Sony's PSN Changes didn't change a thing, Hackers Can still get your psn shit
71 replies, posted
[URL]http://sony.nyleveia.com/2011/05/17/warning-all-psn-users-your-accounts-are-still-not-safe/[/URL]
[quote]
I want to make this clear to [B]ALL[/B] PSN users. Despite the methods currently employed to force a password change when you first reconnect to the PlayStation network, your accounts still remain unsafe.[B]
A new hack is currently doing the rounds in dark corners of the internet that allows the attacker the ability to change your password using only your account’s email and date of birth.[/B]
It has been proven to me through direct demonstration on a test account, so I am without any shadow of a doubt that this is real.
I would suggest that you secure your accounts now by creating a completely new email that you will not use ANYWHERE ELSE, and switching your PSN account to use this new email. You risk having your account stolen, when this hack becomes more public, if you do not make sure that your PSN account’s email is one that cannot be affiliated with or otherwise traced to you.
While we originally assumed this was a poor hoax designed only to stir the community into another frenzy, the individual who we are in contact with requested just two pieces of information from us: this being an account email and the date of birth used for that account. We promptly created a new account via us.playstation.com and provided the individual with the email address and date of birth used.
Roughly a minute later they requested that we try to login with the password we used for the account (which they did not know at any point), and sure enough, we were presented with an invalid username and/or password prompt.
In addition to this, within a few minutes we received an email from Sony stating the following:[INDENT][quote]This email confirms that your PlayStation(R)Network password account has been changed successfully.
If you did not change your password…
This email has been sent to you because the password for the relevant PlayStation(R)Network account has been changed.
If you did not change your password, please contact Customer Support at the following address:
[EMAIL="networksupport@uk.playstation.com"]networksupport@uk.playstation.com[/EMAIL]
The PlayStation(R)Network Team[/quote][/INDENT]To the folks over at N4G, I realize that you may be hesitant to believe these claims however I can assure you that they are true.
Details of the exploit have been distributed via a certain PlayStation 3 “hacks” IRC server and are currently being utilized by a small group of people.
In creating this news article we want only to warn people and illustrate a definite way to protect their account while they can – I find the concept of burying ones head in the sand and refusing to believe something until the details of the exploit become widely known and peoples accounts are being compromised a very illogical way of handling things.
Look at things from my perspective, what options do you have here?, Do nothing, then run the risk of having your account compromised because a small relatively unknown site told you to change your email address and you didn’t listen, or take a few minutes of your time to change your email “Just in case”, then be safe in the knowledge that regardless of the outcome, your account is safe.
We have contacted Sony but do not expect any response until morning.
While we are hesitant to reveal too many details regarding how the exploit is performed, for obvious reason, we can say that the exploit specifically involves the web address [URL]https://store.playstation.com/accounts/reset/resetPassword.action?token[/URL] When used in combination with another web address (normally used for password recovery) certain key details can then be extracted and used to trick the server in to allowing the password of an account to be changed without a valid Sony-issued security token.
We will update with further details as soon as possible.[/quote]TL;DR People can still get into your PSN account Via Date of Birth and Email that was leaked with the PSN Info leak
[h2]GO LINK A NEW EMAIL TO YOUR PSN ACCOUNT RIGHT FUCKING NOW[/h2]
Fucking excellent.
God knows why they would put PSN back up without at least telling you this as well as forcing a new password. At the very least, tell you to make a new email
Thats VERY nice to know.
I thought everything was situated.
I guess not.
Eh, at least we're insured.
Basically Go link another Email account right fucking now while you still can.
hey sony now compensate me with some new games plox
Is it possible to cancel a PSN account? I never use my PS3 anymore and nor does anybody in my family, and with shit like this still going on, I don't want to take any chances.
[QUOTE=Sanius;29901695]Is it possible to cancel a PSN account? I never use my PS3 anymore and nor does anybody in my family, and with shit like this still going on, I don't want to take any chances.[/QUOTE]
i think you can decativate it but i dunno how
I wonder where we can find these "hacks" IRC servers, because this honestly sounds fake.
[QUOTE=Wii60;29901675]Basically Go link another Email account right fucking now while you still can.[/QUOTE]
Nah
I have a few bucks in my PSN wallet and if I lose that I can take Sony to small claims court for up to $2k
I doubt they'd send anyone to such a remote area to defend themselves so I'd get a default judgement
don't really believe the article but i changed my email just in case
I called it. I knew they were going to try to hack PSN or at the very least, steal users account.
So, I've recently changed my email password and I haven't logged into PSN for 9 months now (or received the newest update). Could I still be affected?
I'm glad when given the choice between a PS3 and a 360 I chose the latter
I never expected this kind of stuff to happen though
[QUOTE=Sanius;29901624]Fucking excellent.[/QUOTE]
The fuck's your problem? I don't even own a PS3 and I know you're an ignorant idiot.
[editline]18th May 2011[/editline]
Unless you are being sarcastic, it's hard to tell through text.
[QUOTE=A big fat ass;29902650]The fuck's your problem? I don't even own a PS3 and I know you're an ignorant idiot.[/QUOTE]
Nice to know that you can't detect even the most painfully obvious sarcasm. Living up to your username.
yeah you've got to be a dumbass to miss the sarcasm there honestly
Does this also include SoE games accounts for the PC?
"The email address you entered cannot be used"
Guess it doesn't like gmail.
[editline]18th May 2011[/editline]
Meh, I'll just delete my billing info.
Wow, these hackers must really hate Sony.
They probably figured out how to calculate the security token. Piss-easy to fix if that's the case.
if it was piss easy to fix then they would have done it weeks ago
And here we go again.
My trust in Sony is rapidly draining.
[QUOTE=En-Guage V2;29904369]if it was piss easy to fix then they would have done it weeks ago[/QUOTE]
Well, this [I]is[/I] Sony we're talking about here.
I haven't played EverQuest 2 in years. Does this still count for SoE PC?
Wow, it'll take ages before Sony can get up on their feet again.
[QUOTE=En-Guage V2;29904369]if it was piss easy to fix then they would have done it weeks ago[/QUOTE]It wasn't a problem weeks ago.
[QUOTE=chunkymonkey;29902700]"The email address you entered cannot be used"
Guess it doesn't like gmail.
[editline]18th May 2011[/editline]
Meh, I'll just delete my billing info.[/QUOTE]
Im not sure what they do now, but before sony kept all the info even if deleted.
Sorry, you need to Log In to post a reply to this thread.