Feeds

Skype: XSS vuln fix is on the way

Backend backdoor to be firmly plugged

5 things you didn’t know about cloud backup

Updated Skype has promised to fix a cross-site scripting flaw that exposes Windows users of VoIP technology to potential attack.

The flaw was discovered by independent security researcher Levent Kayan, who warned that a hacker might be able to enter a string of JavaScript code into the "mobile phone" field. This would enable a hacker – provided he or she could trick a victim into adding them as a contact – to compromise the user's Skype account (or "trivially hijack session IDs", as Kayan puts it). Kayan (who has published a video on the bug) adds that the vulnerability also creates a possible mechanism to attack "underlying software and operating systems", a contention strongly disputed by Skype.

Skype said that the bug isn't very serious because it only allows access to the Skype home area, an area of the VoIP client that displays web content. Restrictions on web clients means that the flaw can't be used to inject malware, Skype contends. "The person reporting the bug has only demoed a simple javascript prompt, which is a long leap to loading malware, and the web area is not connected to a Skype account," Skype said.

Despite saying the bug is no big deal Skype promised an update address the vulnerability by the end of the week.

The server-side bug created a possible mechanism for miscreants to redirect Skype users to potentially malicious websites, providing they successfully tricked users into adding them as a contact, as the VoIP outfit explains in an update to its official security blog.

Skype for Windows is not correctly validating some fields of your contacts' profiles. What this means is if one of your Skype contacts has put some specific strings into their profile, it could result in your Skype Home area being redirected to another web page or a message being displayed.

In order for someone to cause these messages to be popped up or to redirect you to a website, they would first have to be one of your accepted Skype contacts. However, this vulnerability should not be there and there is a fix, which we are finalising testing of, that is due to be pushed out early next week.

Cross Site Scripting (XSS) flaws, in general, can be used to present content or pop-ups from potentially hostile websites as if the content had originated from other domains. The class of vulnerability is sometimes used as an adjunct to more highly evolved and subtle phishing scams.

Skype said the necessary fix will be applied without troubling its users with software updates, indicating the bug can be resolved by an update to backend systems alone. ®

Updated to Add

Skype have supplied us with a statement regarding this issue in which the firm says:

The XSS issue relates to the Skype home area of the Skype client. This area provides information on your most frequent contacts and their mood messages. It is correct that the fact that your friends could perform an XSS attack could result in them being able to get a web session token or cookie. But this token is extremely limited in what it can do.

It is totally separate to a Skype logon session, i.e. the account itself. In no way does it allow for hijacking of accounts, resetting of passwords [etc].

The Skype home area is an area of the client that displays web content. As such it has all the protections of standard web clients which prohibit the accessing of local systems or executing arbitrary code.

Secure remote control for conventional and virtual desktops

More from The Register

next story
Ice cream headache as black hat hacks sack Dairy Queen
I scream, you scream, we all scream 'DATA BREACH'!
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
JLaw, Kate Upton exposed in celeb nude pics hack
100 women victimised as Apple iCloud accounts reportedly popped
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
New Snowden leak: How NSA shared 850-billion-plus metadata records
'Federated search' spaffed info all over Five Eyes chums
Three quarters of South Korea popped in online gaming raids
Records used to plunder game items, sold off to low lifes
Oz fed police in PDF redaction SNAFU
Give us your metadata, we'll publish your data
prev story

Whitepapers

Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Advanced data protection for your virtualized environments
Find a natural fit for optimizing protection for the often resource-constrained data protection process found in virtual environments.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.