sjvn01

Skype Holes

by sjvn01 ‎17-07-2011 09:44 AM - edited ‎17-07-2011 11:45 AM

If you really know how Skype works, you know it's about as safe as juggling firecrackers. Skype, the popular VoIP program, relies on every PC running Skype between you and who you're calling to serve as stepping stones for your conversation. That's bad. What's worse is when Skype doesn't check to see if Skype calls are actually sent, or received, by the right people.

Or, to quote Levent "Noptrix" Kayan, the security researcher that uncovered this hole, "Skype suffers from a persistent Cross-Site Scripting [XSS] vulnerability due to a lack of input validation and output sanitization of the 'mobile phone' profile entry. Other input fields may also be affected."

What does that mean for you? Noptrix explained, "An attacker could trivially hijack session IDs of remote users and leverage the vulnerability to increase the attack vector to the underlying software and operating system of the victim."

In plain English, it's simple for a hacker to take over your Skype session as you login to Skype. From there it's not much of a trick to take over your Windows PC or Mac and start causing real trouble.

In a report by ZDNet Australia, Skype claims it's not that big a deal. Yeah. Right. At the same time though, Skype admits that it is a real problem and that they'll fix it within the next few days.

I have a better idea. Drop Skype, which will soon belong to Microsoft, and use Google Talk, ooVoo, or another VoIP program instead. Pretty much whatever you pick is going to be safer than Skype. Maybe Microsoft will fix this issue, but I still have real trouble figuring out how Microsoft is going to integrate Skype with its corporate VoIP program Lync. I wouldn't count on Skype being safe to use anytime soon. In fact, if I were you I wouldn't count on Skype at all.

Comments
by Dave(anon) on ‎20-11-2011 10:12 PM
I recently found a great tool for Skype which records calls. Its name Riviera for Skype - take it Skype Call Recorder
by Aristides Salvaterra(anon) on ‎02-04-2013 10:16 PM

 i am trying to instal skype but i was not sucessful. How can i get it?

by sahara sejdovic(anon) on ‎25-04-2013 12:19 AM

sjvn01 wrote:

If you really know how Skype works, you know it's about as safe as juggling firecrackers. Skype, the popular VoIP program, relies on every PC running Skype between you and who you're calling to serve as stepping stones for your conversation. That's bad. What's worse is when Skype doesn't check to see if Skype calls are actually sent, or received, by the right people.

Or, to quote Levent "Noptrix" Kayan, the security researcher that uncovered this hole, "Skype suffers from a persistent Cross-Site Scripting [XSS] vulnerability due to a lack of input validation and output sanitization of the 'mobile phone' profile entry. Other input fields may also be affected."

What does that mean for you? Noptrix explained, "An attacker could trivially hijack session IDs of remote users and leverage the vulnerability to increase the attack vector to the underlying software and operating system of the victim."

In plain English, it's simple for a hacker to take over your Skype session as you login to Skype. From there it's not much of a trick to take over your Windows PC or Mac and start causing real trouble.

In a report by ZDNet Australia, Skype claims it's not that big a deal. Yeah. Right. At the same time though, Skype admits that it is a real problem and that they'll fix it within the next few days.

I have a better idea. Drop Skype, which will soon belong to Microsoft, and use Google Talk, ooVoo, or another VoIP program instead. Pretty much whatever you pick is going to be safer than Skype. Maybe Microsoft will fix this issue, but I still have real trouble figuring out how Microsoft is going to integrate Skype with its corporate VoIP program Lync. I wouldn't count on Skype being safe to use anytime soon. In fact, if I were you I wouldn't count on Skype at all.


 

Post a Comment
Be sure to enter a unique name. You can't reuse a name that's already in use.
Be sure to enter a unique email address. You can't reuse an email address that's already in use.
Type the characters you see in the picture above.Type the words you hear.

The HP Input Output site is sponsored by HP and features articles and content from HP and third-party contributors. Third-party articles and content, while paid for by HP, do not necessarily represent the views and opinions of HP. HP does not endorse this content and is not responsible for its accuracy, availability and quality.

Follow Us
Spotlight
"It's Not My Job" - Handling the Vendor Finger-Pointing Trap Is Teamwork Dead? A Post-Agile Prognosis Improving Your Personal Brand with Social Networking 5 Types of Meetings Every Business Must Explore
┼ Based on energy, paper and toner savings from regular printer usage. Results may vary.