PSN servers were 'unpatched and had no firewall installed,' security expert test

4.6
The House of Representatives Energy & Commerce Subcommittee on Commerce, Manufacturing and Trade continues to seek answers regarding last month's breach of the PlayStation Network's security. The one it got yesterday from Purdue professor and security expert Dr. Gene Spafford is troubling, to say the least, if the situation he detailed actually played out as described.

Spafford told the subcommittee that, according to security mailing lists he subscribes to, "individuals who work in security and participate in the Sony network" had learned "several months ago" that PSN was hosted on servers running "very old versions of Apache software that were unpatched and had no firewall installed."

The professor continued, "they had reported these [issues] in an open forum that was monitored by Sony employees, but had seen no response and no change or update to the software." The timeframe for these events was "two to three months prior to the incident where the break-ins occurred," according to Spafford.

It's important to note that his account of the situation and information is second-hand. Still, the potential for this testimony to cause the subcommittee, headed by representative Mary Bono Mack (R-CA), to demand more answers from Sony -- and, more specifically, the individuals mentioned by Spafford -- does exist.

Sony could not be reached for comment.



http://www.joystiq.com/2011/05/05/psn-servers-were-unpatched-and-had-no-firewall-installed-secu/#comments

Posted:

Comments

"PSN servers were 'unpatched and had no firewall installed,' security expert test" :: Login/Create an Account :: 3 comments

If you would like to post a comment please signin to your account or register for an account.

ZerkosPosted:

oh my, facepalm.

no encrypted passwords now this.

sony are stupid.

Dizzy777Posted:

Haha they can talk a lot of shit about xbox, But yet they cant get their hed outta there asses and worry about their own network. I meen no security, no protection, or even a firewall. Running old software, I'm going to love when microsoft Comes up with something to say about the lack of care for PSN.
Even though now PSN has security they shouldve before when declared war on hackers.

bananapie62Posted:

um...if they knew they didnt have a firewall up then WHY DIDNT THEY FIX IT. mabe if they had the most basic security up they may know who did it but no, they just have to sit with their thumbs up their ass waiting for a breach like this and be surpised when it happened.