Latest news

The instructions for the exploitation of the bug that allows it were found on Pastebin by the Skype-Open-Source blogger, who tested them and confirmed they were effective.
The preparation for the uncomplicated execution of the process requires the download of a modified version of the Skype VoIP software and the addition of a few registry keys to turn on the creation of a debug-log file.
Next, the snooper must move to add the target's contact name to Skype and click on the user to view his information card. The action will make the IP addresses appear in the log file, and can be used to discover the city and country where the user is based, as well as his ISP.
H-Online confirmed that the exploit works and that even when a user was logged in with multiple clients, the IP addresses for all the clients were visible.
Shortly after they also discovered a web service (skype-ip-finder.tk) that offers the Skype users' IP address information without the need to have a valid Skype account.

One must simply enter the target's Skype username, solve a CAPTCHA, and get the IP address.
According to Neowin.net, Microsoft has reacted to the news by saying that an investigation into the matter is ongoing.
"This is an ongoing, industry-wide issue faced by all peer-to-peer software companies. We are committed to the safety and security of our customers and we are takings measures to help protect them," stated Adrian Asher, director of product security for Skype.


Spotlight

IT security jobs: What's in demand and how to meet it
Posted on 15 May 2013. | Let's say you want a career in information security, where do you start? What credentials do you need? What are employers looking for? Read on to find some answers.

Is Microsoft is reading your Skype communications?
Posted on 15 May 2013. | The question of whether Skype allows U.S. intelligence and law enforcement agencies to access the communications exchanged by its users has still not been adequately answered by Microsoft.

Internet Explorer best at blocking malware
Posted on 14 May 2013. | While Chrome’s malware download protection improved significantly, Internet Explorer 10 continues to outperform the other browsers with a block rate of 99.96%.

Researcher refuses to help Saudi telco to spy on people
Posted on 14 May 2013. | You would think that a Saudi Arabian telecom firm interested in monitoring its users' mobile communications would not be asking a well-known pro-privacy researcher for help, but you would be wrong.

Malicious browser extensions are hijacking Facebook accounts
Posted on 13 May 2013. | Facebook users - especially those in Brazil - are being targeted with malicious browser extensions trying to hijack Facebook profiles, warns Microsoft.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





