Share

Related Links

Related Stories

  • Skype - not as secure as you might think
    Although VOIP afficionadoes are wont to promote the encrypted nature of Skype Internet telephony calls, it's now becoming accepted that the use of a compressed data mode within Skype opens the gates to pattern recognition and slow, but steady, text-based decoding of the voice transmissions as a result.
  • Comment: Crimeware and current hot threats
    ESET’s David Harley reviews both the tried-and-true as well as latest methods online criminals are using to steal information, and your money
  • Searching for Security
    With more than 30 000 web pages being compromised every day, search engine results could increasingly lead to malware infection. Kari Larsen asks what the search engines are doing to mitigate security threats, and how users can protect themselves
  • Search for security
    With more than 30 000 web pages being infected every day, search engine results could increasingly lead to malware infection. Kari Larsen asks what the search engines are doing to mitigate security threats, and how users can protect themselves.
  • An injection of new ideas
    Securing IT means coping with Donald Rumsfeld’s ‘known unknowns’ – expected attacks whose nature is a surprise. Concepts from medicine, game theory and crowd sourcing may help, finds Danny Bradbury

Top 5 Stories

News

Security vendor identifies Skype exploit in the wild

17 June 2010

M86 Security has come across active exploitation of a Skype ActiveX vulnerability that affects older versions of the popular VoIP service.

The Skype weakness demonstrated by M86 takes advantage of an unspecified vulnerability addressed by an updated version of VoIP service released in October 2009.

According to a blog posting from M86 SecurityLabs researcher Daniel Chechik, it takes advantage of a security hole in a Skype plug-in called EasyBits Extras Manager, which Skype designed to prevent the illegal dissemination of licensed commercial software.

“Malicious code exploits a Skype ActiveX vulnerability using primitive obfuscation techniques in order to bypass anti-virus security solutions”, noted Chechik’s posting. “We can confirm this exploit code works successfully against vulnerable Skype installations.”

Indeed, according to M86’s submission of the code to analytic website Virus Total, the Skype exploit is detected by only 2.44% of anti-virus engines.

Ed Rowley, product manager at M86, lent his view as to why this exploit has such dismal anti-virus recognition: “The low AV detection rate is due to a combination of factors, but it basically boils down to dynamic code obfuscation rendering, in this case, signature-based AV redundant. Although AV signature-based engines remain a very important and efficient security tool when it comes to dealing with known threats”, he added.

“Cyber-criminals employ a number of techniques to hide the actual intent of the code, from encryption to dynamic code, where parts of the code are randomized so that they appear different each time the page is visited, making signature generation and heuristic analysis more difficult”, Rowley continued.

Chechik believes the real problem here is not with anti-virus detection but a lack of updated software, as fully updated Skype users are not vulnerable to this attack. “Many users continue to run outdated applications for months, even years, and these old versions continue to be exploited by cybercriminals”, said the M86 researcher.

This article is featured in:
Application Security • Internet and Network Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.