Friday, May 01, 2009

New Skype vulnerability discovered

April 2009

A new phishing attack demonstrated by researchers at Secure Science allows hackers to gain access to a user’s Skype client and then pose as a financial institution or proxy outbound calls. The technique is called “SkypeSkrayping” and is similar to a phishing attack only a bit more interactive. According to the report, sing either an inline frame (“iframe”) or image (“img”) tag, attackers could add a Specific Call Forwarding Number, grant attacker ability to receive the victim’s incoming call, obtain a Skype-To-Go Number, and/or grant an attacker the ability to access victim’s voicemail, speed dial, and outbound calling via Spoofed Caller-ID. The company’s IT department is working on resolving the problem.

0 Comments:

Post a Comment

<< Home