Skype bug gives attackers root access to Mac OS X
theregister.co.uk
theregister.co.uk
More hysterical reporting from The Register.
There's no advantage really, though, since the gksu style authentication popup system when you need admin privileges is very painless. I too doubt if many people run their Macs as root.
$ sudo passwd
Changing password for root.
New password:
Retype new password:
passwd: Unable to change the password for record root. Credential verification failed because account is disabled.
$
So there you have it: you couldn't have done it this way.That means this thing is either BS or it is an egregious bug by the Skype team. Remote code execution doesn't happen by chance.
I have no idea what the bug is, all I meant was that it wasn't completely out of the realm of possibility to have something render a payload.
Take an example from earlier today: there's a vulnerability in Exim that can allow arbitrary remote code execution (http://www.vupen.com/english/advisories/2011/1185). For anyone who doesn't know what Exim is, I refer you to Wikipedia (http://en.wikipedia.org/w/index.php?title=Exim&oldid=421...):
"Exim is a mail transfer agent (MTA) used on Unix-like operating systems. Exim is free software distributed under the terms of the GNU General Public License, and it aims to be a general and flexible mailer with extensive facilities for checking incoming e-mail.
...
A large number of Exim installations exist, especially within Internet service providers[1] and universities in the UK. Exim is also widely used with the GNU Mailman mailing list manager, and cPanel."
Great. I run skype on one of my machines (OSX) and it's now vulnerable...
If the former, I don't imagine they'll update it, and this might finally force me to grab 5.1.
Doesn't stop your machine from becoming a vector to attack other users on your contact list though.
http://www.purehacking.com/blogs/gordon-maddern/skype-0day-v...
No mention of root; only remote shell. I have a feeling this is just bad reporting on the part of The Register.
Having said that, I wouldn't give a random person off the street access to my local user account, even if they can't execute as root. Plenty of attackers would be content to rsync all your files to their server for further examination/exploitation.
http://blogs.skype.com/security/2011/05/security_vulnerabili...
I submitted here as well:
So something is not working there.
Sometimes companies release minor updates that are reflected for fresh downloads but don't have the auto-update mechanisms in existing clients to download the update --- usually to save on bandwidth costs.
However, for a security patch that seems 'unfortunate'.
Also, can someone please create a viable Skype alternative that actually works?
Also - Gmail in the browser is integrated with Google Voice and Google Chat, so you don't have to suffer through Skype's client just to chat. And in fact you can continue chatting over your phone through SMS (for free) because Google Voice is awesome.
1. Audio and Video calls do not work with "any compatible client". I have in fact never gotten them to work at all.
2. Most jabber clients are awful and buggy.
3. Jabber support in multi-protocol clients is even more awful and buggy.
4. Nobody uses it, at least over here in europe.
5. Everybody over here uses Skype. If there was a reliable way to bridge jabber<->skype then I would bite and switch again.
2 & 3. ICQ, AIM (I think), iChat, Trillian... Etc. I like all of them.
4. At least in the States everyone uses Gmail (most everyone in SV that is)
5. Skype is prevalent in the work environment, I just don't know why. It sucks pretty hard and everyone hates it.
Just my opinion, I have had great success with Gmail/Google Voice and iChat (for chat with my Gmail Jabber account)
The current version appears to have been built by the most moronic team of developers ever who knows what crap made its way into the new client.
> reported what they believed to be a zero-day vulnerability in Skype for Mac 5.x
Of course, that doesn't rule out other security holes in 2.8.x.
Also, it's obviously not "root" unless there's a separate privilege escalation bug in OS X.
If you have to accept it, then who cares, don't accept attachments from strangers.
You can set your Skype to disallow messages from accounts not in your contact list. I've had trouble with this not working in some way on Skype for Linux, though.
If you read the original post from the hack team in question, they stated the ability to at least get a local shell running as a result, so either there's something resulting in launching local file content (like an interpreter, then passing commands to it) or something able to crash Skype in an interesting and controllable way.
Given that the original authors also stated that when he tested this on his GF, she was unable to use Skype for awhile - I have a feeling it's chat related, was stored in the client chat logs, and was re-launching / re-executing whenever Skype was being opened.