Sony May Have Been Using Outdated Security Software, Claims Expert

Shingro

New member
Oct 4, 2007
28
0
0
Of course... The people who were following this whole debacle all along, and read the irc logs that Keven Steven posted to defend his twitter post about the talk of the database being sold off already know this as that there was plenty of shop talk about the OS version Sony was running and how full of security holes and exploits it is.

C'mon guys those were logs from the *16*th and now this is news?

I guess in 3 weeks we can expect a headline "Sony arrogantly built all PSN defenses client-side to try to make the 'uncrackable console' Ignored recommendations from top engineers and the history of all modern consoles"

I'm sure we'll be shocked, and the same people are going to wander slavishly out and ride to sony's defense regardless of not having any technical knowhow.

Is this so hard to believe though? Let me remind you that *PASSWORDS WERE UNENCRYPTED IN A PLAINTEXT FILE*

but surely they wouldn't have missed patching their OS... surely. ¬_¬
 

Tron Paul

New member
Dec 11, 2009
42
0
0
http://news.cnet.com/8301-17852_3-20060335-71.html
"He reportedly said Internet forums openly discussed that the Apache Web server software used by Sony was 'unpatched and had no firewall installed.' He also reportedly said that these concerns were debated in an open forum that was monitored by Sony employees."

Sony servers were running an older version of the Linux kernel, which can be bad, but what was worse were they were running old versions of Apache. Now updating the kernel, I can see them using an old version to make it easy on themselves. But running old versions of Apache? Really? That's asking for it. Sure you might not want to rewrite some custom code you have for that version, but honestly, what else to you pay server maintenance people for? This is hardly stuff you need "security experts" for.

Sony deserves everything they got coming to them, and probably a bit more.