A browser-level vulnerability has been revealed by Secure Science Corporation that could impact Skype users.
Called Cross-Site Request Forgery (CSRF), the attack is a type of malicious exploit of a Web site whereby unauthorized commands are unknowingly transmitted through a user that the Web site trusts. It works when a link or script in a Web page, email or instant message is activated and accesses a site to which a user is known (or is supposed) to have authenticated.
This exploit can happen to any user who is logged into their account on Skype.com, who simultaneously visits a malicious Web site and is then affected by this attack. The malicious site can then compromise a user's account and perform a limited number of actions, such as change the user's voicemail or call forwarding settings. However, the user's account password is not compromised at any time. Nor does it impact users of the Skype client.
The simplest technique is similar to a phishing attack, only a bit more interactive:
Attacker: Hello, I apologize for the disruption, but this is a friendly reminder that Skype is having a special today. We are offering $25.00 extra credit in your SkypeOut account if you do "X." We will never ask you for your username or password over Skype Instant Messaging.Victim: OK!
That "X" can be anything that requires the user who is logged into their Web-based Skype account to possibly view another site.
OR
Attacker2: Hello, were you just contacted by someone promising 25.00 extra credit. This is the Skype Fraud Detection (SFD) department; we believe that your computer may be infected. We need you to go to this site to check for and eliminate the infection (X-Fake-Security-Site). As this is Skype-specific, anti-virus software cannot eliminate this threat. Note: the SFD will never request your Skype password.Victim: OK!
In both cases, the attacker never asked for the Skype username or password.
To protect yourself from this vulnerability, we recommend that you take the following steps:
- Close all browser windows before logging into your secure account (https) on Skype.com to execute any transactions or change any account settings.
- Make sure to log out of your account on Skype.com when you're done buying Skype credit or a subscription and/or making other changes to your account settings.
- Logging off of secure Web sites is the best practice method before clicking on any links from any source other than the secure page opened. As such, do not visit any other Web sites until you have logged out of your secure Skype.com account.
As always, do not click on links from unknown people in instant messages or links in "spam" or untrusted e-mails. Plus, it's not a good time to multi-task when you are logged into any secure Web site.
Skype is hard at work changing how these Web pages operate in order to address this vulnerability and to keep our users' safe from this type of attack.





Comments
This just popped up on my Skype chat:
sysscan-6702
4:24 PM
Your system registry maybe corrupted and needs to be cleaned immediately. For an complete free Registry scan and go to www.nowfixpc.com failure to do so may cause compromise of personal information stored on your computer or may lead to complete system failure resulting in reinstallation of your hard drive.
ok, looks like these people are at it again. what's interesting is, I'm not even a pc user, I've got a Mac. How many scripts do these people have?
lorandavalon | Thursday, Apr 30
I just received this message (below the stars) from a user "Security Bulletin ®" who "has not shared their information with you."
skype user registry.scan.vivi19
(Sent a copy of this information to Skype security as well.)
********
WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================
ATTENTION ! Security Center has detected
malware on your computer !
Affected Software:
Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 2000
Microsoft Windows Server 2003
Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns
Recommendation: Users running vulnerable version should install a repair
utility immediately
Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.
http: //www. scan-online. net/ (SPACES ADDED TO DISABLE LINK)
For the link to become active, please click on 'Add to contacts' skype button
or type it in manually into your web browser !
rebotalks | Thursday, May 14
Is this some kind of scam> I went to the site and they want 19.95 to "clean", have I compromised my computer? I am scanning with my security software---Is your site this vulnerable that people can send stuff around to everybody---I thought I could only receive from people I approved...
francis.cyril.kelly | Thursday, May 28
I got a Skype message this morning - the message sender knew my last name, not my Skype name! Its obviously a scam. Here's the text:
*** Show messages from: This conversation | Today | This week | Last 30 days | Beginning ***
[8:10:41 AM] Dr Allen William says: Hello Cox,
I have been in search of someone with this last name "Cox", so when I saw your name I was pushed to contact you and see how best we can assist each other. I am Dr. Allen William, i am the regional manager of U. B. A GHANA(UBA). I believe it is the wish of God for me to come across you on search now. I am having an important business discussion I wish to share with you which I believe will interest you because, it is in connection with your last name and you are going to benefit from it.
One Late Shafi Cox,a citizen of your country had a fixed deposit with my bank in 2004 for 36 calendar months, valued at US$18,400,000.00 (Eighteen Million, Four Hundred Thousand US Dollars) the due date for this deposit contract was this 16 of January 2007. Sadly Shafi was among the death victims in the May 26 2006 Earthquake disaster in Jawa, Indonesia that killed over 5,000 people.. He was in Indonesia on a business trip and that was how he met his end.
My bank management is not aware of his death , I know about it because he was my friend and I am his account officer. Shafi did not mention any Next of Kin/ Heir when the account was opened, and he Shafi was not married and no children. Last week my Bank Management requested that should give instructions on what to do about his funds, if to renew the contract.
I know this will happen and that is why I have been looking for a means to handle the situation, because if my Bank Directors happens to know that Shafi is dead and do not have any Heir, they will take the funds for their personal use, so I don't want such to happen. That was why when I saw your last name I was happy and I am now seeking your co-operation to present you as Next of Kin/ Heir to the account, since you have the same last name with him and my bank head quarters will release the account to you. There
is no risk involved; the transaction will be executed under a legitimate arrangement that will protect you from any breach of law.
It is better that we claim the money, than allowing the Bank Directors to take it, they are rich already. I am not a greedy person, so I am suggesting we share the funds equal, 50/50% to both parties, my share will assist me to start my own company which has been my dream. Let me know your mind on this and please do treat this information as TOP SECRET. We shall go over the details once I receive your urgent response strictly through my personal email address. ( william.allen200@gmail.com)
We can as well discuss this on phone; let me know when you will be available to speak with me on phone. Have a nice day and God bless. Anticipating your communication.
Mr. Allen William
grandmomtexas | Monday, Jul 20
Hello,
Today at night my Skype account was hacked and somebody called from my account,
Jul 25 06:25 +966541789216, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 05:39 +966541789216, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 05:38 +966541789216, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 05:34 +966541789216, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 05:17 +966541789216, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 05:17 +966564002708, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 05:16 +966564002708, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 05:14 +966541789216, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 05:12 +966541789216, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 05:12 +966541789216, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 05:12 +966541789216, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 05:12 +966541789216, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 05:12 +966541789216, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 05:10 +966564002708, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 05:10 +966564002708, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 05:09 +966541789216, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 05:07 +966531000280, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 05:07 +966531000280, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 05:07 +966531000280, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 05:03 +966541789216, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 03:23 +966541789216, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 03:22 +966541789216, Saudi Arabia - Mobile SMS $0.132 1 $0.132
Jul 25 03:22 +966541789216, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 03:21 +966541789216, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 02:22 +966569564569, Saudi Arabia - Mobile Call $0.264 04:05 $1.359
Jul 25 02:21 +966554592394, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 02:18 +966555530287, Saudi Arabia - Mobile Call $0.264 00:35 $0.303
Jul 25 00:43 +966531126519, Saudi Arabia - Mobile Call $0.264 00:09 $0.303
Jul 25 00:35 +966599576063, Saudi Arabia - Mobile Call $0.264 03:06 $1.095
Jul 25 00:28 +966599576063, Saudi Arabia - Mobile SMS $0.132 1 $0.132
Jul 25 00:27 +966599576063, Saudi Arabia - Mobile Call $0.264 07:52 $2.151
Jul 25 00:27 +966599576063, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 00:26 +966599576063, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 00:25 +966561775612, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 00:23 +966569643339, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 00:21 +966554320734, Saudi Arabia - Mobile Call $0.264 00:37 $0.303
Jul 25 00:20 +96654320734, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 00:19 +966599576063, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 00:17 +966541789216, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 00:15 +966561252018, Saudi Arabia - Mobile Call $0.264 01:19 $0.567
Jul 25 00:11 +966500530001, Saudi Arabia - Mobile Call $0.264 02:16 $0.831
Jul 25 00:11 +966500530001, Saudi Arabia - Mobile Call $0.264 00:17 $0.303
Jul 25 00:10 +96650053001, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 00:10 +966567100842, Saudi Arabia - Mobile Call $0.264 00:06 $0.303
Jul 25 00:08 +966567100842, Saudi Arabia - Mobile Call $0.264 00:58 $0.303
Jul 25 00:08 +9665567100842, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 00:06 +966592588791, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
Jul 25 00:05 +966567367795, Saudi Arabia - Mobile Call $0.264 00:00 $0.000
When I woke up I changed my password. What else should I do?
iouliakrause | Saturday, Jul 25
Hello All ,
This comment is unrelated to this post , for that I apologize , but we are desperately trying to obtain some information about this, I think most of you are aware of the current situation in Iran , people are currently not using cellphone or landlines to communicate sensitive news or information , particularly to outside of country, instead skype has become a widespread way of communication , the voice is good despite the problems with the internet, for example I am in touch with few of my friends, who take part in demonstrations, over skype where they pass on the accounts of the events, a question lot of people are asking me is that , is skype safe ? , a government that can have absolute controller over the data provider and therefore your ip and internet connection , can they decode or eavesdrop the communications ? , how difficult is such a thing ? ... I thank you in advance for your information,
- A
amiranpa | Thursday, Jul 30
My skype is not working, your FAQ is not helping, and there is no email contact.
leehansheng | Wednesday, Aug 26
Why am I receiving unwanted calls and messages even though my Privacy settings specify that only people from my Contact List can message me. please help - all the requests are sex related and I am disgusted! Thank you
dpgade | Thursday, Sep 3
Why am I receiving unwanted calls and messages even though my Privacy settings specify that only people from my Contact List can message me. please help - all the requests are sex related and I am disgusted! Thank you
dpgade | Thursday, Sep 3