Skype vulnerability discovered by Pure Hacking
purehacking.com
purehacking.com
So don't use Skype on Mac if you can help it, and if you must use it turn off messages from sources not in your contact list.
If I had to guess, they were probably pasting back and forth JavaScript "payloads" for an XSS and broke the parser that Skype is using for formatting chat messages. Not that interesting.
Chat messages on Skype aren't exactly the most effective propogation mechanism either. Don't you have to be approved as someone's friend before they can send you a message? This probably won't be used in any massive attacks any time soon. Until then, continue to annoy your girlfriends as the author apparently did.
As far as propogation, it could definitely be effective, it all depends on how interconnected the graph of Skype friendships is. There have been many nasty worms which travelled across AIM friend lists, for example.
1) The default privacy setting in Skype is to allow anyone to send you a chat message. I know plenty of Skype users who complain to me about random chat messages, which indicates to me that they haven't changed their privacy preferences yet.
2) Regardless of the type of payload they used, "Low and behold I was able to remotely gain a shell." Remote shell. Through a Skype message. Would you give a random person shell access to your computer? It's more than interesting, it's terrible.
3) Spammers already infest the Skype network. If they discover this vuln before Skype patches it, you can fully expect that it will be exploited.
There is no mention of priviledge escalation in the article, but once you have a shell, the world is your oyster. There are bound to be exploitable services locally on the machine. Once you're in, you've got the run of the place.
HN page: http://news.ycombinator.com/item?id=656174
Edit: woops, my bad, apparently SkypeMate is independent.
Sadly the fix seems to be only for the 5.x series and there's no indication for holdouts like myself on whether 2.x is affected or not.