Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Games > Xbox

January 16th, 2012, 15:31 GMT · By

Xbox Live Vulnerability Used by Hackers Might Have Been Uncovered

SHARE:

Adjust text size:


Xbox Live is susceptible to hackers
Enlarge picture
The vulnerability used by hackers to break into Xbox Live accounts might have been uncovered recently, as two websites have posted similar walkthroughs that show how cyber-attackers could exploit Microsoft’s Xbox.com website and force their way into the accounts of its users.

While Microsoft has denied in recent months that its Xbox Live online service was hacked, more and more users are reporting that their accounts were broken into. After accessing the account, hackers would use the credit card information associated with it to buy lots of virtual MS Points and then sell the accounts to other people.

Now, it seems that the vulnerability used by these hackers has been uncovered, as an Xbox Live user called Jason Coutee contacted both Eurogamer and AnalogHype to offer a sort of walkthrough that was used to break into Live accounts.

According to the information provided by the two websites, the vulnerability is tied to Microsoft’s Xbox.com website, which allows users eight password attempts before displaying a special ‘Captcha’ message to ensure it’s not dealing with an automated script.

Jason said that these eight attempts allow hackers to mount brute force attacks that, eventually, result in access to the account.

What’s more, the website also displays two different messages when trying to access an account, a fact that once again comes to the aid of hackers. More specifically, if you enter an email address that doesn’t have an actual Xbox Live account, the error messages says “That Windows Live ID doesn't exist.” If the email address is correct and the password isn’t, the message then says “The email address or password is incorrect.”

Microsoft has yet to comment on this new reveal but, if it’s true, the company needs to seriously improve the security measures on its Xbox.com website in order to prevent hackers from continuing to break into the accounts of its customers.

Expect more details about this situation in the near future.

TELL US WHAT YOU THINK:

846 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Xbox Live Arcade House Party Starts on February 15, Brings Four Great Games

Microsoft Plans Wider Xbox 360 and Windows Integration

Tablet Controller for Xbox 360 Would Be Successful, Analyst Believes

Xbox Live House Party 2012 Includes Alan Wake, I Am Alive, Warp, and Nexuiz

Analysts: Xbox 360 Future Linked to Kinect Use, Live Expansion

READER COMMENTS:


Comment #1 by: WDaquell on 19 Jan 2012, 17:39 UTC reply to this comment

These attacks are normal. I've designed tons of sites that get slammed with these kinds of attacks... any hacker book details brute force attacks. It's not a flaw with the site at all... any site that has usernames and passwords is subject to a brute force attack. Duh!

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM