Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

April 4th, 2011, 14:38 GMT · By

Xbox LIVE Policy Director Has Online Accounts Hijacked

SHARE:

Adjust text size:


Stephen Toulouse's Xbox LIVE account hijacked
Enlarge picture
A disgruntled gamer has managed to hijack the domain, email and Xbox accounts of Stephen Toulouse, Microsoft's director of policy and enforcement for Xbox LIVE.

It seems it all started with a social engineering attack against Network Solution, the registrar used by Toulouse for his stepto.com domain.

The Xbox official confirmed the successful attack on Twitter by writing: "Sigh. please be warned. Network solutions has apparently transferred control of Stepto.com to an attacker and will not let me recover it."

With control over the domain, the hacker managed to obtain access to Toulouse's personal @stepto.com email address and used it to reset the password for his Xbox LIVE account.

The attacker, who calls himself Predator, posted a video (strong language) of him controlling the account on YouTube. Apparently, he was annoyed with Toulouse for repeatedly banning him.

As director of policy and enforcement for Xbox LIVE, Toulouse is responsible for banning people who try to cheat the system.

The hacker offered to hijack other people's accounts for a price of $250, however, he doesn't seem to be very good at covering his tracks.

Domain hijacking incidents are not uncommon. In fact, their number appears to have increased during the past two years, especially those involving high profile websites.

There are several methods of instrumenting such attacks, the most common being the impersonation of the domain owner.

This shouldn't theoretically happen, because large domain registrars have security checks in place for procedures that deal with changing ownership or recovering control of a domain.

However, it only takes one poorly trained employee for this system to break down. For example, Baidu, the company operating the largest Chinese search engine, sued Register.com for gross negligence after one of its staff handed over control of Baidu.com to a hacker.

The attacker failed to produce valid answers for the identity verification checks and used a suspiciously named @yahoo.com email address as new contract for the domain, something that should immediately have triggered red flags.

TELL US WHAT YOU THINK:

1,081 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Google Bangladesh Hijacked by Hacker

Domain Name of Russia's Largest Online Payment Processor Hijacked

Vulnerability Research Vendor's Domain Hijacked

Hackers Hijack Cryptome and Delete Everything

Gross Negligence Surfaces in Baidu Domain Hijacking Incident

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM