XBOX Live Profile Page Defaced
This week I'd like to share the tale of when last year, this time, April 2019, I noticed that my XBOX Live profile page was either defaced or a bug caused my profile image to be replaced with the image at this URL.
One can see in this screenshot of my profile page the defacement. The incorrect image is the Woody Allen portrait drawing.
One can see in this screenshot of my profile page the defacement. The incorrect image is the Woody Allen portrait drawing.
It was interesting to me so I dug around a little bit.
I used the browser developer tools to examine the markup. That wasn't allot of help.
I knew less about website security then. As much as I know it may have been a cross sight scripting attack (XSS). This was an example of a persistent website defacement attack.
This W3Schools page has a straight forward example of an implication of XSS.
I found many users who's profiles had been defaced and when I contacted many of them they thought I was joking or hadn't realized that it had happened to them.
Here is a link to a reddit discussion about it.
When I contacted Microsoft support I did not gain any novel information of course.
Comments
Post a Comment