📜 ⬆️ ⬇️

Disclose the biggest secret of Skype


The link contains the sources of the obfuscated RC4 encryption algorithm , which Skype uses to encrypt traffic.

Upd from enrupt.com:

The published algorithm is EVERYTHING you need to decrypt traffic between clients and supermodes. There is no key. Totally. Because this is the level of obfuscation, designed so that others could not make their clients for the Skype protocol. Therefore, this algorithm was protected as much as possible. Monopoly Skype, which is no more.
Do not worry if Skype changes the protocol, it took us only a few days to get it. We will immediately release an update.
')
Our publication does not affect the privacy of calls, messages or file transfers. They are protected using AES-256, and key negotiation occurs using 1024-bit RSA. So do not panic)

Next month we may put a program that decrypts UDP Skype packets and checks their CRC :)

For more than 10 years, Skype offered us protection that we knew nothing about. The so-called security through obscurity. Obscurity in this case was very good, because in all this time almost no one has figured out how it all works, despite the abundance of Skype binaries. And those who could, for obvious reasons, did not publish their work.

One of the western companies engaged in cryptography, a couple of months ago, the results of the Skype study, which were abruptly used by hackers and spammers, leaked, Skype began to abuse them and, as a result, the company posted them to everyone.

This is not a turnkey solution. How to listen to Skype traffic using this feature they will tell in Berlin at The 27th Chaos Communication Congress (27C3)

PS Not all encryption on Skype is so simple and most of it is implemented according to all the rules.
Skype has 7 types of call encryption: Servers use AES-256, supernotes and clients use 3 different types of RC4: old TCP RC4, old UDP RC4 and new, based on DH-384 TCP RC4.
Customers also use AES-256 over RC4.

Everything is quite confusing, but at the conference they promise to sort everything out.

Well) All secret, as they say ...

The original is here . God bless their god from habraeffekta.

By the way, the same office developed the enRupt algorithm, which, by its characteristics, does all the rest) About it some other time.

UPD:
Put the source here

Source: https://habr.com/ru/post/98546/


All Articles