English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

New Skype vulnerability allows hijacking of your account

Costin Raiu
Kaspersky Lab Expert
Posted November 14, 10:33  GMT
Tags: Microsoft, Skype
0.6
 

Last night, reports have appeared on several Russian forums regarding a Skype account hijacking exploit. The information has been made available on several Russian blogs and is now actively exploited in the wild.

The exploit, which has been available for two months already, takes advantage of the Skype password reset feature. This allows you to reset the password of somebody else's account, as long as you know the e-mail address associated with their main Skype account.

To protect yourself against this exploit, we recommend changing the e-mail address associated with the Skype account to a new, never-before-used address. This should prevent hackers from guessing your e-mail associated with Skype and hijacking it.

Update [14-Nov-2012 10:19am UTC]: the "feature" which allows this bug to work has been temporarily disabled by Microsoft. You can read the Microsoft statement [here].

Follow me on Twitter


3 comments

Oldest first
Threaded view
 

loveislight

2012 Nov 19, 09:41
0
 

nice

Reply    

twinkletoes

2012 Nov 20, 17:13
0
 

RE Update: did you mean Skype, not Microsoft?

Reply    

Costin Raiu

2012 Nov 21, 12:14
0
 

Re:

Thanks for the comment! Skype was actually purchased by Microsoft in May 2011.

Reply    
If you would like to comment on this article you must first
login


Bookmark and Share
Share

Analysis

Blog