Over the last two months, the multi-national Sony Corporation has come under a wide range of attacks from an even wider range of attackers. The backstory about what event prompted who to attack and why will make a mediocre made-for-TV movie someday. This article is not going to cover the brief history of hacks; readers can find details elsewhere. Instead, the following only serves to create an accurate and comprehensive timeline regarding the recent breaches, a cliff notes summary for easy reference.
One thing should be noted; the attacks against Sony are not coordinated, nor are they advanced. Sony has demonstrated they have not implemented what any rational administrator or security professional would consider “the absolute basics”. Storing millions of customer’s personal details and passwords without using any form of encryption is reckless and ridiculous. Even security books from the ’80s were adamant about encrypting passwords at the very least. Several of Sony’s sites have been compromised as a result of basic SQL injection attacks, nothing elaborate or complex.
Elyssa D. Durant. Ed.M.DailyDDoSe © 2007-2014