Live ID exploit

On the 17th june 2007, Erik Duindam, discovered that if you

  1. Create a Live ID using your e-mail address
  2. Modify your e-mail address before activating your account
  3. Then activate the account

Well, in this way you can create fake, authenticated, Live IDs. Actually you can specify an existing e-mail address, for example of someone you want to impersonate.

Source: Wikipedia