Live data from Hacker News

Skype vulnerability allowing hijacking of an account if you know just the email

pixus-ru.blogspot.ru

1–10 of 124 posts

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#2
OP at http://habrahabr.ru/post/158545/ (russian) says that he reported this vulnerability about 3 month ago. The lack of any reaction is unbelievable.

Hint: you can change your email to something like user+skype@gmail.com to avoid registration of new email address.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#3
post #2

OP at http://habrahabr.ru/post/158545/ (russian) says that he reported this vulnerability about 3 month ago. The lack of any reaction is unbelievable. Hint: you can change your email to something like user+skype@gmail.com to avoid registration of new email address.

Even now Skype reaction is unbelievable. They are "investigating the issue" for almost 2 hours.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#4
post #3
post #2

OP at http://habrahabr.ru/post/158545/ (russian) says that he reported this vulnerability about 3 month ago. The lack of any reaction is unbelievable. Hint: you can change your email to something like user+skype@gmail.com to avoid registration of new email address.

Even now Skype reaction is unbelievable. They are "investigating the issue" for almost 2 hours.

Damn, it takes 2 minutes to "investigate the issue" if you simply follow the steps.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#5
post #3
post #2

OP at http://habrahabr.ru/post/158545/ (russian) says that he reported this vulnerability about 3 month ago. The lack of any reaction is unbelievable. Hint: you can change your email to something like user+skype@gmail.com to avoid registration of new email address.

Even now Skype reaction is unbelievable. They are "investigating the issue" for almost 2 hours.

Stop saying "Skype", use "Microsoft" instead, and it's not unbelievable at all.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#6
post #4
post #3

Earlier quoted context omitted.

Even now Skype reaction is unbelievable. They are "investigating the issue" for almost 2 hours.

Damn, it takes 2 minutes to "investigate the issue" if you simply follow the steps.

But probably a little longer to find a fix, test it and release it...

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#7
post #2

OP at http://habrahabr.ru/post/158545/ (russian) says that he reported this vulnerability about 3 month ago. The lack of any reaction is unbelievable. Hint: you can change your email to something like user+skype@gmail.com to avoid registration of new email address.

something like +fi92is82ls8223 is probably better, i.e. something not predictable / guessable.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#8
post #4

Earlier quoted context omitted.

Damn, it takes 2 minutes to "investigate the issue" if you simply follow the steps.

But probably a little longer to find a fix, test it and release it...

I think they can just temporarily turn off password reset to prevent account stealing. After that they can take their time to fix the problem, test it and roll out to the public.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#9
post #4

Earlier quoted context omitted.

Damn, it takes 2 minutes to "investigate the issue" if you simply follow the steps.

But probably a little longer to find a fix, test it and release it...

yes, better to keep 0day working, and roll out fixes with the next release.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#10
I confirm. Just tested on Win7, Skype 6.0.0.120

The notification about the password reset token does appear in the Skype client, but no reset code is shown at first. Then I've pressed Ctrl+F5 on the home screen, skipped the Facebook thing, and here they are!

http://www.xiag.ch/share/2012-11-14_1021.png

On OSX doesn't work, though. The password token notification doesn't come.

Post reply on HN