black_vegeta
Member
Kinyou said:So, are we all fucked?
Yes, No, Maybe
Kinyou said:So, are we all fucked?
Thanks for the confirmation, though a bit of common sense was all we really needed for to debunk it. I do appreciate your work though and it's nice that we can finally put that matter to bed.Fireye said:Tempy linked me to this blog on irc, and I took the time to crawl through logs and debunk it.
The linked server is a gracenote db server, related to cddb/music identification. In no way was this server compromised by the stuff the blogger highlighted, it's a fairly normal security/vulnerability scan (from the looks of it).
See my fuller responses (and amused findings) at the blog site: http://shockwavelounge.blogspot.com/2011/04/playstation-network-log-of-hacker.html
BoilersFan23 said:I doubt that sending out 75+ million emails will take a day.
Considering the amount of FUD going around in this thread, I guess it's excusable.Hylian7 said:Is it sad that I just got scared for a minute that Steam went down?
dallow_bg said:Yup. This is like the 4th or so company in which my personal information may or may not have been accessed.
I take care of my finances, so I'm not worried.
Vinci said:They should have them all on file, never mind the fact that they've had six days.
Rebug most likely had nothing to do with the hack itself. While people used it to get games for free (and I'm sure Sony will not take this lightly, and I fully support them going after the morons who exploited this), and didn't give them any special access to anything on PSN, "just" the ability to add money to their account.Dreamgazer said:*stare at an entire tutorial thread about how to set up fake credit card number on nextgen*BEEP*date site*
(don't believe me? google it)
RIGHTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTT
Oh, I'm sorry, the kiddies at that site are probably more knowledgeable
Please note that we are as upset as you are regarding this attack and are going to proceed aggressively to track down those that are responsible.
If you're smart enough to hack PSN, you probably know how to spoof an IP. Or atleast not dumb enough to do the hacking from work.Morn said:Here's the IP info for the person who apparently hacked PSN:
Either the guy is in the military, or was spoofing his IP.
baekshi said:has anyone got there email from sony yet?
Vinci said:They should have them all on file, never mind the fact that they've had six days.
Vestal said:Ok let me give you a nice little pictorial if you will of what happend.
You have a bunch of hungry SoBs with machetes(Hackers) walking around outside your establishment, but they don't have a key to get in. You see them go into other places but hey your ok, they dont have your key. Now you find out that you missplaced your key and it might have been Duplicated, instead of taking steps to say change the locks, or add security within your establishment to guard that meat locker in the back, you go about your business.
few days later you are surprised when you find a machete attached to your skull...
Y2Kev said:I kind of don't care about my identity. I really want to link my steam account though so if sony could hurry that up thanks be to Ken.
Cth said:Fixed.
user_nat said:If you're smart enough to hack PSN, you probably know how to spoof an IP. Or atleast not dumb enough to do the hacking from work.
Ignorant mainstream media. Give the PSP some credit too!herod said:https://twitter.com/charltonbrooker/status/63006614508150784
I guess this will be on 10 o'clock live this week.
I dunno but I like reading all the armchair experts who are going to come out of the woodwork along with tin foilers how he is gonna get caught or elude the law etc. should be good.Zoibie said:Considering this dude would most likely be behind all manner of proxies and such, how likely is it that Sony/the authorities will catch this guy?
FINALBOSS said:...And then you crybabies would complain that the speedy e-mail didn't have ANY sort of information in it.
It obviously took this long because they were figuring out what exactly happened.
You're not concerned about that now? Is there any chance it'll mean Sony have any Steam details?Y2Kev said:I kind of don't care about my identity. I really want to link my steam account though so if sony could hurry that up thanks be to Ken.
jim-jam bongs said:Yes, Microsoft's extensively documented security fuck ups from a decade ago are absolutely in the same realm as every PSN user's account being compromised.
black_vegeta said:Yes, No, Maybe
Blimblim said:Rebug most likely had nothing to do with the hack itself. While people used it to get games for free (and I'm sure Sony will not take this lightly, and I fully support them going after the morons who exploited this), and didn't give them any special access to anything on PSN, "just" the ability to add money to their account.
CFW firmwares on PS3 allowed people to add their own SSL CA certificate to the ones the PS3 would accept, which enabled them to have proxies who actually would decrypt the PSN https protocol. Someone more than likely found an SQL injection among some of the POST or GET parameters the PS3 sends to the PSN webservices, and exploited it.
Jax said:How are you guys changing passwords etc? Is the service up?
Jax said:How are you guys changing passwords etc? Is the service up?
arnoldocastillo2003 said:It is false the information about the 75,000 credit cards stolen.
black_vegeta said:Yes, No, Maybe
Just use psn/xbl cards like I doShin Dynamo X said:Hey yo son....shit just got mad real up in this punk ass bitch.
http://www.cnn.com/2011/TECH/gaming.gadgets/04/26/playstation.network.hack/index.html
It's major now...sell your stock people. Time to trade in my PS3 fighters for 360 versions now. No more PSN purchases for me, I am not taking any more chances. I'm not saying that 360 is hackproof, but until it happens then i have no other options.
If 360 gets hacked, I am freaking going portable then.
Dreamgazer said:*stare at an entire tutorial thread about how to set up fake credit card number on nextgen*BEEP*date site*
(don't believe me? google it)
RIGHTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTT
Oh, I'm sorry, the kiddies at that site are probably more knowledgeable
PCI-DSS compliance, even at level 2, is quite a burden, it's true. You have to change the way you work to get full compliance, and many companies simply can't afford it completely. Level 1 involves very costly 3rd party audits, but you can't normally cheat and simply say that you are compliant.Jackl said:I wanted to post something witty, but failed miserably. I was just a dumb kid when my credit got hijacked. By the time I found out and worked to get it fixed it took the better part of a year, lots of paperwork, and arguing with creditors to clear it up.
For what its worth in Sony's defense(even though they fucked up massively)
67% of companies fail CC security standards
Shambles said:Wow at the Sony defenders. So you must all be ok with storing all your money in a bank with a huge vault door, laser beams, attack dogs and sniper in front of the door and then wonder how all your money got stolen when there's a screen door half off it's hinges on the back wall of the vault.
It's dem robbers fault!
pantyhelmet said:what they did, was 100% illegal, no matter what their motives, if one of their own went rouge and accessed that info due to what they were able to accomplish during their QUEST FOR JUSTICE *echo* , then they are ALL at fault, need i spell it out? Not too long ago about 42 claiming to be members of anonymous were arrested for similar actions. be serious.
I donno dude, not trying to be a dick, ARK's points are a lot more clear and straight to the point, I couldn't really make anything out of Blimblim's..."rescue"kamorra said:Blimblim to the rescue:
Even still, if you bought anything there is a chance it could be in the server logs.jackdoe said:Thank god I removed my card a week before this shit happened. Still, I'll monitor my cards just in case. Other than that, I am peeved at Sony for taking this long to at least share some suspicions so that users could at least make password changes.