Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Note, according to the original article (http://sony.nyleveia.com/2011/05/17/warning-all-psn-users-yo...) as well as this forum discussion (http://www.neogaf.com/forum/showthread.php?t=430574), this is in fact a new vulnerability that is independent of the original PSN hack.

The problem seems to be that the email validation required for resetting the password could be circumvented. There is no detailed information in the posts how, but likely either the validation hash was generated in a insecure fashion, or the email address input was not properly sanitized and allowed piggybacking (CCing) a 2nd email address to receive the confirmation email.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: