Xbox live accounts being hacked?


Recommended Posts

Did you guys even read the article? Do you seriously think that being able to reset the CAPTCHA so you will have unlimited attempts to find the password isn't a security problem?

If Sony had something like this you all would be letting them have it. Also my password did contain uppercase, lowercase, and numbers in it so it's not just simple password being exploited.

Brute forcing a password is not a 'hack'. If this is it, then it's just these guys using weak passwords.

I agree. Just because they have found a way to brute force it without a CAPCHA doesn't mean its been hacked!

I would hardly call it a serious security flaw.......

I agree. Just because they have found a way to brute force it without a CAPCHA doesn't mean its been hacked!

I would hardly call it a serious security flaw.......

And if your account had been taken over? Of course it's serious, it's not working as it should.

Did you guys even read the article? Do you seriously think that being able to reset the CAPTCHA so you will have unlimited attempts to find the password isn't a security problem?

If Sony had something like this you all would be letting them have it. Also my password did contain uppercase, lowercase, and numbers in it so it's not just simple password being exploited.

Yes... being able to reset the CAPTCHA is a flaw Microsoft should fix asap. However, if your password contained uppercase/lowercase/numbers, wasn't a dictionary word, and wasn't short (<= 6 characters) it would have taken years to brute force your password so it's highly unlikely this flaw has anything to do with it.

Also, since you brought up Sony, does PSN even have any sort of brute force security? I just tried an invalid password 25 times for my PSN account and it didn't lock or display any captcha.

3 failed attempts and the account should simply lock and email recovery is needed. Simple really, throw in a drop down on logon for x, x and x of another password adds another layer of security.

Doh..

Is being able to avoid the CAPTCHA a security flaw? Yes

Is it the reason why your account is being hacked? No. A CAPTCHA is not a replacement for a secure password, if your password is being bruteforced over a network, it is FAR too simple.

This is absolutely NOT the reason why the accounts are being hacked. As others have said, a brute force hack would take years to crack most passwords. Yes, the CAPTCHA method is a flaw on Microsoft's part, but hardly has anything to do with accounts being hacked.

Yup, a security flaw with Live. Not EA. Some people have some back pedaling to do after the recent threads.

Well, at this point this is a "private investigator's" opinion. As far as I'm concerned, it still has not been proven, and if it were that simple, I still think we would be seeing FAR more people getting their accounts "hacked". I still think this is more of a social engineering scam than anything.

3 failed attempts and the account should simply lock and email recovery is needed. Simple really, throw in a drop down on logon for x, x and x of another password adds another layer of security.

Doh..

Agreed. I think that would certainly be wise.

Also, since you brought up Sony, does PSN even have any sort of brute force security? I just tried an invalid password 25 times for my PSN account and it didn't lock or display any captcha.

Wow. THAT is really scary... I guess they haven't learned anything about security whatsoever...

Yup, a security flaw with Live. Not EA. Some people have some back pedaling to do after the recent threads.
The "security flaw" is limited to being able to bypass captcha and then continue brute force. As someone has said already, Sony doesn't even have a captcha. So all those PSN accounts where you "only lost your ID" but no money was lost? They are in equal danger. ;-) (I wouldn't know better, I am not going to play with my WLID and don't have a PSN account to verify one way or the other).

This also shows that all who got hacked had weak passwords and all "I have never used it anywhere but my xbox" were simply stupid. If your password could be brute-forced, then it's not a good password.

If this is really an issue with WLID, which I still doubt it - then MS has bigger things to worry about than Xbox.

This should be merged with this thread: https://www.neowin.net/forum/topic/1036915-xbox-live-accounts-being-hacked/ No need for another one.

This is audio and shakey's day. let them enjoy it. :-D Microsoft is now "hacked" same as Sony. Kind of morale booster, ain't it?

"the email address or password is incorrect" - or not - "That Windows Live ID doesn't exist."

Terrible. That's security 123 students learn in school. Never ever give too much information to hackers.

The message should always be something like "Account informations invalid".

OK, this is absurd for a number of reasons.

First of all, it assumes that the passwords people use are so utterly stupid that they can be brute force hacked in a relatively fast fashion. That's patently stupid, for one. Secondly, most of the phishing or hacking victims have said they had strong passwords (including the couple of people on Neowin who were hacked). So unless they've been attempting to brute force crack someone's password since the original Xbox came out and they got incredibly lucky, then that's no dice. Third, I'm more than willing to bet that many of the hacking victims didn't have their e-mails searchable on Facebook or social networking sites.

It's not even a good theory. The CAPTCHA thing needs to be fixed, absolutely, but that's not even much of a security flaw in the grand scheme of things. You'd have to have good knowledge of what someone would use as a password (or have someone who has an insanely simple password) to have any value in that issue. I'm sure there's some way people are getting this information (and it's more likely they're not even finding out passwords, but using some sort of social engineering to get into someone's account -- like calling customer service and exploiting a flaw in the human system), but this doesn't seem even remotely likely.

Also: can we stop creating a billion topics about this? We only need one, just like all the posts when Sony was hacked were kept in the same place.

I wonder if the same CAPTCHA loophole affects Hotmail.com as well. In any case, I hope Microsoft fixes it soon.

CAPTCHAs are not that much secure.

I would hardly call it a serious security flaw.......

wow glad you are not working for my bank web site.

OK, this is absurd for a number of reasons.

First of all, it assumes that the passwords people use are so utterly stupid that they can be brute force hacked in a relatively fast fashion. That's patently stupid, for one. Secondly, most of the phishing or hacking victims have said they had strong passwords (including the couple of people on Neowin who were hacked). So unless they've been attempting to brute force crack someone's password since the original Xbox came out and they got incredibly lucky, then that's no dice. Third, I'm more than willing to bet that many of the hacking victims didn't have their e-mails searchable on Facebook or social networking sites.

It's not even a good theory. The CAPTCHA thing needs to be fixed, absolutely, but that's not even much of a security flaw in the grand scheme of things. You'd have to have good knowledge of what someone would use as a password (or have someone who has an insanely simple password) to have any value in that issue. I'm sure there's some way people are getting this information (and it's more likely they're not even finding out passwords, but using some sort of social engineering to get into someone's account -- like calling customer service and exploiting a flaw in the human system), but this doesn't seem even remotely likely.

Also: can we stop creating a billion topics about this? We only need one, just like all the posts when Sony was hacked were kept in the same place.

Yeah, I don't believe this either. It just doesn't seem like it would be possible as people have said, their password wasn't an easy guess. It's a flaw that should be fixed though.

Is it possible Microsoft doesn't know how they are accessing accounts ?

Social engineering, inside job or something. Surely an actual hack will lead to something more than Xbox Live which seems small fish if you have someones details.

Even if this isn't the flaw that got hackers into the accounts, it's definitely a good way to learn what accounts exist, and at least attempt common passwords. Knowing the first is a good part of the battle, and of the second even if the success is low (1% maybe, depending how many passwords you try, but not bruteforce) it's still a chance.

Yeah, I don't believe this either. It just doesn't seem like it would be possible as people have said, their password wasn't an easy guess. It's a flaw that should be fixed though.

Is it possible Microsoft doesn't know how they are accessing accounts ?

Social engineering, inside job or something. Surely an actual hack will lead to something more than Xbox Live which seems small fish if you have someones details.

Absolutely. I agree 100%. If they "hacked" all of these people's details, they'd be out to do much more damage than buying a few things on XBox Live... I mean, come on... The fact that that is their focus, leads me to the conclusion that it is not Live, as that would give them access to their e-mail and as a result a TON of other stuff... So, I still chalk this up to social engineering.

hmm claiming this is like the PSN hack is kinda like how lighting candles is like forest fires...

yeah...

I'd bet MS and EA will find some way to stop this, since it's obviously hurting both of them. I'd still guess crappy passwords that are never changed have something to do with it, too. So many people are clueless when it comes to online security and just assume it won't be an issue...until it is.

And i guess some people like you are clueless about server side security. because from what i'm reading it's very weak for xbox live. You never ever say why a login failed. That's gold information for hackers. Live loging does.

You Freeze an account when too much login attempts failed and send a mail to the user to recover the account. Live doesn't not freeze the account but use a weak captcha protection.

Come one that's security 123 students learn in college. Seriously ...

Funny that, im a web designer and have all sorts of I.T knowledge. Yet I still got hacked/phished. Sadly because you know something exists, doesnt mean you wont fall prey.

Don't lose your time. I went thru all this when my wow account got hacked (and i mean it). All people told me it was phishing and such. I am a web dev and knew i did not fall for a scam. I lost a complete night checking my email account log used for my wow account, checking my router log, scanning my HD and memory for a keylogger (even though i play games on my work computer while i surf the web on my secondary computer).

After this night i was 99.99% sure the account was not compromised from my side. Yet people was still telling me it was phishing.

You also always have this guy blaimg your PW strength too saying you need a 50 digits password with asian and russian caracters in (while in fact any good web service will freeze an account before it's even remotely possible to brute force a 8 digits random letters/numbers/symbols/caps PW).

It's a waste of time. They think they are better than anyone ... until the day they'll like me get hacked for the first time.

I don't play wow anymore but i can assure you my SWTOR account is protected using the authenticator app ;).

Interesting. A poster knows more about Microsoft security than Microsoft's multimillion dollar security team? Ok then. Um..no.

I don't. Everyone know about that. Seriously you can't be serious. I simply can't believe it. That's something you learn in the most basic class about security. Carefully word the error messages you show to the end users so you do not tell too much informations to hackers. What hackers get from error messages is gold to them.

Sorry but when you have 2 different error messages, one for when the account doesn't exist and one for when the account login information is wrong this is just bad.

As for the account not being frozen that's hilarious to see some people defending that.

I don't. Everyone know about that. Seriously you can't be serious. I simply can't believe it. That's something you learn in the most basic class about security. Carefully word the error messages you show to the end users so you do not tell too much informations to hackers. What hackers get from error messages is gold to them.

Sorry but when you have 2 different error messages, one for when the account doesn't exist and one for when the account login information is wrong this is just bad.

As for the account not being frozen that's hilarious to see some people defending that.

You still fail to realize that having a valid email or Gamertag really isn't that useful. Unless the password is guessable, then a password shouldn't ever be cracked. Every hacker out there knows that brute force is the worst way of cracking into an account. It's simply not plausible in a short amount of time.

Is it bad that Microsoft confirms if the username is valid? Yes. Is it allowing people to hack into accounts? Absolutely not.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • "Revelation?" I was hoping for this episode to be called "Reunion". Oh, well... In a related note, the Final Fantasy VII compilation has received an EC entry, short for Ever Crisis. For those who don't know, it already had AC, BC, CC, and DC entries, short for Advent Children, Before Crisis, Crisis Core, and Dirge of Cerberus. I hope it doesn't get an FC entry becaude that would be a freakin' crisis.
    • Uh, after intense testing now, 'Samsung Browser' is not the best one outside of 'Microsoft Edge' after all. Opera Air is that. It has "some" bloat, but it's far less than what both Microsoft Edge and Brave browser have.
    • Weekend PC Game Deals: Resident Evil, Mafia, Like a Dragon, and more by Pulasthi Ariyasinghe Weekend PC Game Deals is where the hottest gaming deals from all over the internet are gathered into one place every week for your consumption. So kick back, relax, and hold on to your wallets. The Epic concluded its mystery giveaways this week with another double freebie promotion. As a part of this, you can now grab Rogue Waters and Songs of Conquest to keep. Songs of Conquest is a turn-based 4X strategy game where you'll be managing a kingdom, making tough decisions, and taking down enemy forces in tactical combat. Meanwhile, Rogue Waters is a roguelike where, as a pirate captain, you command a ship and crew through procedurally generated encounters. The double giveaway is coming to an end on June 11. On the same day, Warhammer 40K Speed Freeks will join in as the next freebie. Another Humble Choice offer was revealed earlier this week, bringing a refreshed eight-game selection to jump into. The June selection is Octopath Traveler 2, The Riftbreaker, Life is Strange: Double Exposure, INDIKA, Citizen Sleeper 2: Starward Vector, Construction Simulator, Hell Clock, and Overlooting to keep as Steam keys. The $15 bundle gives you all eight games from this month's Choice selection. The month-long promotion will come to an end on July 6, giving you ample time to decide on whether you want the titles. The Humble Store also brought in standard gaming collections this week. The IGN Live Bundle kicked things off with games like Control, Shadow Gambit: The Cursed Crew, Blair Witch, Rollerdrome, and The Last Campfire for $10. At the same time, the We Will Always be Here bundle carried in titles like Bad End Theater, Thirsty Suitors, Vampire Therapist, and Tavern Talk for $12. Next, the 2K Sports Champions Bundle comes touting games like NBA 2K26, PGA TOUR 2K25, OlliOlli World Rad Edition, and TopSpin 2K25 with a hefty $25 price tag. Lastly, the Redline Racing Bundle is touting games like Art of Rally, Descenders, Mudrunner, and Assetto Corsa Competizione with a $10 price tag. Big Deals The biggest promotions of this weekend come from franchise discounts for hits like Mafia, Like a Dragon, Resident Evil, and more. With all those and more, here's our hand-picked big deals list for the weekend: Mafia: The Old Country – $34.99 on Steam ARC Raiders – $31.99 on Steam Forza Horizon 5 – $29.99 on Steam Monster Hunter Wilds – $29.39 on Steam Satisfactory – $27.99 on Steam No Rest for the Wicked – $27.99 on Steam Satisfactory – $27.99 on Steam Esoteric Ebb – $19.99 on Steam Street Fighter 6 – $19.99 on Steam Cloudheim – $19.79 on Steam Pacific Drive – $17.99 on Steam Like a Dragon: Infinite Wealth – $17.49 on Steam ACE COMBAT 7: SKIES UNKNOWN – $14.99 on Steam Yakuza 0 Director's Cut – $14.99 on Steam Like a Dragon Gaiden: The Man Who Erased His Name – $14.99 on Steam Like a Dragon: Pirate Yakuza in Hawaii – $14.99 on Steam Grand Theft Auto V Enhanced – $14.99 on Steam Lost Judgment – $13.99 on Steam The Crew Motorfest – $13.99 on Steam Stronghold Crusader: Definitive Edition – $12.59 on Steam The Stanley Parable: Ultra Deluxe – $12.49 on Steam Blood West – $12.49 on Steam Yakuza Kiwami 2 – $11.99 on Steam Judgment – $11.99 on Steam Like a Dragon: Ishin! – $11.99 on Steam Alien: Isolation – $11.99 on Steam Goat Simulator: Remastered – $10.19 on Steam Resident Evil Village – $9.99 on Steam Yakuza 4 Remastered – $9.99 on Steam Yakuza 5 Remastered – $9.99 on Steam Yakuza 6: The Song of Life – $9.99 on Steam Caravan SandWitch – $9.99 on Steam Spyro Reignited Trilogy – $9.99 on Steam Assassin's Creed III Remastered – $9.99 on Steam The Expanse: A Telltale Series – $9.99 on Steam Sons Of The Forest – $8.99 on Steam Untitled Goose Game – $7.99 on Steam Resident Evil 2 – $7.99 on Steam Resident Evil 3 – $7.99 on Steam Resident Evil 7 Biohazard – $7.99 on Steam Yakuza: Like a Dragon – $7.99 on Steam Airborne Kingdom – $7.49 on Steam Assassin's Creed Syndicate – $7.49 on Steam The Wolf Among Us – $7.49 on Steam Amnesia: The Bunker – $7.49 on Steam Mini Motorways – $6.99 on Steam Age of History 3 – $6.99 on Steam Fabledom – $6.29 on Steam Trine 4: The Nightmare Prince – $5.99 on Steam Mafia: Definitive Edition – $5.99 on Steam Mafia II: Definitive Edition – $5.99 on Steam Resident Evil 6 – $4.99 on Steam Resident Evil 5 – $4.99 on Steam Resident Evil Revelations 2 – $4.99 on Steam Resident Evil 3 Nemesis (1999) – $4.99 on Steam Terra Memoria – $4.99 on Steam FOR HONOR – $4.49 on Steam Metro Exodus – $4.49 on Steam The Forest – $4.39 on Steam Mini Metro – $3.99 on Steam Songs of Conquest – $0 on Epic Store Rogue Waters – $0 on Epic Store Gravity Circuit – $0 on Steam DRM-free Specials The DRM-free store GOG has plenty of discounts to look over this weekend too. Here are some highlights: Trials of Mana - $14.99 on GOG SPORE Collection - $14.99 on GOG Stellaris - $12.49 on GOG FINAL FANTASY VIII - REMASTERED - $7.99 on GOG Final Fantasy IV (3D Remake) - $7.99 on GOG Final Fantasy III (3D Remake) - $7.99 on GOG FINAL FANTASY IX - $6.29 on GOG The Forgotten City - $6.25 on GOG Warlords Battlecry 3 - $5.99 on GOG Heroes of Might and Magic 3: Complete - $4.99 on GOG Heroes of Might and Magic 4: Complete - $4.99 on GOG SimCity 4 Deluxe Edition - $4.99 on GOG FINAL FANTASY VII - $4.79 on GOG Cultures 1+2 - $3.99 on GOG Outlast - $3.75 on GOG Dungeon Keeper 2 - $2.99 on GOG Theme Hospital - $2.99 on GOG Sid Meier's Alpha Centauri Planetary Pack - $2.99 on GOG Dungeon Keeper Gold - $2.99 on GOG Alba: A Wildlife Adventure - $2.55 on GOG Disciples 2 Gold - $1.99 on GOG Outcast - Second Contact - $1.49 on GOG Disciples: Sacred Lands Gold - $1.49 on GOG Port Royale 2 - $0.99 on GOG Keep in mind that availability and pricing for some deals could vary depending on the region. That's it for our pick of this weekend's PC game deals, and hopefully, some of you have enough self-restraint not to keep adding to your ever-growing backlogs. As always, there are an enormous number of other deals ready and waiting all over the interwebs, as well as on services you may already subscribe to if you comb through them, so keep your eyes open for those, and have a great weekend.
    • Exciting! It’s amazing how hearing Japanese can naturally enhance the perceived quality of any experience or product.
  • Recent Achievements

    • Week One Done
      pestcontrol46 earned a badge
      Week One Done
    • One Month Later
      pestcontrol46 earned a badge
      One Month Later
    • Week One Done
      JKR earned a badge
      Week One Done
    • Rookie
      moog19 went up a rank
      Rookie
    • Mentor
      grik went up a rank
      Mentor
  • Popular Contributors

    1. 1
      +primortal
      490
    2. 2
      PsYcHoKiLLa
      271
    3. 3
      Skyfrog
      75
    4. 4
      Steven P.
      68
    5. 5
      FloatingFatMan
      64
  • Tell a friend

    Love Neowin? Tell a friend!