TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Skype vulnerability discovered by Pure Hacking

39 pointsby voodookidabout 14 years ago

5 comments

jimrandomhabout 14 years ago
There is easily enough information in this post for a reasonably clever blackhat to rediscover the vulnerability. I'm reasonably certain I can guess what it is.<p>So don't use Skype on Mac if you can help it, and if you must use it turn off messages from sources not in your contact list.
dguidoabout 14 years ago
"About a month ago I was chatting on skype to a colleague about a payload for one of our clients,” he wrote. “Completely by accident, my payload executed in my colleagues skype client."<p>If I had to guess, they were probably pasting back and forth JavaScript "payloads" for an XSS and broke the parser that Skype is using for formatting chat messages. Not that interesting.<p>Chat messages on Skype aren't exactly the most effective propogation mechanism either. Don't you have to be approved as someone's friend before they can send you a message? This probably won't be used in any massive attacks any time soon. Until then, continue to annoy your girlfriends as the author apparently did.
评论 #2522715 未加载
评论 #2522681 未加载
评论 #2523709 未加载
评论 #2522718 未加载
Jachabout 14 years ago
How long until Skype fixes it and we see the details? Skype seems really bad about fixing/disclosing things. Anyone else remember this? <a href="http://forum.skype.com/index.php?s=17fbdf08801503eebf66d315f03d14b6&#38;showtopic=310121&#38;st=20&#38;p=1633781&#38;#entry1633781" rel="nofollow">http://forum.skype.com/index.php?s=17fbdf08801503eebf66d315f...</a><p>HN page: <a href="http://news.ycombinator.com/item?id=656174" rel="nofollow">http://news.ycombinator.com/item?id=656174</a><p>Edit: woops, my bad, apparently SkypeMate is independent.
tavabout 14 years ago
Skype claim to have already fixed the bug with their release last month on April 14th: <a href="http://blogs.skype.com/security/2011/05/security_vulnerability_in_mac.html" rel="nofollow">http://blogs.skype.com/security/2011/05/security_vulnerabili...</a><p>Sadly the fix seems to be only for the 5.x series and there's no indication for holdouts like myself on whether 2.x is affected or not.
mahrainabout 14 years ago
Another scary thing here is that, since Skype 5.0 sucks so badly, many people downgraded to 2.x and Skype probably will ignore that release when they fix the vulnerability.