On TV.com: FAMILY GUY Special Finds New Sponsor
BNET Business Network:
BNET
TechRepublic
ZDNet

April 13th, 2009

New Skype Vulnerability Discovered

Posted by Dave Greenfield @ 5:22 am

Categories: Skype, Uncategorized

Tags: Vulnerability, Skype Technologies S.A., Phishing, Hacking, Security, Spam And Phishing, Dave Greenfield

A new phishing attack demonstrated by the folks over at Secure Science allows hackers to  gain access to a user’s Skype client and then  pose as a financial institution or proxy outbond calls. The technique is called “SkypeSkrayping” and is similar to a  phishing attacking only a bit more interactive:

According to the report, attackers would only have to do the following:

[SkypeSkrayper: Hello, I apologize for the disruption, but this is a friendly reminder that Skype is having a special today. We are offering $25.00 extra credit in your SkypeOut account if you do "X". We will never ask you for your username or password over Skype Instant Messaging.

Victim: OK!]

That “X” can detail many things but only requires the user to have logged into their web-based Skype account within a 30 minute time frame and then possibly view another site, which can optionally be trusted or not depending on the security of that site.

This specific 30 minutes of time enables an opportunity for the attacker to do something clever like this:

[SkypeSkrayper2: Hello, were you just contacted by someone promising 25.00 extra credit. This is the Skype Fraud Detection (SFD) department; we believe that your computer may be infected.  We need you to go to this site to check for and eliminate the infection (X-Fake-Security-Site).  As this is Skype-specific, anti-virus software cannot eliminate this threat.  Note: the SFD will never request your Skype password.

Victim: OK!]

Then, according to the report, using either an inline frame (“iframe”) or image (“img”) tag, attackers could

  • add a Specific Call Forwarding Number
  • grant attacker ability to receive the victim’s incoming call
  • obtain a Skype-To-Go Number
  • grant an attacker the ability to access victim’s voicemail, speed dial, and outbound calling via Spoofed Caller-ID

My contacts at Skype tell me the company’s gurus are hunkered down working on resolving the problem.

David GreenfieldDavid Greenfield is the principal in STAnalytics. a global technology-marketing consultancy where he advises enterprises on emerging technologies. See David Greenfield's full profile and disclosure of his industry affiliations.

Email David Greenfield

Subscribe to Team Think via Email alerts or RSS.

  • Talkback
  • Most Recent of 1 Talkback(s)
Well, it was only a matter of time...  RealOne@... | 04/14/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc