Pipe 2XJ Xbox password flaw exposed by five year old boy

Xbox password flaw exposed by five year old boy

by
in games on (#2XJ)
Microsoft proves its security team is still top notch. Turns out, the backdoor password was a series of spaces.
Kristoffer discovered that if he simply pressed the space bar to fill up the password field, the system would let him in to his dad's account.
Sounds like the Windows 98 network login dialog - the one where you just press "Cancel" and it lets you log into the desktop, networking still enabled.

History


Deprecated: mb_convert_encoding(): Handling HTML entities via mbstring is deprecated; use htmlspecialchars, htmlentities, or mb_encode_numericentity/mb_decode_numericentity instead in /var/pipedot/include/diff.php on line 25

Deprecated: Creation of dynamic property FineDiff::$granularityStack is deprecated in /var/pipedot/lib/finediff/finediff.php on line 217

Deprecated: Creation of dynamic property FineDiff::$edits is deprecated in /var/pipedot/lib/finediff/finediff.php on line 218

Deprecated: Creation of dynamic property FineDiff::$from_text is deprecated in /var/pipedot/lib/finediff/finediff.php on line 219

Deprecated: Creation of dynamic property FineDiff::$last_edit is deprecated in /var/pipedot/lib/finediff/finediff.php on line 372

Deprecated: Creation of dynamic property FineDiff::$stackpointer is deprecated in /var/pipedot/lib/finediff/finediff.php on line 373

Deprecated: Creation of dynamic property FineDiff::$from_offset is deprecated in /var/pipedot/lib/finediff/finediff.php on line 375

Deprecated: Creation of dynamic property FineDiffCopyOp::$len is deprecated in /var/pipedot/lib/finediff/finediff.php on line 155
2014-04-04 18:54
Xbox password flaw exposed by five year old boy
bryan@pipedot.org
Microsoft proves its security team is still top notch. Turns out, the backdoor password was a series of spaces.
Kristoffer discovered that if he simply pressed the space bar to fill up the password field, the system would let him in to his dad's account.
Sounds like the Windows 98 network login dialog - the one where you just press "Cancel" and it lets you log into the desktop, networking still enabled.
Reply 0 comments