Sony Ericsson online store, Sony BMG Japan reportedly hacked

Attacks mount as hacker group says it looks to embarrass Sony

Sony's security woes are continuing unabated as two more hacking groups today claim to have broken into the company's networks.

According to information posted Tuesday on Pastebin.com, hackers have apparently broken into a database at Sony Ericsson's Eshop online store for mobile phones in Canada and extracted the names, usernames and passwords of thousands of users.

The Hacker News , an online news site, reported that the Eshop hack was carried out by Idahca, a Lebanese hacking group. The hackers claimed to Hacker News that they extracted the whole database and have leaked its contents via their Facebook and Twitter accounts.

The news site also reported that hacker group Lulz Sec claims to have accessed a database of Sony BMG Japan and posted its contents, minus usernames and other personal information, on Pastebin.com.

Lulz Sec also claimed to the Hacker News site that it has discovered more vulnerable Sony BMG databases. The news site posted links to two pages on Sony Music's Japanese Web site that it said contain the SQL injection vulnerabilities used to break into the Sony database.

Sony did not respond to requests for comment on the reported hacks.

Chester Wisniewski, senior advisor at security firm Sophos, said it isn't clear whether the hackers could inject data into the vulnerable Sony BMG Japan database or simply access its contents. "If they are able to alter the records, this could be used to insert malicious code that could be used to compromise people browsing the [Sony BMG Japan] site," Wisniewski wrote in a blog post today.

The latest attacks were said by the Hacker News to be enabled by SQL injection flaws on Sony websites.

THN editor Mohit Kumar told Computerworld in an email that the Sony Pictures' site in Japan may have also fallen victim to a hacker attack, while another of the company's sites in Europe contains the same flaw that allowed hackers to break into the other Sony sites. That site has not been reported as being hacked, but hacker groups are actively discussing breaking into it, he claimed.

The recent breaches appear to be attempts to humiliate Sony.

"This isn't a 1337 h4x0r (elite hacker in Leetspeak)," Lulz Sec noted in a message posted on Hacker News. "We just want to embarrass Sony some more. Can this be hack number 8? 7 and a half," the message noted in apparent reference to the series of recent intrusions at Sony.

Sony sites have been hacked several times in several weeks, which analysts say shows that the company's online networks are very porous.

The biggest of these attacks by far happened in mid-April, when attackers broke into Sony's PlayStation Network and Sony Online Entertainment and compromised personal data of some 70 million account holders and another 12 million or so credit and debit card holders.

Those attacks caused Sony to take down PSN and SOE for several days while it worked with three external security firms to find and fix the security holes. About 10 days ago, Sony announced that it had fixed all problems with its PSN and SOE networks and partially restored those services.

Since then, there have been at least five publicly known hacks of Sony web sites around the world, including the two reported today. Two of the attacks were reported last week, while another one against Sony BMG Greece was reported yesterday.

According to Kumar, extracting Sony BMG Japan's database would have been "just a kid(s) game" for anyone using an automated SQL injection tool such as those used by penetration testers.

All that a would-be hacker would need to do is put one of the URL's into the SQL tool and have it analyzed, Kumar claimed. "The tool will extract whole database (sic) with one click," he said.

The important thing for Sony is to find and fix such vulnerable links quickly, Kumar said.

"Hacker News motive is to alert Sony this time," because several hacker groups are actively looking for ways to break into other Sony sites as well, he said.

"We can't stop hackers, but can alert Sony about holes in the rest of their sites," he said. "All these hackers (are) doing free of cost auditing for Sony. So Sony should take benefit from this" and secure its systems, Kumar said.

Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at @jaivijayan , or subscribe to Jaikumar's RSS feed . His e-mail address is jvijayan@computerworld.com.

Read more about security in Computerworld's Security Topic Center.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags FacebooktwittersonysophosEricssonMalware and Vulnerabilities

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jaikumar Vijayan

Computerworld (US)
Show Comments

Cool Tech

Toys for Boys

Skywatcher Dobsonian 8″ Collapsible Telescope

Learn more >

Family Friendly

Whodunnit™ Duo-Scope MFL-007 Microscope Kit

Learn more >

Stocking Stuffer

Logitech Ultimate Ears Wonderboom 2 Bluetooth Speaker

Learn more >

Christmas Gift Guide

Click for more ›

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Tom Sellers

MSI P65

This smart laptop was enjoyable to use and great to work on – creating content was super simple.

Lolita Wang

MSI GT76

It really doesn’t get more “gaming laptop” than this.

Jack Jeffries

MSI GS75

As the Maserati or BMW of laptops, it would fit perfectly in the hands of a professional needing firepower under the hood, sophistication and class on the surface, and gaming prowess (sports mode if you will) in between.

Taylor Carr

MSI PS63

The MSI PS63 is an amazing laptop and I would definitely consider buying one in the future.

Christopher Low

Brother RJ-4230B

This small mobile printer is exactly what I need for invoicing and other jobs such as sending fellow tradesman details or step-by-step instructions that I can easily print off from my phone or the Web.

Aysha Strobbe

Microsoft Office 365/HP Spectre x360

Microsoft Office continues to make a student’s life that little bit easier by offering reliable, easy to use, time-saving functionality, while continuing to develop new features that further enhance what is already a formidable collection of applications

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?