also @ TechSpot: Google warns users infected with DNSChanger malware, provides help

Skype security flaw found

By

On May 30, 2006, 3:35 PM EST

Security-Assessment.com, an Australian security firm, has revealed the existence of a flaw in a Skype URI (Uniform Resource Identifier) type that could potentially allow hackers to make file transfers on affected machines. In order to prevent malware writers from successfully exploiting this flaw, and creating relevant malware, Security-Assessment.com worked with Skype to find a solution to the problem first, before the flaw could be exploited; news was kept quiet until a solution was found. Skype seemingly have a patch now.

The flaw is not that easy to exploit. Seemingly, in order for an attack based on the flaw to be carried out, an attacker must authorise the target on his or her contact list, which doesn't require authorisation from the target, and then get the target to visit a website under the attacker’s control. Further to this, the attacker must also know the location of whatever files he or she wants from the victim's machine. Perhaps this might be used to read the user's Skype config file, or to gain access to some operating systems files that could facilitate further attacks.

More information may be found here.

Related Stories

No tags on this story

User Comments (3)

Post a comment
DragonMaster
on May 30, 2006
4:28 PM
Mainstream = Flaws easily found. Either it's because it's poorly written OR there's a lot of people using it so it's easier to find flaws.

Reply

nathanskywalker
on May 30, 2006
4:48 PM
So, basically as long as you utilize common sense you should be ok. And scince the fixed it anyway, i guess it's not real big deal.

Reply

canadian
on May 30, 2006
6:36 PM
Still, runng Skype is safer than running windows.

Reply

Browse more commented news

Post a new comment

Guest user

To post as an anonymous
user click here
.

Members

If you are a TechSpot member,
please login first.


By signing up you gain complete access to the TechSpot community. Join thousands of computer and technology enthusiasts that contribute and share knowledge in our forum. Post messages, get a private inbox, upload your own photo gallery and more.

Subscribe to TechSpot

Get free exclusive content, learn about new features and tech breaking news.