Skype Security Problems Multiply
Aviv Raff showed me proof-of-concept code that fired a code execution exploit whenever I visited a booby-trapped Web page. The exploit worked even if Skype was not running--visiting the Web page automatically opened Skype, attempted to load a video, and then launched the executable code. After Raff's second discovery--which is a combination of a cross-site scripting bug in Metacafe and a cross-zone scripting vulnerability in Skype--the eBay-owned company completely removed the Add a Video feature until a patch is ready. |


Comments (4)
This additional warning is appreciated. However to clarify this situation you may want to state specifically when the vulnerabilty is active. Is it (1) with Skype showing in the taskbar "Offline" and in other taskbar modes, or (2) is there's some unusual feature in Skype that allows it to be started and "run" remotely even after someone "Quits" Skype and it's not showing in the taskbar. Thanks!
Posted by jonmca | January 28, 2008 2:05 PM
That's one ef the many troubles with using a closed, proprietary system like Skype: you are forced to put up with the software they provide, you can't switch to anything else.
Whereas if you were using open, standards-based VOIP, if one client had a security hole in it that the vendor was being tardy about fixing, you could switch to another client.
Posted by Lawrence D'Oliveiro | January 29, 2008 4:32 AM
One such free and open source/open standards based service is "Wengophone"
http://wengo.org
Not only is it "open" but the computer to telephone rates are cheaper than Skype.
Posted by canuckistani | January 31, 2008 2:00 AM
I found a potential security bug in Skype by accident, searched and found this article. When I am on a skype-to-skype call I can see the other person's skype-out credit. Even after the call, my skype window continues to show their credit not mine. I am using Skype 3.8 on XP and they had the latest version on Mac.
I can still see their credit going down as they use it, even though the call with them was some time ago. However, during a call, I see my credit and my credit is reduced, so I don't believe this allows me to use their credit, only see it. I don't know about hacking so I have no idea if or how this can be exploited. It's very annoying though.
Posted by Jay | May 21, 2009 9:49 AM