Skype tackles hack vulnerability that put accounts at risk
Page 1 of 1
Skype tackles hack vulnerability that put accounts at risk
Skype has suspended its password reset function after it emerged the facility could be used to hijack the video chat service's accounts.
The vulnerability was discussed on a Russian blog about three months ago, but was only tackled after details were shared on news site Reddit.
The issue could have exposed answerphone messages, old text message conversations and user details including date of birth.
Skype is looking into the problem.
"We have had reports of a new security vulnerability issue," wrote engineer Leonas Sendrauskas.
"As a precautionary step we have temporarily disabled password reset as we continue to investigate the issue further. We apologise for the inconvenience but user experience and safety is our first priority."
Easy-to-use attack
A how-to-guide was first shared on Russian forum Xeksec.
It involves using a victim's Skype-registered email address to create a new account which is also linked to an email account owned by the attacker.
If a password change is then requested using the target's username, the hijacker can access the resulting reset token via the Skype app itself using the newly-created bogus log-in.
This can then be used to lock out the account's owner and access their details.
Skype blanks all but the last four digits of stored credit card accounts preventing the hackers from being able to steal cash, however they could have used up spare credit.
The security hole was confirmed by The Next Web which subsequently brought it to Skype's attention.
It follows on from a revelation last month that the program could be used to distribute malware via its instant message tool.
The news comes amid a campaign by Microsoft to convince members of its Windows Live Messenger chat tool to switch to Skype.
It plans to retire WLM by March 2013 across the world, with the exception of China.
http://www.bbc.co.uk/news/technology-20325684
The vulnerability was discussed on a Russian blog about three months ago, but was only tackled after details were shared on news site Reddit.
The issue could have exposed answerphone messages, old text message conversations and user details including date of birth.
Skype is looking into the problem.
"We have had reports of a new security vulnerability issue," wrote engineer Leonas Sendrauskas.
"As a precautionary step we have temporarily disabled password reset as we continue to investigate the issue further. We apologise for the inconvenience but user experience and safety is our first priority."
Easy-to-use attack
A how-to-guide was first shared on Russian forum Xeksec.
It involves using a victim's Skype-registered email address to create a new account which is also linked to an email account owned by the attacker.
If a password change is then requested using the target's username, the hijacker can access the resulting reset token via the Skype app itself using the newly-created bogus log-in.
This can then be used to lock out the account's owner and access their details.
Skype blanks all but the last four digits of stored credit card accounts preventing the hackers from being able to steal cash, however they could have used up spare credit.
The security hole was confirmed by The Next Web which subsequently brought it to Skype's attention.
It follows on from a revelation last month that the program could be used to distribute malware via its instant message tool.
The news comes amid a campaign by Microsoft to convince members of its Windows Live Messenger chat tool to switch to Skype.
It plans to retire WLM by March 2013 across the world, with the exception of China.
http://www.bbc.co.uk/news/technology-20325684
wyatt1- ..........
- Posts : 10029
Similar topics
» Real risk of a Maunder minimum 'Little Ice Age' says leading scientist
» Risk aversion in old age down to changes in brain structure, scans suggest
» Put down that drink! Men with beer bellies warned they are at risk of weaker bones
» Gym Rats Are at Risk of This Once-Obscure Kidney Injury
» Nooooooooooooooooooooo!!!!!!! Bacon Eaters Warned Of Deadly Cancer Risk
» Risk aversion in old age down to changes in brain structure, scans suggest
» Put down that drink! Men with beer bellies warned they are at risk of weaker bones
» Gym Rats Are at Risk of This Once-Obscure Kidney Injury
» Nooooooooooooooooooooo!!!!!!! Bacon Eaters Warned Of Deadly Cancer Risk
Page 1 of 1
Permissions in this forum:
You cannot reply to topics in this forum
Sun Dec 04, 2022 11:49 pm by fatbob5
» Pork Markets
Mon Oct 24, 2022 3:56 am by fatbob5
» Why Elon Musk Couldn't Save Free Speech
Thu Aug 18, 2022 2:09 pm by fatbob5
» so..............hows the freedom jab going??
Wed Aug 03, 2022 3:44 am by fatbob5
» NOT GUILTY ON ALL COUNTS
Sat Dec 18, 2021 10:07 am by Flap Zappa
» DEAN!!!!!
Sun Nov 14, 2021 1:38 pm by smelly-bandit
» Scams becoming more sophisticated
Fri Nov 12, 2021 2:56 am by smelly-bandit
» An Interesting Tweet
Tue Oct 19, 2021 8:10 pm by smelly-bandit
» Have you seen...
Mon Oct 11, 2021 6:43 pm by Flap Zappa
» tories prepare for genocide
Thu Sep 30, 2021 4:16 pm by dragonfly
» PLANET OF THE HUMANS
Thu Sep 30, 2021 3:59 pm by dragonfly
» Blood is on bidens hands
Wed Sep 08, 2021 12:40 am by fatbob5
» A list of joe Bidens accomplishments during his 47 years in politics
Tue Aug 31, 2021 3:59 pm by smelly-bandit
» Mickey Mouse has ruined my life
Thu Aug 26, 2021 5:44 pm by Flap Zappa
» Turkish Wildfires
Sat Aug 21, 2021 10:44 pm by Flap Zappa