SQL Injection Vulnerability in Sony Playstation Network

The personal data of Sony PlayStation Network users could be once again at risk due to a bug that allows blind SQL injection in of, as a penetration tester claims.
20-year-old Aria Akhavan from Austria reports that he discovered one which could allow an attacker to obtain information from the website's database using SQL queries.SQL Injection SQL Injection SQL Injection SQL Injection
Vulnerability is difficult to exploit, but it is not impossible.
A blind SQL injection is more difficult to pay off compared to a regular SQL injection, because the they do not appear on the website immediately. The page returns a generic error message and the attacker would have to start asking true or false with SQL queries in order to retrieve the database information.

Despite the fact that this kind of Although it takes more time to perform, it can be accelerated by using automated tools once the target and vulnerability have been identified.

The security researcher, he said in an interview with Effect Hacking that she has been in contact with Sony for this issue since mid-October, but has not yet received a response. Meanwhile, vulnerability continues to exist.

Akhavan stated that he studies techniques for about five years and refused to share the results of the tests it performed on Sony's site.

Please be reminded that Sony has a history of data breach. Some time ago the company was a fixed target of a group known as the Lizard Squad. The team carried out DDoS attacks, cutting access to the online network.

DDoS attacks are not designed to steal data, although they can be used to distract from a different attack that has this purpose and is done "from behind".

An earlier attack on the PlayStation Network led to personal and financial data leakage from at least 77 millions of company customers.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).