• Home
  • Downloads
  • EBOOT Fixes
  • Forums
  • New Posts
  • Register
    • Welcome, Register Now! 
    • Premium VIP Membership
    • PS3 Sticky
      • PS3 CFW & MFW
      • PS3 Debug Firmware
      • PS3 Decrypted PSN Links for CFW
      • PS3 Downloads
      • PS3 EBOOT.BIN Original File Links
      • PS3 Firmware
      • PS3 Game Releases List
      • PS3 Guides & Tutorials
      • PS3 Hacking Guides and Tutorials
      • PS3 Hacks & JailBreak
      • PS3 Help & Support
      • PS3 JailBreak Game Compatibility List
      • PS3 JB2 / True Blue (TB) Game Links
      • PS3 multiMAN Updates
      • PS3 Resources
      • PS3 Reviews
      • PS3 Save Files Repository
      • PS3 Themes
      • PS3 Trophies List
      • PS3 Videos
      • PS Vita Trophies List
    • Quick Links
      • Affiliates
      • Contact Us
      • FAQ
      • Post News
      • Site Rules
      • Tag Cloud
 

Sony Turns Off PSN Sign-In Due to Password Reset Security Issues

Category: PlayStation 3 & PSN News  By: PS3 News - (sony.nyleveia.com)
Tags: sony turns off psn sign-in psn exploit psn password reset psn security issues

105w ago - Today Nyleveia.com (linked above) reports news of a security issue with the PlayStation Network 'Password Reset' feature, and as a result Sony has turned off the PSN sign-in to remedy the matter.

Sony has also confirmed that it was indeed not a hack, but a URL exploit that was subsequently fixed.

To quote from Community Team Moderator Yaster via the official PS EU Forum:

"Hey Guys. Please note that PSN sign in is currently unavailable for the following services:

• PlayStation.com
• PlayStation forums
• PlayStation Blog
• Qriocity.com
• Music Unlimited via the web client
• All PlayStation game title websites

Unfortunately this also means that those who are still trying to change their password password via Playstation.com or Qriocity.com will be unable to do so for the time being. This is due to essential maintenance and at present it is unclear how long this will take.

In the meantime you will still be able to sign into PSN via your PlayStation 3 and PSP devices to connect to game services and view Trophy/Friends information."





From Kotaku, below is the exploit that was used but has since been disabled, to quote:

This is the purported exploit as provided to Kotaku. As PlayStation services are now offline, this exploit is no longer able to be executed:

The prodecure WAS as follows:
1) Navigate to : https://store.playstation.com/accounts/reset/resetPassword.action?token (this is normally, via email, https://store.playstation.com/accounts/reset/resetPassword.action?token=YYYYYYYYYYYYYYYYYYYYYYYY with the y's being a unique token) - do not enter the code at this point.
2) Open a new tab in firefox, and go to fr.playstation.com (other pages will work too most likely), and click Login (Connexion)
3) Click Recover password
4) Enter the email and date of birth of the target account
5) Click continue, then on the confirmation page, click "Reset using E-mail"
6) Switch back to the original tab, and enter the code, then click continue
7) You will now be asked to enter a new password for the target account

Finally, from Nyleveia.com to quote: "I want to make this clear to ALL PSN users. Despite the methods currently employed to force a password change when you first reconnect to the PlayStation network, your accounts still remain unsafe.

A new hack is currently doing the rounds in dark corners of the internet that allows the attacker the ability to change your password using only your account's email and date of birth.

It has been proven to me through direct demonstration on a test account, so I am without any shadow of a doubt that this is real.

I would suggest that you secure your accounts now by creating a completely new email that you will not use ANYWHERE ELSE, and switching your PSN account to use this new email. You risk having your account stolen, when this hack becomes more public, if you do not make sure that your PSN account's email is one that cannot be affiliated with or otherwise traced to you.

While we originally assumed this was a poor hoax designed only to stir the community into another frenzy, the individual who we are in contact with requested just two pieces of information from us: this being an account email and the date of birth used for that account. We promptly created a new account via us.playstation.com and provided the individual with the email address and date of birth used.

Roughly a minute later they requested that we try to login with the password we used for the account (which they did not know at any point), and sure enough, we were presented with an invalid username and/or password prompt.

In addition to this, within a few minutes we received an email from Sony stating the following:

This email confirms that your PlayStation(R)Network password account has been changed successfully.

If you did not change your password... This email has been sent to you because the password for the relevant PlayStation(R)Network account has been changed. If you did not change your password, please contact Customer Support at the following address:

networksupport@uk.playstation.com

The PlayStation(R)Network Team

While we will not reveal specific details regarding how the exploit is performed for obvious reasons, we can say that the exploit involves a vulnerability in the password reset form currently implemented, not properly verifying tokens.

UPDATE: In the interest of sidestepping the naysayers and getting the warning out there, if someone working for a larger, more well known site (Kotaku, Destructoid, IGN, etc) wants to contact me for a live demonstration that this exploit is the real deal, you can do so at nevada@nyleveia.com.

UPDATE 2: Web based PSN login / Password recovery is now down for maintenance, hopefully as a result of our contact with SCEE. And more importantly, hopefully to fix the security issue.

UPDATE 3: To clarify the situation, we had confirmed ourselves the method used last night, and contacted SCEE, SCEE have acted upon this information, we felt the information previously provided in our tweets and this article may have been a little too revealing to the vulnerability, thus we "dumbed down" the explanation of the security hole. We have provided SCEE with a detailed description of the security hole.

While it's unclear at this time if they will actually patch the flaw while they have the system taken down, I can also confirm that the system went down approximately 15 minutes after I received a response from SCEE on the matter.

We for rather obvious reasons do not want to elaborate further on the exact details of the exploit, on the off chance that when the web based interface for PSN is restored the exploit has not been patched.

UPDATE 4: Last update on the topic most likely, i notice a lot of people are saying that we should not have posted this information and simply contacted Sony, and you're right in thinking this, however we contacted SCEE as soon as we had confirmed that the exploit was in fact real, the problem was that at the time there was a good 8-9 hour stretch where SCEE would not see our messages and given the rate at which the exploit method was spreading in the dark corners of the internet, we felt as though we needed to publicise the exploit advising users to change the emails used for their PSN accounts to secure them until Sony could patch the security hole.

Originally we posted rough details on how the exploit operated, to give further evidence to users that it was a valid reason for them to change their passwords, as with most news like this on the internet, people tend not to believe something until hoards of users have been affected, we posted an article on N4G advising PSN users to switch their email addresses which was promptly reported as spam/lame/fake by several users who refused to believe the news due to our site just being a small news outlet.

All along our main priority and focus has been to assist Sony and PSN users in keeping their accounts safe. If the current downtime for the web based forms results in the exploit being patched then our job is done and the potential thieft of countless user accounts has been nipped in the bud as early as humanly possible.

Thank you to everyone that has taken our warnings seriously and acted upon it, and to SCEE for their swift response to the matter.

UPDATE 5: Okay, due to the email response I felt i should answer some general common questions regarding the topic.

Q. If I already reset my password am I safe?
A. The exploit was possible on any account the email and date of birth was known for, regardless of if the password was changed or not, or what region the account was tied to.

Q. What if they don't know my Date of Birth or Email account?
A. Then the average user would not be able to take your account, however due to the database being illegally accessed in April, it's safe to assume that someone, somewhere, has access to a large number of users details, which include date of birth and email addresses, this alone should be reason enough to change your email.

Q. Are you sure this is real?
A. Yes, it was demonstrated to one of our empty accounts, then we were able to repeat the process ourselves after figuring out the method, this was additionally confirmed when a twitter user provided us with his data and requested that we change his password as proof.
We have since emailed him his new password, and no other data on his account was changed.

Q. Can Sony fix it?
A. Shortly after containing SCEE, the online forms connected to login and password recovery for the PlayStation and other linked networks was shut down and placed in a maintenance mode, I can only assume this is a direct response to our detailed reports to SCEE, with that said, I assume that when services resume the exploit will be patched and everyone's data once again safe.

Q. If Sony fixes the hole should I worry?
A. I would suggest that everyone, regardless of if they have been affected or not, create a new password and change their account email to one they do not use anywhere else, and will not be sharing with anyone else just for additional security.

Q. Will you give us more details on the exploit?
A. Until we have confirmed that the security hole has been patched we will not release further details on how and why the exploit was possible."



Stay tuned for more PS3 Hacks and PS3 CFW news, follow us on Twitter and be sure to drop by the PS3 Hacks and PS3 Custom Firmware Forums for the latest PlayStation 3 scene updates and homebrew releases!

Comments 12 Comments - Go to Forum Thread »

Errors

The following errors occurred with your submission

Okay

Quick Reply Quick Reply

  • Decrease Size
    Increase Size
  • Wrap [QUOTE] tags around selected text
Posting Quick Reply - Please Wait Posting Quick Reply - Please Wait
barrybarryk's Avatar
#12 - barrybarryk - 103w ago
Reply
Looks like the PSN details are in the wild, I had used a seperate email account only for PSN and low and behold it started sending spam out last night. Someone in Kazakstan apparently:
Quote IP address: 178.91.65.48
Reverse DNS: [No reverse DNS entry per pri.authdns.ripe.net.]
ASN: 9198
ASN Name: KAZTELECOM-AS (JSC Kazakhtelecom)
IP range connectivity: 3
Registrar (per ASN): RIPE
Country (per IP registrar): KZ [Kazakstan]
Country IP Range: 178.88.0.0 to 178.91.255.255

GrandpaHomer's Avatar
#11 - GrandpaHomer - 104w ago
Reply
It's back BTW in case you've not noticed or checked by yourselves ...

matrixdts's Avatar
#10 - matrixdts - 104w ago
Reply
Hi all, how do you change the password via the ps3 please? I was sent the reset email 27 hours after it was sent and the link in the e-mail had expired after 3 hours, handy considering they sent it at 4 in the morning. Thanks all.

elser1's Avatar
#9 - elser1 - 104w ago
Reply
and this is how the experts that have charged sony millions of dollars fix things.. makes you feel a little bit safer.. LOL

GrandpaHomer's Avatar
#8 - GrandpaHomer - 104w ago
Reply
Originally Posted by leukotic View Post
Quote Just wish I could change my DOB.

You can - by calling the Customer service...

Page 1 of 3 123›LAST »

Related PS3 News and PS3 CFW Hacks or JailBreak Articles

• NIS America Announces Mugen Souls Officially Hits PSN Tuesday
• Black Ops II Uprising Out Today: Mob of the Dead, 4 New Maps
• Ratchet & Clank: Full Frontal Assault Updates from Insomniac Games
• Hands on with The Last of Us on PlayStation 3: Whatever It Takes
• Remember Me: New Art, Interactive Journal and Director PS3 Q&A
• Atomic Ninjas Storm PS3 and PlayStation Vita Later This Year
Affiliates  NewsNow  Privacy  PS3 CFW & MFW  PS3 Hacks & JailBreak  PS3 Reviews  PS3 Videos  © 2013 PlayStation 3 News

PlayStation 3 Links

• Contact Us E-Mail
• PS3 Affiliates
• PS3 CFW & MFW
• PS3 Debug Firmware
• PS3 Decrypted PSN Links for CFW
• PS3 Downloads
• PS3 EBOOT.BIN Original File Links
• PS3 Firmware
• PS3 Game Releases List
• PS3 Guides & Tutorials
• PS3 Hacking Guides and Tutorials
• PS3 Hacks & JailBreak
• PS3 Help & Support
• PS3 JailBreak Game Compatibility List
• PS3 JB2 / True Blue (TB) Game Links
• PS3 multiMAN Updates
• PS3 News Forums
• PS3 News Site FAQ
• PS3 News Site Advertising FAQ
• PS3 News Site Posting FAQ
• PS3 News Site Privacy FAQ
• PS3 News Site Rules
• PS3 News Site Tag Cloud
• PS3 News Site Terms
• PS3 Resources
• PS3 Reviews
• PS3 Save Files Repository
• PS3 Themes
• PS3 Trophies List
• PS3 Videos
• PS Vita Trophies List

PlayStation 3 News Discussions
a little help recqired plzzz - 5m ago

mughal1990's Avatar
Quote i am on 3.55 cfw and want to go to 4.4cfw , if i do so will my backed up games on my ps3's hard dive will be lost/deleted or will it be retained ? plz...
By mughal1990 with
 0 Comments »
PS3 Fan Control Utility v0.3 for 4.31 and 4.40 CFW CEX is Released - 50m ago

mschumacher69's Avatar
Quote There's no such thing as DREX firmware, D-REX is REX but installable on DEX firmware. Once you install D-REX, you end up on REX. So this sentence s...
By mschumacher69 with
 18 Comments »
Introductions: Hello Everyone, I'm New at PS3News.com! - 2h ago

veritech4's Avatar
Quote Hey im new as well have a 120gb psc cech 2501A and interested on opening up the walls...
By veritech4 with
 6984 Comments »
Introductions: Hello Everyone, I'm New at PS3News.com! - 3h ago

mateen1610's Avatar
Quote Hello. New user here. Find this website very resourceful. Hope I can contribute. Cheers....
By mateen1610 with
 6984 Comments »

Latest PlayStation 3 Trophies
PixelJunk Monsters : Encore : Zero Carat
PixelJunk Monsters : Encore : Wishing Well
PixelJunk Monsters : Encore : Scrooge's Return
PixelJunk Monsters : Encore : Black Flag

Latest PlayStation Vita Trophies
Jacob Jones and the Bigfoot Mystery : Low Notes
Jacob Jones and the Bigfoot Mystery : Unjammed
Jacob Jones and the Bigfoot Mystery : Low Roller
Jacob Jones and the Bigfoot Mystery : Quick Packer

Latest PlayStation 3 Releases
Muvluv Alternative Total Eclipse JPN PS3-HR - 05-17-2013
Skate 2 EUR PS3-Googlecus - 05-16-2013
The Walking Dead A Telltale Games Series PS3-COLLATERAL - 05-15-2013
The Cube PS3-ANTiDOTE - 05-14-2013

Latest PlayStation 3 Themes
Wolverine Origins PS3 Theme - 05-11-2013
Heavy Rain (Official) Dynamic PS3 Theme - 05-09-2013
Wipeout HD Fury Dynamic PS3 Theme - 05-06-2013
Batman Arkham City Dynamic PS3 Theme - 05-04-2013
  • Contact Us
  • -
  • PS3 News