Feeds

Account pretexters plague Xbox Live

Account thieves numerous and brazen

Using blade systems to cut costs and sharpen efficiencies

When Kevin Finisterre got his virtual guns handed to him in an online game of Halo 2 last Thursday, he called his opponents on their none-too-subtle hacks that skewed the game in their favour and turned the battle into a rout.

His opponents - who rarely died while racking up nearly 100 kills on Finisterre's team - didn't take the accusations well. Among a tirade of name-calling, one player threatened to steal his account, the security researcher told SecurityFocus.

Finisterre did not put much store in the threat until the next day, when he found his girlfriend's account - which he had been using the day before - kicked off the system with a message that someone else was using her gamer tag on Microsoft's service, Xbox Live. Finisterre confirmed that he could no longer log onto the service, and a message on the Account Management page indicated that the account had been suspended.

After more than a half dozen calls to the support staff of XBox Live, which Halo 2 uses to authenticate players, the status of the account is still in limbo.

"There has been no real explanation why we have been banned," Finisterre said. "But it is odd that a day after they threatened to steal the account, someone else is in control."

The ban, originally for two days but now extended apparently indefinitely, is a symptom of account stealing, a tactic used by an up-and-coming breed of gamers that take losing as an affront and hack online game systems to give themselves an overpowering advantage. Research by both Finisterre and SecurityFocus has turned up more than a dozen complaints on online forums of Xbox Live accounts being stolen. And support people that Finisterre spoke with said that a handful of other incidents had happened on the same day.

The players that have stolen accounts are not shy about their activities. Several clans - the teams of players that have banded together to play first-person shooter games - have boasted online about their ability to steal accounts.

"We here at Infamous steal at least 10 accounts a day depending on there (sic) levels," claimed a site belonging to Clan Infamous, which bills itself as "the best account stealing + boosting clan" in Halo 2. "If you talk s**t we will mod on your account until it is banned. If the levels on it are good, we will use the Credit Card on your account to then change the gamer tag."

SecurityFocus made several attempts to contact members of the clan, but without success.

The clan's website, however, does detail the method its members use to steal accounts. Rather than hacking computer servers, the clan's account stealers claim to rely on social engineering to convince support personnel at Microsoft - and its subsidiary Bungie Studios, the creator of the Halo game series - to help the attackers take control of the accounts. To do so, the players spin a story about something going wrong with their account - from a crashed box to a sibling changing the password - and ask for help "recovering" the data.

"You call 1-800-4my-xbox, pretend to be that person, make up a story about how your little brother put in the information on the account and it was all fake," stated the Clan Infamous website. "You might get one little piece of information per call, but then you keep calling and keep calling, every time getting a little bit more information...once you have enough information you can get the password (and) the Windows Live ID reset."

Account hijacking in online games is nothing new. Online gamers have frequently been the targets of password-stealing Trojan horse programs that grab credentials so data thieves can break into a victim's accounts. In December, Chinese authorities arrested a 44-member ring of thieves that had mined stolen accounts for virtual goods to sell online.

In the latest case, grabbing the accounts gives that attackers fodder to boost their own rankings in the Halo 2 grading system. Halo 2 is not the only game plagued by the issues. Victims have also complained about losing accounts for Microsoft's Gears of War and Sega's Phantasy Star Online - the latter a massively multiplayer online role-playing game whose accounts can be mined for virtual items.

Boost IT visibility and business value

More from The Register

next story
Secure microkernel that uses maths to be 'bug free' goes open source
Hacker-repelling, drone-protecting code will soon be yours to tweak as you see fit
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
Four fake Google haxbots hit YOUR WEBSITE every day
Goog the perfect ruse to slip into SEO orfice
Putin: Crack Tor for me and I'll make you a MILLIONAIRE
Russian Interior Ministry offers big pile o' roubles for busting pro-privacy browser
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Securing Web Applications Made Simple and Scalable
Learn how automated security testing can provide a simple and scalable way to protect your web applications.