Sony Ericsson online store, Sony BMG Japan reportedly hacked

Attacks mount as hacker group says it looks to embarrass Sony

Sony's security woes are continuing unabated as two more hacking groups today claim to have broken into the company's networks.

According to information posted Tuesday on Pastebin.com, hackers have apparently broken into a database at Sony Ericsson's Eshop online store for mobile phones in Canada and extracted the names, usernames and passwords of thousands of users.

The Hacker News , an online news site, reported that the Eshop hack was carried out by Idahca, a Lebanese hacking group. The hackers claimed to Hacker News that they extracted the whole database and have leaked its contents via their Facebook and Twitter accounts.

The news site also reported that hacker group Lulz Sec claims to have accessed a database of Sony BMG Japan and posted its contents, minus usernames and other personal information, on Pastebin.com.

Lulz Sec also claimed to the Hacker News site that it has discovered more vulnerable Sony BMG databases. The news site posted links to two pages on Sony Music's Japanese Web site that it said contain the SQL injection vulnerabilities used to break into the Sony database.

Sony did not respond to requests for comment on the reported hacks.

Chester Wisniewski, senior advisor at security firm Sophos, said it isn't clear whether the hackers could inject data into the vulnerable Sony BMG Japan database or simply access its contents. "If they are able to alter the records, this could be used to insert malicious code that could be used to compromise people browsing the [Sony BMG Japan] site," Wisniewski wrote in a blog post today.

The latest attacks were said by the Hacker News to be enabled by SQL injection flaws on Sony websites.

THN editor Mohit Kumar told Computerworld in an email that the Sony Pictures' site in Japan may have also fallen victim to a hacker attack, while another of the company's sites in Europe contains the same flaw that allowed hackers to break into the other Sony sites. That site has not been reported as being hacked, but hacker groups are actively discussing breaking into it, he claimed.

The recent breaches appear to be attempts to humiliate Sony.

"This isn't a 1337 h4x0r (elite hacker in Leetspeak)," Lulz Sec noted in a message posted on Hacker News. "We just want to embarrass Sony some more. Can this be hack number 8? 7 and a half," the message noted in apparent reference to the series of recent intrusions at Sony.

Sony sites have been hacked several times in several weeks, which analysts say shows that the company's online networks are very porous.

The biggest of these attacks by far happened in mid-April, when attackers broke into Sony's PlayStation Network and Sony Online Entertainment and compromised personal data of some 70 million account holders and another 12 million or so credit and debit card holders.

Those attacks caused Sony to take down PSN and SOE for several days while it worked with three external security firms to find and fix the security holes. About 10 days ago, Sony announced that it had fixed all problems with its PSN and SOE networks and partially restored those services.

Since then, there have been at least five publicly known hacks of Sony web sites around the world, including the two reported today. Two of the attacks were reported last week, while another one against Sony BMG Greece was reported yesterday.

According to Kumar, extracting Sony BMG Japan's database would have been "just a kid(s) game" for anyone using an automated SQL injection tool such as those used by penetration testers.

All that a would-be hacker would need to do is put one of the URL's into the SQL tool and have it analyzed, Kumar claimed. "The tool will extract whole database (sic) with one click," he said.

The important thing for Sony is to find and fix such vulnerable links quickly, Kumar said.

"Hacker News motive is to alert Sony this time," because several hacker groups are actively looking for ways to break into other Sony sites as well, he said.

"We can't stop hackers, but can alert Sony about holes in the rest of their sites," he said. "All these hackers (are) doing free of cost auditing for Sony. So Sony should take benefit from this" and secure its systems, Kumar said.

Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at @jaivijayan , or subscribe to Jaikumar's RSS feed . His e-mail address is jvijayan@computerworld.com.

Read more about security in Computerworld's Security Topic Center.

Join the Good Gear Guide newsletter!

Error: Please check your email address.

Tags sophosEricssonsecuritytwitterMalware and VulnerabilitiessonyFacebook

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jaikumar Vijayan

Computerworld (US)
Show Comments

Essentials

Microsoft L5V-00027 Sculpt Ergonomic Keyboard Desktop

Learn more >

Lexar® JumpDrive® S57 USB 3.0 flash drive

Learn more >

Mobile

Lexar® JumpDrive® S45 USB 3.0 flash drive 

Learn more >

Exec

Lexar® Professional 1800x microSDHC™/microSDXC™ UHS-II cards 

Learn more >

Audio-Technica ATH-ANC70 Noise Cancelling Headphones

Learn more >

Lexar® JumpDrive® C20c USB Type-C flash drive 

Learn more >

HD Pan/Tilt Wi-Fi Camera with Night Vision NC450

Learn more >

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?