Showing posts with label SONY. Show all posts
Showing posts with label SONY. Show all posts

Thursday, October 30, 2014

Sony Xperia Sending your Data To China Thanks to Baidu Spyware.

Update: See the bottom of the post to see an easy way to block  Baidu folder from being created.
Xperia Breach, Sony Xperia Phones Calling Beijing? http://snapvoip.blogspot.com/

Your Sony smartphone, with Android 4.4.x firmware, might be sending your personal data to China. You must be wondering why an American/Japanese firms phone be sending data to China. Only connection I can make is that they are made in China, just like your iPhone.Baidu Spyware, (as per Foresafe Mobile Security) is a threat to you and your data.
Screenshot1.png
IP 202.108.23.105 in the OS Monitor capture above is in Beijing, China. (China Unicom)
As revealed by a post on Sony forums, "Unknown folder baidu is created on starting phone each time", it looks like more than just a Baidu folder creation, to which Sony has responded saying that Baidu folder creation, will be removed in a future release. But it does not say anything calling Beijing (at least I could not find any).
One user on the forum posted the folder structure for the Baidu folder;
baidu (date 21/01/1970 08:35:27) main folder on /mnt/sdcard
    pushservice (same date & time as above)
          files
          one more folder with 2 SQLite databases in it
                pushstat_4.1.db
                pushstat_4.1.db-journal

XDA Forum also has a thread about the issue.
While waiting for the Sony to respond, one user posted the following procedure which disables MyXperia app/service and does not void the Sony warranty, like if the phone is rooted.

  1. Back up important data on the phone and do a factory reset.
  2. Start up the phone, go to Settings -> Apps -> Running and force stop the myXperia apps running (there are 2). Remove the baidu folder using File Kommander.
  3. Next, enable developer mode, Settings -> About Phone -> Click 7 times on the Build Number.
  4. Download or install the Android SDK. Install it. Connect the phone to the computer with USB cable.
  5. Next, run the adb tool in the android sdk's platform tools folder as (to be done in a command line window)
  6. adb shell <enter>
  7. <in the adb shell>pm block com.sonymobile.mx.android
  8. exit adb
  9. reboot
This will stop the Baidu folder from being created but there is no guarantee that the /system/libbdpush_V2_0.so library is not in use.

 Sony later responded that this is expected behavior for the MyXperia app and it is done to support both Chinese customers and Others outside China. But there are no explanations as to why users outside China connects to these Chinese servers, without any user interaction or permission.
Another user had a simple but effective solution, "First create a file named baidu on you PC. Then connect to PC through USB, delete the baidu folder and copy the baidu to your device. Now the baidu folder will not be created." Neat.

Monday, June 06, 2011

SONY Hacked Again And LulzSec Compromised (NOTz)

Sony Lulzsec http://snapvoip.blogspot.com/
People saw today at the same time as Apple WWDC 2011 Keynote was on the way, Lulsec releasing Sony Computer Entertainment’s Developer Network Source Code to several file sharing websites. LulzSec was mainly responsible for most Sony Network compromises according to the news we see.
The Sony Developer source code could be the one delivered to Sony developers, who develop games for Sony PS3 etc and if so, it is already in the public. Yes the developers are restricted from sharing the code, just like other developer networks, like Apple or Microsoft.
But today's stinger news was that LulzSec was compromised and one of it's members, Robert Cavanaugh, was apprehended and taken into custody by the FBI after an apparent counter attack, according to an article on Epoch Times that somehow got on to the SlashDot.
But don't be so heart broken, I went searching for the truth after reading the news. So the first place I landed was Twitter and checked on @Lulzsec, and I found the following message;


I guess possibly Epoch Times looking for publicity and Sony is still insecure, I meant unsecured. the case is closed, for now.

Thursday, June 02, 2011

LulzSec Hacks SONY Network (SonyPictures.com) Again

LulzSec Hacks SONY http://snapvoip.blogspot.com/
Looks like Sony is not getting a break from hackers. I am sure now the up nosed company must be thinking we should not have banned installing Linux on Playstation 3's. Sony failed to understand, that once you sell the box, that it should limit heavy handed control of what users do with it, withing legal limits. Installing Linux on it should have been users wish, not Sony's law. In any case how many do go around hacking their boxes? If they have acted properly, I doubt they would have received the moniker, Sony Bully. My teachers always told me that most bullies are very insecure. Now I guess Sony is a bully.

SonyPictures.com and It compromised over 1,000,000 users'personal information, including passwords, email addresses, home addresses,dates of birth, and all Sony opt-in data associated with their accounts. I thought after what happened with other Sony networks, it would have learned a lesson and tightened the network security. According to a statement by LulzSec, it was not that hard to break into and they have posted data on a few places on the net.

Message By Lulzsec:

Our goal here is not to come across as master hackers, hence what we're about to reveal: SonyPictures.com was owned by a very simple SQL injection, one of the most primitive and common vulnerabilities, as we should all know by now. From a single injection, we accessed EVERYTHING. Why do you put such faith in a company that allows itself to become open to these simple attacks?What's worse is that every bit of data we took wasn't encrypted. Sony stored over 1,000,000 passwords of its customers in plaintext, which means it's just a matter of taking it. This is disgraceful and insecure: they were asking for it.

Wednesday, May 18, 2011

Did Google And Amazon Help Apple To Get On Music Cloud Sooner?

Apple  Music Cloud http://snapvoip.blogspot.com/
After signing up with Warner Music earlier and now that Apple got EMI music (via CNET) on it's side, looks like the cloud streaming business is totally on it's side. You might wonder what about the other two big players in the music field? Sony and Universal?? yes they too seem to be on the way to sign on with Apple according to the same source.
Even though Apple has not announced about it's cloud streaming service, it has been at it for a while, discussing deals with the likes of Warner, EMI, Sony and Universal. According to CNET, all might be in Apple's bag, whether they want or not. Perhaps, the services from Google and Amazon may have accelerated these music labels jumping in with Apple that they do not like very much.
The license free or license less service from Google and Amazon has been announced without support from Music labels, in fact that have been crying foul all along. Now that Apple has Music labels on it's side will be able to offer much more services and enhancements than Google and Amazon could. So we might hear a different tune from Apple at this year's WWDC in June.
read more at CNET

Thursday, March 10, 2011

Dutch Grab 300,000 Sony Playstations While Sony Grabs Your IP Addresses Via Geohot Case. No Rootkits Needed This Time!

Update:
Sony prevailed over LG and the PlayStation seizure order has been lifted (Damn)


Dutch Grab Sony Playstations While Sony Grabs Your IP Addresses. http://snapvoip.blogspot.com/
In the news today is that Dutch Customs have confiscated 300,000 playstation 3's and I hope they will hold them for ever as in the Goehot case (Hotz vs SONY) the judge has granted SONY rights to get all IP addresses of everyone who visited Goehot's site. I wonder how these people become judges. Because it is not wise. Since the news broke out about the case I think I have visited to get information about the case and so have millions of others. According to Wired;

"Bluehost maintains Hotz's geohot.com site. The approved subpoena requires the company to turn over 'documents reproducing all server logs, IP address logs, account information, account access records and application or registration forms' tied to Hotz's hosting. The Bluehost subpoena also demands 'any other identifying information corresponding to persons or computers who have accessed or downloaded files hosted using your service and associated' with the www.geohot.com website, including but not limited to the 'geohot.com/jailbreak.zip file.'"

How about people who visited the site to get information about the case and people who visited to get information about iPhone Jailbreak, which is legal.
What is worse is that the same judge granted subpoenas to Hotz's Blogger.com account, Twitter account and YouTube account. The YouTube account contains a video called "Jailbroken PS3 3.55 with Homebrew," and Sony has managed to convince the judge to grant the company access to the IP addresses of anyone who watched the video or posted comments on the video.
I think Judge is setting a bad precedent with this case but the good thing about is that there are many people who visited those sites and so will be the size of backlash. If the way Geohot raised money for the SONY case is any evidence, it will be pretty strong. One thing is sure, Sony has Microsoft IP address as well;

I really hope LG wins in the patent case and hope those 300,000 PS3 consoles seized by Dutch get thrown in to Rotterdam harbor! :), Oops that will be a ecological disaster.
I think we did not learn enough with Sony Rootkits. I will tattoo "No Sony" on my brain, Perhaps a LG TV to replace my current one!
Wired via Time

Thursday, January 20, 2011

Sony vs. Hotz. SONY Sues Researchers, EFF.

#Sony vs Hotz http://snapvoip.blogspot.com/
It is just sickening even to write about this. Sony seem to be using anti-circumvention provisions of the Digital Millennium Copyright Act to get at people who are more than mere users. Sony has sued several security researchers for publishing information about security holes in Sony’s PlayStation 3.
So how do you know that will not extend to Sony Android phones. As far as I am concerned, I will get another Android phone! Because I want to root my Android phone without getting sued.
What is more, according to EFF,

"Simply put, Sony claims that it's illegal for users to access their own computers in a way that Sony doesn't like. Moreover, because the CFAA has criminal as well as civil penalties, Sony is actually saying that it's a crime for users to access their own computers in a way that Sony doesn't like."
Well NO thank you SONY you forgot, we have better choices.! Welcome HTC, Motorola, Apple, LG, Samsung, and others. Oh WII and XBOX does not look bad either.
Sony v. Hotz: Sony Sends A Dangerous Message to Researchers -- and Its Customers

Blog Widget by LinkWithin