A security flaw in Skype’s peer-to-peer voice-over-IP (VoIP) software has been closed, thanks to diligent work by a Kiwi security expert.Brett Moore, chief technology officer of Australian independent security company Security-Assessment.com, uncovered the flaw in Skype’s software. Skype is now advising users to upgrade to its latest version to fix the bug.Moore said the type of vulnerability found in Skype is fairly common with applications that interact with Internet browsers.“We have previously discovered this type of vulnerability in two separate programs, and there are public releases of similar issues in other programs,” he said. The security flaw manifests itself through the way Skype handles uniform resource identifiers (URIs) that point to names or addresses referring to resources.Security-Assessment.com discovered that with one type of URI handler installed by Skype, it was possible to include additional command-line switches. One such switch will set up a file transfer session that will allow data written to the local hard disk to be sent to another Skype user. For an attacker to successfully exploit the flaw, he must know the exact name and location of the file he wants to transfer on the victim’s computer. The attacker must also authorize the victim, Security-Assessment.com said. This is easily done, with the attacker simply adding the victim to his contact list.There are further URI handler flaws in Skype, Security-Assessment.com said. Other command-line switches could be exploited to manipulate or obtain victims’ Skype user credentials.Security-Assessment.com regularly performs application testing for its customers or as part of its own R&D, said Moore.“In this case, we were reviewing Skype as part of a larger VoIP research program. Often we will notice what appears to be the potential for a vulnerability and investigate further.”Moore said that a targeted attack is required to exploit this particular vulnerability.“The person to be exploited must be specifically selected, and they must be convinced to browse to a webpage or click on a hyperlink,” he said. “While there are certain mitigating factors involved in a successful attack, the potential is there for an attacker to steal confidential files, including the user’s Skype configuration.” Theft of the Skype configuration could lead to further attacks such as ID theft, or listening in on users’ conversations, he said.“The best solution is to install the vendor-supplied update,” Moore said.“As always, users should be aware of malicious e-mails and e-mail attachments.”When discovering security flaws, the company works directly with the vendor involved to help secure the software, Moore said. “Skype was very happy to work with us on this issue. They phoned me shortly after receiving our security report and kept me up to date with their progress,” he said.“During the patch development, they called me to discuss further details, and sent me a pre-release install to verify that they had fixed the problem.”Moore was a little surprised to find the bug in Skype because it has already undergone independent security reviews, and also because of the large numbers of users.-Ulrika Hedquist and Juha Saarinen, Computerworld New Zealand OnlineFor related news coverage, read Aussie Firm Finds Skype Flaw.Check out our CIO News Alerts and Tech Informer pages for more updated news coverage. Related content feature Expedia poised to take flight with generative AI CTO Rathi Murthy sees the online travel service’s vast troves of data and AI expertise fueling a two-pronged transformation strategy aimed at growing the company by bringing more of the travel industry online. By Paula Rooney Jun 02, 2023 7 mins Travel and Hospitality Industry Digital Transformation Artificial Intelligence case study Deoleo doubles down on sustainability through digital transformation The Spanish multinational olive oil processing company is immersed in a digital transformation journey to achieve operational efficiency and contribute to the company's sustainability strategy. By Nuria Cordon Jun 02, 2023 6 mins CIO Supply Chain Digital Transformation brandpost Resilient data backup and recovery is critical to enterprise success As global data volumes rise, business must prioritize their resiliency strategies. By Neal Weinberg Jun 01, 2023 4 mins Security brandpost Democratizing HPC with multicloud to accelerate engineering innovations Cloud for HPC is facilitating broader access to high performance computing and accelerating innovations and opportunities for all types of organizations. By Tanya O'Hara Jun 01, 2023 6 mins Multi Cloud Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe