Sony Pictures hacked

  • Thread starter Thread starter Assax
  • Start date Start date
  • Views Views 6,956
  • Replies Replies 57

Assax

Well-Known Member
Member
Joined
Sep 15, 2007
Messages
183
Solutions
1
Reaction score
1
Trophies
1
Age
34
Location
Germany
Website
Visit site
XP
180
Country
Gambia, The
LulzSec just posted that they have successfully hacked Sony Pictures compromising over data of over 1Million accounts.
Included are according to LulzSec: [/p]

QUOTE said:
... personal information, including passwords, email addresses, home addresses,
dates of birth, and all Sony opt-in data associated with their accounts.
Among other things, we also compromised all admin details of Sony Pictures
(including passwords) along with 75,000 "music codes" and 3.5 million "music coupons". ...

According to LulzSec they were able to grab all the data by a single SQL Injection, everything was stores in Plaintext format on Sony's servers.

Lulzsec has before announced their Project Sowange to start on May 31st.

Update: Link removed
Update 2:

Sony claims that no hacks were detected and nothing has happened to Sony Pictures

http://www.ibtimes.com/articles/156397/201...hacked-sony.htm
Thanks to Joe88

Update 3:
Yesterday (03.06.2011) Sony has CONFIRMED that Sony Pictures was hacked.
http://news.cnet.com/8301-31021_3-20068857.../?tag=mncol;txt

QUOTE said:
"The cybercrime wave that has affected Sony companies and a number of government agencies, businesses, and individuals in recent months has hit Sony Pictures as well," the Sony statement reads.




QUOTE
Greetings folks. We're LulzSec, and welcome to Sownage. Enclosed you will
find various collections of data stolen from internal Sony networks and websites,
all of which we accessed easily and without the need for outside support or money.

We recently broke into SonyPictures.com and compromised over 1,000,000 users'
personal information, including passwords, email addresses, home addresses,
dates of birth, and all Sony opt-in data associated with their accounts.
Among other things, we also compromised all admin details of Sony Pictures
(including passwords) along with 75,000 "music codes" and 3.5 million "music coupons".

Due to a lack of resource on our part (The Lulz Boat needs additional funding!)
we were unable to fully copy all of this information, however we have samples
for you in our files to prove its authenticity. In theory we could have taken
every last bit of information, but it would have taken several more weeks.

Our goal here is not to come across as master hackers, hence what we're about
to reveal: SonyPictures.com was owned by a very simple SQL injection, one of
the most primitive and common vulnerabilities, as we should all know by now.
From a single injection, we accessed EVERYTHING. Why do you put such faith in
a company that allows itself to become open to these simple attacks?

What's worse is that every bit of data we took wasn't encrypted. Sony stored
over 1,000,000 passwords of its customers in plaintext, which means it's just
a matter of taking it. This is disgraceful and insecure: they were asking for it.

This is an embarrassment to Sony; the SQLi link is provided in our file contents,
and we invite anyone with the balls to check for themselves that what we say
is true. You may even want to plunder those 3.5 million coupons while you can.

Included in our collection are databases from Sony BMG Belgium & Netherlands.
These also contain varied assortments of Sony user and staffer information.

Follow our sexy asses on twitter to hear about our upcoming website. Ciao!
 
OMFG! This is just ridiculous!
mad.gif
 
lol suggest you remove link as it contains illegal data

heres the talk from it tho

Code:
. /$$ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ /$$ÂÂÂÂÂÂÂÂÂÂÂÂ/$$$$$$ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ
.| $$ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ| $$ÂÂÂÂÂÂÂÂÂÂ /$$__ÂÂ$$ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ
.| $$ÂÂÂÂÂÂ /$$ÂÂ /$$| $$ /$$$$$$$$| $$ÂÂ\__/ÂÂ/$$$$$$ÂÂ /$$$$$$$
.| $$ÂÂÂÂÂÂ| $$ÂÂ| $$| $$|____ /$$/|ÂÂ$$$$$$ÂÂ/$$__ÂÂ$$ /$$_____/
.| $$ÂÂÂÂÂÂ| $$ÂÂ| $$| $$ÂÂ /$$$$/ÂÂ\____ÂÂ$$| $$$$$$$$| $$ÂÂÂÂÂÂ
.| $$ÂÂÂÂÂÂ| $$ÂÂ| $$| $$ÂÂ/$$__/ÂÂ /$$ÂÂ\ $$| $$_____/| $$ÂÂÂÂÂÂ
.| $$$$$$$$|ÂÂ$$$$$$/| $$ /$$$$$$$$|ÂÂ$$$$$$/|ÂÂ$$$$$$$|ÂÂ$$$$$$.$
.|________/ \______/ |__/|________/ \______/ÂÂ\_______/ \_______/
ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ//Laughing at your security since 2011!

.--ÂÂÂÂ.-""-.
.ÂÂ ) (ÂÂÂÂ )
.ÂÂ(ÂÂ )ÂÂ (
.ÂÂÂÂ /ÂÂÂÂ )
.ÂÂÂÂ(_ÂÂÂÂ_)ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ 0_,-.__
.ÂÂÂÂÂÂ(_ÂÂ)_ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ |_.-._/
.ÂÂÂÂÂÂ (ÂÂÂÂ)ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ|lulz..\ÂÂÂÂ
.ÂÂÂÂÂÂÂÂ(__)ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ |__--_/ÂÂÂÂÂÂÂÂÂÂ
.ÂÂÂÂ |''ÂÂ ``\ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ |
.ÂÂÂÂ | [Lulz] \ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ|ÂÂÂÂÂÂ/b/
.ÂÂÂÂ |ÂÂÂÂÂÂÂÂ \ÂÂ,,,---===?A`\ÂÂ|ÂÂ,==y'
.ÂÂ ___,,,,,---==""\ÂÂÂÂÂÂÂÂ|M] \ |;|\ |>
.ÂÂÂÂÂÂÂÂÂÂ _ÂÂ _ÂÂ \ÂÂ ___,|H,,---==""""bno,
.ÂÂÂÂoÂÂOÂÂ(_) (_)ÂÂ \ /ÂÂÂÂÂÂÂÂÂÂ_ÂÂÂÂ AWAW/
.ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ /ÂÂÂÂÂÂÂÂ _(+)_ÂÂdMM/
.ÂÂÂÂÂÂ\@_,,,,,,---=="ÂÂ \ÂÂÂÂÂÂ\\|//ÂÂMW/
.--''''"ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ ===ÂÂd/
.ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ//ÂÂ SET SAIL FOR FAIL!
.ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ,'_________________________
.ÂÂ \ÂÂÂÂ\ÂÂÂÂ\ÂÂÂÂ \ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ ,/~~~~~~~~~~~~~~~~~~~~~~~~~~~
.ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ _____ÂÂÂÂ,'ÂÂ~~~ÂÂ .-""-.~~~~~~ÂÂ.-""-.
.ÂÂÂÂÂÂ.-""-.ÂÂÂÂÂÂÂÂÂÂ ///==---ÂÂ /`-._ ..-'ÂÂÂÂÂÂ-.__..-'
.ÂÂÂÂÂÂÂÂÂÂÂÂ`-.__..-' =====\\\\\\ V/ÂÂ.---\.
.ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ ~~~~~~~~~~~~, _',--/_.\ÂÂ.-""-.
.ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ.-""-.___` --ÂÂ\|ÂÂÂÂÂÂÂÂ -.__..-
ÂÂÂÂÂÂÂÂ
Greetings folks. We're LulzSec, and welcome to Sownage. Enclosed you will
find various collections of data stolen from internal Sony networks and websites,
all of which we accessed easily and without the need for outside support or money.

We recently broke into SonyPictures.com and compromised over 1,000,000 users'
personal information, including passwords, email addresses, home addresses,
dates of birth, and all Sony opt-in data associated with their accounts.
Among other things, we also compromised all admin details of Sony Pictures
(including passwords) along with 75,000 "music codes" and 3.5 million "music coupons".

Due to a lack of resource on our part (The Lulz Boat needs additional funding!)
we were unable to fully copy all of this information, however we have samples
for you in our files to prove its authenticity. In theory we could have taken
every last bit of information, but it would have taken several more weeks.

Our goal here is not to come across as master hackers, hence what we're about
to reveal: SonyPictures.com was owned by a very simple SQL injection, one of
the most primitive and common vulnerabilities, as we should all know by now.
From a single injection, we accessed EVERYTHING. Why do you put such faith in
a company that allows itself to become open to these simple attacks?

What's worse is that every bit of data we took wasn't encrypted. Sony stored
over 1,000,000 passwords of its customers in plaintext, which means it's just
a matter of taking it. This is disgraceful and insecure: they were asking for it.

This is an embarrassment to Sony; the SQLi link is provided in our file contents,
and we invite anyone with the balls to check for themselves that what we say
is true. You may even want to plunder those 3.5 million coupons while you can.

Included in our collection are databases from Sony BMG Belgium & Netherlands.
These also contain varied assortments of Sony user and staffer information.

Follow our sexy asses on twitter to hear about our upcoming website. Ciao! [img]http://gbatemp.net/vanilla/emoticons/happy.gif[/img]
 
I'm getting sick of these, not just about the hacks as it seems more like e-peen flexing, but also because Sony is seriously flawed with their security, with only fixing that which has been affected when the rest of their infrastructure is designed similarly as those that have been hacked. If one part is compromised, then don't think the rest isn't going to be.
 
Joe88 said:

Yeah lets trust sony because they are always right XD. I don't blame the hackers that are going after sony, they really brought it on there self with Geohot. As long as hackers do not abuse personal customer data then there is no more harm done then which sony already created.
 
machomuu said:
KirbyBoy said:
How about doing something else instead of hacking them? It's not gonna get you anything.
Satisfaction and possibly money. At least that's what I assume.
What satisfaction? What money? The only thing I see them gaining is hate.
 
KirbyBoy said:
machomuu said:
KirbyBoy said:
How about doing something else instead of hacking them? It's not gonna get you anything.
Satisfaction and possibly money. At least that's what I assume.
What satisfaction? What money? The only thing I see them gaining is hate.

Some men just want to watch the world burn.
But honestly I for myself don't even care that much about those hacks, sure they are discussable but I also think its important to "show" how Sony treats user data.
Not only PSN related user data but in general as well, which is kind of really shocking, I can't think of any other ways to do this.
Sure, releasing the SQL Injection and the stolen user data was a dick move, that I agree on.
 
Thats not only it:

02/06/11
• Sownage press release | http | http (-snip-.com) | -snip-
• Sownage summary | http | http (-snip-.com) | -snip-
• Sonypictures.com AutoTrader users database | http | http (-snip-.com) | -snip-
• Sonypictures.com Summer of Restless Beauty users database | http | http (-snip-.com) |-snip-
• Sonypictures.com Sony Wonder coupons database | http | http (-snip-.com) | -snip-
• Sonypictures.com Sony Wonder music codes database | http | http (-snip-.com) |-snip-
• Sonypictures.com Seinfeld Del Boca Vista database | http | http (-snip-.com) | -snip-
• Sonypictures.com database tables | http | http (-snip-.com) | -snip-
• Sonybmg.nl database | http | http (-snip-.com) | -snip-
• Sonybmg.be database | http | http (-snip-.com) | -snip-
30/05/11
• PBS.org defacement (pbs.org/lulz) snapshot | http
• PBS.org defacement (fake Tupac article) snapshot | http
• PBS.org internal hosts | http
• PBS.org database list | http
• PBS.org staffers database | http
• PBS.org authors database | http
• PBS.org pressroom users database | http
• PBS.org stations database | http
• PBS.org MySQL users database | http
23/05/11
• Sonymusic.co.jp database | http
15/05/11
UK ATM database | http
10/05/11
• Fox.com innerworkings | http
• Fox.com/sales database (SQL) | http
• Fox.com/sales database (txt) | http
• Fox.com/sales database cracked passwords | http
07/05/11
• X Factor contestants database (SQL) | http | -snip-
• X Factor contestants database (txt) | http | -snip-

My goodness...
 
Assax said:
KirbyBoy said:
machomuu said:
KirbyBoy said:
How about doing something else instead of hacking them? It's not gonna get you anything.
Satisfaction and possibly money. At least that's what I assume.
What satisfaction? What money? The only thing I see them gaining is hate.

Some men just want to watch the world burn.
But honestly I for myself don't even care that much about those hacks, sure they are discussable but I also think its important to "show" how Sony treats user data.
Not only PSN related user data but in general as well, which is kind of really shocking, I can't think of any other ways to do this.
Sure, releasing the SQL Injection and the stolen user data was a dick move, that I agree on.
But is hacking really the best option?
 
Sony's been hacked quite a bit in the past few weeks, you'd think they'd learn to set up a decent security system.
 
KirbyBoy said:
machomuu said:
KirbyBoy said:
How about doing something else instead of hacking them? It's not gonna get you anything.
Satisfaction and possibly money. At least that's what I assume.
What satisfaction? What money? The only thing I see them gaining is hate.
They're immune to hate sir, they're anonymous.
 
KirbyBoy said:
machomuu said:
KirbyBoy said:
How about doing something else instead of hacking them? It's not gonna get you anything.
Satisfaction and possibly money. At least that's what I assume.
What satisfaction? What money? The only thing I see them gaining is hate.
I'm sure most Nintendo and Microsoft fans aren't hating them.
 

Site & Scene News

Popular threads in this forum