![]() |
|
|
#1 (permalink) |
|
Ex-BadHumor Man
Join Date: May 2002
Location: New Jersey, USA
|
XBox live hacked and my friends credit card # swiped?
My best friend just told me his kids Live account was hacked. It got his password and the credit card info he used to sign up. They are still fighting to get the stolen charges erased. WTF?
|
|
|
|
|
|
#2 (permalink) |
|
Nuked for Morbid
Join Date: Aug 2004
Location: Savannah,GA
|
They know for a fact that it was hacked from XBL and now say a purchase from amazon or some subscription to a pornsite? Maybe some part time kid at the local movie rental place decided he needed some extra money so when your friend rented a movie and all his info came up the kid just wrote it down and went to town with it.
I'm just sayin'....
__________________
"We better win the F**king emmy for this this year or I swear to god..." Ronald D. Moore My DVD Collection |
|
|
|
|
|
#3 (permalink) |
|
Producer/Admin
NSFW Off 'the list' Join Date: Jul 2001
Location: Sacto, Ca --Near Galt, home of LeVar Burton
|
Yeah...is that really even possible?
More likely, if it was from the xbox itself, that it was done locally, at the machine, by, like a friend. ![]()
__________________
The Order of the Zombie. The world's greatest zombie culture website. "Ph'nglui mglw'nafh Cthulhu R'lyeh wagn'nagl dominos" In his house in R'lyeh, dead Cthulhu waits for the pizza delivery guy. |
|
|
|
|
|
#5 (permalink) | |
|
It's Good to Play Together
Join Date: Oct 2001
Location: NJ, USA
|
Quote:
More likely the user voluntarily gave up their Live account info (i.e. phishing email), assuming the console was not stolen.
__________________
For every shadow, no matter how deep, is threatened by morning light. |
|
|
|
|
|
|
#7 (permalink) |
|
Actor
Join Date: Aug 2003
Location: canada
|
I know some users have the resources to hack the console to enable game cheats in XBL, but thats all I've seen out of the ordinary.
I hope your friend is able to sue MS for millions!
__________________
DVD, HD DVD & BD Collection Finished supporting High-Def. Time for Blu to go mainstream. |
|
|
|
|
|
#8 (permalink) |
|
Nuked for Morbid
Join Date: Aug 2004
Location: Savannah,GA
|
I know one thing that your friend might want to look into. If there kids ever goes to a friends house and recovers there gamertag on that friends 360 they have to go through a process that requires them to put in the email address associated with the account and a password. Now after the password is typed in it asks if you want to save the password. If they put in YES then that would let whos ever 360 that is recover that gamer tag whenever they wanted and would also give them access to all of the account info. Given that that gamertag is xbox live enabled and it has a credit card number associated with it of course.
__________________
"We better win the F**king emmy for this this year or I swear to god..." Ronald D. Moore My DVD Collection |
|
|
|
|
|
#9 (permalink) | |
|
Ex-BadHumor Man
Join Date: May 2002
Location: New Jersey, USA
|
Quote:
|
|
|
|
|
|
|
#10 (permalink) |
|
Actor
Join Date: Jun 2002
Location: "Vyenna", VA
|
That sucks for your friend Iggy. I would suggest that they dispute the charges with the credit card company for the amount given to MS. Even if MS doesn't want to credit it back, your friend should not have to pay it. You can tell them to call their credit card company and say they tried to reason with MS and were unsuccessful. I have found the credit card companies are a lot more effective at getting the money taken back than retailers are sometimes.
__________________
HOOK'EM!!! UT LONGHORNS - National Champs 2005-2006!!! http://ganthc.youaremighty.com |
|
|
|
|
|
#11 (permalink) |
|
It's Good to Play Together
Join Date: Oct 2001
Location: NJ, USA
|
It does suck but there are a couple of things to keep in mind:
1. There is no realistic way to hack or steal an XBOX Live account password without the user somehow compromising it. Some examples of this might be: * User voluntarily enters their XBOX Live username/password in a phishing/scam email that appears to be coming from XBOX.COM but if looked at closely is actually from a rogue website. This is also usually how identity theft happens, as well as stolen Steam accounts. * User enters their XBOX Live username/password in friend's console, and saves the information there. Their friend may then compromise the password in any of these ways alos. * User's password sucks. An example of this is a person with gamertag "Freddy" and password "freddy". Might be convenient to remember, but it is also easily guessed. It is always good to use numbers in your password as well as words that will not easily guessed, with a length of ~8 characters minimum to be immune to brute force attacks. 2. The person who hijacked the account essentially has permanent free copies of the XBOX Live Arcade games and DLC he bought on his XBOX 360 hard drive, wherever that XBOX 360 is located. However, these games and DLC are also permanently stored in the original user's XBOX Live account. So this person's son's account now has access to all of these games bought. If the charge is disputed, Microsoft is going to have to go through the person's account and remove the DRM license for all games claimed to not be downloaded by the original user otherwise the son will have free access to all of the games bought by the other person. Note that Microsoft keeps track of the IP address of all download purchases, so they will likely not refund the money if the content was in actuality bought by the son in his own house and he is using the theft as an excuse -which is of course a possibility Microsoft must investigate. 3. The whole Zune points thing baffles me. As far as I know any Zune points bought with the account are deposited directly into the account. While that person could then buy Zune songs, Zune DRM is setup that it requires online re-authorization of songs at certain points (unlike 360 DRM) I believe. So while those downloaded songs might temporarily work, once the account is recovered I believe they will cease working so buying them would be pointless in the first place. 4. Everytime Microsoft points are purchased, Microsoft immediately notifies the person via the gamertag-associated email how many points were purchased and on what date/time they were purchased. Therefore this person should have been receiving emails every time the thief bought points, as he claims his email address remained intact for the account. This should have immediately prompted him that his account was hijacked and if he was more cogent he probably could have prevented the said damage earlier. Just some points to keep in mind. There is no real reliable way to "intercept" or "hack" a 360 or Steam password through the internet. Some sort of user error is generally involved whether it is falling for a scam email or using a weak password, where the user voluntarily gives up their password to the thief unknowingly or simply does not use a good password to protect their account in the first place.
__________________
For every shadow, no matter how deep, is threatened by morning light. Last edited by Ruined : 05-05-2008 at 04:38 PM. |
|
|
|
|
|
#12 (permalink) | |
|
Ex-BadHumor Man
Join Date: May 2002
Location: New Jersey, USA
|
From my friend:
Quote:
![]() |
|
|
|
|
|
|
#13 (permalink) |
|
Actor
Join Date: May 2001
Location: Toronto, ON Canada
|
How old is Albert?
Unless he's a pre-teen, my money's on him not telling his dad the full story. Granted, I don't know this kid or his family, but I have a hell of an easier time believing that some teenage kid was irresonsible with his account than that someone hacked his Xbox. KM
__________________
Blog, blog, bo blog. Banana, fana, fo flog. Me, my, mo mlog. Blog! DVD Profiler - The most features. The largest database. User-created plugins. Simply the best. |
|
|
|
|
|
#14 (permalink) |
|
Nuked for Morbid
Join Date: Aug 2004
Location: Savannah,GA
|
Yeah from that last response from your friend Iggy is sounds like he's trying to blame someone else for a mistake that took place with either him or his son. Don't know whys he's including the bungie site in the response. Did they buy something from them too??
It's too bad something like this has to happen but I'm betting that Astrakan is pretty close to the bullseye. When kids know they have screwed the pooch they are more willing to keep there mouths shut and rather than tell the truth let the adults start drawing conclusions and hope those conclusions go in a direction that they aren't standing.
__________________
"We better win the F**king emmy for this this year or I swear to god..." Ronald D. Moore My DVD Collection |
|
|
|
|
|
#15 (permalink) |
|
Producer/Admin
NSFW Off 'the list' Join Date: Jul 2001
Location: Sacto, Ca --Near Galt, home of LeVar Burton
|
Something is fishy in this story Iggy. I doubt it is actually possible to hack into a 360 remotely and steal that information.
__________________
The Order of the Zombie. The world's greatest zombie culture website. "Ph'nglui mglw'nafh Cthulhu R'lyeh wagn'nagl dominos" In his house in R'lyeh, dead Cthulhu waits for the pizza delivery guy. |
|
|
|
|
|
#16 (permalink) |
|
Ex-BadHumor Man
Join Date: May 2002
Location: New Jersey, USA
|
My friend is pretty pissed about all this so I'm going to drop it for now. However it happened, happened. I kinda feel bad for bringing it up on this forum too so if you fellas don't mind, I'm going to bail on posting any more replies.
|
|
|
|
|
|
#17 (permalink) | |
|
It's Good to Play Together
Join Date: Oct 2001
Location: NJ, USA
|
Quote:
99% chance it was one of the things in my above post.
__________________
For every shadow, no matter how deep, is threatened by morning light. |
|
|
|
|
|
|
#18 (permalink) |
|
Producer/Admin
NSFW Off 'the list' Join Date: Jul 2001
Location: Sacto, Ca --Near Galt, home of LeVar Burton
|
And so the guy gets pissed and doesn't want to talk about it anymore? Heh, he wont listen to reason and he doesn't want to think about any other possibilities beyond mysterious hackers.
Sounds like denial to me. I bet there's some other problem underneath all this. Likely it's none of our business, but that doesn't mean people should think their 360's are in danger of this sort of thing happening.
__________________
The Order of the Zombie. The world's greatest zombie culture website. "Ph'nglui mglw'nafh Cthulhu R'lyeh wagn'nagl dominos" In his house in R'lyeh, dead Cthulhu waits for the pizza delivery guy. |
|
|
|
|
|
#19 (permalink) | |
|
Ex-BadHumor Man
Join Date: May 2002
Location: New Jersey, USA
|
Quote:
Hey, I was worried I may have been told of a 'problem' with Xbox Live and wanted to report it to you folks. That's all. If it's completely false in your and everyone elses eyes...cool. I apologize and shouldn't have posted it to begin with. Seriously, sorry I brought the whole thing up. Feel free to delete the thread too as it may cause unnecessary concerns for those that frequent these boards. I don't want to be responsible for that as well as pushing a sensitive subject onto the one few real life friends I have. ![]() |
|
|
|
|
|
|
#20 (permalink) |
|
Producer/Admin
NSFW Off 'the list' Join Date: Jul 2001
Location: Sacto, Ca --Near Galt, home of LeVar Burton
|
Ok, that's fine.
Don't get upset with us though, YOU brought it up, we're just responding to your inquiry --that MS isn't handling the situation well in refunding charges; we're pointing out that MS probably isn't responsible for this in the first place. ![]()
__________________
The Order of the Zombie. The world's greatest zombie culture website. "Ph'nglui mglw'nafh Cthulhu R'lyeh wagn'nagl dominos" In his house in R'lyeh, dead Cthulhu waits for the pizza delivery guy. |
|
|
|
|
|
#22 (permalink) |
|
Producer/Admin
NSFW Off 'the list' Join Date: Jul 2001
Location: Sacto, Ca --Near Galt, home of LeVar Burton
|
Diggity
![]()
__________________
The Order of the Zombie. The world's greatest zombie culture website. "Ph'nglui mglw'nafh Cthulhu R'lyeh wagn'nagl dominos" In his house in R'lyeh, dead Cthulhu waits for the pizza delivery guy. |
|
|
|
|
|
#23 (permalink) |
|
Actor
Join Date: Jun 2005
|
There was an article on ZDNet dated March 20, 2007 that outlined something pretty similar to this happening. A follow up article states that Microsoft denied the hack and said it was some "social engineering attack." Posts following both articles from people who say that they were hacked, and others saying it's not possible. Doing a Google search will get you the articles, but I'm not going to link to them because one of them outlines how to supposedly hack an XBox Live account.
|
|
|
|
|
|
#24 (permalink) | |
|
Actor
Join Date: Jun 2002
Location: "Vyenna", VA
|
Quote:
__________________
HOOK'EM!!! UT LONGHORNS - National Champs 2005-2006!!! http://ganthc.youaremighty.com |
|
|
|
|
|
|
#25 (permalink) | |
|
It's Good to Play Together
Join Date: Oct 2001
Location: NJ, USA
|
Quote:
I think most have the false idea of scary hackers busting open their accounts from watching movies like "Hackers" where the main characters just pull up a terminal and start breaking into people's accounts through secret methods - that is pure fiction and is a fruitless endendeavor. Real hacking of a single account could take weeks or months, and by the time you got the password not only would you have gotten caught by your millions of failed attempts, but you probably could have easily captured 100 accounts in the same time by phishing/social engineering techniques - bulk send emails with fake websites that look like the real deal. To have someone actually hack these days without essentially having the user voluntarily give up their information is very, very rare.
__________________
For every shadow, no matter how deep, is threatened by morning light. Last edited by Ruined : 05-07-2008 at 02:44 PM. |
|
|
|
|
|
|
#26 (permalink) |
|
Producer/Admin
NSFW Off 'the list' Join Date: Jul 2001
Location: Sacto, Ca --Near Galt, home of LeVar Burton
|
You would have to be a massive target, that's for sure.
And even yet, I doubt a "hacker" could get access to the credit card information remotely.
__________________
The Order of the Zombie. The world's greatest zombie culture website. "Ph'nglui mglw'nafh Cthulhu R'lyeh wagn'nagl dominos" In his house in R'lyeh, dead Cthulhu waits for the pizza delivery guy. |
|
|
|