what I meant. There's more American users than elsewhere, so more Americans making fake accounts. (We also make more fake assassinations of Osama Bin Laden.)

      I always liked the Euro store better than the US store. In particular their ps1 downloads were far better. We got Jet Moto 1 and 2, and Europe got C&C Red Alert. And gave away Rag Doll Kung Fu for free! Stupid game but it was free.

    33. evadave
      05-02-2011
      06:18 AM
      33

      Whoever typed up the list of hacked accounts cannot spell or use spell check. Countires? What is a "Countire" Sony?

    34. Pockets69
      05-02-2011
      06:27 AM
      34

      Originally Posted by OoZic View Post
      I do my research when something affects me

      Would Sony understand they were reverse engineering to find their Epic Fail no.2
      Oh, I remember again..... only normal people are not allowed to reverse engineer according to Sony. Sony = GOD so Sony has all rights to forbid something they are allowed to do themselves.....
      yeah i came across the full logs 4 days ago or so... but yeah i would believe that this would be failnetw0rk LOL
      yeah we are not allowed to thinker with our own hardware... cause the law states that we can't mess with sony hardware! in fact every country has that law XD

    35. lochte30000
      05-02-2011
      08:49 AM
      35

      Osama Bin Laden is dead... Amazing what the Americans can do when the Playstation Network is down.

    36. lochte30000
      05-02-2011
      12:41 PM
      36

      How did they get Osama bin Laden's address? It's not been confirmed but I think he bought a Sony Playstation 3 last month..