Xbox.com Exploit Discovered - Microsoft Apparently Ignoring a Website Security Flaw

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Shawn Zipay
    Managing Communities 24/7
    • Apr 2003
    • 69279

    #1

    Xbox.com Exploit Discovered - Microsoft Apparently Ignoring a Website Security Flaw

    Is this the reason why so many Xbox Live accounts are getting hacked may have been discovered. Apparently, a security issue lies in the hands of Xbox.com and the method Microsoft uses to let people log in with their Live ID. Analog Hype and Eurogamer both have similar articles on the matter, both brought to light by someone named Jason Coutee, a network infrastructure manager who had his own account hacked.

    Apparently, due to the way in which the Xbox Live login utilizes the use of CAPTCHA, it leaves a hole wide open for people to brute force their way into your account.



    Thanks to Facebook, Twitter, or any other links that have their email advertised, hackers now have a potential list of Windows Live ID’s. Now the hackers check to see if the email is a valid Windows Live ID. To do this, hackers headed to Xbox.com Typing in the email and a random password like blah.

    If the hacker got the error message “account is invalid” they move on to another email.

    When the hacker comes across the error message “password is wrong” then that account is in trouble.

    Now with a simple script, hackers can brute force their way into your Xbox Live account. The script would batch run a list of potential password, which anybody can find online with a simple Google search. The script will attempt to enter these potential passwords until it gets in. Xbox allows you to enter your password incorrectly 8 times on the website, then it asks for a CAPTCHA code. When hackers get to that CAPTCHA code, there is a link for “try with another Live ID”. Clicking this link resets the CAPTCHA code and hackers can continue to force their way in 8 more times before they need to click the link again. This process can easily be automated by a skilled hacker. Once a hacker is in your account, nothing is safe. Hackers will take your credit card info, Netflix, Hulu Plus, the works.



    From there, once they're into your account all they have to do is spend your MS Points, make purchases with your credit card that you may still have tied to your Live account, and transfer ownership to anybody they wish to. Purchasing a Family Pack on your account is another common tactic, one that will tie three additional tags to your account and under their control.

    So what did Microsoft do once Jason found out about this major security flaw? Nothing.

    A call to Microsoft support and Microsoft HQ both resulted in the run-around. He was told to contact a help email at Microsoft. The call to Xbox Support had him speaking with a supervisor who instructed Jason to make a post on the official Xbox.com forums. A last attempt found Jason contacting Microsoft's Piracy and Phishing department, who refused to help him with "anything Xbox related."

    Brute forcing is just one method that may be an issue and really only an issue that affects simple passwords. Brute forcing is nothing new and certainly nothing that should result in the recent outbreak of Xbox Live accounts that have been stolen. However, it is still a security hole that should be taken care of while the search for the true cause for the recent thefts continues.
  • K-16
    ...
    • Sep 2026
    • 2018

    #2
    I wonder if this is the same method used to hijack Windows Live Hotmail accounts? I recall mine was sending fake E-mails to everyone on my address list, yet despite scanning with six different virus/malware scanners my computer came up with nothing and claims it's clean. Changing the password stopped the fake E-mails from being sent out... Until it got hijacked again weeks later. Changing the password the third time (with the intention of shutting the account down should it happen again) stopped the hijack again and I have not heard anybody receive any fake E-mails since. Point is, could this be the same exploit used for Xbox Live? If so, this is a really old vulernability which somehow spread to something completely different. I will admit the third time involved changing the consistency of my password completely at the risk of having difficulty in remembering it myself, so perhaps brute forcing this one would take too long to be worth it.

    Comment

    • Linux
      wat da gah?
      • Sep 2026
      • 382

      #3
      Re: Xbox.com Exploit Discovered - Microsoft Apparently Ignoring a Website Security Flaw

      Originally posted by K-16
      I wonder if this is the same method used to hijack Windows Live Hotmail accounts? I recall mine was sending fake E-mails to everyone on my address list, yet despite scanning with six different virus/malware scanners my computer came up with nothing and claims it's clean. Changing the password stopped the fake E-mails from being sent out... Until it got hijacked again weeks later. Changing the password the third time (with the intention of shutting the account down should it happen again) stopped the hijack again and I have not heard anybody receive any fake E-mails since. Point is, could this be the same exploit used for Xbox Live? If so, this is a really old vulernability which somehow spread to something completely different. I will admit the third time involved changing the consistency of my password completely at the risk of having difficulty in remembering it myself, so perhaps brute forcing this one would take too long to be worth it.
      I wouldn't doubt this is the same hack that has now been blown up into a huge problem because if you think about it Hotmail is owned by Microsoft and it uses the Windows Live ID. Most Microsoft services + many web sites around the world links with Microsoft's Live ID, which ultimately has now created a huge security flaw in the system. The way Microsoft works at fixing this it going to be extremely slow and I doubt we'll see any major changes happening unless Microsoft takes all the news of this floating around as a threat to their current customer base.

      What drives me nuts is that I can't remove my credit card information without putting something in place of it. I've never trusted Microsoft and I still don't to this day because simple security flaws like this create bigger problems.

      Comment

      • Thortok2000
        Dominant
        • Sep 2026
        • 382

        #4
        Best way to get this info to people that can actually fix it is Microsoft's Newsgroups, in my opinion. That's about the only place I've seen any Microsoft developer or PR person post anything.

        Comment

        • CptainCrunch
          I am the 1%
          • Oct 2007
          • 12976

          #5
          I knew it! A very simple exploit that could be easily fixed.The only way to get Microsoft to do anything about is make the exploit as public as possible. They never do anything to small issues.Like Thortok said, make it a PR thing and it will get resolved.
          Twitter: @CptainCrunch
          Battlelog/Origin: CptainCrunch

          Comment

          • Shawn Zipay
            Managing Communities 24/7
            • Apr 2003
            • 69279

            #6
            Re: Xbox.com Exploit Discovered - Microsoft Apparently Ignoring a Website Security Flaw

            Originally posted by Linux
            What drives me nuts is that I can't remove my credit card information without putting something in place of it. I've never trusted Microsoft and I still don't to this day because simple security flaws like this create bigger problems.
            What do you mean that you have to put something in place of it? I've had my CC removed from my Xbox Live account now for a couple of years. Granted, I had to call support to do it since this was in the days BEFORE they let you remove it via the console itself, but still. I've never been forced to have another payment method added since.

            Comment

            • DunkinSPE
              OT's Daddy Warbucks
              • Aug 2006
              • 452

              #7
              Re: Xbox.com Exploit Discovered - Microsoft Apparently Ignoring a Website Security Flaw

              Originally posted by CptainCrunch
              I knew it! A very simple exploit that could be easily fixed.The only way to get Microsoft to do anything about is make the exploit as public as possible. They never do anything to small issues.Like Thortok said, make it a PR thing and it will get resolved.
              Or just have someone Brute Force their way into Big Daddy Gates' Windows Live Account. Then it gets fixed like quick.
              "We're all very different people. We're not Watusi. We're not Spartans. We're Americans, with a capital 'A', huh? You know what that means? Do ya? That means that our forefathers were kicked out of every decent country in the world. We are the wretched refuse. We're the underdog. We're mutts! Here's proof: his nose is cold! But there's no animal that's more faithful, that's more loyal, more loveable than the mutt." -John Winger (Bill Murray) Stripes

              Comment

              • Stev0esque
                5t3v0 (I miss leetspeech)
                • Feb 2008
                • 6786

                #8
                Re: Xbox.com Exploit Discovered - Microsoft Apparently Ignoring a Website Security Flaw

                Originally posted by DunkinSPE
                Or just have someone Brute Force their way into Big Daddy Gates' Windows Live Account. Then it gets fixed like quick.
                But I don't know if he is CEO anymore, so you may find that he'll just join in the (justified) crowd in calling for a change

                Comment

                • K-16
                  ...
                  • Sep 2026
                  • 2018

                  #9
                  Still a chairman, so pissing off a key member of the Board of Directors does tend to threaten the CEO's job security if there is no swift response. That said, I don't like the idea of encouraging hijacking key members' accounts to raise awareness, since that's basically terrorism (as actual terrorism tends to happen for the same reason, but on a more political/government level). As a joke I can understand, but I hope nobody takes that suggestion to heart. I do like the newsgroup idea though. Also, I'm starting to think Mr. Keighley won't have time to cover this issue, especially now that everyone else already explained the whole story; I was hoping for exposure on GT.TV to spread this issue with a screenshot or two of TGN/CS-Nation's coverage.

                  Comment

                  Working...