Windows Live may be a vulnerability for Xbox Live users
In continuation with the ongoing investigation regarding suspicious activity on the accounts of Xbox Live users, some gamers are taking matters into their own hands. Jason Coutee, a network infrastructure manager who had his Xbox Live account hacked decided to look into the issue himself after Xbox Live customer service failed to be of much help.
After Coutee had realized that his credit card had been charged with a purchase of 8000 Microsoft Points, he called the Xbox Live support desk only to find out that another transaction for an Xbox Live Family Pack was in the middle of being processed. Coutee canceled the purchase and customer service offered him the standard 30 day account freeze in order to investigate.
Coutee researched potential account vulnerabilities and came away with a possible link to Microsoft’s Windows Live ID system. Hackers can feasibly gather a list of gamertags from any Xbox Live multiplayer game and enter each one on Google. Certain social networking sites may turn up in the search with a valid e-mail address attached to that gamertag. The hackers would then check that e-mail on the Windows Live login page. If the hacker gets the error message, “account is invalid”, the user may have updated their information. However if the error message, “password is wrong” comes up, the hacker has found a valid ID and simply needs to figure out the password.