PSX-SCENE Forum Discussion for Sony PlayStation/PsOne/PS2/PS3/PSP/PS VITA
  • PlayStation Password Reset Page Unsecure

    Generally when a company has such a massive breach of security such as Sony did with the PlayStation Network, they will take their time to ensure security is enhanced before bringing it back. It appeared that Sony was doing just that and playing it safe when it took them about a month to bring the PSN back. Today however, their security has failed them once again. Their PlayStation password reset page was revealed to be exploitable by Nyleveia.com. Soon after the website contacted Sony, the password reset page was taken offline for "maintenance".

    Eurogamer has seen video evidence that verifies reports that Sony's PlayStation Network password reset system suffers from an exploit that allows attackers to change your password using only your PSN account email and your date of birth – information compromised in the PSN hack of 20th April.

    Sony today made PSN sign-in unavailable for a number of its websites, including PlayStation.com and the PlayStation forums. All PlayStation game titles are also unavailable.

    Crucially, the website users are directed to by password reset emails is now down.

    "Unfortunately this also means that those who are still trying to change their password via Playstation.com or Qriocity.com will be unable to do so for the time being," Sony said. "This is due to essential maintenance and at present it is unclear how long this will take.

    "In the meantime you will still be able to sign into PSN via your PlayStation 3 and PSP devices to connect to game services and view Trophy/Friends information."

    Sony later tweeted: "Clarification: this maintenance doesn't affect PSN on consoles, only the website you click through to from the password change email."

    The exploit was first revealed on Nyleveia.com.

    "I would suggest that you secure your accounts now by creating a completely new email that you will not use ANYWHERE ELSE, and switching your PSN account to use this new email," recommends the site.

    "You risk having your account stolen, when this hack becomes more public, if you do not make sure that your PSN account's email is one that cannot be affiliated with or otherwise traced to you."

    NeoGAF users have also corroborated the claim.

    Nyleveia claims to have contacted Sony about the exploit. "The system went down approximately 15 minutes after I received a response from SCEE on the matter."

    Sony has taken the page in question down, and with any luck is fixing the exploit.

    Eurogamer has contacted Sony for comment.
    Updates via Nyleveia
    UPDATE 2: Web based PSN login / Password recovery is now down for maintenance, hopefully as a result of our contact with SCEE. And more importantly, hopefully to fix the security issue.


    UPDATE 3: To clarify the situation, we had confirmed ourselves the method used last night, and contacted SCEE, SCEE have acted upon this information, we felt the information previously provided in our tweets and this article may have been a little too revealing to the vulnerability, thus we “dumbed down” the explanation of the security hole. We have provided SCEE with a detailed description of the security hole.
    While it’s unclear at this time if they will actually patch the flaw while they have the system taken down, I can also confirm that the system went down approximately 15 minutes after I received a response from SCEE on the matter.



    We for rather obvious reasons do not want to elaborate further on the exact details of the exploit, on the off chance that when the web based interface for PSN is restored the exploit has not been patched.


    UPDATE 4: Last update on the topic most likely, i notice a lot of people are saying that we should not have posted this information and simply contacted Sony, and you’re right in thinking this, however we contacted SCEE as soon as we had confirmed that the exploit was in fact real, the problem was that at the time there was a good 8-9 hour stretch where SCEE would not see our messages and given the rate at which the exploit method was spreading in the dark corners of the internet, we felt as though we needed to publicise the exploit advising users to change the emails used for their PSN accounts to secure them until Sony could patch the security hole.


    Originally we posted rough details on how the exploit operated, to give further evidence to users that it was a valid reason for them to change their passwords, as with most news like this on the internet, people tend not to believe something until hoards of users have been affected, we posted an article on N4G advising PSN users to switch their email addresses which was promptly reported as spam/lame/fake by several users who refused to believe the news due to our site just being a small news outlet.


    All along our main priority and focus has been to assist Sony and PSN users in keeping their accounts safe. If the current downtime for the web based forms results in the exploit being patched then our job is done and the potential thieft of countless user accounts has been nipped in the bud as early as humanly possible.
    Thank you to everyone that has taken our warnings seriously and acted upon it, and to SCEE for their swift response to the matter.


    UPDATE 5: Okay, due to the email response I felt i should answer some general common questions regarding the topic.
    Q. If I already reset my password am I safe?
    A. The exploit was possible on any account the email and date of birth was known for, regardless of if the password was changed or not, or what region the account was tied to.

    Q. What if they don’t know my Date of Birth or Email account?
    A. Then the average user would not be able to take your account, however due to the database being illegally accessed in April, it’s safe to assume that someone, somewhere, has access to a large number of users details, which include date of birth and email addresses, this alone should be reason enough to change your email.

    Q. Are you sure this is real?
    A. Yes, it was demonstrated to one of our empty accounts, then we were able to repeat the process ourselves after figuring out the method, this was additionally confirmed when a twitter user provided us with his data and requested that we change his password as proof.
    We have since emailed him his new password, and no other data on his account was changed.

    Q. Can Sony fix it?
    A. Shortly after containing SCEE, the online forms connected to login and password recovery for the PlayStation and other linked networks was shut down and placed in a maintenance mode, I can only assume this is a direct response to our detailed reports to SCEE, with that said, I assume that when services resume the exploit will be patched and everyone’s data once again safe.

    Q. If Sony fixes the hole should I worry?
    A. I would suggest that everyone, regardless of if they have been affected or not, create a new password and change their account email to one they do not use anywhere else, and will not be sharing with anyone else just for additional security.

    Q. Will you give us more details on the exploit?
    A. Until we have confirmed that the security hole has been patched we will not release further details on how and why the exploit was possible.


    Sources: EuroGamer.Net
    Nyleveia.com
    Comments 24 Comments
    1. fistsofchaos's Avatar
      fistsofchaos -
      WTF SONY!!! i dont even like psn and this sh*ts getting old! first woot woot
    1. Guppie77-PSG's Avatar
      Guppie77-PSG -
      second ^^^^
      Sony fails xd
    1. ch13696's Avatar
      ch13696 -
      It makes me wonder what Microsoft does to thwart hackers. OH, THAT'S RIGHT!!! They don't **** with them. They just ban people and try not to take people's money.
    1. perspex's Avatar
      perspex -
      both of you are immature ^ lol, sony is starting to piss everyone off, they started right from the beginning of the "next gen" consoles. First they lied their *** off with motorstorm, and it was NOTHING like they promised. Lying F**KS.

      Then they overcharge for the ps3, then they give users the crappiest of all online experience with intense lags and sometimes fail matches(with MK vs DC). Then they become uncreative d**ks and steal nintendo's idea and makes the PS move controller.
      Then comes the intense almost year long hackers battle and legal cases., then comes them getting a$$ ra*ped by anonymous and others and shuts down psn for a month, comes back only to find their security is still total CR*P.

      Even xbox sucked with all the RROD problems. The entire "NEXT GEN" was a f**ked up time of the gaming generation filled with problems,issues,hacks,cheaters,frauds,liars,legal cases. Only person who stayed cool and good was nintendo and i didn;t like them also because of their insanely BAD GRAPHICS on their wii.

      Hope they dont f**k up the "NEXT GEN" again in 2014!
    1. merkinmaker's Avatar
      merkinmaker -
      Let me just say...I'm very glad that my console will not be visiting the interwebs any time soon. I am also pleased that I have never used my credit/debit card for any transactions on the PSN. With this being said, Sony's incessant security failures are becoming quite entertaining. Sorry to those that actually use this tangled mess of cables known as the PSN.
    1. Hkas's Avatar
      Hkas -
      lol gotta love it... only console i ever used a credit card on was my 360 and i dont even have that card anymore...
    1. indecks-PSG's Avatar
      indecks-PSG -
      who cares. Honestly.
    1. zombmodz-PSG's Avatar
      zombmodz-PSG -
      Quote Originally Posted by indecks View Post
      who cares. Honestly.
      Seriously, can we even believe any of these ******** $ony stories anymore? Just another excuse for MORE SECURITY.
    1. solo0891's Avatar
      solo0891 -
      Quote Originally Posted by ch13696 View Post
      It makes me wonder what Microsoft does to thwart hackers. OH, THAT'S RIGHT!!! They don't **** with them. They just ban people and try not to take people's money.
      I agree , sony has the fault for trying to **** with the hackers , now they **** sony and consequence is people dont trust in sony now or maybe microsoft has the elite security information system experts on the world working for them , i know that there are not a unhackeable system but i never heard of a attack like this to microsoft .
    1. Turkish-PSG's Avatar
      Turkish-PSG -
      I'm playing back online looooooooooooooooooooooool, thanks Sony
    1. NEO117-PSG's Avatar
      NEO117-PSG -
      Quote Originally Posted by Turkish View Post
      I'm playing back online looooooooooooooooooooooool, thanks Sony
      Oh goodie. :3

      See you in MK. Oh wait...
    1. darkshin0b1-PSG's Avatar
      darkshin0b1-PSG -
      Quote Originally Posted by Turkish View Post
      I'm playing back online looooooooooooooooooooooool, thanks Sony
      here we go... hey turkish u still ra*pin goats out there hehehe..but on topic..F*A*K SONY..You deserve it for taking away my Linux and PS2 capabilites..you could secure that!!!!
    1. badkiller2-PSG's Avatar
      badkiller2-PSG -
      AGAIN?!?! AT LEAST TRY TO LEARN FROM YOUR ******* MISTAKES!!! SONY keeps making me feel stupid for being a supporter once each and every ******* time....

      This is a really bad joke. Let's see you weasel talk out of THAT, Kaz!!! is there also going to be another petty little WelcomeWelcome back gift?? HAH..



      Quote Originally Posted by Turkish View Post
      I'm playing back online looooooooooooooooooooooool, thanks Sony
      I hope that was sarcasm.
    1. gsharpshooter80's Avatar
      gsharpshooter80 -
      Quote Originally Posted by Turkish View Post
      I'm playing back online looooooooooooooooooooooool, thanks Sony
      hahaha "back online" ?? what are you talking about buddy I have been on xlinkkai this whole time with cod black ops and never lost anything, only gained actually after Sony's fail(s) !
    1. Guillermo Nolasco's Avatar
      Guillermo Nolasco -
      Quote Originally Posted by gsharpshooter80 View Post
      hahaha "back online" ?? what are you talking about buddy I have been on xlinkkai this whole time with cod black ops and never lost anything, only gained actually after Sony's fail(s) !
      xlink kai is a piece of **** and u can on play up to 4 people **** that **** hahaha psn is way better then kai
    1. TLX317's Avatar
      TLX317 -
      It's like all you people don't know he's a troll and keep feeding the damn thing.

      Also, I just got an email saying my PSN password's been changed, I haven't gotten on to change it yet... hmm...
    1. One2thr456svn's Avatar
      One2thr456svn -
      Why dose this not surprise me
    1. Tranced's Avatar
      Tranced -
      Sons'y security flaws are OUTSTANDING (MK)
    1. Hkas's Avatar
      Hkas -
      Quote Originally Posted by Guillermo Nolasco View Post
      xlink kai is a piece of **** and u can on play up to 4 people **** that **** hahaha psn is way better then kai
      lol well youre a ****** you just need the right setup and connection and kai is perfect...
      and yeah to my knowing kai hasnt gotten hacked yet but look at psn its still revealing itself to be a piece of crap just like sonyy
    1. Marsupilami74-PSG's Avatar
      Marsupilami74-PSG -
      I want to make this clear to ALL PSN users. Despite the methods currently employed to force a password change when you first reconnect to the PlayStation network, your accounts still remain unsafe.
      A new hack is currently doing the rounds in dark corners of the internet that allows the attacker the ability to change your password using only your account’s email and date of birth.

      It has been proven to me through direct demonstration on a test account, so I am without any shadow of a doubt that this is real.

      I would suggest that you secure your accounts now by creating a completely new email that you will not use ANYWHERE ELSE, and switching your PSN account to use this new email. You risk having your account stolen, when this hack becomes more public, if you do not make sure that your PSN account’s email is one that cannot be affiliated with or otherwise traced to you.

      While we originally assumed this was a poor hoax designed only to stir the community into another frenzy, the individual who we are in contact with requested just two pieces of information from us: this being an account email and the date of birth used for that account. We promptly created a new account via us.playstation.com and provided the individual with the email address and date of birth used.

      Roughly a minute later they requested that we try to login with the password we used for the account (which they did not know at any point), and sure enough, we were presented with an invalid username and/or password prompt.

      In addition to this, within a few minutes we received an email from Sony stating the following:

      This email confirms that your PlayStation(R)Network password account has been changed successfully.

      If you did not change your password…
      This email has been sent to you because the password for the relevant PlayStation(R)Network account has been changed.
      If you did not change your password, please contact Customer Support at the following address:

      networksupport@uk.playstation.com

      The PlayStation(R)Network Team

      While we will not reveal specific details regarding how the exploit is performed for obvious reasons, we can say that the exploit involves a vulnerability in the password reset form currently implemented, not properly verifying tokens.

      Source:
      http://sony.nyleveia.com/2011/05/17/...till-not-safe/
  • Daily Digest


    Want to receive the latest PSX info in your email?

    Sign up for our Daily Digest!



    Want to learn more about the team keeping you up to date with the latest scene news?

    Read about them now!

    Check out our Developer bios, too!

  • Recent Threads

    Alderaan

    Help with PK2 file - Star Wars ROTS

    Thread Starter: Alderaan

    Can anyone help me with the exact location of the Jedi Mantra audio data (in the jedi temple you can hear a voice going through the sentences of the mantra)?

    Last Post By: Alderaan Today, 05:34 AM Go to last post
    InfernalFury

    Possible to transfer trophies to another profile user?

    Thread Starter: InfernalFury

    I've recently been banned a week ago due to using cfw. Created a new psn account using unban program and managed to resign my saves to match my newly

    Last Post By: bitsbubba Yesterday, 11:14 PM Go to last post
    nokiajavi

    USBUtil 2.1 Ultimate.REV.1.2[UPDATE]

    Thread Starter: nokiajavi

    USBUtil 2.1 (rev 1.2) May 2010

    Due to bugs reported these last weeks, USBUtil has been revised.



    Quote ISEKO

    Last Post By: RandQalan Today, 04:31 AM Go to last post
    Dante69

    THE DUPLEX VER OF Pixars UP Game is in French...Anyone know how to install in ENGLISH?

    Thread Starter: Dante69

    THE DUPLEX VER OF Pixars UP Game is in French...Anyone know how to install in ENGLISH?

    I installed this game called "Up (2009) "

    Last Post By: BahumatLord Yesterday, 09:01 PM Go to last post
    ncc2906

    error 80010017

    Thread Starter: ncc2906

    Hi,
    what does it means erro 80010017 ?
    This error occur only when I launch Sonic The Hedgehog (BLES00028).
    I have Regub 4.41.2 lite.

    Last Post By: No0bZiLLa Yesterday, 09:55 PM Go to last post
    Tsukino Kaji

    I Just Want to Hack Games.

    Thread Starter: Tsukino Kaji

    I'm not big on online console gaming, that's what PCs were made for. lol
    I mostly just use my PS3 for RPGs and what not, the most online content

    Last Post By: nova89 Yesterday, 07:50 PM Go to last post
  • Recent Comments

    eustolio

    SDAT Creator by oakhead69

    Under this method, you can create edat_decrypter_creator?
    Thanks for u work oakhead69! Go to last post

    eustolio Today 04:53 AM
    opium2k

    {Guide} Install multiMAN Themes via a PKG File

    Nice of them to mention me but I haven't my multiMAN themes in ages. Probably best stick with more... Go to last post

    opium2k Today 03:35 AM
    the-green

    IrisManager v2.45 -- Various Additions and Improvements

    thanks for this update !!! Go to last post

    the-green Today 03:27 AM
    STLcardsWS

    Sony's Testing a Better, Faster Video Streaming Technology.

    :superfacepalm::superfacepalm:

    You get two :)

    More and more people are dropping... Go to last post

    STLcardsWS Today 02:45 AM
    BahumatLord

    Sony's Testing a Better, Faster Video Streaming Technology.

    You think that people with an internet connection for this streaming video test don't have cable?... Go to last post

    BahumatLord Today 02:29 AM
    bitsbubba

    New Multiman Themes by hcode123

    and the rest: :p

    Bioshock Infinite theme.zip
    Blue Bleach Theme.zip
    Evangelion Theme.zip... Go to last post

    bitsbubba Today 02:07 AM
    STLcardsWS

    New Multiman Themes by hcode123

    The captcha on mediafire are random./ Basically if you download a few things it wants you to prove... Go to last post

    STLcardsWS Today 02:00 AM
    STLcardsWS

    Sony's Testing a Better, Faster Video Streaming Technology.

    :facepalm:

    While i agree those are older movies. However "COMPLETELY FREE OF CHARGE"? You are... Go to last post

    STLcardsWS Today 01:40 AM
    Gradius

    PSIO Team Update To Project PlayStation Input Output - A PS1 SD Card Hack

    Should be below US$ 50 as the only expensive IC is the Altera Cyclone EP3C5E144C8N ($12.8ea).
    ... Go to last post

    Gradius Today 01:37 AM
    InfernalFury

    New Multiman Themes by hcode123

    All of them actually.. The links that are on media fire I have been getting that captcha error :/... Go to last post

    InfernalFury Today 12:06 AM