Sony investigating another hack

23:39 • 03.06.11

Sony is investigating another hacking attack on one of its websites, the third major attack since April.

A group called Lulz Security claims to have broken into Sonypictures.com and accessed details of a million users, the BBC News reported.

Passwords, home addresses and other personal information relating to several thousand of the accounts was released online.
Details of the latest attack were made available on the recently created Lulz Security website.

A LulSec press release said: "SonyPictures.com was owned by a very simple SQL injection, one of the most primitive and common vulnerabilities, as we should all know by now.

"From a single injection, we accessed EVERYTHING. Why do you put such faith in a company that allows itself to become open to these simple attacks?".

SQL attacks are generally regarded as one of the more straightforward ways of gaining unauthorised access to a website.

Typically, an attacker will attempt to bypass the username and password system by sending code or characters that confuse the site's programming.

The release also claims that user information on Sonypictures.com was stored in unencrypted, plain text format.

LulSec explained that it was unable to make the entire user database available, however it released a portion of it, totalling roughly 50,000 users.

Sony has yet to respond to the claims, but said in a tweet: "We are looking into the claims about reports of attacks on Sony Pictures websites. Please follow us for latest updates."

Mikko Hypponen, chief research officer at security firm F-Secure, said that another Sony breach had been almost inevitable.
"I'm not surprised by anything about Sony anymore," he told BBC News.

"It will be hard for a company of that size to make sure they are secure if someone wants to go and find holes."

 

Sony investigating another hack