Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

Hack Attack Exposes 1.3 Million Sega Accounts

LulzSec says to watch your Facebook, Gmail, and Skype passwords, though no one has claimed responsibility for the Sega breach.

10 Massive Security Breaches
(click image for larger view)
Slideshow: 10 Massive Security Breaches
Another day, another hacked website belonging to a video game manufacturer. On Friday, Sega confirmed news reports that attackers had compromised its systems, exposing data on 1.3 million users. Sega took the hacked Sega Pass system, which is both a newsletter and account management system for the company's online games, offline on Thursday. It gave no estimate for when the service would be restored.

According to a message posted on the Sega Pass website, "we had identified that unauthorized entry was gained to our Sega Pass database." Attackers stole Sega Pass members' email addresses, dates of birth, and encrypted passwords. "None of the passwords obtained were stored in plain text," said Sega, although it didn't detail the encryption technique used.

Despite the passwords having been encrypted, Sega reset all users' Sega Pass passwords. It also cautioned that "if you use the same login information for other websites and/or services as you do for Sega Pass, you should change that information immediately."

The attack against Sega follows comments made by Sega West CEO Mike Hayes to Eurogamer last month, in which he said that the PlayStation Network (PSN) hack, which resulted in over 77 million user accounts being compromised, was "an interesting wake up call for all of us." In particular, it led Sega to conduct an immediate security audit. "Fortunately we seemed pretty solid so we didn't have to do too many additional changes," he said.

The prolific hacking group known as LulzSec said it wasn't responsible for the Sega attack. Suspicion immediately fell on the group, which exploited SonyPictures.com, leading to one million user accounts being exposed, as well as game developer Bethesda, after which LulzSec released no user information, but rather exhorted Bethesda to improve its security and also finish its games more quickly.

In the case of Sega, LulzSec offered to help find the perpetrators. "@Sega - contact us. We want to help you destroy the hackers that attacked you. We love the Dreamcast, these people are going down," said a message posted to the LulzSec Twitter feed.

On a related noted, LulzSec on Friday released a public warning of sorts via Pastebin, saying that the recent flurry of hack attacks likely masks a far greater number of unreported attacks. "Do you think every hacker announces everything they've hacked? We certainly haven't, and we're damn sure others are playing the silent game," said the LulzSec message. "Do you feel safe with your Facebook accounts, your Google Mail accounts, your Skype accounts? What makes you think a hacker isn't silently sitting inside all of these right now, sniping out individual people, or perhaps selling them off?"

On Sunday, in yet another Pastebin manifesto, LulzSec also announced that it was joining forces with Anonymous (from which it's rumored to have sprung), in a venture dubbed Operation Anti-Security (#AntiSec). "Top priority is to steal and leak any classified government information, including email spools and documentation," it said. "Prime targets are banks and other high-ranking establishments."

As if to prove their point, LulzSec said on Sunday, via Twitter, that it had "recently" hacked into the website of InfraGard Connecticut, stealing information on more than 1,000 members. Meanwhile, on Monday, the group said that #AntiSec had launched a distributed denial of service (DDoS) attack against the website of Britain's Serious Organized Crime Agency. A statement released by the law enforcement agency said that its public website had been taken offline in the wake of a DDoS attack, in part to mitigate its impact on the external service provider that hosts the site. The agency said that the affected website hosted no sensitive material.

LulzSec, which has already hacked the public websites of InfraGard Atlanta, the CIA, and broken into a U.S. Senate network, said that more attacks were already underway. "DDoS is of course our least powerful and most abundant ammunition. Government hacking is taking place right now behind the scenes," it said via Twitter.

In the new, all-digital Dark Reading supplement: What industry can teach government about IT innovation and efficiency. Also in this issue: Federal agencies have to shift from annual IT security assessments to continuous monitoring of their risks. Download it now. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
7 Tips for Infosec Pros Considering A Lateral Career Move
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2020
For Mismanaged SOCs, The Price Is Not Right
Kelly Sheridan, Staff Editor, Dark Reading,  1/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
IT 2020: A Look Ahead
Are you ready for the critical changes that will occur in 2020? We've compiled editor insights from the best of our network (Dark Reading, Data Center Knowledge, InformationWeek, ITPro Today and Network Computing) to deliver to you a look at the trends, technologies, and threats that are emerging in the coming year. Download it today!
Flash Poll
How Enterprises are Attacking the Cybersecurity Problem
How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-3154
PUBLISHED: 2020-01-27
CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.
CVE-2019-17190
PUBLISHED: 2020-01-27
A Local Privilege Escalation issue was discovered in Avast Secure Browser 76.0.1659.101. The vulnerability is due to an insecure ACL set by the AvastBrowserUpdate.exe (which is running as NT AUTHORITY\SYSTEM) when AvastSecureBrowser.exe checks for new updates. When the update check is triggered, the...
CVE-2014-8161
PUBLISHED: 2020-01-27
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.
CVE-2014-9481
PUBLISHED: 2020-01-27
The Scribunto extension for MediaWiki allows remote attackers to obtain the rollback token and possibly other sensitive information via a crafted module, related to unstripping special page HTML.
CVE-2015-0241
PUBLISHED: 2020-01-27
The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a (1) large number of digits when processing a numeric ...