[+] Wayc0de's Blog[+]

Tampilkan postingan dengan label Sony. Tampilkan semua postingan
Tampilkan postingan dengan label Sony. Tampilkan semua postingan

18/10/11

Alleged LulzSec hacker of Sony Pictures faces trial date in December

23-year-old accused of having posted millions of users' details on group's website after hacking into Sony Pictures Europe systems


LulzSec
The background from LulzSec's Twitter page. Leaked IRC logs show the group's inner workings. Photograph: AP
An alleged member of the clandestine hacking group LulzSec pleaded not guilty on Monday to charges of taking part in an extensive computer breach of the Sony Pictures Entertainment film studio's European systems.

Cody Kretsinger, 23, entered not guilty pleas to one count each of conspiracy and unauthorized impairment of a protected computer during a brief hearing in U.S. District Court in Los Angeles.

US Magistrate Judge Victor Kenton set a trial date of 13 December for Kretsinger, who spoke only in response to questions from the judge.

Kenton also ordered that Kretsinger be represented by a court-appointed public defender.

Kretsinger faces a maximum sentence of 15 years in prison if convicted. He declined to comment to the Reuters after the hearing.

A nine-page federal grand jury indictment unsealed in September charges Kretsinger with obtaining confidential information from Sony Pictures' computer systems using an SQL injection attack against its website, a technique commonly used by hackers to steal information.

The indictment asserts that Kretsinger, who it is claimed went by the online handle "recursion", helped post information he and his co-conspirators stole from Sony on LulzSec's website and announced the intrusion via the hacking group's Twitter account.

LulzSec, an underground group also known as Lulz Security, at the time published the names, birth dates, addresses, e-mails, phone numbers and passwords of thousands of people who had entered contests promoted by Sony.

"From a single injection we accessed EVERYTHING," the hacking group said in a statement at the time. "Why do you put such faith in a company that allows itself to become open to these simple attacks."

A number of Britons have been charged with offences relating to LulzSec's activities; they are not due to come to trial until early in 2012.

The de facto leader of LulzSec, who goes by the handle Sabu, recently responded to a string of questions on the Reddit website and suggested that he was "effectively on the run" - although he is not believed to have moved from his location, believed to be in New York.

Hackers previously had accessed personal information on 77 million Sony PlayStation Network and Qriocity accounts, the vast majority of which were users in North America and Europe, in what was then the biggest such security breach in history. Nobody and no group has ever directly claimed responsibility, and Sony has never released any details about how the attack was carried out. At one point it did suggest that members of the loose hacking collective Anonymous may have been responsible, but that has never been confirmed by either side.
Read More...

13/10/11

Sony PlayStation Network hacked again; 93,000 accounts compromised

Summary: Sony says “a large amount of unauthorized sign-in attempts” at its PlayStation Network has led to the hijacking of valid sign-in IDs and passwords.

Sony has confirmed another security breach at its popular PlayStation Network and warned that about 93,000 user accounts have been compromised.

The latest breach follows a massive hack in April 2011 that led to the theft of names, addresses and possibly credit card data belonging to 77 million user accounts.

The latest hack, flagged by Sony as “a large amount of unauthorized sign-in attempts,” led to the hijacking of valid sign-in IDs and passwords.

From Sony’s statement:

Less than one tenth of one percent of our PSN, SEN and SOE consumers may have been affected. There were approximately 93,000 accounts (PSN/SEN: approximately 60,000 accounts; SOE:

approximately 33,000) where the attempts succeeded in verifying those accounts’ valid sign-in IDs and passwords, and we have temporarily locked these accounts. As a preventative measure, we will be sending email notifications to these account holders and will be requiring secure password resets or informing consumers of password reset procedures.
The company said credit card numbers associated with these accounts are not at risk as a result of these unauthorized attempts.

“Only a small fraction of these 93,000 accounts showed additional activity prior to being locked. We are continuing to investigate the extent of unauthorized activity on any of these accounts,” Sony added.
Read More...

11/10/11

Lulzsec hacker: 'we still have Sun emails, stored in China

Sabu, the erstwhile leader of the hacking crew, says he is effectively on the run as he gives interview to Reddit readers about LulzSec's achievements, Facebook, sentencing and more


The LulzSec hacking group has said it is to disband
 
 
The LulzSec hacking group hit a number of sites in a spree in May and July 2011; now its leader Sabu has given an interview on Reddit. Photograph: Reuters
The hacker who styles himself "Sabu", erstwhile leader of the LulzSec hacking crew, claims to have a cache of emails copied from the Sun which are being stored on a Chinese server, along with data from a number of other hacks.

But he claimed this weekend that they will not be released yet: "there are a lot of interesting dumps we're sitting on due to timing," he wrote on his Twitter feed. He claims that hackers have broken into banks including HSBC and "a few others" but that they have found "no smoking guns yet" in the data there.

Sabu – who says his online handle is a tribute to the American professional wrestler – says that after the arrests in the UK and US of a number of people alleged to have been involved with the crew, he is effectively on the run. But his writing also suggests he is staying put where he lives.

"I'm past the point of no return. Not trying to sound like a bad ass, however, it's the truth," he wrote. Later he added: "The ironic twist will be that my own friends will take me down, and not these idiots who hide behind the patriot veil." He also says that "technically, I'm on the run, so there you go."

LulzSec was an offshoot of the Anonymous hacking collective which during a hacking spree in May and July 2011 broke into a number of sites, including Sony Pictures Europe, Fox.com, PBS and finally the News International site.

At the latter it altered the Sun's web page so that it redirected viewers first to a faked story about Rupert Murdoch's death, and then to their Twitter feed. The group also attacked the US Congress's web site, an FBI affiliate and brought down the web site for the UK's Serious Organised Crime Agency by using a "distributed denial of service" attack.

Sabu effectively acted as the leader of the group, maintaining discipline over what they did, as leaked chatroom logs published in June by the Guardian show.
At that time he told members of the crew not to give interviews – but says his willingness to do so now is because "that was during the height of LulzSec. We all agreed to do no interviews till the end if there was ever one."

LulzSec's achievements, he says, were that it "exposed the sad state of security across the media, social, government online environments".

After the Sun hack, Sabu claimed on his Twitter feed that he was looking at 4GB of emails from the company. The claim was never confirmed, although remote access to News International's systems had been compromised.

Sabu's revelations came in a long and sometimes detailed "Ask Me Anything" (AMA) thread on Reddit. Sabu responds to a number of questions and appears to reveal a number of details about himself, such as that he is married, studied social sciences and English, that his technical hacking skills are self-taught, and that he teaches "sometimes". He claims to speak three languages – English, Spanish and German – fluently, and to have "decent" Portuguese and Italian. He says he turned towards computer hacking in 2000, when the US government "ignored the peoples' please to stop bombing Vieques" – a part of Puerto Rico used by the US navy as a bombing range until 2003. He says he likes working on cars, playing music and spending time with his family: "I'm loving life a lot this year. I barely have time for ops [hacker operations] like I used to."

That confirms other details that have been collected by rival hackers about Sabu which suggest that he is of Puerto Rican extraction, aged about 30 and based in New York.

He insists that he had no knowledge of the identities of any of the other members of LulzSec. "I simply don't know anyone's identity at Anonymous." He says that when one alleged member was arrested in the Shetland Islands, north of Scotland, he had to go and look up its location: "I was a bit impressed, even." He vehemently denies the suggestions by some that he "snitched" on other LulzSec members to the authorities.

The breakup of LulzSec meant he has "lost too many friends. [I] will probably never talk to them ever again." But he thinks that it "has already achieved what it set out to achieve".

He suggests that one of the LulzSec members, called Avunit, who quit the group when it took aim at the FBI, "is relaxing somewhere on a boat".

Asked whether he is "safe", he replies: "no one can prove it's me anyway. The beauty of Anonymous." The closest that the authorities have come to him is when in September they arrested a hacker alleged to have gone by the online handle "Recursion", who was tracked down via logs held by the British company HideMyAss, which unwittingly provided a virtual private network (VPN) connection for the attack on Sony Pictures Europe.

That arrest was "probably the closest they ever got", Sabu says. He also makes a veiled threat against HideMyAss: he alleges it "turns out to be owned by some … people who are going around buying smaller VPN providers ... We should have a nice exposé for HMA and its mother computer/investors soon. Point is: research your VPN provider thoroughly."

He says he takes a number of precautions to evade law enforcement, using prepaid phones and BlackBerrys for calls and Twitter: "they're expendable. I don't ignore you, I simply don't know you." He trusts Twitter – to some extent: "believe it or not, Twitter has not been sleeping in bed with LEAs [law enforcement agencies]. In fact it's a process [for LEAs] to get account info."

He rails at the sentencing guidelines in place for computer activity: "The penalties for any cybercrime (with the exception of child pornography) is severely archaic. And enforced by non-computer users. A DDOS (distributed denial of service) should not [attract a sentence of] 10 years at all especially when rapists and murderers do LESS than time." (The Guardian's James Ball made a similar point earlier this year.)

He thinks a hacking attack against Facebook "is pointless unless some very courages [sic] individual go and burn down its datacenter containing DBs [databases]". But he calls Facebook "a serious global cancer … they have half a billion people's psychology and family down in a database".

LulzSec does not have a Google Plus account, he says: "We do NOT have a g+ account. So whoever is running it is more than likely posing and has no affiliation to us." (Other Reddit users said that files distributed from that account contain malware.) Google Plus was launched well after LulzSec apparently broke up.
His advice to would-be emulators: "Stick to yourselves. If you are in a crew – keep your opsec up 24/7. Friends will try to take you down if they have to."

Anonymous, he says, is "no leaders, no hierarchy, no cointelpro [counter-intelligence program] drama. And we are a living, moving mass of like-minded individuals." He says it is "pure democracy", though that can be anarchic. But he thinks it will spawn "many organisations and political parties". But he says that "you don't need to be 'anonymous' or need to hack to be Anonymous. It's an idea, not a job."

He says he hopes to give a talk at the next HOPE (Hackers on Planet Earth) conference in New York, expected to run in July 2012.
Read More...

24/09/11

FBI Snags Lulzsec Member Involved in Sony Hack

LulzsecThe FBI continued its pursuit of members of the hacking group LulzSec on Thursday, arresting a 23 year old Phoenix, Arizona man believed to be part of an online hacking crew that attacked systems belonging to Sony Pictures, the Bureau said in a statement Thursday.

The arrest, conducted by agents from the FBI's Los Angeles office arrested Cody Kretsinger of Phoenix Arizona on Thursday. Kretsinger was named in a September 2 federal grand jury indictment and charged with conspiracy and unauthorized impairment of a protected computer for his role in attacks in May and June against computer systems belonging to Sony Pictures Entertainment, according to the statement. Published reports indicate that other arrests took place in Ohio, San Francisco, California, Montana, Minnesota and New Jersey.

Kretsinger, who used the online handle "recursion" is alleged to have carried out SQL injection attacks on Sony's application servers, connecting through a proxy server to mask his Internet Protocol (IP) address.

After compromising Sony's networks, Kertsinger is alleged to have distributed information stolen from Sony and to have publicized the attack on LulzSec's Web site and through its Twitter account.

Sony's network became a target in April, after Lulzsec targeted the company for its legal pursuit of PS3 hacker George Holtz (aka "GeoHot"). The hackers broke into the company's online gaming network, PSN Network. The company's Sony Online Entertainment and Station.com networks were also breached, with data on around 100 million users exposed, all told.

Kretsinger is just the latest in a string of arrests and searches of both high- and low level members of LulzSec and Anonymous. In June, a 19 year old man, Ryan Cleary of Essex, England, was arrested and charged with five counts of violating that country's Computer Misuse Act and Criminal Law Act. Subsequent raids and arrests of members of LulzSec and Anonymous claim to have targeted high ranking members of both LulzSec and Anonymous, including the member known as "Topiary" (allegedly 18 year old Jake Davis of the remote Shetland Islands in the UK) and, more recently, individuals believed to be linked to the online identity "Kayla," a key player in many of LulzSec's most notable hacks.

nb : threatpost Read More...

Arrested LulzSec Supsect Pined for Job at DoD

A 23-year-old Arizona man arrested on Thursday in connection with the hack of Sony Pictures Entertainment last May was a model student who saw himself one day defending networks at the Department of Defense and the National Security Agency.

Wired.com’s Threat Level, the Associated Press, and other news outlets are reporting that Tempe, Ariz. based Cody Andrew Kretsinger is believed to be a member of the LulzSec group, an offshoot of the griefer collective Anonymous. According to the indictment against Kretsinger, he was involved executing and later promoting the high-profile and costly attack on Sony’s networks. Sony estimates that the breaches would cost it more than $170 million this year.


UAT interview with Kretsinger
Kretsinger is a network security student at Tempe, Ariz. based University of Advancing Technology, according to Robert Wright, director of finance for UAT.  A cached page from UAT’s Web site shows that Kretsinger was named student of the month earlier this year. That page, which indicates Kretsinger was to graduate from the institution in the Fall semester of 2011, includes an interview with the suspected LulzSec member. In it, Kretsinger says he would like to work at the DoD after graduating.

Where do you want to work after graduation? 

“I hope that I’ll be able to work for the Department of Defense. From what I hear, they’re pretty good at what I want to do.

Where do you see yourself in 5 years? 

“Traveling, doing Network Security as a profession with the Department of Defense. While I wouldn’t mind being a penetration tester, I think it’s a lot more fun to try to build and secure a network and its devices from the ground up. I suppose I wouldn’t mind being in management, either.”

What’s the ultimate dream for your life? 

“Good secure job, great family, maybe a ’64 GTO or something to that effect. I think a job with the NSA or Department of Defense is my ultimate dream.
I hope that I’ll be able to work for the Department of Defense. From what I hear, they’re pretty good at what I want to do.”

Kretsinger may have a difficult time finding work in the public sector. In June, LulzSec claimed responsibility for hacking into computers at the Arizona Department of Public Safety’s computers and releasing hundreds of law enforcement files. The hacking group also claimed to have breached the websites of the CIA and the U.S. Senate.

nb : krebsonsecurity Read More...

23/09/11

Alleged LulzSec Sony hacker arrested

The 23-year-old Phoenix student is accused of using SQL injection to break into Sony Pictures' database

The U.S. Federal Bureau of Investigation has arrested a Phoenix student, claiming that he is one of the LulzSec hackers responsible for a database attack on Sony Pictures computers that claimed more than 1 million victims.

Cody Kretsinger, 23, was arrested Thursday morning on hacking and conspiracy charges. Prosecutors say he was "Recursion," an LulzSec hacker who used a database attack technique called SQL injection to break into Sony Pictures systems. Kretsinger allegedly provided data that was used in a mammoth June 2, 2011, data dump by LulzSec that included coupon codes along with email addresses and passwords belonging to Sony customers.

[ Get your websites up to speed with HTML5 today using the techniques in InfoWorld's HTML5 Deep Dive PDF how-to report. | Learn how to secure your Web browsers in InfoWorld's "Web Browser Security Deep Dive" PDF guide. ]

At the time that LulzSec posted its data, Sony was already recovering from a devastating break-in to its PlayStation Network. That intrusion knocked the service offline for more than two months and cost the company an estimated ¥14 billion ($183 million) to clean up.

"The extent of damage caused by the compromise at Sony Pictures is under investigation," the FBI said Thursday in a statement.

Sony's heavy-handed response to the release of "jailbreak" code for its PS3 console, which could be used to run unauthorized software on the device, had made the company the enemy of hackers everywhere, and the LulzSec hackers were not the only ones to go after the company's computer systems.

LulzSec had a brief run of Internet mayhem earlier this year, breaking into websites belonging to corporations and law enforcement agencies and then posting the data publicly with gleeful disregard to any consequences.

Since then, the group seems to have been largely rounded up by law enforcement in a series of arrests in the U.S. and U.K.

Kretsinger allegedly covered his tracks by using the Hidemyass.com proxy service and wiping his computer hard drive after the attack. He faces 15 years in prison if convicted.

Separately, the FBI also announced the arrest of two alleged members of the Peoples Liberation Front, a group that claimed credit for a 30-minute long 2010 distributed denial of service attack against Santa Cruz County, California. Like LulzSec, Peoples Liberation has affiliated itself with the Anonymous hacking movement.

Christopher Doyon and Joshua Covelli are both facing hacking charges in the case. Covelli had previously been charged in connection with an Anonymous-sponsored December 2010 attack on Paypal.com.

nb : infoworld Read More...

FBI arrests Sony LulzSec hacking suspect

Sony executives Shiro Kambe, Kazuo Hirai  and Shinji Hasejima
 
At a May press conference in Tokyo, Sony executives bow to apologise for thefts of personal data from Sony's computer networks. An alleged member of LulzSec has been arrested in Arizona by the FBI. Photograph: Toru Yamanaka/AFP/Getty
A suspected member of the clandestine hacking group LulzSec has been arrested in Arizona by the FBI on charges of taking part in an extensive breach of the Sony Pictures computer system.

A federal grand jury indictment charges Cody Kretsinger, 23, with conspiracy and the unauthorised impairment of a protected computer in connection with the attack in May and June.

Kretsinger is alleged to have used the online name, or handle, of "recursion" as part of the hacking crew.

LulzSec, an underground group also known as Lulz Security, at the time published the names, birth dates, addresses, emails, phone numbers and passwords of thousands of people who had entered contests promoted by Sony.

"From a single injection we accessed EVERYTHING," the hacking group said in a statement at the time. "Why do you put such faith in a company that allows itself to become open to these simple attacks?"
Hackers previously had accessed personal information on 77m PlayStation Network and Qriocity accounts, 90% of which belonged to users in North America and Europe, in what was then the biggest such security breach in history.
The nine-page indictment said Kretsinger and co-conspirators obtained confidential information from Sony Pictures' computer systems using an "SQL injection" attack against its website, a technique commonly used by hackers to exploit vulnerabilities and steal information.

The indictment said that Kretsinger, as "recursion", helped post information he and his co-conspirators stole from Sony on LulzSec's website and announced the intrusion via the hacking group's Twitter account.

The extent of damage caused by the breach of the studio's computer network remained under investigation, the FBI said.

Chat logs obtained by the Guardian reveal that two members of LulzSec, "recursion" and "devrandom", decided to leave the group after 3 June after it attacked an FBI-affiliated site.

There have been four arrests in the UK of people alleged to be associated with LulzSec. Trials of three of them are expected to begin in 2012.

LulzSec, an underground group also known as Lulz Security, at the time published the names, birth dates, addresses, emails, phone numbers and passwords of thousands of people who had entered contests promoted by Sony.

"From a single injection we accessed EVERYTHING," the hacking group said in a statement at the time. "Why do you put such faith in a company that allows itself to become open to these simple attacks."

Hackers previously had accessed personal information on 77m PlayStation Network and Qriocity accounts, 90% of which belonged to users in North America and Europe, in what was then the biggest such security breach in history.
Other high-profile companies targeted by cyber attacks included Lockheed Martin and Google.

Sony officials did not comment on Thursday's arrest.

LulzSec is reputed to be affiliated with the international hackers collective called Anonymous, which has claimed responsibility for cyber attacks on government and private institutions around the world.

Kretsinger faces a maximum sentence of 15 years in prison if convicted. The government is trying to extradite him to Los Angeles, where Sony Pictures' computer system is located and where the case against him has been filed.

nb : guardian
Read More...

Homeless hacker arrested by FBI in LulzSec/Anonymous investigation

Homeless manAccording to media reports, the FBI has arrested two alleged hackers in San Francisco and Phoenix, believed to be associated with the LulzSec and Anonymous hacktivist groups.

And one of them is homeless.

FoxNews reports that search warrants have also been executed in the states of Minnesota, Montana and New Jersey as part of a wider FBI investigation into the groups who have launched attacks against government websites as well as corporations such as Sony.

23-year-old Cody Kretsinger, from Phoenix, Arizona, has been charged with computer offences, and is alleged to be the LulzSec member known as "Recursion". Kretsinger is accused of being involved in an SQL injection attack that stole information from Sony Pictures in June, exposing users email addresses and passwords.

According to the indictment against Kretsinger, he is accused of using the hidemyass.com proxy service to cloak probes he made of Sony Pictures' computer systems in May 2011, hunting for vulnerabilities.

Sony passwords leakedApproximately 150,000 confidential records were subsequently published online by LulzSec who criticised Sony's weak security.

Authorities allege that Kretsinger wiped the hard drives used to carry out the attack on Sony in an attempt to hide forensic evidence.

"Recursion" is one of many handles used by members of the LulzSec hacking gang, and features in internet chat logs that have previously published of the group having what they believed to be private conversations.

Chat log between LulzSec members Topiary and Recursion
Meanwhile, the FBI arrested an alleged Anonymous member in San Francisco. The man, who is reported to be homeless, is said to have been involved in internet attacks against Santa Cruz County government websites.

Just because a man is homeless, of course, doesn't mean that he can't get an internet connection. Coffee houses, cafes, libraries, etc can all offer cheap or free internet access - and because the computer being used can be a shared device, it may be harder to identify who might have been responsible for an attack compared to a PC at a home.

At the same time, public places are often watched with CCTV cameras which means that if the authorities were able to identify a time and place, they may also be able to gather evidence as to who was at the location when an attack was begun from a particular computer.

Both LulzSec and the larger Anonymous hacktivist collective have had a tough time of late, with a series of arrests in the USA, UK and elsewhere around the globe.

Wannabe hackers might be wise to read the FBI's press release about the Kretsinger arrest, which points out that if convicted of the hacking offences he could face up to 15 years in prison.

nb : nakedsecurity.sophos
Read More...

07/09/11

Former DHS Cybersecurity Chief Reitinger Named Sony CISO

Former Department of Homeland Security cyber-security chief Philip Reitinger has been named as the new executive vice president and Chief Information Security Officer of Sony Corporation.

In his new position, Reitinger will be in charge of global information security and privacy at the electronics giant effective today. More specifically, Reitinger will be responsible for maintaining the security of Sony’s information assets and services in addition to managing information security, privacy and internet safety across the corporation.

This announcement comes shortly after a speech last week at the IFA consumer electronics conference wherein Sony’s CEO, Howard Stringer, claimed that the company was more secure than ever. Of course, Sony’s PlayStation Network went down for nearly a month last spring after suffering a data breach that eventually ended up affecting some 100 million individuals. The company’s security woes broadened after its home country of Japan made it wait to bring the network back online citing security concerns, a position validated two days later when the network went down again during the mandatory password reset process.

Reitinger most recently served as the top information security official at DHS, a position from which he resigned in mid-May amid surges in troublemaking from hacker-collectives like Anonymous and LulzSec and a rash of high profile attacks on the US government, businesses and government contractors.

Before joining DHS in March 2009, he worked in Microsoft’s Trustworthy Computing division, and according to the Sony press release, he has also worked with the US departments of Defense and Justice.
While with DHS, Reitinger had reportedly done a decent job curbing some of the notorious inter-departmental bickering for which the federal government’s information security efforts had been known for the better part of the last decade.

 nb : threatpost Read More...