📜 ⬆️ ⬇️

Skype vulnerability allows you to determine the IP address of a particular user.


Skype's security hole allows you to determine the user's IP address not just during a call, but even if he does not answer the call and the connection is not established.

The author of the study, computer science professor Keith Ross (Keith Ross) of the Polytechnic Institute of the University of New York, explains the essence of the vulnerability to the ability to establish a direct connection (P2P) between the attacked computers and the hacker's computer, which allows besides information such as Skype ID to get an IP address user

To test their observation, the team of experts initiated about 10,000 video calls to random Skype users, after which it was determined that user data can be obtained even if he does not answer the call and the connection is not established.
')
Interesting is that the safety study, which established the presence of the gap, was made by Professor Ross back in 2010 and Skype itself was notified of it at the same time. However, the professor says, he still hasn’t received any answer, although "... to identify the IP address of the Skype subscriber can" any college-level hacker. "

At the request of the publication that reported the flaw publicly, a Skype representative promised to take action on the problem as soon as possible.

[ Source ]

Source: https://habr.com/ru/post/133963/


All Articles