|
GAF's Bob Woodward
(05-18-2011, 01:29 PM)
|
#101
Rather frightening that this could slip through (supposedly) multiple independent audits by external experts. I guess it goes to show that perfect processes don't exist.
I guess the only silver lining here is that the people who exposed the exploit appear to be white-hat, and I presume little if any damage was done as a result. Sony's under a microscope at the moment, but that's no bad thing for the longer term security of PSN. |
|
|
|
Member
(05-18-2011, 01:29 PM)
|
#102
Originally Posted by TTP:
Specifically, they posted a link about the reset token, then they followed it up w/ a line that more or less said "when this is used in conjunction w/ another address/link". I figured if someone dicked around a bit on the website, one could accidentally stumble upon the correct procedure. Like I said, after a few minutes, I had a sudden feeling of "Oh shit, if Sony someone is able to trace this, I'm going to be locked out of my own PSN account", so I stopped at that point. :p Oh and to clarify, I'm not a hacker-type of person. To me, this seems more on the levels of "any schmuck can probably figure this out". And hey, I have schmuck-level hacking skills, so I figured, what the hell. |
|
Member
(05-18-2011, 01:30 PM)
|
#103
Originally Posted by TTP:
|
|
Scary Euro Man
(05-18-2011, 01:32 PM)
|
#104
Originally Posted by V_Arnold:
|
|
Have a fun! Enjoy!
(05-18-2011, 01:33 PM)
|
#105
Originally Posted by Oni Jazar:
You too HaRyu. Ty :) |
|
Member
(05-18-2011, 01:33 PM)
|
#106
Originally Posted by expy:
|
|
Member
(05-18-2011, 01:35 PM)
|
#107
Originally Posted by TTP:
http://www.neogaf.com/forum/showpost...postcount=1882 |
|
Member
(05-18-2011, 01:36 PM)
|
#108
Originally Posted by iapetus:
|
|
Member
(05-18-2011, 01:36 PM)
|
#109
Originally Posted by mujun:
*shakes fist* CURSE YOU EXPY! |
|
(05-18-2011, 01:36 PM)
|
#110
One clarification, I think the red square isn't the new password. It might be the name on my accuont, it's just that when I created the account I probably used some random name that I don't remember and I thought it would have been the new password.
But there's a space in the middle, and PSN passwords don't allow spaces. |
|
Banned
(05-18-2011, 01:39 PM)
|
#111
Sony this gen: 599 fucks up the ass
|
|
(05-18-2011, 01:41 PM)
|
#112
Originally Posted by Metalmurphy:
|
|
Member
(05-18-2011, 01:41 PM)
|
#113
Originally Posted by Utako:
|
|
Member
(05-18-2011, 01:41 PM)
|
#114
Originally Posted by mujun:
|
|
Member
(05-18-2011, 01:41 PM)
|
#115
Originally Posted by Utako:
|
|
It is illegal to Tag Fish in Tag Fishing Sanctuaries by law 38.36 of the GAF Wildlife Act
(05-18-2011, 01:42 PM)
|
#116
I know that you could bypass some of the password security by changing 'security' by 'reset' in an URL or something like that.
Thats how i had to reset my password. I just had to put my Date of Birth and mail and BAM! New Password. |
|
needs to fix his kismet
(05-18-2011, 01:44 PM)
|
#117
Originally Posted by iapetus:
|
|
XP-39Cē
(05-18-2011, 01:45 PM)
|
#118
So this only potenially affected people who hadnt rested their password? What about those who had rest their password?
|
|
Member
(05-18-2011, 01:46 PM)
|
#119
Originally Posted by Fersis:
Next thing we'll find out is they didn't string-escape their input fields and people took over entire databases! lol NOT SAYING IT HAPPENED, JUST A JOKE. =P |
|
Member
(05-18-2011, 01:47 PM)
|
#120
Originally Posted by test_account:
Because you needed those two things to do this "hack".. but maybe people are thinking that the "original psn hackers" have this info.. |
|
It is illegal to Tag Fish in Tag Fishing Sanctuaries by law 38.36 of the GAF Wildlife Act
(05-18-2011, 01:47 PM)
|
#121
Originally Posted by test_account:
The thing was to make SONY to send you a 'password' reset email, then youll change some of the URL and bam! If you have a new password they dont send you a mail with the URL. At least thats how i think it works. ITS NOT A FACT KOTAKU!
Originally Posted by brentech:
|
|
Member
(05-18-2011, 01:48 PM)
|
#122
Originally Posted by Fersis:
|
|
It is illegal to Tag Fish in Tag Fishing Sanctuaries by law 38.36 of the GAF Wildlife Act
(05-18-2011, 01:50 PM)
|
#123
Originally Posted by RbBrdMan:
Thanks. |
|
Member
(05-18-2011, 01:51 PM)
|
#124
Originally Posted by test_account:
|
|
Junior Member
(05-18-2011, 01:51 PM)
|
#125
Originally Posted by expy:
|
|
Member
(05-18-2011, 01:51 PM)
|
#126
Considering how we're on the 3rd page and all...
From what I gather, Sony was told, and they took the page that could have caused the exploit down to try and fix the issue, right? So how is that, as the thread title implies, "Trying to hide it"? |
|
Member
(05-18-2011, 01:52 PM)
|
#127
Originally Posted by kurtrussell:
Warning shots fired. |
|
It is illegal to Tag Fish in Tag Fishing Sanctuaries by law 38.36 of the GAF Wildlife Act
(05-18-2011, 01:52 PM)
|
#128
Originally Posted by HaRyu:
Theyre hiding it by not confirming that this is the reason why they took down the websites. |
|
Member
(05-18-2011, 01:53 PM)
|
#129
Originally Posted by HaRyu:
|
|
thanks for the laugh
(05-18-2011, 01:54 PM)
|
#130
Originally Posted by mujun:
|
|
Member
(05-18-2011, 01:55 PM)
|
#131
Originally Posted by gofreak:
|
|
Banned
(05-18-2011, 01:57 PM)
|
#132
Originally Posted by kurtrussell:
|
|
(05-18-2011, 01:57 PM)
|
#133
Originally Posted by HaRyu:
"Fortunately we have got ISPs to release outstanding emails; unfortunately, a small amount of maintenance is required to improve this process" |
|
XP-39Cē
(05-18-2011, 01:57 PM)
|
#134
Originally Posted by Hanmik:
Originally Posted by Fersis:
Also, is there a way to figure out which birthday you have registered on PSN? I checked my PSN email from when i registered my account, but it doesnt mention any birthdate there. Since i used fake name and adress, i'm pretty sure that i used a fake birthdate as well. EDIT:
Originally Posted by DarkUSS:
|
|
Banned
(05-18-2011, 02:00 PM)
|
#135
Seriously, no kidding. I'm really glad they were white hat.
Does anyone still use "hacker" and "cracker" to differentiate? Is that still a thing being pushed? I can never get myself to accept "cracker" as black hat, at least not with the racial nomenclature that its had slapped onto it. |
|
#upliftingtherace
(05-18-2011, 02:00 PM)
|
#136
it's a good thing NeoGAF isn't like so many forums out there that have a wealth of information displayed on user pages like birthdate and email...
so many other forums have all that stuff listed and have those 'HAPPY BIRTHDAY TO ____' things up etc... |
|
Member
(05-18-2011, 02:00 PM)
|
#137
Originally Posted by Fersis:
Never mind. :p |
|
Have a fun! Enjoy!
(05-18-2011, 02:00 PM)
|
#138
So I just applied for a password change on my US account, and since my PS3 is not active under that account I've got the confirmation link, which looks like this:
store.playstation.com/accounts/security/resetPassword.action?token=* So I see the link in the OP has a slightly different URL. It says ...reset/resetPassword.action... instead of ...security/resetPassword.action... Guess this is what Fersis was talking about. I do wonder how one can get that URL and change it without having access to the recipient email.
Last edited by TTP; 05-18-2011 at 02:04 PM.
|
|
Member
(05-18-2011, 02:02 PM)
|
#139
Originally Posted by kurtrussell:
|
|
Member
(05-18-2011, 02:05 PM)
|
#140
Originally Posted by test_account:
|
|
Member
(05-18-2011, 02:09 PM)
|
#141
Great, and the DoB was the one thing that it doesn't appear I can change in my profile. I changed my other personal information to bogus info but couldn't figure out how to change that. Does anyone know a way to do it?
|
|
Member
(05-18-2011, 02:14 PM)
|
#142
Hold on. If you had to click on the link that was sent to your email - of which only you have access to - then how was that done?
Have I missed something here? |
|
Spelling is Hard
(05-18-2011, 02:14 PM)
|
#143
Everything is exploitable. All the hackers are probably pooling their resources into finding every possible Sony one. I'm not surprised if they find more. If all these hackers put all their efforts into doing the same for Microsoft I bet they'd find exploits there as well.
|
|
LATIN, MATRIPEDICABUS, DO YOU SPEAK IT
(05-18-2011, 02:15 PM)
|
#144
Originally Posted by test_account:
|
|
Member
(05-18-2011, 02:15 PM)
|
#145
This is hardly encouraging... How did they not discover this exploit before some guy on the internet? Thank god it was a good guy.
Doubt I'll ever feel comfortable having personal information and software licenses linked to my PSN account. |
|
(05-18-2011, 02:16 PM)
|
#146
Originally Posted by MarkMclovin:
|
|
XP-39Cē
(05-18-2011, 02:16 PM)
|
#147
Originally Posted by DarkUSS:
|
|
#upliftingtherace
(05-18-2011, 02:17 PM)
|
#148
Originally Posted by Angry Fork:
|
|
Have a fun! Enjoy!
(05-18-2011, 02:17 PM)
|
#149
Originally Posted by MarkMclovin:
|
|
Member
(05-18-2011, 02:17 PM)
|
#150
Originally Posted by Angry Fork:
|