Sony's PSN password page exploit
When will it end?
Eurogamer has seen video evidence that verifies reports that Sony's PlayStation Network password reset system suffers from an exploit that allows attackers to change your password using only your PSN account email and your date of birth – information compromised in the PSN hack of 20th April.
Sony today made PSN sign-in unavailable for a number of its websites, including PlayStation.com and the PlayStation forums. All PlayStation game titles are also unavailable.
Crucially, the website users are directed to by password reset emails is now down.
"Unfortunately this also means that those who are still trying to change their password via Playstation.com or Qriocity.com will be unable to do so for the time being," Sony said. "This is due to essential maintenance and at present it is unclear how long this will take.
"In the meantime you will still be able to sign into PSN via your PlayStation 3 and PSP devices to connect to game services and view Trophy/Friends information."
Sony later tweeted: "Clarification: this maintenance doesn't affect PSN on consoles, only the website you click through to from the password change email."
The exploit was first revealed on Nyleveia.com.
"I would suggest that you secure your accounts now by creating a completely new email that you will not use ANYWHERE ELSE, and switching your PSN account to use this new email," recommends the site.
"You risk having your account stolen, when this hack becomes more public, if you do not make sure that your PSN account's email is one that cannot be affiliated with or otherwise traced to you."
NeoGAF users have also corroborated the claim.
Nyleveia claims to have contacted Sony about the exploit. "The system went down approximately 15 minutes after I received a response from SCEE on the matter."
Sony has taken the page in question down, and with any luck is fixing the exploit.
Eurogamer has contacted Sony for comment.
You may also like...
-
Nintendo reveals evolved Wii U GamePad, Xbox-like Pro Controller 53
-
In Theory: How The Cloud Could Run Backwards-Compatible PlayStation Games 96
-
From Assets on VHS to Execs Going Mad and Journos in Jail: Eurogamer's E3 Memories 33
-
Nintendo reveals online Wii U network Miiverse 18
-
Epic opening new studio with Kingdoms of Amalur devs 20
-
Face-Off: Dragon's Dogma 94
-
Is Nintendo HD Ready? 88
-
Sports Interactive boss denies Sega Europe closure rumour 25
-
App of the Day: Baseball Superstars 2012 6
-
Batman: Arkham City - Harley Quinn's Revenge Review 38
-
App of the Day: Spelltower 8
-
Face-Off: Ghost Recon: Future Soldier 58
-
Saturday Soapbox: Eurogamer's Love Letter to E3 28
-
Sleeping Dogs Preview: United Front's Open World Game Isn't What You'd Expect 50
-
New Gears of War confirmed 102
Comments (144) Latest comment 1 year ago
Comments for this article are now closed, but please feel free to continue chatting on the forum!
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
lol
Comment below viewing threshold Show
Comment below viewing threshold Show
or
"has a security hole"?
There's a big difference
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
Its a security hole/exploit call it what you will in the system.
Edit: Wesley's been good enough to edit his story, so its only fair I take the EG bashing out of mine
Comment below viewing threshold Show
Comment below viewing threshold Show
That whole case seems so long ago now.
Comment below viewing threshold Show
EDIT: Great, bashing Sony has become popular again. A hacked website can happen to anybody, get off Sony's back.
Comment below viewing threshold Show
Somebody's getting a P45
Comment below viewing threshold Show
In a world hacker free, there ll be none of this plus Windows not getting daily updates and so on.
Comment below viewing threshold Show
Comment below viewing threshold Show
I also deleted my billing info from PSN.
Sorry Sony I just can't trust that you won't get hacked again. Looks like I was right to be cautious.
Comment below viewing threshold Show
I know people are annoyed at Sony but they need a bit of empathy from us gamers. They've spent 20 odd days getting our services up and running, given us a more than generous welcome back offer and now are still being victimised by these cyber tossers.
Okay so not a hack (revokes above rant) but still, can people please stop ranting on about Sony. The selfish part of me wants to see all this crap happen to Xbox owners so they can get off their high horses. But the reality is that I wouldn't wish this scenario on any gamers of any platform.
Comment below viewing threshold Show
Comment below viewing threshold Show
This is beyond ridiculous now
Comment below viewing threshold Show
Comment below viewing threshold Show
And Poole is loving every second of it.
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
I'm not re-signing up to Sony ever again.
Totally incompetent.
Comment below viewing threshold Show
This is the second time today isn't it?
Comment below viewing threshold Show
Comment below viewing threshold Show
Good man
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
A hack is breaking into a system - which most times, involves using exploits to gain access
An exploit is getting a system to do things that it shouldn't do (but at no time actually breaking into it).
Comment below viewing threshold Show
cwk, see x201's reply above mine, he explains it better. Hacking is the process of breaking into a system, usually through the use of exploits.
Comment below viewing threshold Show
Also, I must admit that I'm somewhat of a PS3 fanboy due to my innate sense of mistrust towards Microsoft (that and Uncharted and God of War) but even I'm getting tired of this.
These continued hacks are like kicking your opponent when they're down on the ground and sobbing for mercy.
Comment below viewing threshold Show
Comment below viewing threshold Show
Such a secure system, eh?
Comment below viewing threshold Show
PWND
lulz
etc
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
Still the breach was found and they are in the process of fixing it.....no evidence that any hackers have actually used the exploit yet.
Not a good few weeks for Sony, hopefully they can bounce back from this
Comment below viewing threshold Show
Comment below viewing threshold Show
Hackers have NOTHING to do with this. An exploit has been found - ONCE AGAIN DUE TO SONY'S INCOMPETENCE WITH NETWORKED SOFTWARE AND SERVICES.
But I've only been saying for several YEARS that Sony can't 'do' networked software and services.
Comment below viewing threshold Show
I messed up my new password and had to reset it again because I'd forgotten a special character or something. I noticed all you need is date of birth and email to request the password change. Sony, I think you need to force us to add some new security info now all that stuff's been lifted...
Comment below viewing threshold Show
Comment below viewing threshold Show
Couldn't Sony splurge for a nice website that gives PSN users a free e-mail address and send copies to that address by default?...
username@myps3.com or something?
Not linked to anything else, plus they can put their ads up all over the place...
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
Seems some guys have their fun with you now.
Comment below viewing threshold Show
You're at no risk now that they've taken the page down.
As long as you haven't received an unsolicited password change confirmation email - then you'll be OK.
Comment below viewing threshold Show
Comment below viewing threshold Show
Asking for email and date of birth is not security for changing passwords. A lot of this information can be obtained relatively easily for a lot of people anyway - regardless of what hackers may have been taken earlier.
When you haven't got a secured means (ie. a registered PS3 console), then they should be asking for the original password and/or generating a validation token that is sent to the email address, that people then have to verify the request.
Complete utter fail, Sony. What's the compensation package for this cock-up?
And Stringer - this complete incompetence, following your outburst the other day - when are you packing your bags?
Comment below viewing threshold Show
Get on the ball.
Comment below viewing threshold Show
But games I already have do not make up for this ENDLESS STREAM OF HASSLE TO ME AS A CUSTOMER, FUCKING SORT IT PLEASE!!!
Comment below viewing threshold Show
IT'S TOTALLY COOL THOUGH GUYS. WE'VE GOT THE GREATEST MINDS IN DATA SECURITY WORKING ON THIS.
yes, yes you have.
Comment below viewing threshold Show
Comment below viewing threshold Show
Once caged they can be fed an hourly dose of sensationalist "Sony is failing headlines" to prevent their heads from exploding.
Oh, apparently they already have, they called the so called cage eurogamer
Comment below viewing threshold Show
Short version afaik is that an exploit was found where a hacker could redirect/intercept the confirmation email sent after a password reset was requested.
Fortunately it seems that both requests (the initial request for a change, and the actual confirmation of the password change) do go to the original owner so its not like this could be done without the victim being sent two emails confirming the action.
If anything has happened to you, you'll know about it, and so will Sony.
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
That's not the way to invoke coolbritannia's. You have to call his name 3 times
coolbritannia
coolbritannia
coolbritannia
Does anyone else have a suspicious feeling that M$ might be behind all this hacking, as a major publicity plot??????????
No, MS and their products are under attack every single day. They have more experience in this area unlike Sony. Since the day Sony declared war, they will find themselves in the same position as MS. They are a focus for people who love to hack, exploit or grief a company. From now on Sony will have to make sure they secure everything. Any exploit will be taken advantage of. It will make Sony stronger if they can take it but it will also be a constant assault they will have to endure.
Comment below viewing threshold Show
Thanks
Comment below viewing threshold Show
Pretty shoddy work to be honest though at least it should be clear that this has happened to you (since it still seems to send out two emails).
Comment below viewing threshold Show
Oh well, just a case of logging in on my PS3 and swapping it over hopefully. Providing I can still log in.
Comment below viewing threshold Show
Comment below viewing threshold Show
No don't worry. Microsoft are totally on the ball when it comes to online security and would never, ever, release any product that has any type of potential security issue that hackers could exploit.
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
I stand corrected, although regardless of the methodology the email conformations thankfully do get sent!
That said, if the person exploiting the system like this already have your PSNID, email address and DoB why do they need to hack you again? Just seems like a griefing attack tbh.
Comment below viewing threshold Show
coolbritannia
coolbritannia
coolbritannia "
Heeeeere's Britney!
Honestly though, it's no big deal, Sony cannot fail any further in my eyes. Completely and utterly useless in every way. Their online will be forever compromised.
Comment below viewing threshold Show
You've just had your customers details syphoned from your servers. You've just spent three weeks improving the security and applying the server patches you should have done months ago.
Then you *don't* make a list of the different portals where your details can be changed and check whether the processes in place can be exploited with those lost details?
That really doesn't inspire me with confidence.
Comment below viewing threshold Show
wait,,, isnt its should be "fixing the vulnerability" ?
"Eurogamer has seen video evidence that verifies reports that Sony's PlayStation Network password reset system suffers from an exploit that allows attackers to change your password using only your PSN account email and your date of birth "
become
"Eurogamer has seen video evidence that verifies reports that Sony's PlayStation Network password reset system suffers from an vulnerability that when exploited allows attackers to change your password using only your PSN account email and your date of birth "
Comment below viewing threshold Show
Swings and roundabout mate! don't need people like you sticking the boot in every 2 minutes.
Comment below viewing threshold Show
Howard Stringer, Sony Corp. Chief Executive, a couple of days ago.
Comment below viewing threshold Show
Anyway, all of this reminds that I still need to turn my PS3 on and change the password on my account.
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
That's stupid beyond belief!
Comment below viewing threshold Show
if you did, you certainly wouldn't change the locks and leave the doors open, like they have here.
Comment below viewing threshold Show
If I'm not bothering you, why don't you just ignore me? Or is that not possible with your OCD?
Comment below viewing threshold Show
Comment below viewing threshold Show
@topkatt, don't feed the trolls ffs.
Comment below viewing threshold Show
Where's Ken when you need him? Maybe they need to use the selling spiel they used when the PS3 price tag was announced?
"You should all work harder to earn more money and pay for a proper online service. Xbox Live."
Comment below viewing threshold Show
Ah, but I'm not the one having to resort to insults am I? Surely to get down to that level, I must be bothering him? He's not bothering me which is why I haven't insulted the little gobshite.
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
"Fuck off chan, you stupid boring cunt.
@topkatt, don't feed the trolls ffs. "
?????
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
18/05/11 @ 16:19
console gamers *sigh* small children the lot of them.
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
What's the solution here.
I've created a new email. Where can I change my PS account email to it? I'm not at home, but is there an option on the PS3 where you can switch your associated email account?
Comment below viewing threshold Show
Comment below viewing threshold Show
If you open it out to Sony and not just the PS3 you can add Lik-Sang, the Malware scandal, telling people to work harder to earn more money and "deserve" the PS3, the PS2 disc read error scandal, saying they wouldn't copy achievements just before they announced trophies, saying rumble was a last gen feature before they settled the court case with Immersion, trying to bully Kotaku....
And then there's always this!
Comment below viewing threshold Show
Anyway, my Eurogamer experience just got a bit more enjoyable:
ACHIEVEMENT UNLOCKED
You ignored the fanboys!
Comment below viewing threshold Show
It's more like after finding out that the burglar used the key you keep under a flowerpot to open your front door, you change all the locks on all the doors. Then you put the key under a different flowerpot.
Although TBH, this isn't much of an issue. After all, in order to use this exploit, they need your PSN email address and your DoB. The only people who will have this will be the original hackers or someone who will be specifically targeting you. If this were the case, losing your PSN account would be the least of your worries.
Still looks very poor on Sony's Part.
Comment below viewing threshold Show
Comment below viewing threshold Show
My, how the SDF all cackled, like Shakesperian witches.
That turned out well, didn't it!
Comment below viewing threshold Show
Christ, I know I can be immature at times but some of the people in here really need to grow the fuck up.
Comment below viewing threshold Show
Comment below viewing threshold Show
On the PS3, under Account Management you can change your Sign In Address. (you'll get prompted for your current password first) then simply put in the new email address
Account Management>Account Information>Sign-In ID (Email Address)
Comment below viewing threshold Show
You ignored the fanboys!
Blocked yourself have you, Tefal boy?
Comment below viewing threshold Show
Comment below viewing threshold Show
My, how the SDF all cackled, like Shakesperian witches.
That turned out well, didn't it!
Not only did people here at Eurogamer believe that Sony won a major victory over the hackers but there were analyst out there saying the same thing. I wonder if the Hackers were sitting there smiling as they had the smoking gun. The victory still might go to Sony but it will be a hard earned victory. Even if Sony get the win today, I believe they will constantly find themselves under assault.
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
The prodecure is as follows:
1) Navigate to : https://store.playstation.com/accounts/r... (this is normally, via email, https://store.playstation.com/accounts/r... with the y's being a unique token) - do not enter the code at this point.
2) Open a new tab in firefox, and go to fr.playstation.com (other pages will work too most likely), and click Login (Connexion)
3) Click Recover password
4) Enter the email and date of birth of the target account
5) Click continue, then on the confirmation page, click "Reset using E-mail"
6) Switch back to the original tab, and enter the code, then click continue
7) You will now be asked to enter a new password for the target account
Absolutely amazing that Sony didn't check something so simple. I mean this really is Forrest Gump territory now.
Comment below viewing threshold Show
Comment below viewing threshold Show
He blew up a building once because his friend made a phonecall.
Comment below viewing threshold Show
However, it seems Nyleveia.com did the right thing and report it to Sony before reporting it online. It's good to see that there are also 'white hat' hackers on the case. Sony apparently need all the help they can get, however sad that is.
It's embarrassing for sure but so far there's been no evidence of people actually taking advantage of the exploit, and realistically the chance was very small to begin with.
As long as you didn't have an unsolicited password reset, you're fine.
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
Absolutely. This is a big huge blow no matter how you spin it. It's like sony having their gentleman's sausage chewed off. Their best hope is that it can be sewed on again and that it will still do the job. But it's ugly to begin with.
Comment below viewing threshold Show
Comment below viewing threshold Show
I know I'm alone in this, but now I feel like 'go get 'em hackers.'
Comment below viewing threshold Show
Just useless.
Comment below viewing threshold Show
Comment below viewing threshold Show
I know I'm alone in this, but now I feel like 'go get 'em hackers.' "
Be careful though, "hacker" is a really broad term. They might be good ones this time, but many hackers are just after your wallet.
I'm not cheering for hackers unconditionally.
Comment below viewing threshold Show
Nope, I haven't blocked myself mate, haven't blocked you either. Out of interest, how am I a fanboy? Is it because I don't think this is a major issue? For the record, neither Sony nor MS mean much to me, they're just companies. I own both a PS3 and a 360 and I wouldn't do without either of them, although they both have good and bad points. Coolbritannia you may be a fanboy but at least you've got a sense of humour and you're not abusive like charliechan and his ilk.
Kinect is shite though.
Comment below viewing threshold Show
Comment below viewing threshold Show
How dare you! It has untapped potential! UNTAPPED!
Comment below viewing threshold Show
Comment below viewing threshold Show
It's quite sad really.
Comment below viewing threshold Show
Comment below viewing threshold Show
Deja vu all over again. Interesting enough Sony was the cause each time instead of just plain old fanboism.
Comment below viewing threshold Show
Comment below viewing threshold Show
http://www.bbc.co.uk/news/technology-13454201
Comment below viewing threshold Show
shoes</STRONG></A> louboutin shoes <A
href="">http://www.jordansvip.com/"><STRONG>jordan shoes</STRONG></A> jordan shoes
[link url=">http://www.sunglasskey.com/]<STRONG>oakley sunglasses</STRONG>[/link]
oakley sunglasses 2 <A
href="">http://www.christianlouboutinkey.com/"><STRONG>louboutin
shoes</STRONG></A> louboutin shoes <A
href="">http://www.jordansvip.com/"><STRONG>air jordan shoes</STRONG></A> air
jordan shoes <A href="">http://www.sunglasskey.com/"><STRONG>oakley
sunglasses</STRONG></A> oakley sunglasses 3 <A
href="">http://www.christianlouboutinkey.com/"><STRONG>louboutin
shoes</STRONG></A> louboutin shoes <A
href="">http://www.jordansvip.com/"><STRONG>jordan shoes for cheap</STRONG></A>
jordan shoes for cheap <A href="">http://www.sunglasskey.com/"><STRONG>oakley
sunglasses</STRONG></A> oakley sunglasses