Feeds

Skype blocks poison movie peril

Video pwnd the radio star

Beginner's guide to SSL certificates

Skype said it has blocked a bug that created a means for hackers to attack vulnerable Windows PCs using malicious video files.

The cross-zone scripting vulnerability involves the interaction between Skype and video-sharing sites such as DailyMotion, which allows users to download video clips and add them to their Skype VoIP client. The vulnerability had the potential to affect users of Skype 3.5 and 3.6 for Windows who used Skype’s video gallery to access booby-trapped DailyMotion videos.

The flaw, said to affect online video site MetaCafe as well as DailyMotion, came to light in a post by security researcher Miroslav Lucinskij to a full-disclosure mailing list on Thursday. For example, the security bug makes it possible to inject a malicious script to the "Add video to chat" dialogue using the title field of DailyMotion movie clips.

"This means that an attacker can now upload a movie, set a kewl popular keyword (e.g. 'Paris Hilton'), and own any user that will search for a video with those keywords through Skype," explains Israeli security researcher Aviv Raff, who has published a harmless proof-of-concept demo to illustrate concern about the bug.

Raff blames a poor security architecture in how Skype hooks into Internet Explorer for the vulnerability. Skype uses Internet Explorer web control within the application to render internal and external HTML pages.

Skype is running these web controls in Local Zone and, worse, accessing HTML pages in an unlocked Local Zone mode, Raff explained.

Other security researchers agreed with Raff that the bug opens the door up to all sorts of mischief. "The attack vector is a bit convoluted, but very much possible and quite practical," said Petko Petkov, a UK-based penetration tester. "The most obvious approaches would be to either social engineer the user or spam DailyMotion with hundreds of infected movies that correspond to popular keywords."

The eBay VoIP subsidiary said that the vulnerability was "neutralized before attackers took advantage of it". Skype said on Friday that it has temporarily disabled users' ability to add videos from the DailyMotion gallery until an official fix has been made available. In turn, DailyMotion is addressing the vulnerability on their website, it added. A security advisory from Skype on the vulnerability can be found here.

Petkov criticised Skype's security architecture more generally. He suggested that unencrypted data within Skype's ads created a means for hackers to taint ad traffic with malware by using packet injection tools such as Airpwn in environments such as public wireless hotspots. Skype is yet to respond to our request for comment on this by tapas time. ®

Providing a secure and efficient Helpdesk

More from The Register

next story
Brits: Google, can you scrape 60k pages from web, pleeease
Hey, c'mon Choc Factory, it's our 'right to be forgotten'
Of COURSE Stephen Elop's to blame for Nokia woes, says author
'Google did have some unique propositions for Nokia'
FCC, Google cast eye over millimetre wireless
The smaller the wave, the bigger 5G's chances of success
It's even GRIMMER up North after MEGA SKY BROADBAND OUTAGE
By 'eck! Eccles cake production thrown into jeopardy
Mobile coverage on trains really is pants
You thought it was just *insert your provider here*, but now we have numbers
Don't mess with Texas ('cos it's getting Google Fiber and you're not)
A bit late, but company says 1Gbps Austin network almost ready to compete with AT&T
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.