Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Skype bug gives attackers access to Mac OS X machines
The Register ^ | 6th May 2011 19:40 GMT | By Dan Goodin in San Francisco

Posted on 05/06/2011 4:33:50 PM PDT by Swordmaker

'Extremely wormable and dangerous'

Mac users running Skype are vulnerable to self-propagating exploits that allow an attacker to gain unfettered system access by sending a specially manipulated attachment in an instant message, a hacker said.

“The long and the short of it is that an attacker needs only to send a victim a message and they can gain remote control of the victim's Mac,” Gordon Maddern of Australian security consultancy Pure Hacking blogged on Friday. “It is extremely wormable and dangerous.”

The vulnerability, which Maddern said isn't present in the Windows or Linux versions of the popular VoIP program, was confirmed by Skype spokeswoman Brianna Reynaud, who said a fix will be rolled out next week. Its disclosure comes the same week that researchers discovered a new crimekit that streamlines the production of Mac-based malware. It also comes as new malware surfaced for Apple's OS X that masquerades as a legitimate antivirus program.

Reynaud said there are no reports that the Skype vulnerability is being actively exploited.

Maddern said he stumbled on the critical flaw by accident.

“About a month ago I was chatting on skype to a colleague about a payload for one of our clients,” he wrote. “Completely by accident, my payload executed in my colleagues skype client. So I decided to test another mac and sent the payload to my girlfriend. She wasn't too happy with me as it also left the her skype unusable for several days.”

He then set out to write proof-of-concept attack code that used payloads borrowed from the Metasploit exploit framework. The result: a Skype exploit that allows him to remotely gain shell access on a targeted Mac. Because it's sent by instant messages, it might be possible to force each infected machines to send the malicious payload to a whole new set of Macs, causing the attack to grow exponentially.

Maddern didn't say what interaction is required on the part of the victim, and he didn't immediately respond to an email seeking clarification. His blog post says he notified Skype of the vulnerability more than a month ago, and that he will withhold specific details until a patch is released to prevent malicious attacks. ®

The headline in this article was updated to correct the nature of the vulnerability. It remotely gives shell access.


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: skype
Navigation: use the links below to view more comments.
first 1-2021-37 next last

1 posted on 05/06/2011 4:33:51 PM PDT by Swordmaker
[ Post Reply | Private Reply | View Replies]

To: ~Kim4VRWC's~; 1234; 50mm; Abundy; Action-America; acoulterfan; AFreeBird; Airwinger; Aliska; ...
Mac Skype users... this may be a first... Skype worm possible... may be the first Mac OSX Worm... PING!

Please, No Flame Wars, Discuss technical issues, software, and hardware.
Don't attack people!

Don't respond to the Anti-Apple Thread Trolls!
PLEASE IGNORE THEM!!!


Apple Security Alert Ping!

If you want on or off the Mac Ping List, Freepmail me.

2 posted on 05/06/2011 4:35:43 PM PDT by Swordmaker (This tag line is a Microsoft product "insult" free zone.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker
Mac Skype users... this may be a first... Skype worm possible... may be the first Mac OSX Worm... PING!
It remotely gives shell access.
What are the limitations of "shell access?"

3 posted on 05/06/2011 4:49:39 PM PDT by conservatism_IS_compassion (DRAFT PALIN)
[ Post Reply | Private Reply | To 2 | View Replies]

To: conservatism_IS_compassion
What are the limitations of "shell access?"

Not much limitation... user access. So don't run as administrator. This is not good.

Why is Skype running data in an executable area??? That is stupid and unforgivable!

4 posted on 05/06/2011 4:54:52 PM PDT by Swordmaker (This tag line is a Microsoft product "insult" free zone.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: conservatism_IS_compassion

Better idea... don’t run Skype...


5 posted on 05/06/2011 4:55:36 PM PDT by Swordmaker (This tag line is a Microsoft product "insult" free zone.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Swordmaker

I am actually amazed Skype could even do that. I find Apple products usually are not as loose as that.


6 posted on 05/06/2011 4:56:47 PM PDT by CodeToad (Islam needs to be banned in the US and treated as a criminal enterprise.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Swordmaker

***So don’t run as administrator. This is not good.***

So what do you do if you’re an only user and have to be administrator?


7 posted on 05/06/2011 5:06:29 PM PDT by kitkat ( I sure HOPE that it's time for a CHANGE from Obama.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Swordmaker

The update says:

“...a hotfix for the vulnerability was released in mid April.

‘As there were no reports of this vulnerability being exploited in the wild, we did not prompt our users to install this update, as there is another update in the pipeline that will be sent out early next week,’ Skype’s Adrian Asher wrote.

He added:
This vulnerability, which they blogged about earlier today, is related to a situation when a malicious contact would send a specifically crafted message that could cause Skype for Mac to crash. Note, this message would have to come from someone already in your Skype Contact List, as Skype’s default privacy settings will not let you receive messages from people that you have not already authorized, hence the term malicious contact.”


8 posted on 05/06/2011 5:06:37 PM PDT by Leonard210 (Tagline? We don't need no stinkin' tagline.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

All I can find - that it messes up skype on the “affected computer”? So - “self-propagating” means that a user has to manually send it to another user? I guess I don’t understand...

Also - this is a problem with Skype’s code, not Apple’s... Yes?


9 posted on 05/06/2011 5:30:36 PM PDT by TheBattman (They exchanged the truth about God for a lie and worshiped and served the creature...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Why would you skype when you can facetime?


10 posted on 05/06/2011 5:35:44 PM PDT by brytlea (Trying to think of something worth the waste of a keystroke...)
[ Post Reply | Private Reply | To 5 | View Replies]

To: kitkat
So what do you do if you’re an only user and have to be administrator?

You don't have to be the administrator even if you are the only user. Go into system preferences, select Accounts, create a new administrator user (give it an imaginary, difficult but memorable name such as "Senat0rF0gh0rnLegh0rn" [those are zeros where the 'Os' are, just don't use "Admin"!], and a hardened password that you won't forget), make that account an administrator. Turn on Fast User Switching in Login Options (that's at the bottom of the user list)... with the Name option selected. I'd turn off Automatic login. Now Log Off your account. Log into the new Administrator. Change your usual account to Standard User. Lock the Accounts Pane by clicking on the padlock in the lower left corner. Log Off the new Administrator account...

Log back into your usual account and continue your usual operations. You can still add software and install stuff, but you will have to provide the new Administrator name and password when you need to do that... a much safer way of operating. You can always switch to the Administrator for long jobs requiring administration by clicking on your name on the upper right of the menu bar and selecting the Admin account... and logging on. Always remember to log off the Admin account when not using it.

11 posted on 05/06/2011 5:37:57 PM PDT by Swordmaker (This tag line is a Microsoft product "insult" free zone.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Swordmaker; conservatism_IS_compassion
Better idea... don’t run Skype...

It's my understanding that this affects Skype 5, the latest version. The older versions are not affected. Still, very stupid on Skype's part.

12 posted on 05/06/2011 5:42:41 PM PDT by stripes1776
[ Post Reply | Private Reply | To 5 | View Replies]

To: Swordmaker

Well that sucks, I just loaded it to see my grandsons who are in Germany with their dad who is stationed there.


13 posted on 05/06/2011 5:57:08 PM PDT by MileHi ( "It's coming down to patriots vs the politicians." - ovrtaxt)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker
...a Skype exploit that allows him to remotely gain shell access on a targeted Mac.

Unless I'm missing something, shell access (SSH) would have to have been previously enabled on the target Mac.

14 posted on 05/06/2011 6:01:06 PM PDT by 6SJ7 (atlasShruggedInd = TRUE)
[ Post Reply | Private Reply | To 1 | View Replies]

To: stripes1776
It's my understanding that this affects Skype 5, the latest version. The older versions are not affected. Still, very stupid on Skype's part.

Sigh... Adding insult to injury. I'm a Mac and Skype user and I hate the latest version of Skype! Unfortunately, I'm not the most computer-literate person in the world (hence my preference for Macs) and I need to figure out how to ditch this current "upgrade" of Skype and bring back my old version.

I really, really hate the latest Skype upgrade! Did I mention that I really hate this latest version of Skype?

15 posted on 05/06/2011 6:02:03 PM PDT by Gena Bukin
[ Post Reply | Private Reply | To 12 | View Replies]

To: TheBattman
Also - this is a problem with Skype’s code, not Apple’s... Yes?

Yes, but Apple should prohibit the access that Skype is using...

16 posted on 05/06/2011 7:38:56 PM PDT by Swordmaker (This tag line is a Microsoft product "insult" free zone.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: 6SJ7
Unless I'm missing something, shell access (SSH) would have to have been previously enabled on the target Mac.

Most likely true... and unless you have activated ROOT not too dangerous.

17 posted on 05/06/2011 7:40:17 PM PDT by Swordmaker (This tag line is a Microsoft product "insult" free zone.)
[ Post Reply | Private Reply | To 14 | View Replies]

To: Gena Bukin
I really, really hate the latest Skype upgrade! Did I mention that I really hate this latest version of Skype?

Uh, no, would you care to repeat that?

18 posted on 05/06/2011 7:41:08 PM PDT by Swordmaker (This tag line is a Microsoft product "insult" free zone.)
[ Post Reply | Private Reply | To 15 | View Replies]

To: Gena Bukin
I'm a Mac and Skype user and I hate the latest version of Skype! Unfortunately, I'm not the most computer-literate person in the world (hence my preference for Macs) and I need to figure out how to ditch this current "upgrade" of Skype and bring back my old version.

Do you still have the old installation file for Skype in the Downloads folder (or possibly in the Trash folder)? If so you can go to the Applications folder and drag Skype to the Trash. Then click on the old installation file to install the old version.

19 posted on 05/06/2011 7:48:17 PM PDT by stripes1776
[ Post Reply | Private Reply | To 15 | View Replies]

To: Leonard210
Skype’s default privacy settings will not let you receive messages from people that you have not already authorized, hence the term malicious contact.”
Unless I've been stupid and changed that default, I wouldn't put too much store by that - I've had some spam in Skype messenger.

20 posted on 05/06/2011 10:19:57 PM PDT by conservatism_IS_compassion (DRAFT PALIN)
[ Post Reply | Private Reply | To 8 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-37 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson