Feeds

Account pretexters plague Xbox Live

Account thieves numerous and brazen

Securing Web Applications Made Simple and Scalable

When Kevin Finisterre got his virtual guns handed to him in an online game of Halo 2 last Thursday, he called his opponents on their none-too-subtle hacks that skewed the game in their favour and turned the battle into a rout.

His opponents - who rarely died while racking up nearly 100 kills on Finisterre's team - didn't take the accusations well. Among a tirade of name-calling, one player threatened to steal his account, the security researcher told SecurityFocus.

Finisterre did not put much store in the threat until the next day, when he found his girlfriend's account - which he had been using the day before - kicked off the system with a message that someone else was using her gamer tag on Microsoft's service, Xbox Live. Finisterre confirmed that he could no longer log onto the service, and a message on the Account Management page indicated that the account had been suspended.

After more than a half dozen calls to the support staff of XBox Live, which Halo 2 uses to authenticate players, the status of the account is still in limbo.

"There has been no real explanation why we have been banned," Finisterre said. "But it is odd that a day after they threatened to steal the account, someone else is in control."

The ban, originally for two days but now extended apparently indefinitely, is a symptom of account stealing, a tactic used by an up-and-coming breed of gamers that take losing as an affront and hack online game systems to give themselves an overpowering advantage. Research by both Finisterre and SecurityFocus has turned up more than a dozen complaints on online forums of Xbox Live accounts being stolen. And support people that Finisterre spoke with said that a handful of other incidents had happened on the same day.

The players that have stolen accounts are not shy about their activities. Several clans - the teams of players that have banded together to play first-person shooter games - have boasted online about their ability to steal accounts.

"We here at Infamous steal at least 10 accounts a day depending on there (sic) levels," claimed a site belonging to Clan Infamous, which bills itself as "the best account stealing + boosting clan" in Halo 2. "If you talk s**t we will mod on your account until it is banned. If the levels on it are good, we will use the Credit Card on your account to then change the gamer tag."

SecurityFocus made several attempts to contact members of the clan, but without success.

The clan's website, however, does detail the method its members use to steal accounts. Rather than hacking computer servers, the clan's account stealers claim to rely on social engineering to convince support personnel at Microsoft - and its subsidiary Bungie Studios, the creator of the Halo game series - to help the attackers take control of the accounts. To do so, the players spin a story about something going wrong with their account - from a crashed box to a sibling changing the password - and ask for help "recovering" the data.

"You call 1-800-4my-xbox, pretend to be that person, make up a story about how your little brother put in the information on the account and it was all fake," stated the Clan Infamous website. "You might get one little piece of information per call, but then you keep calling and keep calling, every time getting a little bit more information...once you have enough information you can get the password (and) the Windows Live ID reset."

Account hijacking in online games is nothing new. Online gamers have frequently been the targets of password-stealing Trojan horse programs that grab credentials so data thieves can break into a victim's accounts. In December, Chinese authorities arrested a 44-member ring of thieves that had mined stolen accounts for virtual goods to sell online.

In the latest case, grabbing the accounts gives that attackers fodder to boost their own rankings in the Halo 2 grading system. Halo 2 is not the only game plagued by the issues. Victims have also complained about losing accounts for Microsoft's Gears of War and Sega's Phantasy Star Online - the latter a massively multiplayer online role-playing game whose accounts can be mined for virtual items.

Mobile application security vulnerability report

More from The Register

next story
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
NUDE SNAPS AGENCY: NSA bods love 'showing off your saucy selfies'
Swapping other people's sexts is a fringe benefit, says Snowden
Own a Cisco modem or wireless gateway? It might be owned by someone else, too
Remote code exec in HTTP server hands kit to bad guys
British data cops: We need greater powers and more money
You want data butt kicking, we need bigger boots - ICO
Crooks fling banking Trojan at Japanese smut site fans
Wait - they're doing online banking with an unpatched Windows PC?
NIST told to grow a pair and kick NSA to the curb
Lrn2crypto, oversight panel tells US govt's algorithm bods
prev story

Whitepapers

Reducing security risks from open source software
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.