Bakuryukun said:
Perhaps a better question than why we would put faith in sony is, WHY IN GODS NAME WOULD WE PAY YOU TO TAKE BREAK INTO PEOPLES PERSONAL INFORMATION TO PROVE A POINT?
I hate how hackers always talk so whimsically about what they do when they hack a site, like they think they are heroes or really cool Spanish gentlemen thieves or something.
They didn't "break into people's personal information", they just sodomized another one of SONY's "secure" systems... maybe the thing to take out of this is
be more careful whom and what kind of information you give on the INTERNET, it can always come back to bite you.
For anyone wondering what a SQL Injection is, you basically know those "form-field" for instance on this forum where you put in your Username and Password and it checks against the database if there is such an user?
You basically just have to enter a SQL-command into it similar to "SELECT * FROM users WHERE name = '' OR '1'='1'" etc., there are different kinds of "Injections" but that is the basic jist of it and everyone that had a course regarding databases should know to check against it and invalidate any commands etc. or simply use escape Strings...
It's really simple stuff, you can look it up on Wikipedia for instance or Google it: http://en.wikipedia.org/wiki/SQL_injection
http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/
They didn't need to "Hack" anything, SONY basically handed em everything on a silver platter and begged for more...