Feeds

Skype blocks poison movie peril

Video pwnd the radio star

The Essential Guide to IT Transformation

Skype said it has blocked a bug that created a means for hackers to attack vulnerable Windows PCs using malicious video files.

The cross-zone scripting vulnerability involves the interaction between Skype and video-sharing sites such as DailyMotion, which allows users to download video clips and add them to their Skype VoIP client. The vulnerability had the potential to affect users of Skype 3.5 and 3.6 for Windows who used Skype’s video gallery to access booby-trapped DailyMotion videos.

The flaw, said to affect online video site MetaCafe as well as DailyMotion, came to light in a post by security researcher Miroslav Lucinskij to a full-disclosure mailing list on Thursday. For example, the security bug makes it possible to inject a malicious script to the "Add video to chat" dialogue using the title field of DailyMotion movie clips.

"This means that an attacker can now upload a movie, set a kewl popular keyword (e.g. 'Paris Hilton'), and own any user that will search for a video with those keywords through Skype," explains Israeli security researcher Aviv Raff, who has published a harmless proof-of-concept demo to illustrate concern about the bug.

Raff blames a poor security architecture in how Skype hooks into Internet Explorer for the vulnerability. Skype uses Internet Explorer web control within the application to render internal and external HTML pages.

Skype is running these web controls in Local Zone and, worse, accessing HTML pages in an unlocked Local Zone mode, Raff explained.

Other security researchers agreed with Raff that the bug opens the door up to all sorts of mischief. "The attack vector is a bit convoluted, but very much possible and quite practical," said Petko Petkov, a UK-based penetration tester. "The most obvious approaches would be to either social engineer the user or spam DailyMotion with hundreds of infected movies that correspond to popular keywords."

The eBay VoIP subsidiary said that the vulnerability was "neutralized before attackers took advantage of it". Skype said on Friday that it has temporarily disabled users' ability to add videos from the DailyMotion gallery until an official fix has been made available. In turn, DailyMotion is addressing the vulnerability on their website, it added. A security advisory from Skype on the vulnerability can be found here.

Petkov criticised Skype's security architecture more generally. He suggested that unencrypted data within Skype's ads created a means for hackers to taint ad traffic with malware by using packet injection tools such as Airpwn in environments such as public wireless hotspots. Skype is yet to respond to our request for comment on this by tapas time. ®

Build a business case: developing custom apps

More from The Register

next story
Scotland's BIG question: Will independence cost me my broadband?
They can take our lives, but they'll never take our SPECTRUM
iWallet: No BONKING PLEASE, we're Apple
BLE-ding iPhones, not NFC bonkers, will drive trend - marketeers
Trying to sell your house? It'd better have KILLER mobile coverage
More NB than transport links to next-gen buyers - study
Auntie remains MYSTIFIED by that weekend BBC iPlayer and website outage
Still doing 'forensics' on the caching layer – Beeb digi wonk
Speak your brains on SIGNAL-FREE mobile comms firm here
Is goTenna tech a goer? Time to grill CEO, CTO
NBN Co adds apartments to FTTP rollout
Commercial trial locations to go live in September
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Backing up Big Data
Solving backup challenges and “protect everything from everywhere,” as we move into the era of big data management and the adoption of BYOD.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.