Sony PlayStation 3
Sony's PlayStation website has been compromised by hackers

Hackers hit Sony PS3 website

SQL injection vulnerability compromises web pages

Written by Robert Jaques

Hackers have "compromised" pages on the US Sony PlayStation website, a security firm claimed today.

Sophos said that cyber-criminals used an SQL injection vulnerability to add unauthorised code to pages promoting PlayStation games SingStar Pop and God of War.

Advertisement

The malware claims to undertake an antivirus scan and displays a fake message stating that the visitor's computer has been infected.

The visitor is then urged to purchase a bogus security product to clean up the 'infection'.

Sophos warned that it would be "trivial" for the hackers who have compromised the web pages to alter the payload so that it became more malicious.

They could install code designed to harvest confidential information from users, or turn innocent victims' PCs into botnet zombies.

Surfing a website like this could potentially infect users with malware

Graham Cluley Sophos

"There are millions of video game lovers around the world, many of whom will visit Sony's PlayStation website regularly to find out more about the latest console games," said Graham Cluley, senior technology consultant at Sophos.

"Most would never expect that surfing a website like this could potentially infect them with malware.

"It is essential that all websites, especially high profile ones like this, have been properly hardened to prevent hackers from injecting malicious code into legitimate web pages."

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Shaun Nichols and Iain Thomson

10 Oct 2008

7.33 MBPodcast Special: Views from the Valley More...

Podcast image

09 Oct 2008

12.99 MBComputing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security More...

Shaun Nichols and Iain Thomson

03 Oct 2008

6.49 MBPodcast Special: Views from the Valley More...

Poll

Google Android

Google Android

Are you intending to try out a Google Android mobile phone?

Previous poll results

Spotlight

Ministry of Defence

MoD data loss total could hit 1.7 million

New figures far higher than initial estimates   More...

Sun Microsystems

Sun Sparc server shatters seven standards

T5440 sets new benchmark records   More...

Gary McKinnon

Home Office turns down latest McKinnon appeal

Home Secretary informs lawyers of arrangements for US extradition   More...

Network cables

Network Instruments touts nanosecond apps troubleshooting

Observer 13 offers upgraded performance and forensic network analysis   More...

Primary Navigation