On CBS.com: Sat Night Fights Returns to CBS 11/7 9pm
BNET Business Network:
BNET
TechRepublic
ZDNet

December 22nd, 2008

PlayStation Home virtual world hacked

Posted by Ryan Naraine @ 10:23 am

Categories: Arbitrary Code Execution, Botnets, Browsers, Data theft, Exploit code, Flash, Hackers, Malware, Passwords, Social Networking Applications, Viruses and Worms, Vulnerability research

Tags: Virtual World, Sony Playstation, Ryan Naraine

PlayStation Home virtual world hacked

Hackers are using a combination of DNS redirection, software vulnerabilities and the open-source Apache Web server to exploit holes in Sony’s new PlayStation Home virtual world, according to a Telegraph report.

The hack is allowing developers to customize their PlayStation Home experience beyond the options provided by Sony but there’s a worrysome component to this platform weakness…

[T]he security loophole that allows tech-savvy users to upload any file to the Home server, or delete any file from the Home server. It raises the spectre of malicious hackers spreading viruses and malware across the PlayStation Home platform, or even launching sustained attacks on the virtual world’s servers to force it offline.

[ SEE: QuickTime hack allows Second Life currency theft ]

More from the report:

One hack uses a combination of the Apache web server and DNS re-direction to allow users of PlayStation Home to watch their own movies on display screens within the game, and change text and music to whatever they choose.

A second hack enables players to download any file they want from PlayStation Home’s servers, such as a fellow user’s profile or avatar, the cartoon-like representation of themselves they create to appear in the virtual world.

This is not the first documented vulnerability — and attack — affecting virtual world users.   A year ago, security researchers Dino Dai Zovi and Charlie Miller found a way to exploit an unpatched QuickTime vulnerability to steal Linden Dollars from users in the Second Life virtual world.

These attacks — both real and theoretical — are a major worry because of the growth of malware targeting online games.  Property accumulated in virtual world accounts have financial value in the real world, leading to an exploding underground market for stolen virtual world accounts.

At the Virus Bulletin conference this year, I listened to an eye-opening discussion about the underground virtual world hacking economy and I’m convinced we’ll see these types of attacks expand to affect computers users inside and outside of the virtual worlds.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 17 Talkback(s)
RE: PlayStation Home virtual world hacked
So far, I'm much more impressed by the Wii. With the new Wii Fit, all of the members of my family are playing and enjoying it. While I really liked the games on the Xbox 360, it has turned into a gi... (Read the rest)
Posted by: Bob C User Posted on: 12/30/08 You are currently: a Guest | | Terms of Use
Sony is run by idiots  T1Oracle | 12/22/08
Aggreed to an extent  gnesterenko | 12/22/08
Hope the PS3 will sink Sony  Mectron | 12/22/08
Nice console but  evolucion8 | 12/24/08
They'll never catch Xbox Live now...  storm14k | 12/22/08
They are.....  daMan25 | 12/22/08
backwards compatibility  zclayton2 | 12/23/08
backwards compatibility  DeepThoughtsShallowMind | 12/23/08
You waited too long  midenginedrift | 12/24/08
We're NOT all Rich  Timewellwasted | 12/29/08
You nailed it  baileysc | 12/24/08
RE: PlayStation Home virtual world hacked  windowsknowitall | 12/22/08
ps3 capabilities  DeepThoughtsShallowMind | 12/23/08
RE: PlayStation Home virtual world hacked  Brinn1 | 12/23/08
RE: PlayStation Home virtual world hacked  midenginedrift | 12/24/08
Are you living in a fantasy world rendered by Sony?  Skullet | 12/29/08
RE: PlayStation Home virtual world hacked  Bob C User | 12/30/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline