Re: [Full-disclosure] Xbox live accounts are being stolen (update)

2008-04-01 Thread blah
I'd like to introduce you to a new friend you haven't met before:

http://images.jupiterimages.com/common/detail/80/16/22421680.jpg

"march 26th 2008 I been talking to Xbox for two weeks now its march 31st "

Hacked 3/26.  Now 3/31.  2 weeks?

Here:
http://www.amazon.com/Subtraction-Flash-Cards-Pack-54/dp/0307249522/ref=pd_bbs_sr_1?ie=UTF8&s=books&qid=1207073496&sr=8-1

All of that aside, hope you get things restored.

2008/3/31 Xavier lassiter <[EMAIL PROTECTED]>:
>
>
> Hi My Name Is Xavier And You said to send you any info on Hacked Xbox live
> accounts just like to tell you my account was also Hacked since Wednesday
> march 26th 2008 I been talking to Xbox for two weeks now its march 31st well
> me and two of my friends accounts got stolen by my friend giving me this web
> site for free Microsoft Points like (Excuse me for my langue) Like a Fucking
> Dumb ass I went to the web site I looks just like a Xbox web site here is a
> link www.freempz.110mb.com when you look at the website it looks so real so
> I put in my e-mail address and password just like Xbox.com and it signed me
> in nothing happened so I got of my computer and went on my Xbox and a few
> minutes later I get a friend request from another person it was my friend
> and he told me not to go to that web site because they took his information
> when he told me that I went to change my information it was to late the
> email was changed and the password so what I did was I was going to stay on
> but it kicked me of I did not say I singed off but I tried to sign back in
> it said that my account was recovered so I called Xbox im going to try to
> remember everything ok I called them and I told them my account was stolen
> they did not know what the hell I was talking about after I spent  Five
> minutes explaining to them that my account was stolen so they man I was
> talking to asked me for the gamertag Xman1231 they they asked me what was
> the address oh and this is on the first day and he asked me what was my
> secret password what was my pets name first I said I don't have a pet and I
> told him that I put my favorite food and I told  him that everything was
> changed my address name last name everything they that's when the guy got
> what the hell I was talking about it would been good if I wrote there names
> down but I did not let me get back the subject at hand ok then they put me
> on hold and then they put me on hold again and that's when they put me in
> contact with the supervisor Matt I talked to him and everything and he said
> that he can suspend the account oh while this was happening they puck ass
> hacker was on my account but the I told they guy everything I told the man I
> was talking to that was they supervisor told me they will be in contact with
> me at the end of this week or next week in my mind I know there not going to
> call but they supervisor told me that I can make another account while I
> wait for there call he gave me a reference number and I got off the phone
> and I made a new account and I was thinking that can they just remove the
> email address and pass word that's there and add a new one but it was to
> late to call I apologize for my writing and thank you for reading this
> e-mail. if any question to asked you can contact me at my e-mail address
> [EMAIL PROTECTED]
>
> 
> OMG, Sweet deal for Yahoo! users/friends: Get A Month of Blockbuster Total
> Access, No Cost. W00t
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>
<>___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Xbox live accounts are being stolen (update)

2008-04-01 Thread Valdis . Kletnieks
On Mon, 31 Mar 2008 16:58:12 PDT, Xavier lassiter said:
> info on Hacked Xbox live accounts just like to tell you my account was also 
> Hacked since Wednesday march 26th 2008 I been talking to Xbox for two weeks 
> now

So you've been talking to them for two weeks about something that happened
less than a week ago.

Moral: If you don't even know what day of the week it is, you probably shouldn't
be using the Internet.


pgpF457v24sQZ.pgp
Description: PGP signature
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] Xbox live accounts are being stolen (update)

2008-04-01 Thread Xavier lassiter
Hi My Name Is Xavier And You said to send you any 
info on Hacked Xbox live accounts just like to tell you my account was also 
Hacked since Wednesday march 26th 2008 I been talking to Xbox for two weeks now 
its march 31st well me and two of my friends accounts got stolen by my friend 
giving me this web site for free Microsoft Points like (Excuse me for my 
langue) 
Like a Fucking Dumb ass I went to the web site I looks just like a Xbox web 
site 
here is a link www.freempz.110mb.com when you look at the website it looks so 
real so I put in my e-mail address and password just like Xbox.com and it 
signed me in nothing happened so I got of my computer and went on my Xbox and a 
few minutes later I get a friend request from another person it was my friend 
and he told me not to go to that web site because they took his information 
when he told me that I went to change my information it was to late the email 
was changed and the password so what I did was I was going to stay on but it 
kicked me of I did not say I singed off but I tried to sign back in it said 
that my account was recovered so I called Xbox im going to try to remember 
everything ok I called them and I told them my account was stolen they did not 
know what the hell I was talking about after I spent  Five minutes explaining 
to them that my account was stolen so they man I was talking to asked me for 
the gamertag Xman1231 they they asked me
 what was the address oh and this is on the first day and he asked me what was 
my secret password what was my pets name first I said I don’t have a pet and I 
told him that I put my favorite food and I told  him that everything was 
changed my address name last name everything they that’s when the guy got what 
the hell I was talking about it would been good if I wrote there names down but 
I did not let me get back the subject at hand ok then they put me on hold and 
then they put me on hold again and that’s when they put me in contact with the 
supervisor Matt I talked to him and everything and he said that he can suspend 
the account oh while this was happening they puck ass hacker was on my account 
but the I told they guy everything I told the man I was talking to that was 
they supervisor told me they will be in contact with me at the end of this week 
or next week in my mind I know there not going to call but they supervisor told 
me that I can make
 another account while I wait for there call he gave me a reference number and 
I got off the phone and I made a new account and I was thinking that can they 
just remove the email address and pass word that's there and add a new one but 
it was to late to call I apologize for my writing and thank you for reading 
this e-mail. if any question to asked you can contact me at my e-mail address  
[EMAIL PROTECTED]  





  

You rock. That's why Blockbuster's offering you one month of Blockbuster Total 
Access, No Cost.  
http://tc.deals.yahoo.com/tc/blockbuster/text5.com___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Xbox live accounts are being stolen (is the training working?)

2007-08-09 Thread Scott Hirnle
Hi Kevin,

For Hardware calls, we don't verify the same information as we do on Live 
calls.  The reason for this is because some people (in fact many people) who 
call into the hardware queue are not even Xbox Live customers.  Therefore, they 
don't have the same data to verify against and as a result, our agents don't 
have visibility into it and our entitlement process is different for each line 
of business.

Scott

-Original Message-
From: Kevin Finisterre (lists) [mailto:[EMAIL PROTECTED]
Sent: Thursday, August 09, 2007 8:21 AM
To: full-disclosure@lists.grok.org.uk
Cc: Ashley Wilson
Subject: Re: [Full-disclosure] Xbox live accounts are being stolen (is the 
training working?)

I find it kind of ironic that my Xbox broke last night after an
update and I am now on the phone with a Xbox live representative.
After the whole stolen accounts fiasco I remember calling in an
having techs flat out refuse to work with you until you verified your
full name, address, phone number, gamer tag, xbox console serial
number and email address used on the account.

I just finished talking to a tech about my xbox after only giving her
my First name, Address and Phone number (I couldn't give my serial
because my xbox is not near me). After asking to speak with her
supervisor about some other issues I asked him to remind me of what
information should be verified prior to speaking with someone. He
told me that "First and Last name, Address, Phone Number, Email and
Serial Number had to be verified and if any one item was missing or
not available to be verified via other means" then they have been
instructed to not speak with you. I asked him what happened with
Gamertag verification and he stated that only applied to Xbox live
issues and it was not verified for Xbox console issue. I didn't
bother telling him the tech that passed me on to him didn't quite
verify all the data, I simply said thanks and hung up.

At the very least this may help illustrate that no amount of training
can fully curb human behavior. The tech I talked to had no problem
ignoring the lack of serial number and email address on my account.
So Ashley... yeah I guess it is entirely possible that accounts *can*
still be stolen. Hell for all I know it could be the same kids since
no one was ever produced as the culprit of the previous caper.

Good luck!
-KF



___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] Xbox live accounts are being stolen (is thetraining working?)

2007-08-09 Thread Jay
This list is about Full Disclosure, exploits vulnerabilities etc.

Noone gives a rat arse whether some whiny n00bz cant play Halo.

Find another list to gripe about customer service issues.

Futhermore there isnt any proof provided that ppl didnt get compromised by 
getting phished themselves. I'm sure the same mindless twitz that are whinning 
here have to have a myspace account spilling all their personal information 
anyway.

Jay

- Original Message -
From: Kevin Finisterre (lists) [mailto:[EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Cc: full-disclosure@lists.grok.org.uk,[EMAIL PROTECTED]
Sent: Thu, 9 Aug 2007 11:44:50 -0400
Subject: Re: [Full-disclosure] Xbox live accounts are being stolen (is 
thetraining working?)

Which is fine... I was more than anything pointing out that this
individual still chose to ignore company policy. And being
stereotypical it sounded like the *same* call center I called into
before, so if she is doing it I am sure others are as well. Hopefully
she had minimal access to personal data.

And I guess I was also highlighting the fact that no one was really
paraded around for us to tar and feather for stealing accounts. Did
you guys actually catch someone or did they get off Scott free?
This issue had honestly been out of my mind for some time, I was
quite surprised to hear of it happening again.
-KF

On Aug 9, 2007, at 11:26 AM, Scott Hirnle wrote:

> Hi Kevin,
>
> For Hardware calls, we don't verify the same information as we do
> on Live calls.  The reason for this is because some people (in fact
> many people) who call into the hardware queue are not even Xbox
> Live customers.  Therefore, they don't have the same data to verify
> against and as a result, our agents don't have visibility into it
> and our entitlement process is different for each line of business.
>
> Scott
>
> -Original Message-
> From: Kevin Finisterre (lists) [mailto:[EMAIL PROTECTED]
> Sent: Thursday, August 09, 2007 8:21 AM
> To: full-disclosure@lists.grok.org.uk
> Cc: Ashley Wilson
> Subject: Re: [Full-disclosure] Xbox live accounts are being stolen
> (is the training working?)
>
> I find it kind of ironic that my Xbox broke last night after an
> update and I am now on the phone with a Xbox live representative.
> After the whole stolen accounts fiasco I remember calling in an
> having techs flat out refuse to work with you until you verified your
> full name, address, phone number, gamer tag, xbox console serial
> number and email address used on the account.
>
> I just finished talking to a tech about my xbox after only giving her
> my First name, Address and Phone number (I couldn't give my serial
> because my xbox is not near me). After asking to speak with her
> supervisor about some other issues I asked him to remind me of what
> information should be verified prior to speaking with someone. He
> told me that "First and Last name, Address, Phone Number, Email and
> Serial Number had to be verified and if any one item was missing or
> not available to be verified via other means" then they have been
> instructed to not speak with you. I asked him what happened with
> Gamertag verification and he stated that only applied to Xbox live
> issues and it was not verified for Xbox console issue. I didn't
> bother telling him the tech that passed me on to him didn't quite
> verify all the data, I simply said thanks and hung up.
>
> At the very least this may help illustrate that no amount of training
> can fully curb human behavior. The tech I talked to had no problem
> ignoring the lack of serial number and email address on my account.
> So Ashley... yeah I guess it is entirely possible that accounts *can*
> still be stolen. Hell for all I know it could be the same kids since
> no one was ever produced as the culprit of the previous caper.
>
> Good luck!
> -KF
>
>
>

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Xbox live accounts are being stolen (is thetraining working?)

2007-08-09 Thread Kevin Finisterre (lists)

On Aug 9, 2007, at 12:20 PM, Jay wrote:

> This list is about Full Disclosure, exploits vulnerabilities etc.
>
> Noone gives a rat arse whether some whiny n00bz cant play Halo.
>
> Find another list to gripe about customer service issues.

Fire up your inbox filter... gripe about your list issues elsewhere.  
I equally could give half a shit.

>
> Futhermore there isnt any proof provided that ppl didnt get  
> compromised by getting phished themselves. I'm sure the same  
> mindless twitz that are whinning here have to have a myspace  
> account spilling all their personal information anyway.

What part of my recorded conversations of an Xbox live employee  
divulging information involved the end user getting fished ya twit?  
Besides Microsoft owned up to it ... isn't that enough?


-KF

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] Xbox live accounts are being stolen (is the training working?)

2007-08-09 Thread Kevin Finisterre (lists)
Which is fine... I was more than anything pointing out that this  
individual still chose to ignore company policy. And being  
stereotypical it sounded like the *same* call center I called into  
before, so if she is doing it I am sure others are as well. Hopefully  
she had minimal access to personal data.

And I guess I was also highlighting the fact that no one was really  
paraded around for us to tar and feather for stealing accounts. Did  
you guys actually catch someone or did they get off Scott free?
This issue had honestly been out of my mind for some time, I was  
quite surprised to hear of it happening again.
-KF

On Aug 9, 2007, at 11:26 AM, Scott Hirnle wrote:

> Hi Kevin,
>
> For Hardware calls, we don't verify the same information as we do  
> on Live calls.  The reason for this is because some people (in fact  
> many people) who call into the hardware queue are not even Xbox  
> Live customers.  Therefore, they don't have the same data to verify  
> against and as a result, our agents don't have visibility into it  
> and our entitlement process is different for each line of business.
>
> Scott
>
> -Original Message-
> From: Kevin Finisterre (lists) [mailto:[EMAIL PROTECTED]
> Sent: Thursday, August 09, 2007 8:21 AM
> To: full-disclosure@lists.grok.org.uk
> Cc: Ashley Wilson
> Subject: Re: [Full-disclosure] Xbox live accounts are being stolen  
> (is the training working?)
>
> I find it kind of ironic that my Xbox broke last night after an
> update and I am now on the phone with a Xbox live representative.
> After the whole stolen accounts fiasco I remember calling in an
> having techs flat out refuse to work with you until you verified your
> full name, address, phone number, gamer tag, xbox console serial
> number and email address used on the account.
>
> I just finished talking to a tech about my xbox after only giving her
> my First name, Address and Phone number (I couldn't give my serial
> because my xbox is not near me). After asking to speak with her
> supervisor about some other issues I asked him to remind me of what
> information should be verified prior to speaking with someone. He
> told me that "First and Last name, Address, Phone Number, Email and
> Serial Number had to be verified and if any one item was missing or
> not available to be verified via other means" then they have been
> instructed to not speak with you. I asked him what happened with
> Gamertag verification and he stated that only applied to Xbox live
> issues and it was not verified for Xbox console issue. I didn't
> bother telling him the tech that passed me on to him didn't quite
> verify all the data, I simply said thanks and hung up.
>
> At the very least this may help illustrate that no amount of training
> can fully curb human behavior. The tech I talked to had no problem
> ignoring the lack of serial number and email address on my account.
> So Ashley... yeah I guess it is entirely possible that accounts *can*
> still be stolen. Hell for all I know it could be the same kids since
> no one was ever produced as the culprit of the previous caper.
>
> Good luck!
> -KF
>
>
>

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] Xbox live accounts are being stolen (is the training working?)

2007-08-09 Thread Kevin Finisterre (lists)
I find it kind of ironic that my Xbox broke last night after an  
update and I am now on the phone with a Xbox live representative.  
After the whole stolen accounts fiasco I remember calling in an  
having techs flat out refuse to work with you until you verified your  
full name, address, phone number, gamer tag, xbox console serial  
number and email address used on the account.

I just finished talking to a tech about my xbox after only giving her  
my First name, Address and Phone number (I couldn't give my serial  
because my xbox is not near me). After asking to speak with her  
supervisor about some other issues I asked him to remind me of what  
information should be verified prior to speaking with someone. He  
told me that "First and Last name, Address, Phone Number, Email and  
Serial Number had to be verified and if any one item was missing or  
not available to be verified via other means" then they have been  
instructed to not speak with you. I asked him what happened with  
Gamertag verification and he stated that only applied to Xbox live  
issues and it was not verified for Xbox console issue. I didn't  
bother telling him the tech that passed me on to him didn't quite  
verify all the data, I simply said thanks and hung up.

At the very least this may help illustrate that no amount of training  
can fully curb human behavior. The tech I talked to had no problem  
ignoring the lack of serial number and email address on my account.  
So Ashley... yeah I guess it is entirely possible that accounts *can*  
still be stolen. Hell for all I know it could be the same kids since  
no one was ever produced as the culprit of the previous caper.

Good luck!
-KF



___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] Xbox live accounts are being stolen

2007-08-08 Thread Jail Halvar
It was Halvar Flake.


On Tue, Aug 07, 2007 at 06:08:51PM -0300, Ashley Wilson wrote:
> Hey there,
> 
> I'm so very frustrated with Microsoft and went on a search to see if anyone
> else has had the same issue and low and behold, I came across you're article
> of sorts.
> 
> Its been over a month now, since I was hacked. I woke up on a Sunday
> morning, check my email as I do everyday. I had 4 emails from Microsoft
> stating I purchased 2 Microsoft points and a year subscription. As most
> people would, I panicked and wondered what kind of insane thing happened.
> When I turned on my Xbox and attempted to log into my account, I couldn't.
> My boyfriend shortly after that, recovered my account on the Xbox and we
> came to find out that my username had been changed, all my friends had been
> deleted off my list and my motto was changed to "LOL I got jacked."
> 
> I was furious to think someone could do such a thing. They not only stole my
> account but over 400 dollars was spent on my credit card.
> 
> I called Microsoft support shortly after that. I got the "run around."
> Transferred to one agent and then another. They basically accused me of
> giving out the information. I eventually got to speak to a supervisor, who
> assured me that everything would be taken care of. They even said they would
> catch the individual that did this and assured me a phone call in a few
> days, as they had to send in a full investigation the next day.
> 
> 3 weeks later and I was still waiting for a call.
> 
> I decided it was time for me to call them, since obviously I as a customer
> wasn't important to them. Again, the "run around." I spoke with again,
> another supervisor who informed me that they hadn't even sent out the
> investigation yet. He assured me that he would send it out that very day and
> I should receive a call within 3 days.
> 
> I sat home waiting to receive a call for 3 days.
> 
> Again, I never received a phone call.
> 
> By the 4th day, I called again.
> 
> Speaking with an agent who assured me, I will receive a call. "Its under
> investigation now, you have to wait for a phone call."
> 
> Now, 2 weeks later and I called again today.
> 
> I'm told that they attempted to call me today and I have to wait to speak
> with them because there is nothing they can do. I paid for a subscription
> that I am not getting to use and apparently won't be able to use. I'd also
> like to mention when he said they tried calling today, he said they left a
> voice mail message. I don't have voice mail, so I got concerned. Then he
> read "my phone number" It wasn't even my number and I had never heard the
> number in my life. Slightly odd, since I gave them my phone number the
> previous time I had called.
> 
> Now I'm suppose to receive a call this Thursday. We will see I won't
> hold my breathe.
> 
> I am so very frustrated that Microsoft as huge a cooperation as they are,
> doesn't even have the decency to call me or reimburse me for a 50 dollar
> Xbox live account.
> 
> I apologize for this longwinded email and I'm not even sure if you still
> care about this issue but I was quite overjoyed to see I wasn't alone.
> 
> Sincerely
> 
> Ashley Wilson

> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] Xbox live accounts are being stolen

2007-08-08 Thread Glenn.Everhart
When someone fraudulently charges your credit card you should immediately 
complain to the card issuer in writing so the charge can be reversed and
charged back to the merchant who accepted the fraudulent credentials. That is
one of the advantages of a credit card - the loss can be charged back, and
a merchant who accepts bogus information is liable if it turns out to be
fake. 

There is often a 60 day period to notify of this, so if you have not written
your card issuer before, don't delay. Some of the "wait..." tactics
can have the effect of your losing the right to get the purchase charged
back if you don't get the notice out in time.

As with any such messages, too, send with return receipt requested so you can
prove that you got the message sent and that it got to the bank. It is probably
ok to send two letters, one normal and one with return receipt, mentioning they
both exist, in case a mail room doesn't know how to handle one of them. That
is not malice, just human confusion, but it's easy to print out two letters and
might help especially if your time is now short.

Writing in like this does not mean the merchant can't make things right; it
just ensures the fraud claim gets known by the card issuer bank and that it
should not be treated as an ordinary charge on your card bill. It can also 
sometimes
get the merchant's attention since the bank will now be after the merchant to 
prove
the charge was not fraudulent...it's not just you vs. the company.

These kinds of cases are possibly harbingers of the future. Trusting some 
consumer owned
box as evidence of who he is is not foolproof. Bets on that being an issue with 
consumer
PCs, cell phones, etc.?

Glenn Everhart


-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] Behalf Of Kevin
Finisterre (lists)
Sent: Wednesday, August 08, 2007 9:34 AM
To: Ashley Wilson
Cc: Scott Hirnle; full-disclosure@lists.grok.org.uk
Subject: Re: [Full-disclosure] Xbox live accounts are being stolen


Hi Ashley... I can certainly understand your frustration. Although my  
account was "taken care of" and I was ultimately given some things to  
quiet me down, I never got an explanation of what *really* happened,  
I never got any information about who I could prosecute or anything  
like that. As you can see I had to be very vocal about the whole  
situation in order to get my issue taken care of and the process was  
quite lengthy, time consuming and frustrating, so good luck.

I have CC'd a gentleman from Microsoft that got me taken care of in  
the past. He should hopefully be able to help you out, no promises of  
course.

I think it would be fair of me to say really don't like Microsoft's  
"disclosure policy" under these circumstances.
-KF

On Aug 7, 2007, at 5:08 PM, Ashley Wilson wrote:

> Hey there,
>
> I'm so very frustrated with Microsoft and went on a search to see  
> if anyone else has had the same issue and low and behold, I came  
> across you're article of sorts.
>
> Its been over a month now, since I was hacked. I woke up on a  
> Sunday morning, check my email as I do everyday. I had 4 emails  
> from Microsoft stating I purchased 2 Microsoft points and a  
> year subscription. As most people would, I panicked and wondered  
> what kind of insane thing happened. When I turned on my Xbox and  
> attempted to log into my account, I couldn't. My boyfriend shortly  
> after that, recovered my account on the Xbox and we came to find  
> out that my username had been changed, all my friends had been  
> deleted off my list and my motto was changed to "LOL I got jacked."
>
> I was furious to think someone could do such a thing. They not only  
> stole my account but over 400 dollars was spent on my credit card.
>
> I called Microsoft support shortly after that. I got the "run  
> around." Transferred to one agent and then another. They basically  
> accused me of giving out the information. I eventually got to speak  
> to a supervisor, who assured me that everything would be taken care  
> of. They even said they would catch the individual that did this  
> and assured me a phone call in a few days, as they had to send in a  
> full investigation the next day.
>
> 3 weeks later and I was still waiting for a call.
>
> I decided it was time for me to call them, since obviously I as a  
> customer wasn't important to them. Again, the "run around." I spoke  
> with again, another supervisor who informed me that they hadn't  
> even sent out the investigation yet. He assured me that he would  
> send it out that very day and I should receive a call within 3 days.
>
> I sat home waiting to receive a call for 3 days.
>
> Again, I never received a phone call.
>
> By the 4th day, I call

Re: [Full-disclosure] Xbox live accounts are being stolen

2007-08-08 Thread Kevin Finisterre (lists)
Hi Ashley... I can certainly understand your frustration. Although my  
account was "taken care of" and I was ultimately given some things to  
quiet me down, I never got an explanation of what *really* happened,  
I never got any information about who I could prosecute or anything  
like that. As you can see I had to be very vocal about the whole  
situation in order to get my issue taken care of and the process was  
quite lengthy, time consuming and frustrating, so good luck.

I have CC'd a gentleman from Microsoft that got me taken care of in  
the past. He should hopefully be able to help you out, no promises of  
course.

I think it would be fair of me to say really don't like Microsoft's  
"disclosure policy" under these circumstances.
-KF

On Aug 7, 2007, at 5:08 PM, Ashley Wilson wrote:

> Hey there,
>
> I'm so very frustrated with Microsoft and went on a search to see  
> if anyone else has had the same issue and low and behold, I came  
> across you're article of sorts.
>
> Its been over a month now, since I was hacked. I woke up on a  
> Sunday morning, check my email as I do everyday. I had 4 emails  
> from Microsoft stating I purchased 2 Microsoft points and a  
> year subscription. As most people would, I panicked and wondered  
> what kind of insane thing happened. When I turned on my Xbox and  
> attempted to log into my account, I couldn't. My boyfriend shortly  
> after that, recovered my account on the Xbox and we came to find  
> out that my username had been changed, all my friends had been  
> deleted off my list and my motto was changed to "LOL I got jacked."
>
> I was furious to think someone could do such a thing. They not only  
> stole my account but over 400 dollars was spent on my credit card.
>
> I called Microsoft support shortly after that. I got the "run  
> around." Transferred to one agent and then another. They basically  
> accused me of giving out the information. I eventually got to speak  
> to a supervisor, who assured me that everything would be taken care  
> of. They even said they would catch the individual that did this  
> and assured me a phone call in a few days, as they had to send in a  
> full investigation the next day.
>
> 3 weeks later and I was still waiting for a call.
>
> I decided it was time for me to call them, since obviously I as a  
> customer wasn't important to them. Again, the "run around." I spoke  
> with again, another supervisor who informed me that they hadn't  
> even sent out the investigation yet. He assured me that he would  
> send it out that very day and I should receive a call within 3 days.
>
> I sat home waiting to receive a call for 3 days.
>
> Again, I never received a phone call.
>
> By the 4th day, I called again.
>
> Speaking with an agent who assured me, I will receive a call. "Its  
> under investigation now, you have to wait for a phone call."
>
> Now, 2 weeks later and I called again today.
>
> I'm told that they attempted to call me today and I have to wait to  
> speak with them because there is nothing they can do. I paid for a  
> subscription that I am not getting to use and apparently won't be  
> able to use. I'd also like to mention when he said they tried  
> calling today, he said they left a voice mail message. I don't have  
> voice mail, so I got concerned. Then he read "my phone number" It  
> wasn't even my number and I had never heard the number in my life.  
> Slightly odd, since I gave them my phone number the previous time I  
> had called.
>
> Now I'm suppose to receive a call this Thursday. We will see I  
> won't hold my breathe.
>
> I am so very frustrated that Microsoft as huge a cooperation as  
> they are, doesn't even have the decency to call me or reimburse me  
> for a 50 dollar Xbox live account.
>
> I apologize for this longwinded email and I'm not even sure if you  
> still care about this issue but I was quite overjoyed to see I  
> wasn't alone.
>
> Sincerely
>
> Ashley Wilson
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


[Full-disclosure] Xbox live accounts are being stolen

2007-08-08 Thread Ashley Wilson
Hey there,

I'm so very frustrated with Microsoft and went on a search to see if anyone
else has had the same issue and low and behold, I came across you're article
of sorts.

Its been over a month now, since I was hacked. I woke up on a Sunday
morning, check my email as I do everyday. I had 4 emails from Microsoft
stating I purchased 2 Microsoft points and a year subscription. As most
people would, I panicked and wondered what kind of insane thing happened.
When I turned on my Xbox and attempted to log into my account, I couldn't.
My boyfriend shortly after that, recovered my account on the Xbox and we
came to find out that my username had been changed, all my friends had been
deleted off my list and my motto was changed to "LOL I got jacked."

I was furious to think someone could do such a thing. They not only stole my
account but over 400 dollars was spent on my credit card.

I called Microsoft support shortly after that. I got the "run around."
Transferred to one agent and then another. They basically accused me of
giving out the information. I eventually got to speak to a supervisor, who
assured me that everything would be taken care of. They even said they would
catch the individual that did this and assured me a phone call in a few
days, as they had to send in a full investigation the next day.

3 weeks later and I was still waiting for a call.

I decided it was time for me to call them, since obviously I as a customer
wasn't important to them. Again, the "run around." I spoke with again,
another supervisor who informed me that they hadn't even sent out the
investigation yet. He assured me that he would send it out that very day and
I should receive a call within 3 days.

I sat home waiting to receive a call for 3 days.

Again, I never received a phone call.

By the 4th day, I called again.

Speaking with an agent who assured me, I will receive a call. "Its under
investigation now, you have to wait for a phone call."

Now, 2 weeks later and I called again today.

I'm told that they attempted to call me today and I have to wait to speak
with them because there is nothing they can do. I paid for a subscription
that I am not getting to use and apparently won't be able to use. I'd also
like to mention when he said they tried calling today, he said they left a
voice mail message. I don't have voice mail, so I got concerned. Then he
read "my phone number" It wasn't even my number and I had never heard the
number in my life. Slightly odd, since I gave them my phone number the
previous time I had called.

Now I'm suppose to receive a call this Thursday. We will see I won't
hold my breathe.

I am so very frustrated that Microsoft as huge a cooperation as they are,
doesn't even have the decency to call me or reimburse me for a 50 dollar
Xbox live account.

I apologize for this longwinded email and I'm not even sure if you still
care about this issue but I was quite overjoyed to see I wasn't alone.

Sincerely

Ashley Wilson
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Xbox live accounts are being stolen (update)

2007-03-19 Thread Kevin Finisterre (lists)
Since boatloads of people are asking me about this I figured I would  
just give an update here


Here is an exhaustive list of people experiencing the problem as well  
as a possible source of the account theft (Clan Infamous)


http://www.oinfamouso.moonfruit.com/

They claim to be pretexting Xbox live employees...

1-11-2007 (clan infamous is stealing accounts)(http://www.oinfam0uso.tk/ site 
frozen)
http://forums.xbox.com/10384176/ShowPost.aspx

1-27-2007 (The oiNFAMOUSo Clan)(Because they just find it so dignifying to 
* people over by stealing accounts.)
http://www.o8oballers.com/

?-??-2007 (clan home page of account stealers)
http://www.oinfamouso.moonfruit.com/
1.  Says "I'm Unjackable! my account is Invalid!"
2.  Same as above
3.  Talked so much shit to GoD and entire Clan!
4.  He talked shit with some people to CODY!
5.  Stole from clan LeGiT x Ownage
6.  Talked Shit to JuStCaLLMeFRESH
7.  its BxR RaMpAgE, also jacked JuStCaLLMeFRESH


2-20-2007
http://forums.xbox.com/10475598/ShowPost.aspx

12-12-2006
http://forums.xbox.com/8999275/ShowPost.aspx

2-28-2007 (account recovery used in a tournament)
http://forum.teamcompete.com/forum_posts.asp?TID=3485&PN=1

2-25-2007 (team booted for account recovery)
http://forum.teamcompete.com/forum_posts.asp?TID=3935

2-06-2007 (more talk about the team booted) 
http://forum.teamcompete.com/forum_posts.asp?TID=3599&PID=55974

3-12-2007 (SilentKilla Post)
http://forum.teamcompete.com/forum_posts.asp?TID=4110&PID=60103#60103

3-07-2007 (The FB Hacker Discovered)
http://www.youtube.com/watch?v=1QdG_xwkPH4

2-27-2007 (Bungie hacked rumors)
http://www.bungie.net/Forums/posts.aspx?postID=10180727

7-10-2006 (Steal accounts with Cain)
http://www.se7ensins.com/forums/bridging-help/18735-how-steal-accounts-cain.html

09-??-2006 (pro halo player account stolen)
http://newbc.blackcode.com/forum/index.php?t=msg&th=396&start=0&rid=0

03-11-2007 (gamer tag stolen)
http://forums.xbox.com/10873499/ShowPost.aspx

1-23-2007 (account stolen)
http://forums.xbox.com/10028940/ShowPost.aspx

12-18-2006 (someone is stealing gamer tags) 
http://forums.xbox.com/8938575/ShowPost.aspx

12-16-2006 (more on clan infamous)
http://forums.xbox.com/8908831/ShowPost.aspx 

12-08-2006 (more on clain inf)
http://forums.xbox.com/8736659/ShowPost.aspx
http://forums.xbox.com/8741323/ShowPost.aspx
12-15-2006 
http://forums.xbox.com/8872897/ShowPost.aspx

2-11-2007 (stolen account)
http://forums.xbox.com/10259201/ShowPost.aspx

2-16-2007 (stolen accounts)
http://forums.xbox.com/10387443/ShowPost.aspx

5-24-2006
http://forums.xbox.com/4510368/ShowPost.aspx


Need more? find em yourself... 

http://forums.xbox.com/search/SearchResults.aspx?q=stolen%20account&forum=&u=&PageIndex=3
http://forums.xbox.com/search/SearchResults.aspx?q=stolen+gamertag&forum=&u=



-KF

On Mar 17, 2007, at 5:21 PM, Kevin Finisterre (lists) wrote:


There have been rumor going around that Bungie.net was hacked and
that a portion of Xbox live has been taken over because of it. Some
folks are having their Microsoft points stolen and or points
purchased via their stolen gamer tag.

I just got off the phone with a Microsoft Tech for Xbox live that has
confirmed this to with me and they have stated that accounts are
being stolen and that "Hackers have control of Xbox live and there is
nothing we can do about it"

If anyone else has experienced their Xbox live account info being
stolen let me know. I am trying to archive as much info on this as
possible. During the conversations I have had with Xbox live support
I would certainly say that Microsoft  staff is more than negligent in
dealing with this issue especially with regard to the potential theft
of personal information.

-KF

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Xbox live accounts are being stolen

2007-03-18 Thread php0t

Is bungie.net's title originally 'Satisfying Your Mom Since 1991' ?
Google says, it should be "This One Goes To Eleven."

  If it's obvious or normal, discard this email.


___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] Xbox live accounts are being stolen

2007-03-17 Thread Kevin Finisterre (lists)
Here is someone on youtube with the same problem using a capture  
card to get the guy on video talking about it. He blatantly says he  
can steal any account on your xbox with just your IP address. One  
side of the conversation has been cut out but you can clearly hear  
the gentleman talking about stealing the account.

http://www.youtube.com/watch?v=1QdG_xwkPH4

"Your shit is getting jacked just so ya know"

-KF

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] Xbox live accounts are being stolen

2007-03-17 Thread Kevin Finisterre (lists)

Microsoft points are directly tied to $$$

2000 points is about the equivalent of $25 dollars.

Zune Market Place and Xbox live share the same system for points /  
dollars.

-KF

On Mar 17, 2007, at 8:49 PM, Peter Dawson wrote:


why ??

Is there not a secondary layer of economics for points ??  WoW and  
SL has virtual $$ being  bartered into real world value...


On 3/17/07, Jason Miller <[EMAIL PROTECTED]> wrote:
I'm sorry but I find this funny actually. :-P Seems Microsoft has a  
weakness.


On 3/17/07, Kevin Finisterre (lists) <[EMAIL PROTECTED]>  
wrote:

> There have been rumor going around that Bungie.net was hacked and
> that a portion of Xbox live has been taken over because of it. Some
> folks are having their Microsoft points stolen and or points
> purchased via their stolen gamer tag.
>
> I just got off the phone with a Microsoft Tech for Xbox live that  
has

> confirmed this to with me and they have stated that accounts are
> being stolen and that "Hackers have control of Xbox live and  
there is

> nothing we can do about it"
>
> If anyone else has experienced their Xbox live account info being
> stolen let me know. I am trying to archive as much info on this as
> possible. During the conversations I have had with Xbox live support
> I would certainly say that Microsoft  staff is more than  
negligent in
> dealing with this issue especially with regard to the potential  
theft

> of personal information.
>
> -KF
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Xbox live accounts are being stolen

2007-03-17 Thread Kevin Finisterre (lists)
I find it funny too... there is nothing more than I love to hear than  
an Microsoft employee telling me that their network is pwned and  
there is nothing they can do about it.
-KF

On Mar 17, 2007, at 7:33 PM, Jason Miller wrote:

> I'm sorry but I find this funny actually. :-P Seems Microsoft has a  
> weakness.
>
> On 3/17/07, Kevin Finisterre (lists) <[EMAIL PROTECTED]>  
> wrote:
>> There have been rumor going around that Bungie.net was hacked and
>> that a portion of Xbox live has been taken over because of it. Some
>> folks are having their Microsoft points stolen and or points
>> purchased via their stolen gamer tag.
>>
>> I just got off the phone with a Microsoft Tech for Xbox live that has
>> confirmed this to with me and they have stated that accounts are
>> being stolen and that "Hackers have control of Xbox live and there is
>> nothing we can do about it"
>>
>> If anyone else has experienced their Xbox live account info being
>> stolen let me know. I am trying to archive as much info on this as
>> possible. During the conversations I have had with Xbox live support
>> I would certainly say that Microsoft  staff is more than negligent in
>> dealing with this issue especially with regard to the potential theft
>> of personal information.
>>
>> -KF
>>
>> ___
>> Full-Disclosure - We believe in it.
>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> Hosted and sponsored by Secunia - http://secunia.com/
>>

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] Xbox live accounts are being stolen

2007-03-17 Thread Andrew Redman




Funny, I've always kinda figured that MS was it's own weakness. - ATR

Jason Miller wrote:

  I'm sorry but I find this funny actually. :-P Seems Microsoft has a weakness.

On 3/17/07, Kevin Finisterre (lists) <[EMAIL PROTECTED]> wrote:
  
  
There have been rumor going around that Bungie.net was hacked and
that a portion of Xbox live has been taken over because of it. Some
folks are having their Microsoft points stolen and or points
purchased via their stolen gamer tag.

I just got off the phone with a Microsoft Tech for Xbox live that has
confirmed this to with me and they have stated that accounts are
being stolen and that "Hackers have control of Xbox live and there is
nothing we can do about it"

If anyone else has experienced their Xbox live account info being
stolen let me know. I am trying to archive as much info on this as
possible. During the conversations I have had with Xbox live support
I would certainly say that Microsoft  staff is more than negligent in
dealing with this issue especially with regard to the potential theft
of personal information.

-KF

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


  
  
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
  




___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Xbox live accounts are being stolen

2007-03-17 Thread Peter Dawson

why ??

Is there not a secondary layer of economics for points ??  WoW and SL has
virtual $$ being  bartered into real world value...

On 3/17/07, Jason Miller <[EMAIL PROTECTED]> wrote:


I'm sorry but I find this funny actually. :-P Seems Microsoft has a
weakness.

On 3/17/07, Kevin Finisterre (lists) <[EMAIL PROTECTED]> wrote:
> There have been rumor going around that Bungie.net was hacked and
> that a portion of Xbox live has been taken over because of it. Some
> folks are having their Microsoft points stolen and or points
> purchased via their stolen gamer tag.
>
> I just got off the phone with a Microsoft Tech for Xbox live that has
> confirmed this to with me and they have stated that accounts are
> being stolen and that "Hackers have control of Xbox live and there is
> nothing we can do about it"
>
> If anyone else has experienced their Xbox live account info being
> stolen let me know. I am trying to archive as much info on this as
> possible. During the conversations I have had with Xbox live support
> I would certainly say that Microsoft  staff is more than negligent in
> dealing with this issue especially with regard to the potential theft
> of personal information.
>
> -KF
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Xbox live accounts are being stolen

2007-03-17 Thread Jason Miller
I'm sorry but I find this funny actually. :-P Seems Microsoft has a weakness.

On 3/17/07, Kevin Finisterre (lists) <[EMAIL PROTECTED]> wrote:
> There have been rumor going around that Bungie.net was hacked and
> that a portion of Xbox live has been taken over because of it. Some
> folks are having their Microsoft points stolen and or points
> purchased via their stolen gamer tag.
>
> I just got off the phone with a Microsoft Tech for Xbox live that has
> confirmed this to with me and they have stated that accounts are
> being stolen and that "Hackers have control of Xbox live and there is
> nothing we can do about it"
>
> If anyone else has experienced their Xbox live account info being
> stolen let me know. I am trying to archive as much info on this as
> possible. During the conversations I have had with Xbox live support
> I would certainly say that Microsoft  staff is more than negligent in
> dealing with this issue especially with regard to the potential theft
> of personal information.
>
> -KF
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


[Full-disclosure] Xbox live accounts are being stolen

2007-03-17 Thread Kevin Finisterre (lists)
There have been rumor going around that Bungie.net was hacked and  
that a portion of Xbox live has been taken over because of it. Some  
folks are having their Microsoft points stolen and or points  
purchased via their stolen gamer tag.

I just got off the phone with a Microsoft Tech for Xbox live that has  
confirmed this to with me and they have stated that accounts are  
being stolen and that "Hackers have control of Xbox live and there is  
nothing we can do about it"

If anyone else has experienced their Xbox live account info being  
stolen let me know. I am trying to archive as much info on this as  
possible. During the conversations I have had with Xbox live support  
I would certainly say that Microsoft  staff is more than negligent in  
dealing with this issue especially with regard to the potential theft  
of personal information.

-KF

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/