Page 1 of 2 12 LastLast
Results 1 to 25 of 33

Thread: Sony Network Said to Have Been Invaded by Hackers Using Amazon.com Server

  1. #1
    Xtreme Member xytrius's Avatar
    Join Date
    Feb 2005
    Location
    Chicago
    Posts
    473

    Sony Network Said to Have Been Invaded by Hackers Using Amazon.com Server

    Excerpts from Bloomberg:

    Amazon.com Inc. (AMZN)’s Web Services cloud- computing unit was used by hackers in last month’s attack against Sony Corp. (6758)’s online entertainment systems, according to a person with knowledge of the matter.

    Hackers using an alias signed up to rent a server through Amazon’s EC2 service and launched the attack from there, said the person, who requested anonymity because the information is confidential. The account has been shut down, the person said.

    The development sheds light on how hackers used the so- called cloud to carry out the second-biggest online theft of personal information to date. The incursion, which compromised the personal accounts of more than 100 million Sony customers, was “a very carefully planned, very professional, highly sophisticated criminal cyber attack,” Sony has said.

    ...

    The hackers didn’t break into the Amazon servers, the person said. Rather, they signed up for the service just as a legitimate company would, using fake information.

    ...

    Amazon fell $3.51, or 1.7 percent, to $202.56 yesterday in Nasdaq Stock Market trading. The shares have added 13 percent this year. Sony lost 23 yen to 2,241 yen in Tokyo and have slid 23 percent in 2011.

    Sony offered customers a free year of identify-theft protection after its PlayStation Network and Qriocity entertainment networks were crippled by the attack. Thieves may have stolen credit-card, debit records and other personal information from customers of Sony Online Entertainment, a third service. The New York Attorney General’s office has subpoenaed Sony, according to a person familiar with the probe.
    Source and full information: http://www.bloomberg.com/news/2011-0...om-server.html

  2. #2
    YouTube Addict
    Join Date
    Aug 2005
    Location
    Klaatu barada nikto
    Posts
    17,574
    1) it wasn't done by hackers. It was done by criminals.
    2) Hackers create and invent. [Hackers are the roots of all technological and social advancement in the history of mankind.]
    3) Criminals that use computers are just that criminals. Nothing else and nothing more.
    4) Mistaking the two is like mistaking a doctor and a pedophile. Just because they both see kids, doesn't mean they are the same thing.
    Fast computers breed slow, lazy programmers
    The price of reliability is the pursuit of the utmost simplicity. It is a price which the very rich find most hard to pay.
    http://www.lighterra.com/papers/modernmicroprocessors/
    Modern Ram, makes an old overclocker miss BH-5 and the fun it was

  3. #3
    Xtreme Addict
    Join Date
    Jan 2009
    Posts
    1,445
    Quote Originally Posted by nn_step View Post
    1) it wasn't done by hackers. It was done by criminals.
    2) Hackers create and invent. [Hackers are the roots of all technological and social advancement in the history of mankind.]
    3) Criminals that use computers are just that criminals. Nothing else and nothing more.
    4) Mistaking the two is like mistaking a doctor and a pedophile. Just because they both see kids, doesn't mean they are the same thing.


    i give you all the internets!
    [MOBO] Asus CrossHair Formula 5 AM3+
    [GPU] ATI 6970 x2 Crossfire 2Gb
    [RAM] G.SKILL Ripjaws X Series 16GB (4 x 4GB) 240-Pin DDR3 1600
    [CPU] AMD FX-8120 @ 4.8 ghz
    [COOLER] XSPC Rasa 750 RS360 WaterCooling
    [OS] Windows 8 x64 Enterprise
    [HDD] OCZ Vertex 3 120GB SSD
    [AUDIO] Logitech S-220 17 Watts 2.1

  4. #4
    Banned Movieman...
    Join Date
    May 2009
    Location
    illinois
    Posts
    1,809
    Quote Originally Posted by nn_step View Post
    1) it wasn't done by hackers. It was done by criminals.
    2) Hackers create and invent. [Hackers are the roots of all technological and social advancement in the history of mankind.]
    3) Criminals that use computers are just that criminals. Nothing else and nothing more.
    4) Mistaking the two is like mistaking a doctor and a pedophile. Just because they both see kids, doesn't mean they are the same thing.
    they did make sony re invent there lack of security. so you cant say they didn't do something good LOL

  5. #5
    Xtreme Member
    Join Date
    Jan 2009
    Posts
    203
    i know what you're trying to say...but really: hackers and criminals aren't exactly mutually exclusive descriptions.

  6. #6
    Xtreme Enthusiast
    Join Date
    Jan 2007
    Location
    QLD
    Posts
    942
    Sony is learning the hard way that in a world of crooks you don't leave your pants down.

  7. #7
    I am Xtreme zanzabar's Avatar
    Join Date
    Jul 2007
    Location
    SF bay area, CA
    Posts
    15,871
    amazon was shown to have easy access to cpu time for brute force decryption but i dont see how this is anything more than a proxy as it was not a brute force attack. and the sony attack was supposed to be an inside job from the data center so i dont see how this is related other than being japanese companies in the normal get your data stolen and send out mass emails about it.

    Quote Originally Posted by Dainas View Post
    Sony is learning the hard way that in a world of crooks you don't leave your pants down.
    isnt that, in a world of rapist dont leave your pants down, or, in a world of thieves dont leave your door unlocked, i dont see how crooks would care about pants unless thats what they wanted.
    5930k, R5E, samsung 8GBx4 d-die, vega 56, wd gold 8TB, wd 4TB red, 2TB raid1 wd blue 5400
    samsung 840 evo 500GB, HP EX 1TB NVME , CM690II, swiftech h220, corsair 750hxi

  8. #8
    Xtreme Member
    Join Date
    Apr 2008
    Location
    Hiding under a blanky with a flash light
    Posts
    192
    Quote Originally Posted by nn_step View Post
    1) it wasn't done by hackers. It was done by criminals.
    2) Hackers create and invent. [Hackers are the roots of all technological and social advancement in the history of mankind.]
    3) Criminals that use computers are just that criminals. Nothing else and nothing more.
    4) Mistaking the two is like mistaking a doctor and a pedophile. Just because they both see kids, doesn't mean they are the same thing.
    You make it sound so antiseptic and black/white. Life is not like that.

  9. #9
    Xtreme Addict
    Join Date
    Feb 2008
    Location
    Denmark / Aarhus
    Posts
    1,036
    Quote Originally Posted by BatteryOperated View Post
    You make it sound so antiseptic and black/white. Life is not like that.
    It IS black and white

    There are Whitehats and blackhats (Good and bad) and Hackers and Crackers (Same thing)
    Desktop I5-3570k, 8GB Ram, GTX 560, Silverstone TJ08-E, Crucial M4 128GB, 750W Silver Power, ASUS P8Z77-M
    Laptop ThinkPad W520 2720QM /2 x 4 GB ram / Quadro 1000M / Crucial M4 128GB + 500Gb Hdd / FHD Screen / Intel WiFi Link 6300 AGN WLAN / 9 Cell Battery
    Laptop 2 New Macbook Pro Retina / i7 QuadCore / 650 GT / 16GB Ram / 512 GB SSD
    Server: Athlon II X4 640, ASROCK K10N78, 8GB Ram, LSI MegaRaid 8 port, 64GB Vertex 1, 5 x 1 TB WD Raid6, 3 x 3TB Seagate Raid5

  10. #10
    Xtreme CCIE
    Join Date
    Dec 2004
    Location
    Atlanta, GA
    Posts
    3,842
    Quote Originally Posted by zanzabar View Post
    amazon was shown to have easy access to cpu time for brute force decryption but i dont see how this is anything more than a proxy as it was not a brute force attack. and the sony attack was supposed to be an inside job from the data center so i dont see how this is related other than being japanese companies in the normal get your data stolen and send out mass emails about it.
    +1


    I actually have first-hand experience with Sony's network from a global perspective, and I can say with confidence that this attack was not carried out by "sophisticated" people... or if it was they went out of their way to make their job unnecessarily complicated. Without even sitting down to really mull it over I'm pretty sure I can come up with at least a dozen ways to severely cripple their network or steal data from it.

    Doubly so now that they recently (in the last 18 months) brought all of their equipment in-house, as opposed to having outside companies handle most of it... training and experience takes time to build and has undoubtedly left them more vulnerable over the transition period.

    So yeah, take it from someone with first hand experience in their environment... this was surely not a difficult accomplishment at all. Unless the "hackers" had no idea what they were doing and tried breaking in through the worst possible vector.
    Dual CCIE (Route\Switch and Security) at your disposal. Have a Cisco-related or other network question? My PM box is always open.

    Xtreme Network:
    - Cisco 3560X-24P PoE Switch
    - Cisco ASA 5505 Firewall
    - Cisco 4402 Wireless LAN Controller
    - Cisco 3502i Access Point

  11. #11
    Xtreme Enthusiast
    Join Date
    Aug 2007
    Posts
    668
    Quote Originally Posted by zanzabar View Post
    amazon was shown to have easy access to cpu time for brute force decryption but i dont see how this is anything more than a proxy as it was not a brute force attack. and the sony attack was supposed to be an inside job from the data center so i dont see how this is related other than being japanese companies in the normal get your data stolen and send out mass emails about it.



    isnt that, in a world of rapist dont leave your pants down, or, in a world of thieves dont leave your door unlocked, i dont see how crooks would care about pants unless thats what they wanted.
    It is possible Sony was using Amazon to host some services and used Amazon to get access to some Sony services.

  12. #12
    Xtreme Member
    Join Date
    Jan 2011
    Location
    Orelia
    Posts
    316
    All the information that I have collected on this so far can be found here if people would like to have a look --> http://www.nrnl.org/psn-network-breach-thread-t705.html

    Add me on Facebook
    -=<#*!! 5OUnD PHr33K !!*#>=-

  13. #13
    Xtreme Member
    Join Date
    Oct 2008
    Posts
    115
    Quote Originally Posted by nn_step View Post
    1) it wasn't done by hackers. It was done by criminals.
    2) Hackers create and invent. [Hackers are the roots of all technological and social advancement in the history of mankind.]
    3) Criminals that use computers are just that criminals. Nothing else and nothing more.
    4) Mistaking the two is like mistaking a doctor and a pedophile. Just because they both see kids, doesn't mean they are the same thing.
    It was done by hackers some are criminals and some aren't. As far as I am concerned these ones aren't unless they plan to use the information they stole for their personal monetary gain. If it was simply a hack to embarrass Sony then it's a grey area.

    It's also nothing like comparing a pedophile and doctor it's more like comparing a paediatrics doctor and Josef mengele "the angel of death" both are doctors but in very different ways.

  14. #14
    Hackintosh Lover
    Join Date
    Aug 2009
    Location
    Between London & Eastbourne, United Kingdom
    Posts
    559
    Is quite dissapointed that a company like Sony cant seem to fix a their Security/Network problem.... is been a while now and their network still down (so I heard) I mean I know even the greatest have to learn from others... And to be honest they had it coming for not listening to their customers and keep dismissing them like that.... BUT I spected more from Sony...
    Why Not Try a Hackintosh for A Change?? Steps HERE!!
    Want to installing Mountain/Lion from a DVD or USB on you Apple PC?? Steps Here!


    Super Stable aKa 24/7




    Winners of EURO 08 | World Cup 10 | EURO 12
    Quote: Killin' Tube Kinks One Coil At A Time
    Hackintosh Lover
    "Dumb people" shouldn't use "Smart Phones"


    New Personal Wallpapers Selection

  15. #15
    Xtreme Enthusiast
    Join Date
    Nov 2006
    Posts
    799
    I logged into PSN yesterday afternoon and there was a console update and forced password change waiting for me. I'm just glad I don't have to go through all the BS just to watch Netflix now. I'm also glad I didn't pay for anything with Sony, including the PS3 itself.

  16. #16
    I am Xtreme zanzabar's Avatar
    Join Date
    Jul 2007
    Location
    SF bay area, CA
    Posts
    15,871
    Quote Originally Posted by WangChung View Post
    I logged into PSN yesterday afternoon and there was a console update and forced password change waiting for me. I'm just glad I don't have to go through all the BS just to watch Netflix now. I'm also glad I didn't pay for anything with Sony, including the PS3 itself.
    you should not need psn to use netflix though, u dont need it be logged in but it naggs at u, and there is no need for it to be logged in at all.
    5930k, R5E, samsung 8GBx4 d-die, vega 56, wd gold 8TB, wd 4TB red, 2TB raid1 wd blue 5400
    samsung 840 evo 500GB, HP EX 1TB NVME , CM690II, swiftech h220, corsair 750hxi

  17. #17
    Xtreme X.I.P.
    Join Date
    Nov 2002
    Location
    Shipai
    Posts
    31,147
    I love this whole thing... karma is a ... Sony got what it deserved imo

  18. #18
    Xtreme Enthusiast
    Join Date
    Jan 2007
    Location
    QLD
    Posts
    942
    Some hackers like a challenge true; but even with the most sophisticated hackers, had Sony not been so complacent the damage would have been far more limited. And yet here we are, a month later and they've just finished up the fixes they've deemed necessary; a bit more time than needed check the old locks.
    Last edited by Dainas; 05-16-2011 at 08:42 PM.

  19. #19
    Xtreme Enthusiast
    Join Date
    Dec 2008
    Posts
    811
    Quote Originally Posted by nn_step View Post
    1) it wasn't done by hackers. It was done by criminals.
    2) Hackers create and invent. [Hackers are the roots of all technological and social advancement in the history of mankind.]
    3) Criminals that use computers are just that criminals. Nothing else and nothing more.
    4) Mistaking the two is like mistaking a doctor and a pedophile. Just because they both see kids, doesn't mean they are the same thing.
    The correct term is "crackers" to be honest.
    [SIGPIC][/SIGPIC]

  20. #20
    Xtreme Cruncher
    Join Date
    Mar 2010
    Posts
    451
    I wonder whether the attackers used a gift card or a stolen card to establish EC2 services? If Amazon still allows the use of gift cards for EC2, they might want to re-think that policy. In any event, it's another (albeit small) black eye for their web services.

    Quote Originally Posted by Serra View Post
    I actually have first-hand experience with Sony's network from a global perspective, and I can say with confidence that this attack was not carried out by "sophisticated" people... or if it was they went out of their way to make their job unnecessarily complicated. Without even sitting down to really mull it over I'm pretty sure I can come up with at least a dozen ways to severely cripple their network or steal data from it.

    Doubly so now that they recently (in the last 18 months) brought all of their equipment in-house, as opposed to having outside companies handle most of it... training and experience takes time to build and has undoubtedly left them more vulnerable over the transition period.

    So yeah, take it from someone with first hand experience in their environment... this was surely not a difficult accomplishment at all. Unless the "hackers" had no idea what they were doing and tried breaking in through the worst possible vector.
    Wow. If a network with tens of millions of users run by one of the largest corporations in the world can be brought down by unsophisticated criminals, it kinda makes you wonder how many others are vulnerable. And surprise, Sony has a very different opinion of their attackers abilities. From the Bloomberg article:
    The incursion, which compromised the personal accounts of more than 100 million Sony customers, was “a very carefully planned, very professional, highly sophisticated criminal cyber attack,” Sony has said.


    Looks like judging the sophistication of this attack is a matter of one's perspective and level of knowledge in these matters. Unlike a lot of folks here, I barely know enough to setup/run my home's LAN. So, I'll judge the level of sophistication of Sony's attackers by the amount of time it takes for them to get caught. Caught tomorrow...unsophisticated. Caught never...pretty damn sophisticated. I guess time will tell.

  21. #21
    Xtreme Member
    Join Date
    Jan 2008
    Location
    Traveling through time
    Posts
    480
    Quote Originally Posted by saaya View Post
    I love this whole thing... karma is a ... Sony got what it deserved imo
    I don't think you understand saaya, Sony's CUSTOMERS have been screwed over. People with bills to pay. That's not something to be celebrating over.

    That said, Sony is gonna be feelin' this one for a long time and with some of the they've pulled maybe they did deserve a little slap across the face. But this is just a bad situation for PSN subscribers...
    CPU: i5 3570k @ 4.2 Ghz
    Memory: 2x4gb Kingston HyperX @ 1600Mhz
    Graphics: Sapphire 6950 Toxic on BenQ XL2420TE
    Board: ASUS Sabertooth Z77
    Power: Corsair AX850W (70A)


    HEATware
    Currently playing: Planetside 2, Dead Space 3, Call of Juarez: Gunslinger

  22. #22
    Xtreme Addict
    Join Date
    Nov 2006
    Posts
    1,402
    no code are safe, ...

    and more your add code, more your code is unsafe ...

    so, just be carefull, when a company sell you CDs with rootkits ....

  23. #23
    Xtreme Member
    Join Date
    Jun 2009
    Posts
    145
    Quote Originally Posted by nn_step View Post
    1) it wasn't done by hackers. It was done by criminals.
    2) Hackers create and invent. [Hackers are the roots of all technological and social advancement in the history of mankind.]
    3) Criminals that use computers are just that criminals. Nothing else and nothing more.
    4) Mistaking the two is like mistaking a doctor and a pedophile. Just because they both see kids, doesn't mean they are the same thing.
    Guess what? You lost the PR war in the 90s. Very few care for the distinction between Crackers and Hackers made in the the 80s. Crackers/Black Hats are now synonymous with Hackers. Grow up with the times and the way our language has evolved.

  24. #24
    Xtreme Enthusiast
    Join Date
    Nov 2006
    Posts
    799
    Quote Originally Posted by zanzabar View Post
    you should not need psn to use netflix though, u dont need it be logged in but it naggs at u, and there is no need for it to be logged in at all.
    That's what I'm talking about though, having to go past the "You must be logged into the PlayStation Network to continue" nagging that it was doing. I had to force it like 8-10 times to finally get to the Netflix menu, just a nuisance more than anything. And now I don't have to deal with that.

  25. #25
    Xtreme Addict
    Join Date
    Dec 2003
    Location
    At work
    Posts
    1,369
    What's most exasperating is Sony's lax attitude toward security, continuing to run unpatched servers even after being informed of this fact.

    Yet, they're willing to remove and viciously defend the removal of the "Other OS" option on the PS3, arguing that the option posed a security risk!!

    I'd say the "Other OS" option is far less of a risk than Sony's poor attitude toward security.
    Server: HP Proliant ML370 G6, 2x Xeon X5690, 144GB ECC Registered, 8x OCZ Vertex 3 MAX IOPS 240GB on LSi 9265-8i (RAID 0), 12x Seagate Constellation ES.2 3TB SAS on LSi 9280-24i4e (RAID 6) and dual 1200W redundant power supplies.
    Gamer: Intel Core i7 6950X@4.2GHz, Rampage Edition 10, 128GB (8x16GB) Corsair Dominator Platinum 2800MHz, 2x NVidia Titan X (Pascal), Corsair H110i, Vengeance C70 w/Corsair AX1500i, Intel P3700 2TB (boot), Samsung SM961 1TB (Games), 2x Samsung PM1725 6.4TB (11.64TB usable) Windows Software RAID 0 (local storage).
    Beater: Xeon E5-1680 V3, NCase M1, ASRock X99-iTX/ac, 2x32GB Crucial 2400MHz RDIMMs, eVGA Titan X (Maxwell), Samsung 950 Pro 512GB, Corsair SF600, Asetek 92mm AIO water cooler.
    Server/workstation: 2x Xeon E5-2687W V2, Asus Z9PE-D8, 256GB 1866MHz Samsung LRDIMMs (8x32GB), eVGA Titan X (Maxwell), 2x Intel S3610 1.6TB SSD, Corsair AX1500i, Chenbro SR10769, Intel P3700 2TB.

    Thanks for the help (or lack thereof) in resolving my P3700 issue, FUGGER...

Page 1 of 2 12 LastLast

Tags for this Thread

Bookmarks

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •