Xbox live accounts being hacked?


Recommended Posts

Did you guys even read the article? Do you seriously think that being able to reset the CAPTCHA so you will have unlimited attempts to find the password isn't a security problem?

If Sony had something like this you all would be letting them have it. Also my password did contain uppercase, lowercase, and numbers in it so it's not just simple password being exploited.

Brute forcing a password is not a 'hack'. If this is it, then it's just these guys using weak passwords.

I agree. Just because they have found a way to brute force it without a CAPCHA doesn't mean its been hacked!

I would hardly call it a serious security flaw.......

I agree. Just because they have found a way to brute force it without a CAPCHA doesn't mean its been hacked!

I would hardly call it a serious security flaw.......

And if your account had been taken over? Of course it's serious, it's not working as it should.

Did you guys even read the article? Do you seriously think that being able to reset the CAPTCHA so you will have unlimited attempts to find the password isn't a security problem?

If Sony had something like this you all would be letting them have it. Also my password did contain uppercase, lowercase, and numbers in it so it's not just simple password being exploited.

Yes... being able to reset the CAPTCHA is a flaw Microsoft should fix asap. However, if your password contained uppercase/lowercase/numbers, wasn't a dictionary word, and wasn't short (<= 6 characters) it would have taken years to brute force your password so it's highly unlikely this flaw has anything to do with it.

Also, since you brought up Sony, does PSN even have any sort of brute force security? I just tried an invalid password 25 times for my PSN account and it didn't lock or display any captcha.

3 failed attempts and the account should simply lock and email recovery is needed. Simple really, throw in a drop down on logon for x, x and x of another password adds another layer of security.

Doh..

Is being able to avoid the CAPTCHA a security flaw? Yes

Is it the reason why your account is being hacked? No. A CAPTCHA is not a replacement for a secure password, if your password is being bruteforced over a network, it is FAR too simple.

This is absolutely NOT the reason why the accounts are being hacked. As others have said, a brute force hack would take years to crack most passwords. Yes, the CAPTCHA method is a flaw on Microsoft's part, but hardly has anything to do with accounts being hacked.

Yup, a security flaw with Live. Not EA. Some people have some back pedaling to do after the recent threads.

Well, at this point this is a "private investigator's" opinion. As far as I'm concerned, it still has not been proven, and if it were that simple, I still think we would be seeing FAR more people getting their accounts "hacked". I still think this is more of a social engineering scam than anything.

3 failed attempts and the account should simply lock and email recovery is needed. Simple really, throw in a drop down on logon for x, x and x of another password adds another layer of security.

Doh..

Agreed. I think that would certainly be wise.

Also, since you brought up Sony, does PSN even have any sort of brute force security? I just tried an invalid password 25 times for my PSN account and it didn't lock or display any captcha.

Wow. THAT is really scary... I guess they haven't learned anything about security whatsoever...

Yup, a security flaw with Live. Not EA. Some people have some back pedaling to do after the recent threads.
The "security flaw" is limited to being able to bypass captcha and then continue brute force. As someone has said already, Sony doesn't even have a captcha. So all those PSN accounts where you "only lost your ID" but no money was lost? They are in equal danger. ;-) (I wouldn't know better, I am not going to play with my WLID and don't have a PSN account to verify one way or the other).

This also shows that all who got hacked had weak passwords and all "I have never used it anywhere but my xbox" were simply stupid. If your password could be brute-forced, then it's not a good password.

If this is really an issue with WLID, which I still doubt it - then MS has bigger things to worry about than Xbox.

This should be merged with this thread: https://www.neowin.net/forum/topic/1036915-xbox-live-accounts-being-hacked/ No need for another one.

This is audio and shakey's day. let them enjoy it. :-D Microsoft is now "hacked" same as Sony. Kind of morale booster, ain't it?

"the email address or password is incorrect" - or not - "That Windows Live ID doesn't exist."

Terrible. That's security 123 students learn in school. Never ever give too much information to hackers.

The message should always be something like "Account informations invalid".

OK, this is absurd for a number of reasons.

First of all, it assumes that the passwords people use are so utterly stupid that they can be brute force hacked in a relatively fast fashion. That's patently stupid, for one. Secondly, most of the phishing or hacking victims have said they had strong passwords (including the couple of people on Neowin who were hacked). So unless they've been attempting to brute force crack someone's password since the original Xbox came out and they got incredibly lucky, then that's no dice. Third, I'm more than willing to bet that many of the hacking victims didn't have their e-mails searchable on Facebook or social networking sites.

It's not even a good theory. The CAPTCHA thing needs to be fixed, absolutely, but that's not even much of a security flaw in the grand scheme of things. You'd have to have good knowledge of what someone would use as a password (or have someone who has an insanely simple password) to have any value in that issue. I'm sure there's some way people are getting this information (and it's more likely they're not even finding out passwords, but using some sort of social engineering to get into someone's account -- like calling customer service and exploiting a flaw in the human system), but this doesn't seem even remotely likely.

Also: can we stop creating a billion topics about this? We only need one, just like all the posts when Sony was hacked were kept in the same place.

I wonder if the same CAPTCHA loophole affects Hotmail.com as well. In any case, I hope Microsoft fixes it soon.

CAPTCHAs are not that much secure.

I would hardly call it a serious security flaw.......

wow glad you are not working for my bank web site.

OK, this is absurd for a number of reasons.

First of all, it assumes that the passwords people use are so utterly stupid that they can be brute force hacked in a relatively fast fashion. That's patently stupid, for one. Secondly, most of the phishing or hacking victims have said they had strong passwords (including the couple of people on Neowin who were hacked). So unless they've been attempting to brute force crack someone's password since the original Xbox came out and they got incredibly lucky, then that's no dice. Third, I'm more than willing to bet that many of the hacking victims didn't have their e-mails searchable on Facebook or social networking sites.

It's not even a good theory. The CAPTCHA thing needs to be fixed, absolutely, but that's not even much of a security flaw in the grand scheme of things. You'd have to have good knowledge of what someone would use as a password (or have someone who has an insanely simple password) to have any value in that issue. I'm sure there's some way people are getting this information (and it's more likely they're not even finding out passwords, but using some sort of social engineering to get into someone's account -- like calling customer service and exploiting a flaw in the human system), but this doesn't seem even remotely likely.

Also: can we stop creating a billion topics about this? We only need one, just like all the posts when Sony was hacked were kept in the same place.

Yeah, I don't believe this either. It just doesn't seem like it would be possible as people have said, their password wasn't an easy guess. It's a flaw that should be fixed though.

Is it possible Microsoft doesn't know how they are accessing accounts ?

Social engineering, inside job or something. Surely an actual hack will lead to something more than Xbox Live which seems small fish if you have someones details.

Even if this isn't the flaw that got hackers into the accounts, it's definitely a good way to learn what accounts exist, and at least attempt common passwords. Knowing the first is a good part of the battle, and of the second even if the success is low (1% maybe, depending how many passwords you try, but not bruteforce) it's still a chance.

Yeah, I don't believe this either. It just doesn't seem like it would be possible as people have said, their password wasn't an easy guess. It's a flaw that should be fixed though.

Is it possible Microsoft doesn't know how they are accessing accounts ?

Social engineering, inside job or something. Surely an actual hack will lead to something more than Xbox Live which seems small fish if you have someones details.

Absolutely. I agree 100%. If they "hacked" all of these people's details, they'd be out to do much more damage than buying a few things on XBox Live... I mean, come on... The fact that that is their focus, leads me to the conclusion that it is not Live, as that would give them access to their e-mail and as a result a TON of other stuff... So, I still chalk this up to social engineering.

hmm claiming this is like the PSN hack is kinda like how lighting candles is like forest fires...

yeah...

I'd bet MS and EA will find some way to stop this, since it's obviously hurting both of them. I'd still guess crappy passwords that are never changed have something to do with it, too. So many people are clueless when it comes to online security and just assume it won't be an issue...until it is.

And i guess some people like you are clueless about server side security. because from what i'm reading it's very weak for xbox live. You never ever say why a login failed. That's gold information for hackers. Live loging does.

You Freeze an account when too much login attempts failed and send a mail to the user to recover the account. Live doesn't not freeze the account but use a weak captcha protection.

Come one that's security 123 students learn in college. Seriously ...

Funny that, im a web designer and have all sorts of I.T knowledge. Yet I still got hacked/phished. Sadly because you know something exists, doesnt mean you wont fall prey.

Don't lose your time. I went thru all this when my wow account got hacked (and i mean it). All people told me it was phishing and such. I am a web dev and knew i did not fall for a scam. I lost a complete night checking my email account log used for my wow account, checking my router log, scanning my HD and memory for a keylogger (even though i play games on my work computer while i surf the web on my secondary computer).

After this night i was 99.99% sure the account was not compromised from my side. Yet people was still telling me it was phishing.

You also always have this guy blaimg your PW strength too saying you need a 50 digits password with asian and russian caracters in (while in fact any good web service will freeze an account before it's even remotely possible to brute force a 8 digits random letters/numbers/symbols/caps PW).

It's a waste of time. They think they are better than anyone ... until the day they'll like me get hacked for the first time.

I don't play wow anymore but i can assure you my SWTOR account is protected using the authenticator app ;).

Interesting. A poster knows more about Microsoft security than Microsoft's multimillion dollar security team? Ok then. Um..no.

I don't. Everyone know about that. Seriously you can't be serious. I simply can't believe it. That's something you learn in the most basic class about security. Carefully word the error messages you show to the end users so you do not tell too much informations to hackers. What hackers get from error messages is gold to them.

Sorry but when you have 2 different error messages, one for when the account doesn't exist and one for when the account login information is wrong this is just bad.

As for the account not being frozen that's hilarious to see some people defending that.

I don't. Everyone know about that. Seriously you can't be serious. I simply can't believe it. That's something you learn in the most basic class about security. Carefully word the error messages you show to the end users so you do not tell too much informations to hackers. What hackers get from error messages is gold to them.

Sorry but when you have 2 different error messages, one for when the account doesn't exist and one for when the account login information is wrong this is just bad.

As for the account not being frozen that's hilarious to see some people defending that.

You still fail to realize that having a valid email or Gamertag really isn't that useful. Unless the password is guessable, then a password shouldn't ever be cracked. Every hacker out there knows that brute force is the worst way of cracking into an account. It's simply not plausible in a short amount of time.

Is it bad that Microsoft confirms if the username is valid? Yes. Is it allowing people to hack into accounts? Absolutely not.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • ...but you're Johnny, from Australia?    
    • Glow 26.9 by Razvan Serea Glow provides detailed reporting on every hardware component in your computer, saving you valuable time typically spent searching for CPU, motherboard, RAM, graphics card, and other stats. With Glow, all the information is conveniently presented in one clean interface, allowing you to easily access and review the comprehensive hardware details of your system. Glow provides detailed information on various system aspects, including OS, motherboard, processor, memory, graphics card, storage, network, battery, drivers, and services. The well-organized format ensures easy access to the required information. You can export all the gathered data to a plain text file, facilitating sharing with others for troubleshooting purposes. No installation needed. Just decompress the archive, launch the executable, and access computer-related information. Glow runs on Windows 11 and Windows 10 64-bit versions. Glow 26.9 changelog: New Features The processor hardware detection engine has been significantly enhanced beyond traditional Intel and AMD architectures. Native support is now available for modern platforms such as Apple Silicon (M-Series) and the newly introduced NVIDIA Spark. In addition, all ARM-based processors can now be accurately distinguished between ARM32 and ARM64 architectures, providing precise hardware reporting. This marks a major milestone for Glow's hardware detection capabilities. The RAM manufacturer identification algorithm has been expanded. JEDEC vendor codes for popular brands such as Patriot, PNY, Team Group, GeIL, Lexar (Longsys), and Asgard/Gloway have been integrated into the database. This significantly reduces the likelihood of incorrect or "Unknown Manufacturer" results and improves overall hardware detection accuracy. New Public IP Address and Internet Service Provider (ISP) features have been added to the Network section. To ensure reliability, this information is retrieved from the trusted service ipwho.is. When Hiding Mode is enabled, no requests are sent and these features remain hidden, as they may expose sensitive information. The search engine used in the Installed Drivers, Installed Services, and Installed Applications sections has been enhanced. You can now perform more flexible and accurate searches using initials, partial matches, and loosely arranged character sequences. The TS Preloader loading bar has been rebuilt using our modern TS Custom Controls graphics library, developed entirely in-house. As a result of this infrastructure upgrade, the loading bar now features smooth rendering and rounded corners that align with the visual style of Windows 11. [TS Updater] A new validation algorithm has been added to check whether the target application is currently running before the update process begins. Bug Fixes Resolved a condition that could prevent TS Preloader from shutting down safely during rare application crash scenarios. Fixed a text alignment issue in the Network section affecting the display of DNS addresses. Alignment is now rendered correctly. [TS Updater] Fixed an issue that could prevent the updated application's executable "*.exe" file from being located after the update process. [TS Updater] Fixed a bug that could leave outdated "*.sha256" files in the application directory after an update. [TS Updater] Fixed a rare issue that could cause subfolders to be moved into the root directory after an update. [TS Updater] Fixed an issue during the first launch that could cause flickering and a temporary white window appearance due to Windows Defender interactions. Changes A small improvement has been made to the internet connectivity detection algorithm. Connectivity checks are now performed in the background with minimal impact on the user interface thread. The keyboard shortcuts in the top menu have been reorganized and simplified to provide a consistent experience across all Türkaysoft applications and to avoid potential conflicts with standard Windows shortcuts. The TS Preloader splash image has been updated with a Türkiye-themed stadium design to celebrate Türkiye's qualification for the 2026 FIFA World Cup—its first appearance in 24 years. Congratulations, Türkiye! The TS Custom Controls module has been updated to version 26.6, delivering improved stability and a more polished visual appearance. [TS Updater] The application icon has been redesigned to provide a more modern and refined look. Note: Always unzip the program before using it. Otherwise you may get an error. Download: Glow 26.9 | 1.8 MB (Open Source) Links: Glow Homepage | Screenshot | Github Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • DWARF mini review: the world's smallest smart telescope for night and day sky captures by Steven Parker DWARFLAB reached out to me asking if I was interested in checking out the DWARF mini, which is a portable astronomy telescope designed for amateur astronomers. Why do I say it's for amateurs? Well, for starters, it's not what you'd call "high end"; it's more of a professional-grade starting point for amateurs serious about capturing what's up there in our night and day skies. A typical amateur astronomer is most likely thousands of dollars deep into the hobby, and I will make no claims that this DWARF mini (at a fraction of the cost) could replace it all, okay? Well, if you read on, it will be clearer what I am trying to convey. Disclosure: DWARFLAB provided a free sample without any editorial input or review pre-approval. I have always been interested in looking up and observing the night sky. I see satellites crossing the sky above my garden most nights, and I am always looking at the moon. Yeah, I have a 200MP camera on my phone, but at 200X zoom, AI takes over and makes the pretty moon pictures that I snap, the DWARF mini does not, you get an actual true picture of what you can barely see with the naked eye. Before we start, let's share the highlights of the DWARF mini in bite-sized format: Pocket-Sized & Ultra-Lightweight Weighing just 1.85 lbs (840g), the DWARF mini easily fits into a backpack or large pocket. Its all-in-one, compact design makes it the ultimate grab-and-go digital telescope for hiking, camping, or traveling to dark-sky locations. Intuitive App Control & Built-in Sky Atlas Go from unboxing to your first shot in just 3 minutes! The DWARFLAB App provides a seamless experience with an interactive star map. Simply select your target and start exploring without the steep learning curve of traditional setups. Auto GOTO & 360° Pivot Freedom Enjoy pinpoint automated tracking with full 360° rotation. Powered by a high-sensitivity Sony IMX662 sensor (1/2.8-inch, 2.9μm pixels), it captures amazing, low-noise astro details, bringing faint nebulas and star clusters to life with stunning clarity. Pro-Level EQ Mode & Long Exposure Unlock advanced deep-space imaging with Equatorial (EQ) Mode. Supporting impressive single-frame exposures up to 90 seconds and featuring built-in light pollution filters, it easily cuts through city glow to reveal intricate celestial structures. Smart Cloud Processing & All-Ages Fun Effortlessly enhance your raw data with integrated cloud processing for professional-grade results. Perfect for beginners, kids, and adults, this telescope makes exploring and sharing the wonders of the universe an exciting, family-friendly adventure. The packaging is a pretty minimal affair with the outer box opening like a flap to reveal the plastic mould of the DWARF mini sitting in it. Below, the Sun filter, charging cable, cleaning cloth, and documentation can be found. DWARFLAB also provided a Mini Hydraulic Tripod ($89.99), and I highly recommend getting it if you plan on purchasing the DWARF mini, as it fully supports the motorized tracking feature of the telescope; plus, at 840g, the weight of the telescope, you will need a tripod that supports more than the weight of a smartphone anyway. What's in the box DWARF Mini Smart Telescope × 1 Sun Filter x 1 Type-C to Type-C Cord x 1 Cleaning Cloth x 1 User Guide With that out of the way, here are the full specs: DWARF mini Dimensions (DWH): 60.70 mm x 100.38 × 183.61 (2.39" x 3.95" x 7.23") Weight: 840g (1.85lbs) Aperture diameter: 30 mm (telephoto), 3.4 mm (wide angle) Image Sensor: SONY IMX662 1/2.8" (Telephoto) OmniVision OS02K10 1/2.8" (Wide-angle) Focal length: 150 mm (telephoto), 6.7 mm (wide-angle) Equivalent focal length: 1016 mm (telephoto), 45 mm (wide-angle) Shutter Speed: Tele - 1/10000-90s, Wide - 1/10000-30s Maximum exposure time: 90s (telephoto & wide-angle), Both in EQ mode Rotation range: Lens: 225°, Base: 360° Effective Pixels: 2.07M Maximum Resolution: 1920 × 1080 (Telephoto & Wide-angle) Built-in filters: Astro, Dark, Duo-Band (Telephoto), Astro (Wide-angle) Output: JPG, FITS, TIFF, MP4 Shooting Mode: Photos, Videos, Astronomy, Burst Shooting, Time-lapse Photography Storage: 64 GB Battery: Built-in 7000 mAh, supports external USB charging Charging Port: Type-C NPU: 1 TOPS Features: WiFi, NFC NFC One-Touch Connection Astronomy Post-Processing/Appointment Shooting/Astronomy Mosaic Wi-Fi Transmission Range: 15m (open environment) Color: Black Compatibility: iOS & Android smartphones/tablets Warranty: 2-years (24-months) MSRP: $399 Design Charge port On/off button Lens On the DWARF mini itself, it is a pretty minimal affair. On one side, there is a Type-C USB port to charge the non-removable 7000 mAh battery, and on the other side, a large button to power on or off the telescope. The button is flanked by an LED that is green when connected via the DWARFLAB app, or lights up red when being powered off. Below the button, there are four LEDs that indicate battery power. The DWARF mini does not have any sharp edges as all sides are rounded off; it has a good heft to it, but the weight of it feels quite balanced in the hand, so it isn't top or bottom-heavy. On the front there is the DWARFLAB logo which is quite small and there are no other markings on it. The tripod offers full 360° rotation of the motorized base, which allows for tracking for the time-lapse mode, but also for the 90-second captures of nearer objects in the sky, such as the Sun or the moon. Usage To get started, simply power on the DWARF mini and open the DWARFLAB app, tap on Connect, and it will scan for the DWARF mini over the Wi-Fi network. The device supports both 2.4 GHz and 5 GHz Wi-Fi, as well as Bluetooth for discovery, so connection issues were minimal in my experience with it. As previously noted in the specs, the DWARF mini will stay connected with a phone or tablet up to 15 meters in an open environment, such as a backyard. Lighting status Powering on: The green circular light will rotate and breathe in turn Powering off: The red circular light is gradually extinguished Connecting: Green light strip rotating Connected: Green light strip solid/always on 4 lights 1= 0-25%, 2= 25-50%, 3= 50-75%, 4= 75-100% battery power To view the full lighting status, such as tracking mode and connection failure, you can check the user guide on the official DWARFLAB page. DWARFLAB app Above, you can see the steps undertaken to connect the DWARFLAB app to my Galaxy S26 Ultra. Weirdly, I got an alert that a firmware update failed to get uploaded to the DWARF mini the first time, but upon retrying, it worked. Then place the DWARF mini outside, make sure your smartphone or tablet is connected to it, and then head back inside, because you can manage it from the comfort of your home. Simply enter the Atlas tab in the app and search for what you want to capture, and then tap on the camera icon; the DWARF mini will then attempt to track the object and give you a live view right on your connected device. Results I've had the DWARF mini since April, but even though my garden is south-facing, I had a lot of trouble trying to capture a good image of the moon. In the end, it was possible after I took it with me on a trip to my parents in Southend, UK, at the end of May. Here is a capture of the moon, resulting from 20 stacked images over a 90-second exposure. What you are seeing here is not AI-assisted. A good example of what I mean is the latest flagships with their 200MP cameras claiming to capture things like closeups of the moon, and while they are not as good as the above example on the DWARF mini, the resulting image on smartphones is actually AI-assisted above 30X zoom. Here is an example of a similar shot at the moon at 200X zoom using an HONOR Magic8 Pro. The difference is clear. Next, here we have a shot of the daytime moon. Here is a shot of Arcturus, the red giant star, which is the fourth brightest in the night sky. As previously mentioned, it could be a bit clearer, but clouds passing in front of it muddied the shot a bit. The Sun The DWARF mini also ships with a sun filter, meaning you can take great shots of the sun as well. Tracking Sun Resulting (stacked) shot Live zoom The pictures themselves are limited to Full HD, and some of the examples actually came out in HD (1280x720), but this is because the standard telescopic result is in 720p while "Wide" is in 1080p. Above you can see how in the app the Sun is tracked, the resulting capture, and Live zoom. I have only scratched the surface of what is possible with this telescope; I found several examples online of shots of the Milky Way, among others, such as nebulae and galaxies. All of this requires patience and knowledge, although if you know what you are looking for, simply enter it in the Atlas tab in the DWARFLAB app, tap the camera icon, and the telescope will attempt to track it. Conclusion The good The DWARF mini definitely places itself in a price point that makes astrology accessible to anyone looking to get started in the hobby. Say you want to have a closer look at the moon, simply enter it in the Atlas, and the Live view also lets you zoom in and snap pictures. The bad Some issues I came across while operating the DWARF mini were that it sometimes failed to connect unless I held my smartphone right next to it, and finding and tracking sometimes took several attempts to get it calibrated. I discovered that it helped if I sort of positioned and pointed the telescope in the general area it was supposed to detect, but this obviously wouldn't work with objects you can't see with the naked eye; more testing is required for that. Another bit of advice is to ensure that the lens is clean. While making the examples of live zooming on the sun, I discovered that the telescope lens and sun filter were not completely clean, and only after cleaning with a microfiber cloth was I able to get a decent shot of the sun. Where to buy and a coupon Okay, $399 is not cheap for a side hobby, but nor is a $1,500 smartphone flagship that you'll most likely have for a couple of years. This is a one-time entrance into astrology, and it won't become obsolete in one year like a smartphone. It's a thumbs up from me. The DWARF mini is available to buy right now in the U.S. and U.K. at the links below. DWARF mini for $399 on the official site DWARF mini for $399 on Amazon U.S. Use the NEOWIN5OFF coupon code for an additional 5% off at checkout (expires June 21) As an Amazon Associate, I earn from qualifying purchases.
    • Adobe Acrobat Reader Dis Continued
    • The name, you mean? If so, it's actually the objects common name. There's another one called NGC 7293 which is also known as Helix Nebula (because we're looking at a helix structure top down) but other times also known as the Eye of God. You'll understand when you see it
  • Recent Achievements

    • One Month Later
      lamborghiniv10 earned a badge
      One Month Later
    • Week One Done
      lamborghiniv10 earned a badge
      Week One Done
    • Reacting Well
      X-No-file earned a badge
      Reacting Well
    • One Month Later
      pestcontrol46 earned a badge
      One Month Later
    • Week One Done
      pestcontrol46 earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      504
    2. 2
      PsYcHoKiLLa
      270
    3. 3
      Skyfrog
      75
    4. 4
      +Edouard
      75
    5. 5
      FloatingFatMan
      70
  • Tell a friend

    Love Neowin? Tell a friend!