Results 1 to 3 of 3

Thread: Skype users warned of accounts that can be hijacked with ease

  1. #1
    Join Date
    Apr 2003
    Posts
    13,270
    Rep Power
    35

    Default Skype users warned of accounts that can be hijacked with ease

    A serious security problem has been uncovered in Skype, which allows hackers to hijack accounts just by knowing users' email addresses.

    The Next Web describes how it managed to reproduce the attack, accessing the Skype accounts of staff by just knowing their email address, and then changing the passwords of their "victims" to lock them out.

    According to The Next Web:
    Quote Originally Posted by The Next Web
    "The reason this works is simple, but it's still worrying. When you use an existing email address to sign up with Skype again, the service emails you a reminder of your username, which is okay, since no one else should have access to your email. Unfortunately, because this method enables you to get a password reset token sent to the Skype app itself, this allows a third party to redeem it and claim ownership of your original username and thus account."
    The issue was reportedly documented on Russian forums months ago, and appears to have been easy to exploit.
    Read more: http://nakedsecurity.sophos.com/2012...curity-hijack/
    The Next Web article on it: http://thenextweb.com/microsoft/2012...email-address/
    "The best software is the one that fits your needs." - A_A

    Virus free since: date unknown
    Anti-virus free since: August 2008

  2. #2
    Join Date
    May 2010
    Posts
    3,852
    Rep Power
    17

    Default

    A number of hours after The Next Web revealed a flaw in the way Skype handled password resets, allowing third-parties to hijack accounts using just an email address, Skype has said that it has now fixed the issue. The company has confirmed it first mitigated the issue, but has now updated its password reset process so that it doesn’t send tokens to the client. We have confirmed ourselves that this flaw has been fixed.
    http://thenextweb.com/microsoft/2012...sers-affected/

  3. #3
    Join Date
    Feb 2008
    Posts
    725
    Rep Power
    17

    Default

    issue fixed
    http://heartbeat.skype.com/2012/11/security_issue.html

    and also a 24 hours free call being offered but the server are hammered
    http://www.skype.com/intl/en-us/pric...ld?cm_mmc=AFCJ
    Currently: HP Touchsmart 14t
    SM-G935FD - S7 Edge dual sim: Android 7 Official
    The 3 C's in life: Choice, Chance, Change. You must make the Choice, to take the Chance, if you want anything in life to Change.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •