What's New
Off Topix: Embrace the Unexpected in Every Discussion

Off Topix is a well established general discussion forum that originally opened to the public way back in 2009! We provide a laid back atmosphere and our members are down to earth. We have a ton of content and fresh stuff is constantly being added. We cover all sorts of topics, so there's bound to be something inside to pique your interest. We welcome anyone and everyone to register & become a member of our awesome community.

Skype targets vulnerability that compromised accounts

Jazzy

Wild Thing
Member
Joined
Jan 27, 2010
Posts
79,918
OT Bucks
308,876
[font=arial, helvetica, sans-serif]
Skype has suspended its password reset function after it emerged that a security flaw could be used to hijack user accounts.



The exploit allowed anyone with a user's email address to take over their account, and depended on Skype's policy of reminding new sign-ups of existing usernames they have previously registered when they attempt to re-register using the same email address.



The method was first posted on a Russian forum around three months ago but has only been addressed since Reddit users highlighted the issue.



Hijackers who accessed others' Skype accounts would not have been able to obtain users' credit card details, which are redacted by the voice calling service.



However, bogus users would have free reign over their account credit - and potentially further funds, if the user had enabled Skype's automatic credit top-up feature.



Answerphone messages, old text message conversations and sensitive user details would also be available to hijackers.



[font=arial, helvetica, sans-serif]Full article



[font=arial, helvetica, sans-serif]Does this worry any of you who use Skype?
 
Apparently it's been fixed so no... can't say I'm worried
tongue.png




Although, it's bit of a major flaw...
 
Back
Top Bottom