This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Skype worm...

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.php?storyid=1952
Last Updated: 2006-12-18 23:54:28 UTC

> http://www.symantec.com/enterprise/securit…-121910-5339-99
Updated: December 19, 2006 10:20:42 AM GMT
[See: "TECHNICAL DETAILS"…]
W32.Chatosky - Risk Level 1: Very Low

> http://www.symantec.com/enterprise/securit…gets_skype.html
December 18, 2006 09:52 PM

> http://www.websense.com/securitylabs/blog/….php?BlogID=101
Dec 18 2006 3:08PM

NOTE: http://en.wikipedia.org/wiki/Skype
"Skype is a proprietary peer-to-peer Voice over IP (VoIP) network founded by the entrepreneurs Niklas Zennström and Janus Friis, also founders of the file sharing application Kazaa…"

:ph34r:
FYI…

Malicious Code: Skype Trojan Horse
- http://www.websense.com/securitylabs/alert…php?AlertID=716
December 19, 2006
"…After investigation we have discovered that this is -not- a self propagating worm and is actually a Trojan Horse. After discussions with the very helpful Skype security team, the behavior of this Trojan using the Skype API is as per the specifications of the API. The end-user who is running Skype does get notified that a program is attempting to access it and must acknowledge it.
*there is -no- vulnerability in Skype at this time that has been uncovered*
For more details on the Skype API see
https://developer.skype.com/Docs/ApiDoc/Ove…f_the_Skype_API ."

:ph34r:
FYI…

- http://www.informationweek.com/shared/prin…cleID=196700896
Dec 19, 2006 01:43 PM
"…"The code isn't a worm," says Dan Hubbard (Websense)… "A user with Skype will get a message to download a program from a URL included in a chat message," says Hubbard. "If they click on that, a program runs in the background, then injects itself into the Explorer process. It looks like the Trojan is designed to grab forms and passwords from the browser"… The servers the attacker used to download malicious code to infected computers are now down, Hubbard confirmed…"

> http://www.f-secure.com/weblog/archives/ar…6.html#00001054

!