Free Republic
Browse · Search
General/Chat
Topics · Post Article


1 posted on 05/06/2011 4:33:51 PM PDT by Swordmaker
[ Post Reply | Private Reply | View Replies ]


To: ~Kim4VRWC's~; 1234; 50mm; Abundy; Action-America; acoulterfan; AFreeBird; Airwinger; Aliska; ...
Mac Skype users... this may be a first... Skype worm possible... may be the first Mac OSX Worm... PING!

Please, No Flame Wars, Discuss technical issues, software, and hardware.
Don't attack people!

Don't respond to the Anti-Apple Thread Trolls!
PLEASE IGNORE THEM!!!


Apple Security Alert Ping!

If you want on or off the Mac Ping List, Freepmail me.

2 posted on 05/06/2011 4:35:43 PM PDT by Swordmaker (This tag line is a Microsoft product "insult" free zone.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Swordmaker

The update says:

“...a hotfix for the vulnerability was released in mid April.

‘As there were no reports of this vulnerability being exploited in the wild, we did not prompt our users to install this update, as there is another update in the pipeline that will be sent out early next week,’ Skype’s Adrian Asher wrote.

He added:
This vulnerability, which they blogged about earlier today, is related to a situation when a malicious contact would send a specifically crafted message that could cause Skype for Mac to crash. Note, this message would have to come from someone already in your Skype Contact List, as Skype’s default privacy settings will not let you receive messages from people that you have not already authorized, hence the term malicious contact.”


8 posted on 05/06/2011 5:06:37 PM PDT by Leonard210 (Tagline? We don't need no stinkin' tagline.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Swordmaker

All I can find - that it messes up skype on the “affected computer”? So - “self-propagating” means that a user has to manually send it to another user? I guess I don’t understand...

Also - this is a problem with Skype’s code, not Apple’s... Yes?


9 posted on 05/06/2011 5:30:36 PM PDT by TheBattman (They exchanged the truth about God for a lie and worshiped and served the creature...)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Swordmaker

Well that sucks, I just loaded it to see my grandsons who are in Germany with their dad who is stationed there.


13 posted on 05/06/2011 5:57:08 PM PDT by MileHi ( "It's coming down to patriots vs the politicians." - ovrtaxt)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Swordmaker
...a Skype exploit that allows him to remotely gain shell access on a targeted Mac.

Unless I'm missing something, shell access (SSH) would have to have been previously enabled on the target Mac.

14 posted on 05/06/2011 6:01:06 PM PDT by 6SJ7 (atlasShruggedInd = TRUE)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Swordmaker
Hi Swordmaker,

Well, the vermin are beginning to crawl out of the woodwork at last. As they say, it is not at all the beginning of the end, but it is the end of the beginning. Macs are now officially a target species. Hurrah! (It is a milestone of sorts, eh?)

From TFA:

> Maddern didn't say what interaction is required on the part of the victim, and he didn't immediately respond to an email seeking clarification.
I'll be interested to learn if it circumvents the usual Mother-may-I prompts for administrative access password.

Now, let's see.... I use Skype all day, every day, on both Mac OS-X and Windows 7, and occasionally on my iPod Touch. I cannot function at work without Skype these days, because a few hundred people contact me on skype every week, and won't or can't use other means (email, phone).

And naturally, I'm up-to-date on Skype releases, so I'm using Version 5 everywhere.

Drat. Damned vermin.

So what gets sent, really? I read this:

> ...sending a specially manipulated attachment in an instant message...
Do they mean dropping a file into the chat? I do that occasionally; people do that occasionally to me. But I never chat, much less accept files from, unknown people. I suppose someone could manage to masquerade as a user I know...

Yeeeechhhh!

Well, Skype will patch the bug, and Apple will close the hole, and all will be well until the next one...

21 posted on 05/06/2011 10:24:30 PM PDT by dayglored (Listen, strange women lying in ponds distributing swords is no basis for a system of government!)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Swordmaker

>> It remotely gives shell access.

Impressive access for a chat client. What else can it do?


25 posted on 05/07/2011 1:42:27 AM PDT by Gene Eric (*** Jesus ***)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Swordmaker; SunkenCiv; Ernest_at_the_Beach; ShadowAce; dayglored
So I decided to test another mac and sent the payload to my girlfriend.

Hey now.

26 posted on 05/07/2011 3:50:09 AM PDT by martin_fierro (< |:)~)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: All
Skype releases fix.
34 posted on 05/10/2011 12:49:24 PM PDT by Swordmaker (This tag line is a Microsoft product "insult" free zone.)
[ Post Reply | Private Reply | To 1 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson