Hackers can steal credit card data from used Xbox 360s
Summary: Security researchers at Drexel University and Dakota State University say they can extract credit card information from Microsoft Xbox 360s even after they have been restored to factory settings.
Update: Microsoft investigating used Xbox 360 credit card hack
Hackers can reportedly retrieve credit card data and other personal information from old Microsoft Xbox 360s. Even if the console is restored back to factory settings and its hard drive is wiped, researchers say they can pull off the feat. Ashley Podhradsky, Rob D'Ovidio, and Cindy Casey of Drexel University, along with Pat Engebretson at Dakota State University, bought a refurbished Xbox 360 from a Microsoft-authorized retailer last year. They then downloaded a basic modding tool, gained access to the console's files and folders, and eventually extracted the original owner's credit card information.
"Microsoft does a great job of protecting their proprietary information," Podhradsky told Kotaku. "But they don't do a great job of protecting the user's data." She says she isn't even a gamer, and warns console modders and hackers may find the process even easier. "A lot of them already know how to do all this. Anyone can freely download a lot of this software, essentially pick up a discarded game console, and have someone's identity."
Microsoft will need to verify whether or not all Xbox 360 hard drives, as well as USB drives that have had profiles transferred onto them, store the sensitive information and why the factory reset option isn't deleting this data. If this turns out to be the case, Redmond will have to offer instructions for what users can do to protect their credit card details, especially if they're looking to sell their console.
If you're looking to sell soon, I would personally recommend formatting the HDD yourself with some powerful software that writes 1s and 0s to it directly. Podhradsky specifically says Darik's Boot And Nuke tool gets the job done.
I have contacted Microsoft about this issue and will update you if I hear back.
Update: Microsoft investigating used Xbox 360 credit card hack
See also:
- Visa, MasterCard confirm credit card security breach
- Analysts on Visa, MasterCard credit card security breach
- Visa, MasterCard warn of 'massive' security breach
- Justin Bieber's Twitter account hacked
- US government pays $250,000 for iOS exploit
- New iPad jailbroken on day one
Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.
Talkback
Umm, So what!
Nobody will do this as it isn't worth the time, research like this is pointless...
Umm, so how about ...
Any xbox with a recovered account (ie downloaded onto a loaned xbox) will also download this same profile information. No need to steal one at a time, use those already on your hotel provided xbox. One way to pay for that bill :)
Also - try go remove those details from your xbox. You cant.
You can swap them for another valid/active credit card, but you cant remove them.
Hotel, rental or friends....
@ On-the-edge
Eitherways, you're welcome to the 21st century :)
Hacking tools
Visit http://www.corelink.com/chicago-data-center.htm
Full Format
Where is this information stored?
Microsoft has already refuted this.
Don't know why such an inflamatory title was placed on a snipit of a reposted report.
Then how did they do it?
Good Question
Not surprised
So tired of all the hacking.
Didn't you mean...