Launched a new section Breaking News Around The Globe. Did you miss any of volcanic news? Be updated before the news flashes on your news channel.
Learn How to Earn Online Money. Speak Asia Online Money Earning.

Receive Daily Updates

Enter your email address:

Saturday, May 7, 2011

Skype 0day vulnerability: Skype bug gives root access to Mac OS X

Skype 0day vulnerability: Skype bug gives root access to Mac OS X: Discovered by Pure Hacking
Extremely wormable and dangerous
Mac users running Skype are vulnerable to self-propagating exploits that allow an attacker to gain unfettered system access by sending a specially manipulated attachment in an instant message, a hacker said. The long and the short of it is that an attacker needs only to send a victim a message and they can gain remote control of the victim's Mac, Gordon Maddern of Australian security consultancy Pure Hacking blogged on Friday. It is extremely wormable and dangerous. Reynaud said there are no reports that the Skype vulnerability is being actively exploited. Maddern said he stumbled on the critical flaw by accident. About a month ago I was chatting on skype to a colleague about a payload for one of our clients, he wrote. Completely by accident, my payload executed in my colleagues skype client. So I decided to test another mac and sent the payload to my girlfriend. She wasn't too happy with me as it also left the her skype unusable for several days. He then set out to write proof-of-concept attack code that used payloads borrowed from the Metasploit exploit framework. The result: a Skype exploit that allows him to remotely gain shell access on a targeted Mac. Because it's sent by instant messages, it might be possible to force each infected machines to send the malicious payload to a whole new set of Macs, causing the attack to grow exponentially. Maddern didn't say what interaction is required on the part of the victim, and he didn't immediately respond to an email seeking clarification. His blog post says he notified Skype of the vulnerability more than a month ago, and that he will withhold specific details until a patch is released to prevent malicious attacks.

1 Visitor Reactions & Comments:

Amarjit Singh said...

thanks all for sharing this post