📜 ⬆️ ⬇️

? Skype has turned into a sad likeness ... and a product that allows you to get full access to your system? Is there any hope?

Sorry, boiling! Today’s repeated incident with loading of 500+ MB of parasitic traffic in 15-20 minutes, which I did not order, was the last point when I seriously thought about demolishing the messenger, which I used almost from the very beginning of its creation and refuse from further use. My entire limit of mobile LTE Internet access to 1 GB per day was successfully eaten by Skype, the operator limited the speed to 300 Kbps and you need to wait until the package is updated (you can’t pay and reorder before the deadline without changing the tariff, the 21st century is outside! ). But the reason for my anger is not in this, but in the fact that I am paranoid in the area of ​​security. Skype is now trying to infect me Mac? Track my details? Or are these tricks of hackers who try to hack me through Skype? But in the beginning, before I reveal the facts, I want to recall the history of this mayhem.

A few years ago, I switched to a Mac, and in turn, a few years ago, Skype switched to Microsoft. What irony! Why, why not Skype was bought by Apple? Or any other company that respects its customers and at least does not make it worse! I'm not saying that it would be nice to do better in general, especially against the background of competition with other messengers, such as Telegram, which is also something to criticize, but my biggest problem is there - I can not copy the text beyond the scrolling area, also conveniently, as in Skype, it is necessary to copy in parts.

My opinion is that Microsoft can hardly do anything normally from what comes up with new things; this also applies to their own products, not just purchased ones. A good example is the server Windows licensing system, I still remember how they changed the terms of the SPLA program under the Windows server licenses that we had to use. They didn’t come up with anything better than simply revoking standard license types, raising prices and entering licenses “for the processor”, probably with the aim of increasing revenue. And what do you think happened? That's right, another tryndets! Our clients who installed them and for which they and we successfully paid Microsoft for more than 2 years under the SPLA program, the licenses continued to work, somewhere on 100+ servers, with one difference that they were not completely legal ... Microsoft was one with a flick of the wand they stopped charging us for them, breaking the contract for them. What can I say, even the money is not able to take ... Of course, we did not decide to renew any SPLA with them and now we send clients for licenses to partners and do not want to bear responsibility for the curvature of their program, especially the licensing fees, especially after in Ukraine, they introduced “wonderful” payment rules for “partners” (then we still worked in Ukraine), making working with them for many impossible and unprofitable, and most importantly - very “convenient”. As a result, the customers to whom we sold their software continued to use their product for free, because we were only then intermediaries and provided dedicated services in various data centers and were not responsible for the software and so on, and it’s worth making efforts to pay for such a wonderful "service" - not seen. However, as well as data centers that did not care about this software until Microsoft started imposing a ban on installing trial versions without a key, violating the rights of private users. But now this is not about it ... It just got sore, because I speak globally, about the general approach to business, to partners and to people.
')
Microsoft, well tell me? Can you do anything normal? Why does everything that falls into your hands turn into some kind of dreary similarity ... (substitute the word yourself, I don’t like to swear, but I really want to)? In the beginning, the total lack of support for Skype in the normal form for Mac, the application just hellishly devoured the CPU and disrupted the harmony of using the Mac entirely (a bad method to destroy competitors, users would rather give up on Skype than on Mac), because the battery instead of 10 hours held a maximum of 2 Then, it would seem that you let go ... They finally made a more or less sane version that did not lead to a catastrophe. Message loss when using the messenger on the IPhone. Sometimes for two days problems with the lack of message delivery, synchronization, and those. support that answered nothing and in general it is not clear where it was and how it worked. Once upon a time we had the imprudence to start using Skype for communication between departments, and once it completely paralyzed us .

In 2018, someone apparently ate some bad mushrooms, as it was made just sucks.

The usual Skype and me, which was originally built as a distributed solution, when messages and communications were carried out directly between users, since 2011 (the moment of acquiring Skype for $ 8.5 billion ) began to be serviced exclusively through Microsoft servers, recording users' messages, and in 2018, at the same time, he lost a number of useful functions, let's meet them with a minute of silence:


Perhaps I missed something, correct it, if I suddenly introduced something by mistake. Later, some of them were still restored:


And now it is proposed to send developers wishes on account of the functions that you may need.

Also, such interesting functions were made from Skype:


Security hole


I, alas, faced with the fact that Skype began to consume excessive traffic recently. Of course, I understood that no update for 500+ MB could be uploaded, and when I closed the messenger, the download stopped and did not restart after the restart, but after 10-12 hours I noticed the situation again. And the main traffic was incoming, although outgoing attended. Then I became completely restless.

I tried to execute the following commands (just enter them in any dialog box and press Enter, the other person will not see this message):

/ showplaces - see all devices on which your Skype is now turned on, the result showed no other active versions of macWrap: 1432 / 8.32.0.44 / SkypeX - isActive: true, Subs: 1: HttpLongPoll

And just in case:

/ remotelogout - exit from Skype from all devices except this one.

It's funny, but Skype is so buggy program that sometimes the use of these commands gives “Invalid command; try again".

The fact is that after trying to check the activity of the program on other devices, though this was not done at the moment when incoming traffic went (alas, after a restart, the situation did not happen again), any suspicious activity stopped.

So now I think whether the attacker managed to get access to my system or not, or noticed that I was checking what Skype was doing in the system and stopped working, because there is reason to believe that there is, because recently, as it turned out, an article appeared: Skype can't fix a nasty security bug without a massive code rewrite :
Researcher Stefan Kensek discovered a serious vulnerability in Microsoft Messenger that allows attackers to gain full access to the victim's operating system. The scheme works on the principle of “hijacking DLL libraries” and redirects the installer of Skype updates to malicious code, rather than to the necessary update files. When installing a new version of Skype uses a separate executive file for its own update component. It is this process that can be easily exploited for malicious purposes.

An attacker could “hijack” the update process by loading the infected DLL into a temporary folder. A fake library impersonating a system and safe DLL file that a regular user without administrative rights (UXTheme.dll, for example) can edit. The installer first of all detects a malicious DLL and installs the code of the attackers on the victim’s system. It is done.

The researcher stresses that in Windows, you can use several methods of “hijacking DLL libraries”. He also noted that other operating systems, such as macOS and Linux, may also be subject to similar attacks. Vulnerability can be easily exploited for a variety of purposes, and in the case of a successful execution, the hacker gets access to the level of “Administrator on steroids”. Thus, he can do anything with the victim's computer.

Microsoft found out about security vulnerabilities back in September last year, but the Software giant decided not to fix this problem, since its treatment would require rewriting a large amount of code inside the application. Instead, Microsoft decided to delay the patch until the release of the new version of Skype, to which it sent all its resources.

What is the status of this problem now, I, alas, do not know, but the behavior of Skype is frankly strange and turned on without observation, I no longer leave the messenger. It's a shame that Microsoft did not inform me, as a user, about this problem and I did not even suspect that I could suffer serious losses due to the use of their software.

Rating drop


Not surprisingly, the ratings began to fall, because from a conservative messenger, Microsoft engineers made some kind of youth Snapchat, which personally impresses me only by the level of degradation of its users, perhaps because I’m over 30, or because I highly value every hour of my life. Of course, this could not please those who are accustomed to the old Skype. As a result, ratings on the AppStore fell from 3.5 to 1.5 for the United States and from 3 to 1.5 for Russian users. Although the situation in the Play Market was slightly better in terms of ratings, the decline was also noticeable, despite the fact that, unlike the AppStore, it shows the overall rating, and not the average lately.

Is there a future?


Microsoft is a very conservative company and is not used to hearing and listening to its users, but as always it gives in to newfangled trends that have flooded everything that I, fortunately, do not use - Facebook, Instagram, WhatsApp and other sad ... because the main problem is Skype It was not at all that it was impossible to impose a mask or send a gif or a personal photo without the ability to save it, but above all in cumbersome, buggy and awkwardness.

Of course, Microsoft has the right to destroy Skype, because they bought it. But I, as a user who used it from the very beginning and even paid for a subscription, have the right to express their opinion on this issue and warn Internet users against using the product without proper attention (or using as a whole), because Skype has become not only uncomfortable , but it may well be a threat, given its strange and uncontrollable behavior. And there is simply no chance of getting operational support, as one user said:

“You start to search on the site ... software where to write about glitches and find the answer - write to the community! To the community ...! Awesome support, you all burn in hell ", sometimes, however, comes to the fact that the forums can be found calls for help even from pensioners:

“Understand ... But, I'm a pensioner, I sit, read, and nothing works! I click on the contact rights. button - does not open, nothing, just do not react! I've been sitting here for more than a week now, I don't communicate with anyone, and I don't find a way out. I have a T.viewer, there was no sadness - the devils pumped up / proverb / ".

Perhaps, if Microsoft led a slightly different policy towards users, a smaller amount of negative and psychedelic commercials would appear on the Internet, for some reason this product (11 million views) turned out to be one of the most popular on the Internet:


I am extremely interested in whether someone else encountered a similar problem (uncontrolled siphoning of hundreds of megabytes of traffic), what they managed to figure out and how they decided - share it in the comments, as well as your impressions of the messenger, maybe Microsoft will hear us.

Thank you for staying with us. Do you like our articles? Want to see more interesting materials? Support us by placing an order or recommending to friends, 30% discount for Habr users on a unique analogue of the entry-level servers that we invented for you: The whole truth about VPS (KVM) E5-2650 v4 (6 Cores) 10GB DDR4 240GB SSD 1Gbps from $ 20 or how to share the server? (Options are available with RAID1 and RAID10, up to 24 cores and up to 40GB DDR4).

VPS (KVM) E5-2650 v4 (6 Cores) 10GB DDR4 240GB SSD 1Gbps until December for free if you pay for a period of six months, you can order here .

Dell R730xd 2 times cheaper? Only we have 2 x Intel Dodeca-Core Xeon E5-2650v4 128GB DDR4 6x480GB SSD 1Gbps 100 TV from $ 249 in the Netherlands and the USA! Read about How to build an infrastructure building. class c using servers Dell R730xd E5-2650 v4 worth 9000 euros for a penny?

Source: https://habr.com/ru/post/426813/


All Articles