PDA

View Full Version : X-box live accounts being hacked!


Latino_Heat_1
03-21-2007, 01:14 PM
(http://blogs.zdnet.com/security/?p=131)



Online gaming forums are buzzing with reports that Xbox Live accounts linked to Microsoft's Windows Live ID service are being hijacked by malicious hackers.

Kevin Finisterre, a security researcher at Digital Munition, raised the issue on the Full Disclosure mailing list over the weekend, calling attention to rumors that Microsoft's Bungie.net was the victim of a breach that exposed a portion of Xbox Live.

"Some folks are having their Microsoft points stolen and or points purchased via their stolen gamer tag," Finisterre said.

A quick search of user forums at xbox.com and other gaming sites turned up multiple messages from Xbox Live users complaining about hijacked accounts, which typically link gamer tags to Windows Live ID (formerly .NET Passport).

According to Finisterre, there is a group online called "Infamous Clan" brazenly offering to "jack" Xbox Live accounts and boasting about successful account theft.

Several Xbox Live users contacted me to confirm the rumors and make it clear that the stolen accounts are being used for nefarious purposes.

One reader writes:

"I have been involved with Microsoft Support for days on this exact issue and have spent many hours on the phone trying to prove to them that, first, my Windows Live ID was stolen and, second, the ID and password associated with my ID were changed; two actions that Microsoft swears can NEVER happen; and third that the thief was able then use my credit card information associated with one of my Windows Live ID accounts to purchase over $800 of Microsoft products.

Thank goodness for other websites that still contained my old Windows Live ID information and also the fact that, in order to gain access to those other websites, you NEED a Windows Live ID. After spending over 20+ hours on the phone with support and finally getting them to realize that I did indeed have a Windows Live ID, after pointing them to the other websites, I was told by a supervisor that "Yes, in fact, we have heard of some instances where a user's Windows Live ID had been compromized!"

After finally getting this confirmation and having a case number assigned and forwarded to Microsoft Security Investigations, they, also, confirmed it as a breach, issued me another Windows Live ID and then reinitialized the stolen Microsoft Products that were associated with the old ID over to the new ID."

Another gamer wrote in with an identical complaint, warning that Microsoft's product support staff have been unhelpful. "They admit this is an issue but say there's nothing they can do about it," he added. Digital Munition's Finisterre also made a note about the lack of support from Microsoft:

I just got off the phone with a Microsoft Tech for Xbox live that has confirmed this to with me and they have stated that accounts are being stolen and that "Hackers have control of Xbox live and there is nothing we can do about it."

Microsoft did not respond to a request for comment.

utterdisturbed
03-21-2007, 05:31 PM
uhh its not very hard to steal peoples accounts from what my friend tells me in the first place....if you play halo2 and you bridge, you wait till someone comes in your party and you get there IP adress, and then you can find out all there info from there, AR there GT and then change the password on it, or just keep it so they cant play anymore, and if they have a 360, its way easier then that.

xeoset
03-21-2007, 05:36 PM
Apparently they were stolen in Bungies Website Update. Bungie left themselves partly open to an attack and people who had played Halo 2 and had the Bungie.net logo attatched to their Halo 2 Games, which they had to sign up using Hotmail, the hackers used their Hotmail IDs to gain access to their Gamertags.

I have no idea or knowledge on the subject but will have to wait to see how it turns out.

rand0m
03-21-2007, 05:49 PM
Lets all just hope Microsofts dismal virus record doesnt extend to the Xbox360 live community.

USB
03-21-2007, 05:57 PM
^^^^^ Fail.

aoplayo
03-21-2007, 10:05 PM
Xbox live wasn't hacked. Nor was bungie. People have had their windows live id stolen. They somehow got their password and info stolen. No sites were hacked and neither was live.


From bungie

Recent rumors that Bungie.net has been hacked, and that your personal data has been compromised or stolen, are utterly false. Bungie.net has not been hacked, and frankly, there's nothing to hack. Bungie.net's database does not contain any of your personal information other than your Gamertag and Halo 2 stats.

Durt
03-21-2007, 10:29 PM
M$ft has denied this today and dismissed it as a rumor. Live accounts get stolen all the time but M$ is dening there databases where compremised.

xboxman
03-05-2008, 12:05 AM
Xbox live wasn't hacked. Nor was bungie. People have had their windows live id stolen. They somehow got their password and info stolen. No sites were hacked and neither was live.


From bungie

Recent rumors that Bungie.net has been hacked, and that your personal data has been compromised or stolen, are utterly false. Bungie.net has not been hacked, and frankly, there's nothing to hack. Bungie.net's database does not contain any of your personal information other than your Gamertag and Halo 2 stats.

I just went to bungie.net and it said helloworld on a blank page... maybe its hacked?

At 8:14 March 4th

FlyinG ShoosteR
03-05-2008, 02:20 AM
I just went to bungie.net and it said helloworld on a blank page... maybe its hacked?

At 8:14 March 4th

yeah I saw that too earlier....who knows. if my shit gets stolen, I'll be pissed.