5-year-old boy exposes Microsoft Xbox login vulnerability

10 news:
OCEAN BEACH - A young Ocean Beach boy is in the spotlight after he discovered a back door in to one of the most popular gaming systems in the world.

When 5-year-old Kristoffer Von Hassel is playing his Xbox, his feet don't touch the ground. But something he did has made the smartest guys at Microsoft pay attention.

“I was like yea!” said Kristoffer.

Just after Christmas, Kristoffer's parents noticed he was logging into his father's Xbox Live account and playing games he wasn't supposed to be.

“I got nervous. I thought he was going to find out,” said Kristoffer.

In video shot soon after, his father, Robert Davies, is heard asking Kristoffer how he was doing it.

A suddenly excited Kristoffer showed Dad that when he typed in a wrong password for his father’s account, it clicked to a password verification screen. By typing in space keys, then hitting enter, Kristoffer was able to get in through a back door.
spawnflaggersays...

If this was posted a few days ago, I would have believed it was an April Fools joke.

Also, I bet the dad found the vulnerability, but that story wouldn't make the local news

scrubioussays...

I have learned things about my phone from my four year old. Little kids are good for fuzz testing because they don't know which things should not work.

poolcleanersays...

Not too uncommon of a bug. If there's a bug with the string length of a password field, all you need is the user name and then just type a bunch of random characters so that it's just longer than the maximum number of allowable characters for the system's password. Never a guarantee, but a nice quick win and a chuckle when it works.

@spawnflagger: You're most likely correct. Reminds me of the balloon boy's parents. Lie for the camera, son.

Send this Article to a Friend



Separate multiple emails with a comma (,); limit 5 recipients






Your email has been sent successfully!

Manage this Video in Your Playlists




notify when someone comments
X

This website uses cookies.

This website uses cookies to improve user experience. By using this website you consent to all cookies in accordance with our Privacy Policy.

I agree
  
Learn More