Exploit Results In "Theft" Of Millions In Xbox Live

axxxo

VIP Member
A forum user on website The Tech Game posted a way for people to scam free points for use on Xbox Live. By the time Microsoft found out and shut it down, over $1 million in codes had been "stolen".

User "Dark" is the author of the post explaining the exploit, which was able to generate authentic download codes for Microsoft Points on Xbox Live, essentially letting people get money for nothing.

A report on Save & Quit says that though it only took Microsoft a few hours to discover this exploit and put a stop to it, by the time this took place around $1.2 million in Microsoft Points had been hoisted by those fast enough to get in on the scam.

Microsoft says they are looking into punishing those that took advantage.

Microsoft points might not be real money but they are purchased with real money, at least that's normally the way it's done.

The algorithim used to generate these codes was quickly discovered by Microsoft but not before a substantial number of codes had been stolen.
It is estimated that somewhere in the region of $1.2 million worth of codes had been stolen although Microsoft says "We can't share specific numbers, but the figure is nowhere near the amount that has been reported."
"We are aware of the situation and have taken steps to invalidate the codes obtained illegitimately"

With Microsoft able to track the generated codes, that means they can also track accounts that cashed in the generated codes for points.

"We take safety and security very seriously and require that Xbox LIVE members use the service in compliance with applicable laws and specifically prohibit people from engaging in illegal activity as a part of our Terms of Use and Code of Conduct," the statement continued. Our Policy and Enforcement team is evaluating whether or not certain individuals have violated the Terms of Use for Xbox LIVE and will take the appropriate enforcement on an individual basis."

The algorithim used to generate these (which is no longer available) was URL based and users would simply change the code Index to say 42 which is microsoft points and the Code ID to a random 4 digit number to then generate a working legit code you input on your console.

Other code index could unlock 48 hour trials and halo reach promotional xbox live codes.

Anyone that has used these is advised not to use them as Microsoft will ban your console.
 

Attachments

  • Capture.JPG
    Capture.JPG
    91.3 KB · Views: 26
Back
Top