The official Xbox 360 thread - the console of choice on nuclear submarines
#3651
gamer for life
re: The official Xbox 360 thread - the console of choice on nuclear submarines
what kind of computer can brute force crack a 11-16 digit password though? I just don't think the above articles are really getting to the bottom of this...
#3652
DVD Talk Hall of Fame
Joined: Jun 2002
Posts: 8,487
Likes: 0
Received 0 Likes
on
0 Posts
re: The official Xbox 360 thread - the console of choice on nuclear submarines
There has to be more to the FIFA aspect than "it's just a really popular game." To my knowledge, everyone who has had this happen so far has reported the FIFA angle. It has happened to 2 people on my friends list now (that I'm aware of, could be more).
#3653
DVD Talk Special Edition
Joined: Apr 2002
Posts: 1,501
Likes: 0
Received 0 Likes
on
0 Posts
From: OKC, OK
re: The official Xbox 360 thread - the console of choice on nuclear submarines
Also, not mentioned in the article, but it seems like a lot of the reported hacks involve the hackers exploiting the Xbox Live Family Pack, where they can associate another gamertag and drain your account. I'm guessing that hacking Xbox accounts has picked up steam since the Family Pack was launched last year.
I don't have any idea how they got the password. It was relatively simple so they probably just did bruteforce it. I have a much longer complex password now.
Again my advice to all is make sure there is not credit card or paypal account tied to your xboxlive account and buy everything with prepaid cards. That would have been a HUGE headache. In fact I wouldn't enter the prepaid points cards until you are ready to use them so there isn't 8000 points sitting on your account.
#3654
DVD Talk Godfather
Joined: Apr 1999
Posts: 65,300
Received 2,704 Likes
on
1,602 Posts
From: Gateway Cities/Harbor Region
re: The official Xbox 360 thread - the console of choice on nuclear submarines
Wow. I guess I'm going to go with point cards too. I only spend points on Zune Movie rentals but still....
#3656
DVD Talk Legend
Joined: Apr 2003
Posts: 10,706
Likes: 0
Received 1 Like
on
1 Post
From: Picture a cup in the middle of the sea
re: The official Xbox 360 thread - the console of choice on nuclear submarines
There are people that have never played FIFA and still were hacked.
So yeah, the problem is with Xbox.
So yeah, the problem is with Xbox.
#3657
gamer for life
re: The official Xbox 360 thread - the console of choice on nuclear submarines
I have the family gold plan...and it would not let me take off my paypal account because of it...I turned off auto-renew but it still would not let me take away my paypal account...
So I went into paypal and turned off microsoft as an authorized merchant...it was the only thing I could think to do...
I did get this email though after turning off auto-renew...I hope I don't have interruption to my subscription!!!
Dear FOXDVD,
Your subscription to Gold Family – 12 Month will expire on Friday, November 15, 2013. To avoid a possible interruption of your subscription service, please renew your subscription by Friday, November 15, 2013.
To extend your Xbox LIVE Gold Family Pack membership, just use a credit card online at this site: http://www.xbox.com/extendmembership
To check pricing details or confirm your account information and payment options, go to: https://billing.microsoft.com
If you have already renewed your subscription, please accept our thanks.
Thank you for using Microsoft Online Services.
Xbox LIVE Team
So I went into paypal and turned off microsoft as an authorized merchant...it was the only thing I could think to do...
I did get this email though after turning off auto-renew...I hope I don't have interruption to my subscription!!!
Dear FOXDVD,
Your subscription to Gold Family – 12 Month will expire on Friday, November 15, 2013. To avoid a possible interruption of your subscription service, please renew your subscription by Friday, November 15, 2013.
To extend your Xbox LIVE Gold Family Pack membership, just use a credit card online at this site: http://www.xbox.com/extendmembership
To check pricing details or confirm your account information and payment options, go to: https://billing.microsoft.com
If you have already renewed your subscription, please accept our thanks.
Thank you for using Microsoft Online Services.
Xbox LIVE Team
#3658
DVD Talk Legend
re: The official Xbox 360 thread - the console of choice on nuclear submarines
However, this xkcd comic shows that hacking an 11 character password could take as little as 3 days:
http://xkcd.com/936/
Also keep in mind that its only one of many possible ways someone's account could've been hacked.
In regards to FIFA, it could be that Xbox is being targeted by a specific hacking group, one that has found a specific exploit and is using it to capitalize on a specific product: FIFA. It may be something about the FIFA DLC that lends it particularly appealing to auction off on hacked accounts. The ability to purchase multiple packs on one account is appealing, and it looks like the items in the pack can be traded in-game with other players:
http://en.wikipedia.org/wiki/FIFA_11#Ultimate_Team
http://arstechnica.com/civis/viewtop...bdaa#p22202437
http://www.neoseeker.com/news/17597-...dlc-purchases/
#3659
gamer for life
re: The official Xbox 360 thread - the console of choice on nuclear submarines
#3660
gamer for life
re: The official Xbox 360 thread - the console of choice on nuclear submarines
http://howsecureismypassword.net/
not sure how accurate the above link is...or even if the above link is safe...lol...but it seems to disagree with the comics time frame...
not sure how accurate the above link is...or even if the above link is safe...lol...but it seems to disagree with the comics time frame...
#3662
#3663
DVD Talk Godfather
re: The official Xbox 360 thread - the console of choice on nuclear submarines
Yeah, more details. Joystiq had something the other day that said one of the only links between all the people reporting being hacked was that they used gmail or hotmail as their Live ID address.
Does that fit your profile glassdragon?
Does that fit your profile glassdragon?
#3664
DVD Talk Legend
re: The official Xbox 360 thread - the console of choice on nuclear submarines
http://howsecureismypassword.net/
not sure how accurate the above link is...or even if the above link is safe...lol...but it seems to disagree with the comics time frame...
not sure how accurate the above link is...or even if the above link is safe...lol...but it seems to disagree with the comics time frame...
However, that site and the xkcd are using different methodologies. The site is just assuming a brute-force attack (it calculated the same length of time for a 9 letter word as it did for a password of 9 random letters). xkcd is assuming the hacker would start with a dictionary attack, then try Caps, common letter->number substitutions, the use of a number and/or punctuation mark at the end, etc...
As for FIFA, I think the answer has a lot to do with those gaming packs, where users basically get players in the game like trading cards. EA even advertises the trading/auction feature:
http://www.ea.com/au/football/fifa-ultimate-team
Bid on 100,000's of live auctions from around the globe.
BTW, looking up the auction site mentioned in the feature story at hackedonxbox shows that there are people auctioning off Xbox Live accounts with MSP, and only warrantying them for as little as 2 hours.
#3665
re: The official Xbox 360 thread - the console of choice on nuclear submarines
I got hacked in mid November with no Family Plan, FIFA, or gmail/hotmail so it still seems somewhat random. It took M$ a month to do their research and refund my CC and then they tacked on an extra 1900 points for my troubles. It was well handled from start to finish so I'm pleased with their customer service but no way in heck am I ever putting a CC on my account again.
#3666
DVD Talk Legend
Joined: Apr 2003
Posts: 10,706
Likes: 0
Received 1 Like
on
1 Post
From: Picture a cup in the middle of the sea
re: The official Xbox 360 thread - the console of choice on nuclear submarines
Basically, the way The way Microsoft shows the error message, when you enter a wrong password, is not the right way. Not according to current security standards. You should never say username incorrect or password is wrong. Your error message should just say that there's something wrong, try again. And of course links if your forgot your username and/or password.
About FIFA, it may be hacked some other way, but not related to this Xbox hack. I play FIFA, and FUT (FIFA Ultimate Team), so I'm pretty familiar with the setup. I think Madden has something similar to FUT.
FUT has also a web interface, a web page where you can do the same of auctioning and trading of your cards like you do in the console, but you use your EA account to acces the site, since it's in EA servers. So yeah, I think it's just that the game is popular, and specially FUT, and that's why always shows in these hacks.
About FIFA, it may be hacked some other way, but not related to this Xbox hack. I play FIFA, and FUT (FIFA Ultimate Team), so I'm pretty familiar with the setup. I think Madden has something similar to FUT.
FUT has also a web interface, a web page where you can do the same of auctioning and trading of your cards like you do in the console, but you use your EA account to acces the site, since it's in EA servers. So yeah, I think it's just that the game is popular, and specially FUT, and that's why always shows in these hacks.
#3667
DVD Talk Godfather
re: The official Xbox 360 thread - the console of choice on nuclear submarines
This article shows a possible avenue of attack the hackers may be using:
http://www.analoghype.com/video-game...red-the-truth/
Part of this hinges on knowing your email address, which people could potentially look up via your gamertag, either because your gamertag is the same as your email address username on a popular service, or some webpage out there links your gamertag and email address. Once they know your email address, they can check to see if you have a Windows Live ID tied to it, and start brute forcing the password.
http://www.analoghype.com/video-game...red-the-truth/
Part of this hinges on knowing your email address, which people could potentially look up via your gamertag, either because your gamertag is the same as your email address username on a popular service, or some webpage out there links your gamertag and email address. Once they know your email address, they can check to see if you have a Windows Live ID tied to it, and start brute forcing the password.
Now MS is the ONLY site/entity that knows or is associated with this new email. I'm still wondering if I should go ahead and spend what points I do have in my account and only add them as needed.
If anything in the above article is correct, that should be enough to sleep easy.
#3668
DVD Talk Hall of Fame
Joined: Jan 2000
Posts: 7,936
Likes: 0
Received 0 Likes
on
0 Posts
From: Somewhere out there... YES THERE!!!
re: The official Xbox 360 thread - the console of choice on nuclear submarines
I am willing to bet that most of these are phishing attempts and not brute force. Now mind you, some people in this thread from what I can tell know enough to not get phished, but there are some people that would fall for it. If they know your email it is simple to phish someone. Just send them an authentic email that looks like it's from MS about something with the password and they have to go to a link to verify it. The link looks authentic enough but it all goes to another server. I don't see them brute forcing that many, probably a small percentage of them that aren't phished or the person didn't fall for it.
#3669
DVD Talk Godfather
#3670
gamer for life
re: The official Xbox 360 thread - the console of choice on nuclear submarines
who would win in a fight...a glassdragon or THE glasschicken? I just know we would all be winners if that happened!
#3671
DVD Talk Platinum Edition
Joined: Oct 2001
Posts: 3,402
Likes: 0
Received 0 Likes
on
0 Posts
From: San Diego
re: The official Xbox 360 thread - the console of choice on nuclear submarines
I am willing to bet that most of these are phishing attempts and not brute force. Now mind you, some people in this thread from what I can tell know enough to not get phished, but there are some people that would fall for it. If they know your email it is simple to phish someone. Just send them an authentic email that looks like it's from MS about something with the password and they have to go to a link to verify it. The link looks authentic enough but it all goes to another server. I don't see them brute forcing that many, probably a small percentage of them that aren't phished or the person didn't fall for it.
#3672
gamer for life
re: The official Xbox 360 thread - the console of choice on nuclear submarines
In fact, anyone who was hacked...have you ever played ANY EA game...and if so did you ever take the time to create an EA account...if you are not sure try logging into EA and see if you username/email and password is the same as your xbox...or old xbox password..
#3673
gamer for life
re: The official Xbox 360 thread - the console of choice on nuclear submarines
I think when they finally get to the bottom of it...they are going to find some service/website that has been compromised...a LOT of people use the same password for multiple websites...if it happens to be cheapassgamer or neogaf that was compromised...it could be as simple as them checking if the same password works on an xbox account.
#3674
DVD Talk Godfather
re: The official Xbox 360 thread - the console of choice on nuclear submarines
Makes you wonder. A lot of people on CAG seem to be getting hit.
Thanks for the heads up on EA. I hadn't considered that I would have an account there. Looks like it was tied to EA Sports Active 2. And yeah, I had a uniform password there that I've used many places. Not anymore!
Thanks for the heads up on EA. I hadn't considered that I would have an account there. Looks like it was tied to EA Sports Active 2. And yeah, I had a uniform password there that I've used many places. Not anymore!
Last edited by Michael Corvin; 01-14-12 at 03:01 PM.



