Technique shown for ICQ as well as Skype
Security shortcomings in both ICQ instant messenger for Windows and the ICQ website create a possible mechanism for account hijacking, a security researcher warns.
The technique might be used to steal session cookies, enabling the hijacker to impersonate victims, or (with greater difficulty) to gain access to local files on a compromised PC. Kayan found a similar cross-site scripting flaw involving Skype earlier this month.
Heise Security was able to reproduce the flaw discovered by Kayan using the current 7.5 version of ICQ. ICQ told the security news site that it was in the process of developing and testing a security fix. ®