Google Search

Showing posts with label Skype. Show all posts
Showing posts with label Skype. Show all posts

Saturday, October 5, 2013

SSCC 110 - Skype "surveillance," piracy, small biz and cybersecurity awareness [PODCAST]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Featured, Podcast

Episode #110 of our popular Chet Chat podcast series is out.

Chet and Duck (Chester Wisniewski and Paul Ducklin) offer you an infusion of interesting insights into the latest computer security news.

If this is your first time listening to the Chet Chat: episodes come out every two weeks, and usually last about a quarter of an hour.

That makes the Chet Chat podcast ideal for your daily commute or for a spot of lunchtime listening.

(You can keep up with our podcasts via RSS or iTunes, and catch up on previous Chet Chats and other Sophos podcasts by browsing our podcast archive.)

• Microsoft Skype. Is it really a privacy nightmare that Microsoft is extracting URLs from Skype instant messages to scan for dodgy links? Can we reasonably infer from this that Redmond must be listening to our calls as well?

• The IP Commission Report. A US think tank published a report which seems to suggest that we should go after pirates by locking your computer and forcing you to contact law enforcement to get the password. Legalised ransomware? Is that really what the report said? And, even if it did, is that such a bad idea?

• Small business cybersecurity. A UK survey claims that only 36% of small businesses patch regularly. Should we be surprised? Does it matter? What about the 17% that the survey says don't patch (or concern themselves with cybersecurity) at all?

• CSAWs. Cybersecurity Awareness Weeks are a good idea. But what should those of us who already care about cybersecurity do by way of participating?

• The AusCERT 2013 #sophospuzzle. The fastest three finishers didn't win a prize because the prize draw included all 58 finishers randomly. So Chester persuaded Duck to give them a shout out in the podcast: @pirate_security, Lee Cronin and Phil Rhea.

Don't forget: for a regular Chet Chat fix, follow us via RSS or on iTunes.

http://twitter.com/NakedSecurity

http://twitter.com/duckblog

Image of small business crushed by foot courtesy of Shutterstock.

Tags: #sophospuzzle, chet chat, CSAW, ip commission, Patching, Podcast, ransomware, skype, Small Business, sscc, surveillance


View the original article here

Sunday, December 23, 2012

Skype users warned of serious security problem - accounts can be hijacked with ease

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

SkypeA serious security problem has been uncovered in Skype, which allows hackers to hijack accounts just by knowing users' email addresses.

The Next Web describes how it managed to reproduce the attack, accessing the Skype accounts of staff by just knowing their email address, and then changing the passwords of their "victims" to lock them out.

According to The Next Web:

"The reason this works is simple, but it's still worrying. When you use an existing email address to sign up with Skype again, the service emails you a reminder of your username, which is okay, since no one else should have access to your email. Unfortunately, because this method enables you to get a password reset token sent to the Skype app itself, this allows a third party to redeem it and claim ownership of your original username and thus account."

The issue was reportedly documented on Russian forums months ago, and appears to have been easy to exploit.

Skype has responded to the reports by temporarily disabling password resets for Skype accounts, and published a brief advisory to users:

Skype acknowledges there is a possible problem

"We have had reports of a new security vulnerability issue. As a precautionary step we have temporarily disabled password reset as we continue to investigate the issue further. We apologize for the inconvenience but user experience and safety is our first priority"

Before Skype withdrew the ability for users to reset their passwords, the only protection for users was to change the email address connected with their Skype account to one which was not known by anybody else.

Microsoft-owned Skype has made the headlines for security reasons in the past. For instance, earlier this year it was accused of being slow to fix a flaw that could allow the gathering of information from Skype users, including a victim's city, country, internet provider and IP address.

Follow @gcluley

View the original article here

Saturday, November 17, 2012

Malware attack strikes, posing as Skype password change notification

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Password lock icon. Image from ShutterstockIf Skype users didn't have enough to worry about this week security-wise (with a worm spreading across the system), there's now another threat to warn about.

Emails have been spammed out by cybercriminals, posing as messages from Skype, claiming that you have changed your password on the service.

Here's an example of one such email (click on it for a larger version):

Malicious Skype email. Click for larger version

If you look carefully, you may spot that the spammers made a clumsy spelling mistake:

Password successfully changed
Your new Skype password has been set.

You can now view your attached call history and inscturtions how to change your account settings.
If the changes described above are accurate, no further action is needed. If anything doesn't look right, follow the link below to make changes: Restore password
Talk soon,
The people at Skype

Perhaps surprisingly, the links really do point to the genuine Skype website at skype.com.

However, a file (Skype_Password_insctructions.zip) is attached to the email, and if you make the mistake of unzipping and executing its contents (Skype_Password_inscructions.pdf.exe) you run the risk of infecting your Windows computer.

The malware, which is detected by Sophos products as Troj/Backdr-HN, opens a backdoor onto your computer, giving remote hackers access to your system.

The danger is, of course, that users worried by the recent worm will be frightened that their Skype password has been changed without their consent, and open the attachment - and thus infect their PC.

As always, be on the lookout for unsolicited suspicious emails and always be wary of opening attachments which arrive out of the blue. In this case, the file is using the well-known "double extension trick" to dupe the unwary into believing that they might be clicking on a PDF rather than executable code.

Follow @gcluley

Thanks to SophosLabs researcher Julie Yeates for her assistance with this article.

Lock image from Shutterstock.


View the original article here

Wednesday, November 7, 2012

Skype worm spreads, using LOL trick to infect unwary users

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

SkypeSkype users are warned to be on their guard, regarding malicious instant messages that have been sent through the service, designed to infect Windows computers.

A malicious worm is taking advantage of the Skype API to spam out messages similar to the one below:

lol is this your new profile pic? http://goo.gl/[REDACTED]?img=[USERNAME]

Clicking on the suspicious links leads to the download of a ZIP files (variously called skype_06102012_image.zip or skype_08102012_image.zip) that contains executable files detected by Sophos anti-virus products as Troj/Agent-YCW or Troj/Agent-YDC.

The Trojan horse opens a backdoor, allowing a remote hacker to take control of infected PCs, communicating with a remote server via HTTP.

On execution the malware copies itself to

%PROFILE%\Application Data\Jqfsfb.exe

and sets the autostart entry as below:

entry_location = "HKCU\Software\Microsoft\Windows\CurrentVersion\Run"entry = "Jqfsfb"description = "Skype "publisher = "Skype Technologies S.A."image = "c:\documents and settings\support\application data\jqfsfb.exe"launch_string = "C:\Documents and Settings\support\Application Data\Jqfsfb.exe"

Before you know it, your computer has been recruited into a botnet (the malware is a variant of the Dorkbot worm) and could fall victim to a ransomware attack.

There have been many variants of the Dorkbot attack spotted over the least year or so, spreading via Facebook and Twitter. The threat can also spread via USB sticks, and various instant messaging protocols.

The danger is, of course, that Skype users may be less in the habit of being suspicious about links sent to them than, say, Facebook users.

Always remember to be suspicious of unsolicited out-of-character messages sent to you by your online friends.

You don't know that it was a friend who sent you the message, all you know is that it was their account which posted it to you... and who knows if it was compromised or not?

Follow @gcluley

Thanks to Anna and Julie at SophosLabs for their assistance with this article.


View the original article here

Monday, October 24, 2011

Skype lets hackers track your BitTorrent downloads - Register

Scientists have devised a stealthy and low-cost way to track the internet protocol addresses of tens of thousands of Skype users, and link the information to their online activities such as the sharing of specific files over BitTorrent.

The method, which is laid out in a recently published academic paper, works even when Skype users have configured their accounts to accept calls only from people in their contact lists. It also works against Skype users who aren't currently logged in, as long as they've used the VoIP program in the past three days. The system is able to link an individual Skype user to specific BitTorrent activity, even when they share the IP address with others over a local area network that uses NAT, or network address translation.

“We have shown that it is possible for an attacker, with modest resources, to determine the current IP address of identified and targeted Skype user[s] (if the user is currently active),” the 14-page paper stated. “In the case of Skype, even if the targeted user is behind a NAT, the attacker can determine the user's public IP address. Such an attack could be used for many malicious purposes, including observing a person's mobility or linking the identity of a person to his internet usage.”

The scientists found that it was relatively easy to find the ID of most Skype users when their email address and birth name are known to the attacker. Additional information, such as the target's city of residence, sex, or age, brought greater accuracy to the task.

They then called the target's Skype account using a customized system that sent specially crafted packets. By examining the headers of the data that was returned, they had no trouble determining the person's IP address. Because the scientists prevented a TCP, or transmission control protocol, connection from being fully established during the probing, targets had no idea their Skype accounts were being tracked. The scientists devised the system so that it could track 10,000 people for about $500 per week.

After learning the IP addresses of individuals, the scientists tapped BitTorrent sites to track the specific downloads of addresses in their database. Even when one of the IP addresses was shared among many users on a single network, the method was able to single link a unique Skype user to a specific download by, among other things, collecting identifiers known as infohashes from BitTorrent networks.

The scientists said Google Talk, MSN Live and other real-time communication applications may also be susceptible to the technique, but they singled Skype out for containing what they called “a major privacy vulnerability.”

In a statement, Adrian Asher, chief information security officer in Microsoft's Skype division, said: “We value the privacy of our users and are committed to making our products as secure as possible. Just as with typical internet communications software, Skype users who are connected may be able to determine each other's IP address. Through research and development, we will continue to make advances in this area and improvements to our software.”

The research paper, which is titled I Know Where You are and What You are Sharing, made several recommendations for improving Skype's ability to conceal the identity of its users.

“One solution that would go a long way is to design the VoIP system so that the callee's IP address is not revealed until the user accepts the call,” it stated. “With this property, Alice would not be able to inconspicuously call Bob. Moreover, if Alice is a stranger (that is, not on Bob's contact list), and Bob configures his client to not accept calls from strangers, then this design would prevent any stranger from tracking him, conspicuously or otherwise.”

A PDF of the paper is here. ®


View the original article here