Lulzsec Member Raynaldo Rivera Pleads Guilty To Sony Pictures Breach
hypnosec writes "Raynaldo Rivera has pleaded guilty at the US District Court for the Central District of California to hacking the Sony Pictures Entertainment website in May 2011. The 20-year-old in his plea agreement revealed that he joined Lulzsec in May of last year in a bid to help the hacking collective carry out cyberattacks on governments and businesses. Rivera, who surrendered to the FBI on August 28 this year, admitted that he was the one who launched an SQL injection attack against sonypictures.com that enabled him to extract confidential information from the website's database."
it makes it sound like he did it single handedly, he didnt.
both anonymous and lulzsec trashed them multiple times
lof ast year
http://michaelsmith.id.au
he was guilty.
After I spent an hour of my life watching him open Al Capone's empty vault.
He should have covered his tracks better'; DROP TABLE session; --
Bobby Tables
They clearly learned nothing and refused to learn anything or do anything. Lemme guess, SONY is run by copywrite attorneys and Hollywood 'content' types.
If they hadn't gloated so much and took the proper precautions, they wouldn't have been found. Don't tell anyone, not even anyone on your team, who you are.
When does Sony go to jail, for developing rookits? I bet that affected people on a much larger scale. What about the false advertising regarding the OtherOS feature, which was removed via an updater/backdoor?
Sony screws its customers with DRM and anti-features and attacks software developers. I find it hard to feel sorry for them.
are you an editor?-----third line , start of sentence.....
sorry .
SQL injection? www.sony.com/drop tables;?
Its not so much a matter of "breaking locks and prying the door" and "accidentally stepping through the spider web between the two widely separated rocks they use for security. "Hey, you made it past our rocks: you must be a super cyber thief or something".
When they bragged to the world, I was convinced that
1. They would be found (law enforcement is pretty incompetent, but they do get the idiots and only idiots brag like that)
2. They would turn on each other as they have no personal honor
3. They would be utterly pathetic
Seems to have been spot-on. Incompetence combined with arrogance and self-aggrandizement. A pity that other fine examples of this personality profile can continue unhindered, e.g. in lots of government, administration, corporations, banks and academia.
Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
Possibly 5 years in Jail and $605k in fines is the guilty plea bargain. Sound like a deal to me, go ahead and reciprocate by doing the same time and paying each user who was hacked by Sony and their drm rootkit.
Namaste
I mean, really. So, we're punishing the people who find the holes in the software, while the companies who deploy insecure websites get money because they did something insecurely? I mean, I'm thing of a car analogy and it's odd - the person reaching in (because you left the window down) is at fault, but at the same time why the hell would you leave a window open and expect no one to take your iPad? And you could get compensated (even though he was caught and you lost nothing of value)?
I feel like it's silly that people get arrested for stuff like SQL injection attacks - "OH hey guys, we didn't sanitize user input and someone used that against us. Derp. Let's take those people to court!"
See also: banks that don't use silent alarms and totally don't use safes. At all. You know, if a security threat is obvious, it should probably be the company's responsibility to deal with it instead of "hoping" that some cracker comes along so that they can cash out in a lawsuit and not have to actually invest in security.
and what makes you think, SONY hasn't been breached since .....
just cause whom ever isnt bragging about it like they are....
Just to clarify, I don't know this Reynaldo guy to be part of lulzsec and this may be just as well a security theatre designed to scare actual members away.
> admitted that he was the one who launched an SQL injection attack
Ha ha!
To quote Bertram, "Hmmmmmm... Worth it!"
(-1: Post disagrees with my already-settled worldview) is not a valid mod option.
abuse, why , tell me someone, why is sony not hiring this guy ?
Free speech was meant to be free for all... how can anyone grow up in a nanny state ?