Post: This is how PSN got hacked!
04-26-2011, 10:26 PM #1
ciunas
Insert User Title Here
(adsbygoogle = window.adsbygoogle || []).push({}); You must login or register to view this content.
Above is a screenshot of their PSN servers access logs. This log is created on the main server of the PlayStation Network. Likely many of you have no idea what exactly a log would be. Sony itself has this log file are also publicly retrievable through the URL. Mistake number two, perhaps? Here also some interesting logs:
Originally posted by another user
214.1.211.251 - - [15/Apr/2011: 9:40:11 -0700] "GET / OfficeScan / cgi / cgiChkMasterPwd.exe HTTP/1.1" 404 336 "-" "-"
178.202.110.92 - - [22/Apr/2011: 7:05:00 p.m. -0700] "GET / admin / cdr / counter.txt HTTP/1.1" 404 343 "-" "Mozilla/5.0 (compatible; Windows NT 6.1, de; rv: 1.9.2.16) Gecko/20110319 Firefox/3.6.16 "
214.1.211.251 - - [15/Apr/2011: 9:40:09 -0700] "GET / _vti_bin / fpcount.exe? Page = default.htm | Image = 3 | Digits = 15 HTTP/1.0" 404 325 "- "" - "
214.1.211.251 - - [15/Apr/2011: 9:39:51 -0700] "GET / scripts / foxweb.exe / HTTP/1.0" 404 324 "-" "-"
214.1.211.251 - - [15/Apr/2011: 9:39:48 -0700] "GET / phpwebfilemgr / index.php? F =../../../ etc / services HTTP/1.0" 404 328 " - "" - "

What we see here again include the use of an FVC, local file inclusion, in the last row. With this is that the ip 214.1.211.251, this is possibly the IP of the attacker. Nor has a number of Javascript injections occurred:
Originally posted by another user
214.1.211.251 - - [15/Apr/2011: 9:39:49 -0700] "GET / board.php? <script> FID = alert (document.cookie) </ script> HTTP/1.0" 404 314 "- "" - "
214.1.211.251 - - [15/Apr/2011: 9:39:38 -0700] "GET / servlet / webacc? User.id ="> <script> alert ('eeye2004'Winky Winky </ script> HTTP/1.0 " 404 319 "-" "-"
214.1.211.251 - - [15/Apr/2011: 9:39:30 -0700] "GET / modules.php? Name = Reviews & rop = post & title =% 253cscript comment> alert 2528document.cookie%)% 253c/script> HTTP / 1.0 "404 316" - "" - "

It is frightening to know that Sony is so easy to hack, because come on Sony, FVC and Javascript injections? Really? This looks like the work of a 14 year old boy. Thanks to SKFU Blog for the announcement of the log.

You must login or register to view this content.
(adsbygoogle = window.adsbygoogle || []).push({});

The following 7 users say thank you to ciunas for this useful post:

Aussie_Bob21, ChynkBud, Commodent, GQGK, isigo, NoBodyLovesMe, Zumper
04-27-2011, 12:58 AM #29
Frost1997
Bounty hunter
omg i would think it would be somethink a lot harder
04-27-2011, 01:00 AM #30
I could try this, I suck at hacking and looks like 2 hours or so of work, I just don't want to get in legal trouble.
04-27-2011, 01:07 AM #31
jo2305
▲ ▲ №Өβ ▲ ▲
Originally posted by 4chanPartyVan View Post
If the IP you provided is legit, the attack originated from a military site.. You must login or register to view this content.


HAHAHAHHAHAHAHAHA NOW THAT IS L3G1T

Btw i like your sig
04-27-2011, 01:08 AM #32
iTruceFret
[move]From now on, call me DRAGON.[/move]
Yeah whoever did this...is in deep ball**** with Sony. Not only did they, he, or she hack into their servers, but possibly stole CC information, which is a federal lawsuit. This isn't a DDos attack....this is WAAYY deeper. Whoever hacked this had balls bigger than anyone, and KNEW the consequences, and will now face them. Run and hide you peckerwood. You went too far with this one.
04-27-2011, 01:11 AM #33
USAB
Are you high?
I have a question: now that the servers are down, is it still possible the hacker can get info like cc?
04-27-2011, 01:37 AM #34
Herbal_T_Bag
You talkin to me?
Now everyone knows its not rebug woot
04-27-2011, 02:22 AM #35
ClutchLikeBron
Do a barrel roll!
Originally posted by dakillers1 View Post
Why write something that has no relevance WHATSOEVER to the topic and is not helpful to anybody:n:


Im sry, but it does. The ip address is from columbus ohio so suck it nerd
04-27-2011, 02:58 AM #36
Nero.
Space Ninja
Number to sony please? They are ganna get bitched out!
04-27-2011, 03:11 AM #37
Mr.Ron
Little One
Looks like Sony needs some better security if I do say so!

Copyright © 2026, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo