Download the
Tom's Guide App from the AppsStore
News and trends on internet
/ mobile / "sound & picture" / IT
Yes No

Simple Skype Flaw Enables Account Hijacking

- By - Source : Forbes

German IT security expert Levent Kayan discovered a simple, but particularly nasty vulnerability in Skype that enables an attacker gain access to session IDs and user account data, including passwords.

To exploit the cross-site scripting bug, an attacker needs to enter a command string in the "mobile phone" field of a targeted user.

Skype confirmed the problem, but considers it to be a "minor issue", while the researcher categorizes the threat level as "high". Kayan said that other input fields that lack input validation as well may also be affected by the vulnerability. In a response to Forbes, Skype spokesperson Chaim Haas said that the problem only affects "top contacts" as they need access to this particular field. “As you can imagine, someone who you deal with frequently is probably unlikely to take advantage of this bug anyway,” Haas said.

Kayan noted that there is no sign that the bug is already being exploited by attackers. All Skype versions to versions 5.3.0.120 as well as Windows XP, Vista and 7 and Mac OS X are affected.

Share:
5
Comments
X

Comments

kilo_17 07/21/2011 6:30 AM
Hide
-3+

Right. This is a "minor" issue.

JohnnyLucky 07/21/2011 8:09 AM
Hide
-0+

It seems like some sort of vulnerability is being reported almost every day. It is beginning to sound as if it is business as usual.

otacon72 07/21/2011 8:18 AM
Hide
-2+

kilo_17 :
Right. This is a "minor" issue.



Um it is... if you have to worry about your top contacts hacking your computer then you have more issues then a Skype bug.

custodian-1 07/21/2011 1:26 PM
Hide
-4+

it's a minor issue because there is no fix for it yet. when it's fixed then it becomes a major issue.

dalauder 07/24/2011 11:51 PM
Hide
-0+

otacon72 :
Um it is... if you have to worry about your top contacts hacking your computer then you have more issues then a Skype bug.

Unless a script ran on any infected computer can automatically infect all your top contacts then all that person's top contacts. It sounds to me like it relies on trust of a source that can't be verified as clean, which is a legitimate security threat. I assume it'll get fixed within a week now that it's public though.