Skype Logo
Buy Skype Credit · Help ·
  • Download
  • Use Skype
  • Business
  • Shop
  • Account

Skype Security Blog

News, reviews, opinions about everything to do with Skype security.

What are blogs?

Blogs are a way to share facts, ideas and opinions directly between people. This blog is edited by the makers of Skype and our friends, helpers and partners. Read more...

What is RSS?Hide this

RSS is a tool which you can use to easily track the updates here on Skype blogs, Skype forums and many other sites which support RSS. Read more...

Peter Parkes

A little bit about Trojan.Peskyspy

By My status Peter Parkes on September 3, 2009 in Trojans and viruses.

Some of you may have seen stories circulating about a ‘trojan’ (a malicious piece of software) which can listen in to your Skype calls – and I’d like to set the record straight on two points.

  • In order for this trojan to ‘listen in’, it has to be run on your computer, which means that your computer is already compromised – e.g. by a virus.
  • It doesn’t exploit the Skype software; instead, it ‘listens in’ to the audio data which is transferred between Skype and your computer hardware – your headset and microphone, for example – and it does this using processes which are available in the Microsoft Windows operating system. It’s like standing next to someone when they are talking :)

Screen with padlockSo, what should you do? All the usual security recommendations still apply – make sure you don’t open files from people you don’t trust, stay current on patches and updates for your computer and use an up-to-date anti-virus program.

If you’re looking for more details, the security experts at Symantec sum things up pretty nicely over on their blog:

What this threat is doing is actually grabbing the sound coming from the audio devices plugged into the computer. It does this by hooking various Windows API calls that are used in audio input and output. It then is able to intercept all audio data traveling between the Skype process and the underlying audio device. The extracted audio data is then saved to .mp3 files and stored on the computer.

Because the Trojan listens in the data traveling between the Skype process and the audio device, it gathers the audio independently of any application-specific protocols or encryption applied by Skype when it passes voice data at the network level. Essentially, it sits below these security measures, recording the audio at the Windows level—before outbound audio from the microphone gets to Skype and after incoming audio leaves Skype and reaches the speakers.

Finally, the Trojan contains a back door, which enables an attacker to have the stolen audio conversations sent to a predetermined location, where they can later be listened to.

In terms of impact, we don’t see this threat gaining much of a foothold out in the wild. What we’ve seen is largely proof-of-concept and does not contain any method to spread from one computer to another. However, it is possible that we will see variations on this Trojan theme in the future. With this in mind we recommend keeping your virus definition and IPS signatures up-to-date.

Bookmark and Share

12 comments, latest by lin.ronald. · View blog reactions
Link
Chaim

Cross-Site Request Forgery (CSRF) Vulnerability

By My status Chaim on April 14, 2009 in .

A browser-level vulnerability has been revealed by Secure Science Corporation that could impact Skype users.

Continue reading "Cross-Site Request Forgery (CSRF) Vulnerability" »

Bookmark and Share

9 comments, latest by dpgade. · View blog reactions
Link
Peter Parkes

Skype Lottery Scam Alert

By My status Peter Parkes on December 17, 2008 in Impersonation.

It appears that someone is attempting to perpetrate a form of the ‘Nigerian’ or ‘Foreign Lottery’ scam using the Skype brand, promising to pay significant prize winnings in a contest.

If you have received an email that appears to be from Skype, please do not respond and/or share any personal and private information as the result of this email.

Here's the version of the message we've seen making the rounds:

Subject: Congratulations; SKYPE AWARDS!‏

From: SKYPE AWARDS (info@skype.com)

Sent: December 16, 2008 5:17:26 AM

To: (Unknown)

SKYPE AWARDS PROMO

The Desk Of The Promotions Manager
International Promotions/Skype Award Center
124 Stockport Road, Longsight,
Manchester M60 2DB - United Kingdom.
Tel: +44 703 194 6898
Fax: +44 703 194 6898

Reference Number: 1037231LL

This is to inform you that you have won a prize money of three Hundred Thousand Pounds (GBP300,000: 00.) for the month of December, 2008 Prize promotion which was organized by SKYPE AWARDS. The Skype collects all the email addresses of the people that are active online,among the millions that subscribed to various websites. Six people are selected yearly to benefit from this promotion and you are one of the Selected Winners this year.

PAYMENT OF PRIZE AND CLAIM.

Winners shall choose from one of the payment option stated below:

A] Bank Wire Transfer

For this option, winnners must provide the below stated information:

(1) Bank Full Name:

(2) Bank Full Address (including State and Country):

(3) Bank Telephone Number:

(4) Bank Account Number:

(5) Name of Owner of Account:

(6) Swift Code:

(7) Charge of Transfer (C.O.T) - 750GBP (Must be paid before consignment transfer of funds)

B] International Certified Cheque

For this option, winnners must provide the below stated information:

(1) Your Full Name:

(2) Your Complete Mailing Address:

(3) A Scanned Copy of your I.D clearly showing your face. (Note that this I.D will be required to claim your parcel when it arrives your apartment).

(4) Insurance Fee & Shipment charge of 500GBP (Must be paid before consignment dispatch).

All funds must be claimed no later than 5 days from date of Draw Notification. Any prize not claimed within this period will be forfeited.

Below you will find a Processing Form, requesting your required Particulars. Please provide all requested information to help us processs your claim in good time.

SKYPE ONLINE PROCESSING FORM

REFERENCE NUMBER:

FULL NAMES:

ADDRESS:

CITY:

STATE:

ZIP:

PHONE /FAX:

COUNTRY:

SEX:

AGE:

MARITAL STATUS:

OCCUPATION:

E-MAIL ADDRESS:

NATIONALITY:

PAYMENT OPTION: [A]/[B]

Forms Should be returned to your claim agent with details below:

Agent Michael Mine
E-mail: skypeawardsprom@gmail.com

CONGRATULATIONS ONCE AGAIN
Yours in service
Patricia Elsworth
(Lottery Coordinator)

Note: Do not reply to this email because your entries will not be processed. All entries should be sent to skypeawardsprom@gmail.com

*****************************************************************************

This Notification MUST remain confidential until your funds is successfully handed over to you to avoid disqualification that may arise from double claim. You may also receive similar e-mails from people portraying our image. This is solely to collect your personal information from you and lay claim over your winning. In the event you receive any e-mail similar to this notification letter we have emailed you, kindly delete it from your mail box and make no further correspondence to such persons or body. Skype shall not be held responsible for any loss of fund arising from the above mentioned.

Bookmark and Share

35 comments, latest by shipei56. · View blog reactions
Link
Robin Grant

[RESOLVED] Phishing emails

By My status Robin Grant on July 10, 2008 in Impersonation.

It appears some of our users have been subject to phishing emails - if you have received an email that appears to be from Skype, please DO NOT enter your username and password as the result of this email.

Also, as a consequence of this, skype.com's mail servers are currently down (we are subject to a flood of bounced emails from emails that do not exist as a result of the phishing emails) - this means our customer support is not currently contactable.

We are doing our best to resolve this situation as quickly as we can and will post updates here as soon as we have them. Please bear with us during while work on solving this.

UPDATE: We are happy to let you know that our mail servers are back up, customer support is available and the phishing sites associated with this incident are no longer active. As a reminder, we strongly encourage users to be cautious when responding to any email that requests sensitive personal information.

Bookmark and Share

14 comments, latest by josher19. · View blog reactions
Link
Villu Arak

Skype misidentified as malware

By My status Villu Arak on April 23, 2008 in Reviews and news.

Earlier this week, security researchers at the Microsoft Malware Protection Center discovered that some Microsoft antimalware products such as Windows Live OneCare were incorrectly identifying some versions of Skype as malware. Such products may stop Skype’s operation and falsely notify the user about the following malware: Trojan:Win32/Vundo.gen!D.

The issue may have affected users of the following Microsoft antimalware products: Microsoft Forefront Client Security, Windows Live OneCare and Windows Live OneCare Safety Scanner. Microsoft has already released an update (a fixed signature file) which was pushed to users of Microsoft's antimalware products.

Once the fixed signature is deployed, Skype should be able to run normally. The fix is included in signature files version 1.31.9121.0 and higher. More information is available here.

Bookmark and Share

6 comments, latest by yonatanhalevy. · View blog reactions
Link
Villu Arak

Trojan downloader alert

By My status Villu Arak on February 27, 2008 in Trojans and viruses.

We've seen some instances where a chat message masquerading as a link to an image file instead leads to a piece of malware. The chat messages may look similar to this:

galvao.png

If you receive something like this through a Skype chat message, do not be alarmed. Instead, ignore it and block the sender. Do not click on the link or open the file that the link points to.

When executed, however, the Trojan downloader creates a Microsoft Studio Files folder in the Program Files directory, populating it with a copy of itself (lsass.exe) as well as a script file (vcdg.bat) that helps it bypass the Windows firewall. The program also changes the Windows registry to enable automatic execution upon Windows startup and to bypass the Windows firewall. Following these steps, the program downloads files into the infected system.

The Skype security team would like to remind users to keep their antivirus software updated and maintain a skeptical eye toward chat messages that don't seem quite right and contain internet links, whether they appear to come from friends or total strangers.

Bookmark and Share

23 comments, latest by cicciabc. · View blog reactions
Link
Villu Arak

Skype cross-zone scripting vulnerability now fixed

By My status Villu Arak on February 6, 2008 in Reviews and news, Skype security features.

We recently disabled the ability to use Skype's Live tab to download clips from the Dailymotion and Metacafe video galleries. We took this step as a cautionary measure after security researchers found a vulnerability in Skype 3.5 and 3.6 for Windows that would have allowed an attacker to execute arbitrary code on a Skype user’s Windows PC without their consent.

As we said in our post on January 18, the measure would be temporary. That is, until an official fix to the vulnerability would be made available. We are pleased to report that the core vulnerability has now been addressed and a fix is included in the latest build of Skype for Windows, 3.6.0.248.

For those who have upgraded to the latest build, we have now re-enabled video downloads from both Dailymotion and Metacafe. Users of older versions of Skype for Windows will not be able to access these video galleries and will need to upgrade.

Last but not least, we'd like to encourage all users to frequently upgrade their version of Skype. This helps ensure that the Skype experience is safer and more enjoyable.

Bookmark and Share

5 comments, latest by ehsansommru09. · View blog reactions
Link
Villu Arak

(Resolved) Skype Cross Zone Scripting Vulnerability

By My status Villu Arak on January 18, 2008 in Skype security features.

A vulnerability that allowed an attacker to execute arbitrary code on a Skype user's Windows PC without their consent has been discovered in Skype and on Dailymotion, the video-sharing site where Skype users can download video clips and add them to their Skype moods and chats.

The vulnerability had the potential to affect users of Skype 3.5 and 3.6 for Windows who, in Skype's video gallery, navigated to a Dailymotion video with a specially crafted title.

The issue, demonstrated by security researchers as a proof of concept, was neutralized before actual attackers took advantage of it, therefore Skype users are unlikely to have been affected. Skype has temporarily disabled users' ability to add videos from the Dailymotion gallery until an official fix has been made available. In turn, Dailymotion is addressing the vulnerability on their web site.

For a more detailed description of the issue, please see the most recent Skype Security Bulletin.

Update: We've also temporarily disabled the ability to add videos from the Metacafe video gallery. Both Dailymotion and Metacafe videos will be re-enabled as soon as an official fix has been made available.

- - -

Final update on Feb. 6, 2008 - the issue has been resolved. Please see today's post for more information.

Bookmark and Share

1 comment, latest by dotty777. · View blog reactions
Link
Villu Arak

Vulnerability in Skype for Windows versions older than 3.6.x.216

By My status Villu Arak on December 10, 2007 in Impersonation, Skype security features.

In early November, Zero Day Initiative informed Skype of a vulnerability that allows a remote attacker to execute arbitrary code, provided that the user visits a malicious website.

The flaw exists within the skype4com URI handler component of Skype. An exploitable memory corruption may occur during the parsing of URIs which can result in arbitrary code execution under the user rights of the current Windows account.

The issue was fixed in the public release of Skype 3.6 for Windows. All versions of Skype for Windows updated or installed as of November 15 include the patch.

At Skype, we strive to inform the public of vulnerabilities and malware that may affect Skype software. While this particular vulnerability was fixed, there was an unintentional communication oversight and we failed to bring the case to the public's attention. All we can do now is to apologize.

Meanwhile, we'd like to advise users to always upgrade to the latest version of Skype. This ensures access to the latest features, improvements and fixes, and helps get the most out of your Skype experience.

Bookmark and Share

1 comment, latest by mjcwhite. · View blog reactions
Link
Villu Arak

Password stealer

By My status Villu Arak on December 6, 2007 in Impersonation.

passwordstealer4.png

Looks like virus writers are at it again. Some Skype users have been contacted over chat by people warning against viruses and offering to send the user a file that masquerades as Spyware Doctor, a popular anti-malware program from PC Tools. Needless to say, the file they're attempting to send (SpyWareDoctorSetup.exe) is not the real thing. Instead, it's a piece of malware, affecting Windows users. Do not accept or run this executable file.

Continue reading "Password stealer" »

Bookmark and Share

12 comments, latest by craigcleaver. · View blog reactions
Link
Skype Blogs
  • Share Skype Blog
  • Heartbeat
  • Developer Zone
  • Business
  • Skype Gear
  • Security
  • Garage
  • Mac
  • Linux
  • Eesti keeles
  • 日本語
  • Česky
  • Deutsch
  • Français
  • Italiano
  • Brasil
  • United Kingdom
  • Polski
  • United States
  • 한국어

Recent posts

  • A little bit about Trojan.Peskyspy
  • Cross-Site Request Forgery (CSRF) Vulnerability
  • Skype Lottery Scam Alert
  • [RESOLVED] Phishing emails
  • Skype misidentified as malware
  • Trojan downloader alert
  • Skype cross-zone scripting vulnerability now fixed
  • (Resolved) Skype Cross Zone Scripting Vulnerability
  • Vulnerability in Skype for Windows versions older than 3.6.x.216
  • Password stealer

Archives

  • September 2009
  • April 2009
  • December 2008
  • July 2008
  • April 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • February 2007
  • January 2007
  • December 2006
  • May 2006
  • March 2006
  • February 2006
  • October 2005
  • May 2005

Subscribe to this blog
What? Tell me more…

using RSS Subscribe
via Bloglines Subscribe in Bloglines
using Newsgator Subscribe in NewsGator Online
with MyYahoo
with Google Add to Google
with MyAOL Add to My AOL
with netvibes Add to Netvibes
About us · Partners · Jobs · Prices · Security
Privacy policy · Legal · © 2009 Skype Limited