Hackers Can Steal Credit Card Info From Old Xbox

axxxo

VIP Member
original.jpg


You might not want to sell or give away your Xbox 360 any time soon. Not without taking a hammer to the hard drive. Even restoring your console to factory settings won't remove some of the data it stores, according to an ongoing study from researchers at Drexel University. And with a handful of common tools, hackers and modders can dig into a system's hard drive and excavate your credit card number or other personal information.
Speaking to Kotaku in a phone interview today, researcher Ashley Podhradsky said Xbox publisher Microsoft is doing a "disservice" to its customers by not doing a better job of keeping personal data protected.
"Microsoft does a great job of protecting their proprietary information," she said. "But they don't do a great job of protecting the user's data."
Podhradsky, along with colleagues Rob D'Ovidio and Cindy Casey at Drexel and Pat Engebretson at Dakota State University, bought a refurbished Xbox 360 from a Microsoft-authorized retailer last year. They downloaded a basic modding tool and used it to crack open the gaming console, giving them access to its files and folders. After some work, they were able to identify and extract the original owner's credit card information.
We reached out to Microsoft for comment on this issue, but as of press time, they have not yet responded.
Podhradsky isn't even a gamer, she says. For seasoned modders and hackers, the process might be even easier.
"A lot of them already know how to do all this," she said. "Anyone can freely download a lot of this software, essentially pick up a discarded game console, and have someone's identity."
So what should you do if you want to get rid of your Xbox 360 but you don't want your personal information compromised? Podhradsky recommends detaching your 360's hard drive, hooking it up to your computer, and using a sanitization program like Darik's Boot & Nuke to wipe everything out. Just reformatting the system isn't enough.

"I think Microsoft has a longstanding pattern of this," Podhradsky said. "When you go and reformat your computer, like a Windows system, it tells you that all of your data will be erased. In actuality that's not accurate—the data is still available... so when Microsoft tells you that you're resetting something, it's not accurate.
"There's a lot more that needs to be done."




Kotaku
 
I've had 3 RROD,and i decided to keep my 360's to repair later, my main concern for not putting them up for Auction on Ebay was corcern for the Information from XBOX LIVE, i felt my Credit Card info would be Compromised, it seem's i was correct, Thanks.:)
 
Once you have the correct screwdriver the harddrive is easily removed from the case and can be formatted properly by connecting it to your own computer as mentioned in the original post. It is terrible that one would have to go to that extent in the first place though.

HTC Desire S~Tapatalk
 
Axxxo i read this or something similar via twitter i think. Not read your post but was rather shocked that even after people have taken out the harddrive or think they taken everything off they can still delve into it and get your details and apparently anyone that has know how can do it! Disgusting!!!
 
Formating a 360 hdd outside of xbox dash makes it no longer work again in a xbox360 as it changes file system, so screwed either way :yes!:
 
Formating a 360 hdd outside of xbox dash makes it no longer work again in a xbox360 as it changes file system, so screwed either way :yes!:

True, but if your getting rid of it who cares lol

Besides, there's always a way :)

Code:
http://www.xboxhacker.org/index.php?topic=11813.0
 
Back
Top