On TechRepublic: Five super-secret features in Windows 7
BNET Business Network:
BNET
TechRepublic
ZDNet

By Ina Fried
Posted on ZDNet News: May 25, 2005 6:39:00 PM

Microsoft has patched a flaw in its Xbox 360 Web site that researchers say could have opened the door to a phishing attack.

Security company Finjan Software said that it notified the software maker of the issue last week and that Microsoft patched its site within 12 hours. The flaw was what is known as a cross-site scripting vulnerability, which could have been exploited by hackers to gather credit card data and other personal information from people looking to get more information about the new game console.

"This discovery is another example of our cooperation with Microsoft and other leading software vendors to fix vulnerabilities before they are exploited by the hacking community," Finjan CEO Shlomo Touboul said in a statement.

A Microsoft representative confirmed that Finjan reported the bug and that the two companies worked to close the security hole. The representative said Microsoft is not aware of any attacks that exploited the vulnerability.

Earlier this year, Microsoft and Finjan became embroiled in a disagreement over the timing of flaw disclosure. The software giant criticized the San Jose, Calif.-based company for posting "proof of concept" code to exploit a security hole on the same day Microsoft released a patch.

Microsoft announced its plans for the second-generation Xbox earlier this month. The game player doesn't go on sale until the holiday shopping season, but the Xbox 360 Web site has gone live with some video clips, game previews and an option to sign up for updates.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 8 Talkback(s)
Too Early
Linux isn't set to start taking over the Desktop until 2006. Did you not get the Memo about the coversheet on those TPS Reports?... (Read the rest)
Posted by: nucrash Posted on: 05/26/05 You are currently: a Guest | | Terms of Use
Microsoft plugs phishing hole in Xbox site  Loverock Davidson | 05/25/05
as they say lovey  Monkey_MCSE | 05/25/05
Wala  Jeff Spicoli | 05/25/05
Too Early  nucrash | 05/26/05
Yep..  widge_z | 05/25/05
Oh my...  tty0 | 05/25/05
You all know what is coming next... TwoCare!  Xunil_Sierutuf | 05/25/05
XCare!  Jeff Spicoli | 05/25/05

What do you think?

advertisement

White Papers, Webcasts, and Downloads

Meet Doc

  • Here to help you with your Document Management Needs
  • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
  • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
  • Produced by
    ZDNet and