Xbox Live hacked? 48 million passwords in the wild

Costello

Headmaster
OP
Administrator
Joined
Oct 24, 2002
Messages
14,201
Trophies
4
XP
19,711
Some internet black-hat hacker, already responsible for hacking CNN's website a few days ago, claims to have "brutally owned" Microsoft's Xbox Live. Oddly enough, he states that user passwords were stored in plain text.
download.jpg
Read the NFO by opening the spoiler:
Good morning, faggots

Today is a pretty fine fucking day, and a good day for the underground too, as I believe everything happens for a small tiny reason. Today, one of the biggest IT-companies known as Fagsoft, oh sorry, autocorrect-problems, I meant, Microsoft. They are often known as the biggest cocksuckers that history has ever witnessed. They released a faggotry-infested 1960's-machines inspired Xbox One! They said that they have created 30,000 servers just for this lovely moment. I believe, you better shut the fuck up before you get smacked the fuck up, billy.

Today, Xbox Live has been brutally owned, in true-fashion. I shall not expose the vulnerability this time, as I do not want Benjamin Kuns Mejri masturbating all over my releases, oh and, Vuln-Labs, your advisories fucking suck.

On the second hand, after the downfall of our well-known friends, Lulssec. sony was truly happy, sitting behind their chairs and ejaculating over pictures of Katy Perry. But I believe, that Microsoft should get a taste of some pure ownage too.

I brutally owned Xbox Live a few days ago, but I decided to dump all the super-dooper precious data now.

Oh and, If I get another stupid BBC-journalist talking crap on this lovely work-of-hand, thou shall be cursed.

And most importanly; Microsoft, this is not a dick-sucking contest. You gotta stand the fuck up infront of cyberhackers. You seek help and therefore; You'll get owned.

Lastly, Microsoft is a pest to humanity.

Enjoy this lovely ownage for now.

I have uploaded the entire credentials of every Xbox Live user in an nickname;email;password;joindate format, It contains nearly confidental-info on around 47 million users.

*****(link removed)****
size: 6.12GB

These credentials given below are probably old, these are when Xbox Live was newly annouced, probably dating back from 2009's or something, the newly-created accounts and the latest-ones are in that archive.
UPDATE: Microsoft released a statement denying that any hack ever took place. Who is telling the truth? If you find your account & password in the databases released by the hacker, please make sure to let us know.

-> Read the original article at Consolecrunch
-> A sample of leaked passwords on Pastebin
-> Full leaked database at Bayfiles (link dead?)
 
  • Like
Reactions: kehkou

McHaggis

Fackin' Troller
Member
Joined
Oct 24, 2008
Messages
1,749
Trophies
0
XP
1,466
Country
I was highly sceptical at first, but now I just think this guy's retarded.

A. As a company whose security policies are under constant scrutiny, Microsoft wouldn't be stupid enough to store passwords in plain text.
B. I only looked at a small sample of the list, but the fact that more than half of the ones I looked at were duplicated at least twice and contained purely numeric passwords. That seems unlikely since none of the numbers I looked at were dates (ie date of significant importance to the account holder) or had any other kind of pattern one would normally associate with numeric passwords (credit card numbers, regular lottery numbers, etc). Those numbers were clearly generated by a random number generator.
C. No passwords on that list contained characters outside of the latin range [0-9a-z], which is also unlikely given that the default input characters for an on-screen keyboard would normally be representative of the user's locale. There's also no passwords containing other special characters, like underscores or dashes (though those are understandably the minority for passwords entered using a non-touch based OSK).

Just my thoughts.
 

Costello

Headmaster
OP
Administrator
Joined
Oct 24, 2002
Messages
14,201
Trophies
4
XP
19,711
Can't find my old tag or my new one in the list and I've been on Live nearly 10 years.

did you check the big ass 6GB file ? or the small list posted on pastebin ?
the list on pastebin doesnt look legit, but I haven't downloaded the 6GB dump, so I can't say
 

DinohScene

Gay twink catboy
Global Moderator
Joined
Oct 11, 2011
Messages
22,530
Trophies
4
Location
Восторг
XP
22,731
Country
Antarctica
Pathetic if you ask me.

I doubt that the XBL hack every took place.
However, I won't say it's fake, since every online service can be hacked.
It's just a matter of time.

I was highly sceptical at first, but now I just think this guy's retarded.

A. As a company whose security policies are under constant scrutiny, Microsoft wouldn't be stupid enough to store passwords in plain text.
B. I only looked at a small sample of the list, but the fact that more than half of the ones I looked at were duplicated at least twice and contained purely numeric passwords. That seems unlikely since none of the numbers I looked at were dates (ie date of significant importance to the account holder) or had any other kind of pattern one would normally associate with numeric passwords (credit card numbers, regular lottery numbers, etc). Those numbers were clearly generated by a random number generator.
C. No passwords on that list contained characters outside of the latin range [0-9a-z], which is also unlikely given that the default input characters for an on-screen keyboard would normally be representative of the user's locale. There's also no passwords containing other special characters, like underscores or dashes (though those are understandably the minority for passwords entered using a non-touch based OSK).

Just my thoughts.

I agree on that.
Also, Uzerneme and Pezzwerd?

Sounds like a failed attempt at trolling to me.
 
  • Like
Reactions: McHaggis

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Xdqwerty @ Xdqwerty: @BakerMan, I have a piano keyboard but I never use it