DDOS Attacks Shake Up Xbox Live Stability, Prevents Users From Accessing Content

  • 107 results
  • 1
  • 2
  • 3
Avatar image for austin_walker
austin_walker

568

Forum Posts

5245

Wiki Points

1029

Followers

Reviews: 0

User Lists: 0

Edited By austin_walker
Pictured Above: Microsoft's top IT specialists investigating server issues.
Pictured Above: Microsoft's top IT specialists investigating server issues.

Things have been a little rocky over on Xbox Live recently. Though things seem to have stabilized for now, over the last week or so Xbox One users have been reporting a wide range of issues, none of which sound very pleasant to deal with. According to tips sent in (and a whole lot of frustrated posts on social media and gaming forums), this instability has made it impossible to consistently play multiplayer games online, buy new content from the Xbox Live store, and even launch digital (single-player) games. Yes, that means that if you bought Halo 5 digitally, there's a chance that you wouldn't be able to launch it. It gets even worse: At least some users have been unable to play DVDs and Blu-rays on the system.

While setting the Xbox One to "offline mode" should remedy many of these errors, I've also seen reports from people that insist that the problems remain even after they do this. If I'm being totally honest here: It's a real mess. When we tried to test things out here, everything worked fine--but that doesn't mean that other people haven't been dealing with problems for the last week. It makes this all very hard to investigate.

The problems seem to have been caused by a series of Distributed Denial of Service (DDoS) attacks orchestrated by a group called New World Hackers. In an interview with Newsweek, a representative of the group lays out their motives:

We attacked Xbox to protest. Major companies like this have massive servers but no real protection. We want Xbox to update the protection they have, which isn’t much. ... [The Xbox attacks] also prove we do have as much power as we say we do, going out to the doubters. [We could] honestly knock Xbox off the face of the Earth.

I'm not sure that the altruistic front half of that statement aligns with the braggadocios back half, nor with the attacks themselves, which haven't seemingly demonstrated any novel security failings on the part of Microsoft's servers,just the standard susceptibility to DDoSing. That said, the official Xbox Support Twitter account did just tweet vaguely about "charges going through incorrectly" on user accounts, so maybe there is something else going on, too.

Regardless of the causes of the recent instability, the Xbox Live Status page currently shows all green and another tweet from the Xbox Support account says that things should be back to normal. But given the way that things have been going so far this week, I'm not quite ready to give an all clear.

Avatar image for grimreefz
GRIMREEFZ

400

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

I experienced downage for netflix last night alone. but otherwise all my content was available and I could play mp games without issue. It would be awful to not be able to play MY GAMES for days though..

Avatar image for newmoneytrash
newmoneytrash

2452

Forum Posts

93

Wiki Points

0

Followers

Reviews: 0

User Lists: 11

i haven't been able to play the trackmania beta :(

Avatar image for sparky_buzzsaw
sparky_buzzsaw

9901

Forum Posts

3772

Wiki Points

0

Followers

Reviews: 39

User Lists: 42

Can we just stop being idiots and DDOSing things? Please?

Avatar image for chris_sereday
chris_sereday

29

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

I think WE can. Its the assholes that cant.

Avatar image for finaldasa
FinalDasa

3862

Forum Posts

9965

Wiki Points

0

Followers

Reviews: 9

User Lists: 16

#5 FinalDasa  Moderator

I'm confused and maybe someone can help clarify. A DDOS attack has very little to do with the security of the server correct? Couldn't you DDOS and shut down any publicly accessible server?

Avatar image for mems1224
mems1224

2518

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Bummer for anyone affected but I've been playing Rocket League and watching Netflix all week with no issues. The worst I got was the store page was blank last night.

Avatar image for yummylee
Yummylee

24646

Forum Posts

193025

Wiki Points

0

Followers

Reviews: 88

User Lists: 24

I wasn't able to start Rise of The Tomb Raider for a few days last week, though it's a physical copy. I wonder if this had anything to do with it?

Avatar image for d_w
D_W

1973

Forum Posts

2440

Wiki Points

0

Followers

Reviews: 10

User Lists: 21

I feel like these sorts of hacktivists would be better off doing something other than causing some minor inconveniences for one video game console. I'm sure it sucks for anyone effected by it. I just don't buy that this people are doing it for altruistic means. Though I'm just hearing about this now.

Avatar image for big_jon
big_jon

6533

Forum Posts

2539

Wiki Points

0

Followers

Reviews: 2

User Lists: 18

This was happening to me last night, pretty annoying. I actually got into a game of Halo 5 and couldn't access my rec packs, I was running around for more than half of two games with a pistol and a AR.

Avatar image for deactivated-5ee9f17c410ec
deactivated-5ee9f17c410ec

131

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

@finaldasa: Yes, DDOS attacks don't always need vulnerabilities to target, they can be as simple as just blasting a ton of traffic to drown out legitimate users.

Avatar image for movieflask
MovieFlask

150

Forum Posts

10

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Yesterday evening (EST) was pretty terrible, but most of my friends could access games/streaming services after trying repeated times. However, I wanted to prepurchase and download PvZ GW2, but I couldn't do that until about 2 hours ago today. The purchasing servers were hosed.

Avatar image for pinkcrayon32
PinkCrayon32

98

Forum Posts

2

Wiki Points

0

Followers

Reviews: 0

User Lists: 8

"New World Hackers" Yeah, ok. Surprised they didn't sign off with "hack the planet"

There's no protection against ddos short of having way more servers than are actually necessary so what are they trying to prove?

Avatar image for deactivated-5d61ff6f14b61
deactivated-5d61ff6f14b61

1307

Forum Posts

1718

Wiki Points

0

Followers

Reviews: 3

User Lists: 4

I was locked out of my digital games last night for roughly ten minutes. Everything worked fine after that. I thought it was a simple server quirk at the time. *shrugs*

Script kiddies suck.

Avatar image for officer_falcon
officer_falcon

526

Forum Posts

88

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

@finaldasa: Basically yeah. If you examine the network traffic and you're suddenly getting a spike from a specific IP range you could filter that out but with groups like these they're usually using botnets so there's no simple way to cordon that traffic off.

To put it simply, a DDOS attack is about overloading the capacity for the server to handle requests. Think of a server like a restaurant. It has a finite number of workers at any given time to handle the guests that come in. For times like lunch or dinner, they may schedule more staff to handle the additional load. When a DDOS attack happens, the restaurant is suddenly inundated with guests several orders of magnitude than what they are equipped to handle. They have physical limitations on the amount of guests they can serve at once. Servers have similar limitations as well.

Avatar image for finaldasa
FinalDasa

3862

Forum Posts

9965

Wiki Points

0

Followers

Reviews: 9

User Lists: 16

#15 FinalDasa  Moderator

@officer_falcon: Ok that's pretty much what I understood. So how could a DDOS reveal any security flaws like this hacker group claims?

Avatar image for artisanbreads
ArtisanBreads

9107

Forum Posts

154

Wiki Points

0

Followers

Reviews: 2

User Lists: 6

#16  Edited By ArtisanBreads

I love when hackers try to have some moral reasoning and then are just total dicks like you'd assume a hacker would be. Nice to have it all in one statement, like Austin says, as if those two jive.

Avatar image for lukeweizer
Lukeweizer

3304

Forum Posts

24753

Wiki Points

0

Followers

Reviews: 1

User Lists: 2

#17  Edited By Lukeweizer

While setting the Xbox One to "offline mode"

Remember when it wasn't going to have that?

Avatar image for falilth
falilth

5

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

@grimreefz: the part that was the worst was starting up a show on hulu get to the opening and then it would go to the dashboard and say to insert a disc for hulu if i had one. games reacted the same way, too so I thought itwas fixed only to be dissapointed later.

Avatar image for kanerobot
KaneRobot

2802

Forum Posts

2656

Wiki Points

0

Followers

Reviews: 5

User Lists: 9

#19  Edited By KaneRobot

I was having problems launching a Blu-Ray disc last night. a F'ING BLU-RAY DISC. It would launch, then stop and say something went wrong, or that it was taking too long to load. I eventually kept trying it and it launched, but WHAT THE HELL.

Just glad they decided to be annoying after the Division beta was already over. I didn't run into any issues with that after the first day.

Avatar image for battery24
Battery24

20

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

I've been going all digital this generation and last night made me seriously rethink the decision. I was locked out from EVERYTHING on my Xbox One (games, Netflix, blu-ray player, etc.) when I was connected to XBL. I switched to offline mode and could play single player games, but all the saves from my games are cloud-based apparently, so it appeared as if I'd never played the game before (at least for Wolfenstein). It sucked, as most of what I've been playing lately are online-connected games like Halo 5 and Elite: Dangerous, which was a no-go all night.

Avatar image for ptc
ptc

640

Forum Posts

106

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

I was unable to play Rocket League last night for a couple hours. So I played World of Tanks instead. Everything else I tried seemed to be working fine.

Avatar image for officer_falcon
officer_falcon

526

Forum Posts

88

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

#22  Edited By officer_falcon

@finaldasa: I don't know of how a DDOS by itself would be a way to reveal security flaws. Unless their method of DDOS is being done by exploiting some other vulnerability already. (see NTP server misuse and abuse)

Usually the only options to deal with a DDOS is to either purchase more equipment to handle the increased load or to wait it out until the attacker gets bored. Both are costly options for any target.

Avatar image for shaunage
Shaunage

948

Forum Posts

152

Wiki Points

0

Followers

Reviews: 4

User Lists: 10

Weird. I've been using it all week without a hiccup. Had no idea anything was going on.

Avatar image for finaldasa
FinalDasa

3862

Forum Posts

9965

Wiki Points

0

Followers

Reviews: 9

User Lists: 16

#24 FinalDasa  Moderator
Avatar image for rick
rick

507

Forum Posts

33

Wiki Points

0

Followers

Reviews: 1

User Lists: 1

@finaldasa: There's ways to deal with DDoS attacks. They're expensive but I'm sure Microsoft can afford it. Basically they're just massive servers at the door that eat bad packets and let good ones through.

Avatar image for finaldasa
FinalDasa

3862

Forum Posts

9965

Wiki Points

0

Followers

Reviews: 9

User Lists: 16

#26 FinalDasa  Moderator

@edgework: Would you need something like that if there weren't groups conducting DDOS attacks?

Avatar image for rick
rick

507

Forum Posts

33

Wiki Points

0

Followers

Reviews: 1

User Lists: 1

@finaldasa: Probably not. Though there are DDoSs that originate from bugs not malicious intent but that's the exception.

Avatar image for dwplease
dwplease

9

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

I'm in England and had this issue last night. Netflix stopped working after it finished the episode we were watching (X-Files cliffhanger!) YouTube & Just Cause 3 wouldn't open either. Nothing would launch. Didn't know about the 'offline mode' workaround to try it out. How is that the fix?!?

Avatar image for jigglemaster7
jigglemaster7

113

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Loading Video...

Avatar image for artisanbreads
ArtisanBreads

9107

Forum Posts

154

Wiki Points

0

Followers

Reviews: 2

User Lists: 6

Avatar image for crash_happy
Crash_Happy

816

Forum Posts

283

Wiki Points

0

Followers

Reviews: 1

User Lists: 3

I would guess it hasn't been timed to coincide but it happens that MS have been advertising hard for maybe a week now claiming that their 'cloud' helps them track and combat such things.

Avatar image for thatpinguino
thatpinguino

2988

Forum Posts

602

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

@finaldasa: I wrote a blog explaing how DDoS attacks work if you're interested in the concepts behind them. A true, brute-force DDoS attack doesn't really expose any flaws in server security by itself since it just floods the ordinary channels of internet traffic with way more requests than normal. There are some craftier versions like the one @officer_falcon pointed out that can be the result of server config issues. But for the most part, DDoS attacks to large corporations just prove that the attackers have access to a botnet.

I suppose a DDoS attack could cause a server to do something wonky under all of that load, but that would be an odd case.

Avatar image for clairvoyantvibrations
ClairvoyantVibrations

1619

Forum Posts

72

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Man this seems like a shitty situation. Hope it gets sorted out quick!

Also: @austin_walker. "It gets even worse: At least some users have been unable to play DVDs and Blu-rays own the system." 'Own' should be 'on', should it not? Thanks for the scoops, duder!

Avatar image for kilroyandy
kilroyandy

234

Forum Posts

63

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Weirdly has this post been attacked? Had to get in through the forum as from the main homepage it's a 404?! CHEMTRAILS

Avatar image for atomicoldman
atomicoldman

833

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

@austin_walker

"At least some users have been unable to play DVDs and Blu-rays own the system." Typo?

Also, great. DDOS attacks have always been and will continue to be some real script kiddie tier shit. They've always been frustrating to deal with, but the fact that people build up this ego about it like they're doing something righteous or skillful is just the wooooorst.

Avatar image for hatking
hatking

7673

Forum Posts

82

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#36  Edited By hatking

The only thing I noticed was ads not popping up on the dash (thanks, guys) and also that my fucking pins are stored server side. That last one is being addressed in an update, apparently. Anyway, nothing warms my heart like seeing these kids in handcuffs. So, at least I have something to look forward to now.

Avatar image for bigprimenumbers
BigPrimeNumbers

57

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

This hasn't affected my ability to play my digital games (which is ALL my games) thank god (which it shouldn't if you're playing on your "home" console), but it certainly is annoying, and fucks up game standby/resume for games that try to connect to Xbox Live automatically (even ones like Rise of the Tomb Raider which has superfluous leaderboards for campaign levels).

Avatar image for kmg90
kmg90

514

Forum Posts

2705

Wiki Points

0

Followers

Reviews: 1

User Lists: 8

#38  Edited By kmg90

@hatking said:

The only thing I noticed was ads not popping up on the dash (thanks, guys) and also that my fucking pins are stored server side. That last one is being addressed in an update, apparently. Anyway, nothing warms my heart like seeing these kids in handcuffs. So, at least I have something to look forward to now.

There are ads on the main/home screen on the Xbox one? Are you a gold subscriber? What type of ads are they (content/apps in the store or Slim Jim, Toyota lifestyle ads?)

I don't have an Xbox One nor have I had more than 1-2 hours at most of first hand experience....

Avatar image for onemanarmyy
Onemanarmyy

6406

Forum Posts

432

Wiki Points

0

Followers

Reviews: 2

User Lists: 0

#39  Edited By Onemanarmyy

I still feel like DDOS-ing a site is not a way to expose security flaws. The thing you're exposing is that the servers are not flexible enough to reroute traffic and upscale the amount of bandwith they can handle. This doesn't seem to have anything to do with security to me.

Avatar image for colourful_hippie
colourful_hippie

6335

Forum Posts

8

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

#40  Edited By colourful_hippie

Glad to see that subscription money continue to be almost worthless since they continue to have these bullshit issues. I rarely turn on my console because I use PC but of course the one time I go on to watch the new X-Files season the whole system is on goddamn fire.

Fuck you, MS. Your security cloud commercials are lies!

Avatar image for neozeon
NeoZeon

769

Forum Posts

40

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

@austin_walker I fear that we may have hit a hack within a hack here. Hear me out: Remember when Lizard Squad said they were offering a DDoS service for people to use against whoever they ponied up the cash against? I would bet money that these so-called hackers just rang up Lizard Squad and bought some of that service to use against MS. Have we hit a Hack Inception here or something? True, I have nothing to base that assumption on, but it seems like something people would do just "for the lulz" without having to put much effort in themselves.

Avatar image for hatking
hatking

7673

Forum Posts

82

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

@kmg90: I am Gold, and it's nothing too bad. Most people probably don't register them as ads. They're usually stuff like "Watch Major Nelson talk about this console bundle" or something. It's not like 360 where you'd get car ads. Still, it's clutter, and for a system with a lot of buried functionality, it'd be nice if that space was used to make some things more forward facing.

Avatar image for hatking
hatking

7673

Forum Posts

82

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Glad to see that subscription money continue to be almost worthless since they continue to have these bullshit issues. I rarely turn on my console because I use PC but of course the one time I go on to watch the new X-Files season the whole system is on goddamn fire.

Fuck you, MS. Your security cloud commercials are lies!

Just checking, is this a joke post?

Avatar image for xrayzwei
xrayzwei

191

Forum Posts

2188

Wiki Points

0

Followers

Reviews: 0

User Lists: 6

#44  Edited By xrayzwei

I love that a group wants to highlight issues by performing these attacks, but I'm really curious about what the solutions would be. I'm sure that it would involve users paying MORE than the $60 annually they already pay.

Avatar image for grimluck343
Grimluck343

1384

Forum Posts

20

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

@xrayzwei said:

I love that a group wants to highlight issues by performing these attacks, but I'm really curious about what the solutions would be. I'm sure that it would involve users paying MORE than the $60 annually they already pay.

Except a DDOS attack doesn't really expose a vulnerability.

Avatar image for busto1299
Busto1299

262

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Avatar image for colourful_hippie
colourful_hippie

6335

Forum Posts

8

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

@hatking said:
@colourful_hippie said:

Glad to see that subscription money continue to be almost worthless since they continue to have these bullshit issues. I rarely turn on my console because I use PC but of course the one time I go on to watch the new X-Files season the whole system is on goddamn fire.

Fuck you, MS. Your security cloud commercials are lies!

Just checking, is this a joke post?

Hyperbolic but I'm serious. This is the second time this month. The online services in the past couple days were a nightmare with unbelievable error prompts (insert disc when trying to goddamn stream some X-Files). MS has been making a push (at least more so on the advertising side) that they are a security powerhouse through their cloud resources...well I just don't see it.

Avatar image for busto1299
Busto1299

262

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#48  Edited By Busto1299

Wonder if the issues will persist for a few weeks like the PSN hacks a couple of years ago. ( Maybe DDoS attacks are different?)

Avatar image for nonesun
NoneSun

805

Forum Posts

109

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

@finaldasa: Yes, but there are ways to specifically better help protect yourselves against DDOS attacks in cases.

Avatar image for darknorth
Darknorth

242

Forum Posts

10

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Congratulations hackers. You've used your talents to act like total D-bags.