Xboxist

The GameFlavor Network

 

Xbox Live Hack Down to Pretexting

xbox-hd-dvd-dec-t.jpg

After last week's report by SecurityFocus.com about some Xbox users bragging about stealing Xbox Live accounts, "You call 1-800-4my-xbox, pretend to be that person, make up a story...keep calling and keep calling, every time getting a little bit more information ... once you have enough information you can get the password (and) the Windows Live ID reset.", Microsft, via Director of Programming Larry Hyrb (aka Major Nelson), has finally conceded that the Xbox support center was a victim of a social engineering trick called 'pretexting', which may have allowed an attacker to obtain personal data of an Xbox Live subscriber.

The breakthrough that triggered this turnaround came when Kevin Finisterre of DigitalMunition.com revealed how to hack the accounts by posting his conversation with a Xbox Live support agent on his website. He then forwarded his findings onto Larry Hyrb, who described the audio files, as "painful to listen to". In an attempt to reassure Xbox owners, Hryb went on to state that, "The Xbox Live team has already begun retraining the support staff and partners," Hryb said, "to help make sure we reduce this type of social engineering attack." Contrary to claims of ten or more user accounts stolen a day, Microsoft says that only a handful of Xbox Live accounts have been subverted.

"There's no other way to say it," Hryb said. "This situation shouldn't have happened. Our customers deserve better."

Well let's hope it doesn't happen again.

Want this? Then search and buy on GameFlavor Store now!




Stumble It!
blog comments powered by Disqus

Subscribe


 
GameFlavor: Delicously good video games coverage

Copyright © GameFlavor 2005-2009. All rights reserved - Privacy. Don’t steal our stuff!