• PS3 Hacks, PSN , 18.05.2011

    You have to be surprised at how such a big corporation can fail so badly at keeping their security up to date. It seems that the PSN online login page with password reset was exploited again by hackers. Though not a big as issue as the first, if you go to reset your PSN password all it asks for is your E-mail and date of birth. Hmm lets see, database stolen…they probably have this information….you see where its going.

    As a result all webpage logins/password reset options are now offline. If you legitimately don’t remember your PSN logins, well seems like your out of luck for a while. Looks like everyone should have followed Japans decision eh?

    Whats interesting about the whole situation that a website Nyleveia discovered this exploit and posted about it online (via Twitter), and contacted Sony to take a look at it. Sony took the tip, had the tweets removed and now have the reason for downtime as:

    “Clarification: this maintenance doesn’t affect PSN on consoles, only the website you click through to from the password change email.”
    “Fortunately we have got ISPs to release outstanding emails; unfortunately, a small amount of maintenance is required to improve this process”

    This exploit was confirmed by a user over at Neogaf, you can see the details about it HERE.

    [VIA Nyleveia]

    Tags: , ,

    Discuss in Forums (46)


  • 46 Comments

    1. austindriver13
      05-18-2011
      09:42 AM
      1

      Jesus...By far the most incompetent company I've ever seen!

    2. BobbyBlunt
      05-18-2011
      09:47 AM
      2

      Sony anyone with a 2 year degree in networking would handle this situation better than your so called "engineers" could. Sony you are killing the possibility of anyone buying a PS4

    3. ShadowDaemon
      05-18-2011
      09:53 AM
      3

      but people can still use the psn network services?online and stuff?

    4. Rogerdodger91
      05-18-2011
      09:57 AM
      4

      ill buy a ps4 if i can hack it.

    5. dreamcrawler
      05-18-2011
      10:14 AM
      5

      yet again?

      Ok i'm tired of reading. I rather wait for the movie. Because this is getting so epic it does deserve a movie indeed

    6. bigo93
      05-18-2011
      10:15 AM
      6

      OMG! I am laughing so hard right now!

      First the breach
      Then unappreaciated appreciation program
      And now this!

      Honestly you cant make this stuff up! :D

      Drat this doesnt affect those who already have changed their passwords and can still log in on their console

    7. $n!pR
      05-18-2011
      10:22 AM
      7

      If you know the e-mail address and date of birth you can reset the password to a lot of things...

    8. mars
      05-18-2011
      10:33 AM
      8

      I tried resetting my password yesterday (as it has been so long since I used PSN I honestly couldn't remember it), & they said to be patient receiving the email... it came early this morning, when I was still in bed!

    9. Amendment01
      05-18-2011
      10:39 AM
      9

      Originally Posted by $n!pR View Post
      If you know the e-mail address and date of birth you can reset the password to a lot of things...
      So true... so true...

    10. alienkid
      05-18-2011
      10:55 AM
      10

      Wow.

      What a fiasco!

    11. PS3Ftw
      05-18-2011
      10:55 AM
      11

      Now they just need better things then just 2old ps3 games...
      If they can...
      Let psn store be free sure now no one would spent their creditcard lols.

    12. $n!pR
      05-18-2011
      11:07 AM
      12

      Ok, so what happens is after you try to reset your password you get an email confirmation link. Somehow they bypass using the confirmation link to reset your password.

    13. URETROID
      05-18-2011
      11:11 AM
      13

      Mother ****ers, the next thing will be what ?! Explosion of our ps3 or what. Now I'm glad, no mercy with download !

    14. LuckySnake
      05-18-2011
      11:51 AM
      14

      Thank goodness, most of us cfw users don't care for online as much as the next.

    15. Wolfie708
      05-18-2011
      11:59 AM
      15

      I could do a better job than Sony, and I am absolutely useless lol

    16. CrystalWolf
      05-18-2011
      12:40 PM
      16

      Just one word. Why. This is pure torture .

    17. Raw1ofthegreats
      05-18-2011
      12:49 PM
      17

      See!! Thats why im not on psn and wont be for the foreseeable future. im on 3.60 and will be untill a new cfw or mfw come out for my firmware i knew something was up when the japs declined the online service as if they knew something was wrong with it. I truly hope u ingenious guys around here could figure out a solution for those of us who was forced upon 3.60 due to sending in their console for repair cause otherwise were stuck here 4ever! lol

    18. chaosity
      05-18-2011
      12:58 PM
      18

      Originally Posted by Raw1ofthegreats View Post
      See!! Thats why im not on psn and wont be for the foreseeable future. im on 3.60 and will be untill a new cfw or mfw come out for my firmware i knew something was up when the japs declined the online service as if they knew something was wrong with it. I truly hope u ingenious guys around here could figure out a solution for those of us who was forced upon 3.60 due to sending in their console for repair cause otherwise were stuck here 4ever! lol
      Off topic I know, and apologise, but they force an update on you if you send in your PS3 for repair? Sounds very dodgy to me, but what isnt with Sony atm :P

    19. Rated-R Superstar
      05-18-2011
      01:13 PM
      19

      PS Blog Update - Sony Denies Hack

      We temporarily took down the PSN and Qriocity password reset page. Contrary to some reports, there was no hack involved. In the process of resetting of passwords there was a URL exploit that we have subsequently fixed.Consumers who haven?t reset their passwords for PSN are still encouraged to do so directly on their PS3. Otherwise, they can continue to do so via the website as soon as we bring that site back up.
      Source: http://blog.eu.playstation.com/2011/...reset-process/

    20. PS3Ftw
      05-18-2011
      01:17 PM
      20

      Originally Posted by Raw1ofthegreats View Post
      See!! Thats why im not on psn and wont be for the foreseeable future. im on 3.60 and will be untill a new cfw or mfw come out for my firmware i knew something was up when the japs declined the online service as if they knew something was wrong with it. I truly hope u ingenious guys around here could figure out a solution for those of us who was forced upon 3.60 due to sending in their console for repair cause otherwise were stuck here 4ever! lol
      There will be no 3.60cfw.
      If there will be a 3.60cfw there will be also a 3.61cfw.
      Be serious..

    21. potlick
      05-18-2011
      01:20 PM
      21

      HAHAHAHAHAH

      i knew this was gonna happened. thats why i stayed off. i couldnt trust them to get right the first time. hell i wouldnt trust em fixing it the last. SONY needs to be sent into the corner for fvken up. i wish congress would step up and do something about this. this is ironic.

    22. bigo93
      05-18-2011
      01:23 PM
      22

      Well it wasnt a hack, it was a huge **** up! They thought the process was secure, but forgot the hackers had all the details to fill in the form. For those email accounts they did not have passwords, they found a loophole in the process so didnt have to have access any way.

      So they cannot blame anyone here apart from themselves!

    23. Raw1ofthegreats
      05-18-2011
      02:12 PM
      24

      Originally Posted by PS3Ftw View Post
      There will be no 3.60cfw.
      If there will be a 3.60cfw there will be also a 3.61cfw.
      Be serious..
      do you know how many times ive read about someone updating and missing out on a cfw too many times too count. you cant just say what will or wont happen, especially if your not one of those people who make it happen. yo im not being a dick or nothing i just feel the only way to be safe is to stay put. you never know what sony snuck into 3.61, also its live meaning that whats in 3.61 can also be tampered with by sony just from me logging in. with these rootkits im hearing about. so what we know? 3.60 is old like 3.56 better chance of those ofw being hacked. just cause the number is only 3.61 a .01 change dosent mean its exactly like 3.60. think about it PSN was HACKED !!! if anything is still the same from firmware to network then sony need they ass whipped for stupidity!! just my opinion tho

    24. DaveOMac
      05-18-2011
      02:22 PM
      25

      Oh for lords sake...

    25. bigo93
      05-18-2011
      02:32 PM
      26

      Originally Posted by Raw1ofthegreats View Post
      do you know how many times ive read about someone updating and missing out on a cfw too many too count you cant just say what will or wont happen especially if your not one of those people who make it happen. yo im not being a dick or nothing i just feel the only way to be safe is to stay put you never know what sony snuck into 3.61 also its live meaning that whats in 3.61 can also be tampered with by sony just from me logging in with these rootkits im hearing about. so what we know? 3.60 is old like 3.56 better chance of those ofw being hacked. just cause the number is only 3.61 a .01 change dosent mean its exactly like 3.60 think about it 3.60 was HACKED !!! if anything is still the same from firmware to network then sony need they ass whipped for stupidity!! just my opinion tho

      Well I hear lots of people turned in their ps3 for xboxes or just sold them. I also hear that sony may reduce the price of the ps3 the summer.

      As with having hacked consoles, the general rule these days is have 2 consoles, use one to hack and the other to stay official, this way you will have the best of both world.

      As as stated above, the price of 2nd hand ps3s will fall, so a lot more people will be able to afford a second console, they just have to hope that they are 3.55 or that someone releases a cfw3.61

    26. babyfacecuz
      05-18-2011
      04:00 PM
      27

      or do like i did and have bro give u his broke one and spend 80 bucks for a blue ray and fix it.. now i have best of both worlds

    27. AgentFortyS3v3n
      05-18-2011
      04:34 PM
      28

      Just close down the PSN permanently. Since PSN got hacked my linked email account that never once got spam has been spammed constantly since.

    28. jfeddd
      05-18-2011
      05:48 PM
      29

      you guys are ****ing idiots if you new squat then you would have figured out that all they are doing is stepping up the security it takes to reset your account and if i guess right you probably don't need to use a activated ps3 anymore.

    29. Mystt
      05-18-2011
      06:47 PM
      30

      You have to be surprised at how such a big corporation can fail so badly at keeping their security up to date.
      No.. Not really... no... there is no surprise here at all.

    30. ZOMBIEKILLAH
      05-18-2011
      07:05 PM
      31

      Originally Posted by Raw1ofthegreats View Post
      See!! Thats why im not on psn and wont be for the foreseeable future. im on 3.60 and will be untill a new cfw or mfw come out for my firmware i knew something was up when the japs declined the online service as if they knew something was wrong with it. I truly hope u ingenious guys around here could figure out a solution for those of us who was forced upon 3.60 due to sending in their console for repair cause otherwise were stuck here 4ever! lol
      lol , I did the same thing .I stayed on 360 and away from psn. even though i wanted to change my password .I have a serious amount of dlc & money spent in it. So i just want to keep my account active . i had a bad fealing about sony getting hacked again. I believe sony will possably get hacked again ,looks like someone wants to teach sony a serious lesson = no matter what the consequence . p.s. i love my cfw 355 ps3 sony ,it is great much more to offer than your apps

    31. Amendment01
      05-18-2011
      08:04 PM
      32

      "Contrary to some reports, there was no hack involved. In the process of resetting of passwords there was a URL exploit that we have subsequently fixed."

      Originally Posted by Rated-R Superstar View Post
      PS Blog Update - Sony Denies Hack
      Source: http://blog.eu.playstation.com/2011/...reset-process/
      Definition of hack:
      To gain access to (a computer file or network) illegally or without authorization.

      @Sony, quit talking yourselves up! Admit when you are wrong!
      You are definitely losing future customers... At least, I know you lost this one!!

    32. Vulcanraven
      05-18-2011
      08:43 PM
      33

      I think Sony means a new
      UNSECURITY UPDATE

      I laughed so hard what a big fail haha
      such a big fail for sony...

    33. Shezed
      05-19-2011
      06:54 AM
      34

      Can hackers please make their own psn, i'm sure it will be safer than the real one

    34. Mystt
      05-19-2011
      08:33 AM
      35

      Can hackers please make their own psn, i'm sure it will be safer than the real one
      Why not? Set up a VPN-PSN. Tho to get it on such a grand scale to affect users world wide would be a challenge, it's definitely possible. Only you'd be missing out on "off the launch" game updates, as well as a few other services.

    35. VideoX
      05-19-2011
      10:30 AM
      36

      Originally Posted by mars View Post
      I tried resetting my password yesterday (as it has been so long since I used PSN I honestly couldn't remember it), & they said to be patient receiving the email... it came early this morning, when I was still in bed!
      When I reseted my account, they send me an e-mail that took almost 2 hours to arrive, and it said that I had 3 hours left until the link expired. So, how can they say the e-mails took up to 24 hours and then giving us a deadline of 3?.

      Lucky me I was awake that night, but as mars staed before, he was sleeping.

      Originally Posted by chaosity View Post
      Off topic I know, and apologise, but they force an update on you if you send in your PS3 for repair? Sounds very dodgy to me, but what isnt with Sony atm :P
      They give back to you, the repaired machine (PS3 or PSP as well) with the OFW updated. They don't force you to update it, they do it for you as part of the "repairing process".

      ---------------------------------------

      Now for the movie, on this Winter holidays, maybe I will start making a movie, with interviews and stuff like that. This is going from amaze to anger to pitty to laugh.

    36. LuckySnake
      05-19-2011
      02:31 PM
      37

      VideoX, you can request that they not update the fw. This works if you take it in. Not sure about shipping it.

    37. sangrenegrv
      05-19-2011
      05:08 PM
      38

      I sold my Muteki, i sold my ps3, bye bye sony for ever... Force to graf against the mafia.

    38. danbreen2
      05-19-2011
      05:09 PM
      39

      Originally Posted by babyfacecuz View Post
      or do like i did and have bro give u his broke one and spend 80 bucks for a blue ray and fix it.. now i have best of both worlds
      R do what i did and buy 2 broke ps3s of me mate for 40 euros and fix the lasers with a cotton bud and an alcohol swab, now iv 3 ps3s and can only play 1 at a time lol

    39. VideoX
      05-19-2011
      07:42 PM
      40

      Originally Posted by LuckySnake View Post
      VideoX, you can request that they not update the fw. This works if you take it in. Not sure about shipping it.
      Really?, didn't know that. If you ship it, then add a note written in big bold red capital letters, e.g. "DO NOT UPDATE ME!!!" or something.

    40. CrystalWolf
      05-20-2011
      10:30 AM
      41

      Originally Posted by VideoX View Post
      Really?, didn't know that. If you ship it, then add a note written in big bold red capital letters, e.g. "DO NOT UPDATE ME!!!" or something.
      They would then may know why you don't want the firmware to be updated.

    41. systematic
      05-20-2011
      04:43 PM
      42

      Originally Posted by AgentFortyS3v3n View Post
      Just close down the PSN permanently. Since PSN got hacked my linked email account that never once got spam has been spammed constantly since.
      lol i got spam shut psn down

    42. VideoX
      05-20-2011
      07:56 PM
      43

      Originally Posted by CrystalWolf View Post
      They would then may know why you don't want the firmware to be updated.
      True, but they can't force to update if I don't want to. I really liked the older PS3 booting sound, and the lower OFW where more stable than the last ones.

    43. Silent657
      05-21-2011
      01:10 PM
      44

      yeah from the looks of it sony is heading down hill.

      YouTube - ‪Sony Playstation Network Gets Hacked.....Again‬‏

    44. fuzzydunlop
      05-21-2011
      04:33 PM
      45

      Sony FAILED once again! This does not even surprise me

    45. DaveOMac
      05-21-2011
      04:42 PM
      46

      Well would you expect anything less from the makers of PSN (Pants Security Network) ? I done my old "master of disguise" earlier today and broke into So-Net's technical support earlier. Took this picture of Sonys Chief Security officer as he taught his new staff on the ways of protecting a network.