Live data from Hacker News

Skype vulnerability allowing hijacking of an account if you know just the email

pixus-ru.blogspot.ru

31–40 of 124 posts

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#31

It's even worse! Their website is so broken you can't change your password (new password fields are disabled) and you can't set a new email address as primary (the "make primary" button only appears when the new email address field is empty). Also, if you first add a new email address, save, then set it to primary, it disappears. Wtf. I see no recourse other than closing my account, if that's still possible. [edit] N…

I guess it was done to prevent account stealing while Microsoft works on appropriate fix

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#32

It's even worse! Their website is so broken you can't change your password (new password fields are disabled) and you can't set a new email address as primary (the "make primary" button only appears when the new email address field is empty). Also, if you first add a new email address, save, then set it to primary, it disappears. Wtf. I see no recourse other than closing my account, if that's still possible. [edit] N…

Never use enter to complete forms, use the mouse. That works for me.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#33
post #16

I think it's a good practice to always use unique, unpredictable email addresses when signing for online services. 1. Most people use the same or similar password, so once one account gets hacked, the attacker is probably able to use many other accounts on different services with the same email address/password combo. 2. It's easier to spot services that spam, or that leak your email address (I became aware of a leak…

Are you suggesting to have a different email address for every online service we use? Today I manage about 100 different unique passwords for every online service. This is already very inconvenient. Adding as well as having different bogus email addresses would be at least 2 times more difficult! I think something is really broken in today's web authentication scheme. I think there is really huge need for some indepe…

I use unique and secure passwords for all online services, https://agilebits.com/onepassword makes it really simple.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#34

It's even worse! Their website is so broken you can't change your password (new password fields are disabled) and you can't set a new email address as primary (the "make primary" button only appears when the new email address field is empty). Also, if you first add a new email address, save, then set it to primary, it disappears. Wtf. I see no recourse other than closing my account, if that's still possible. [edit] N…

This appears to be a bug.

After adding the email address and clicking save, logging out, and logging in, I found the email address was successfully added. At this point I could change it to the primary one, click save, paste my password, and click the button on the password prompt to successfully change my primary email address. If I tried to add the email and make it primary in one session, it would not work. If I entered my password and hit enter, it would not work.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#35

I confirm. Just tested on Win7, Skype 6.0.0.120 The notification about the password reset token does appear in the Skype client, but no reset code is shown at first. Then I've pressed Ctrl+F5 on the home screen, skipped the Facebook thing, and here they are! http://www.xiag.ch/share/2012-11-14_1021.png On OSX doesn't work, though. The password token notification doesn't come.

also it seems the password reset link, is not working for me.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#36

It's even worse! Their website is so broken you can't change your password (new password fields are disabled) and you can't set a new email address as primary (the "make primary" button only appears when the new email address field is empty). Also, if you first add a new email address, save, then set it to primary, it disappears. Wtf. I see no recourse other than closing my account, if that's still possible. [edit] N…

And when you try to change your password:

Character not recognized. Please choose a mix of letters and numbers.

...

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#37
post #18

After successfully exploited this on my own account, tried again with my SO's account and https://login.skype.com/account/password-reset-request has been blocked. Pretty good emergency reaction. It should be noted that after my account password is changed, I tried to login with the old password, the Windows Skype app told me the username and password combination is wrong but it still let me logged in. This may be a d…

Apparently, https://login.skype.com/account/password-automation still works.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#38

I confirm. Just tested on Win7, Skype 6.0.0.120 The notification about the password reset token does appear in the Skype client, but no reset code is shown at first. Then I've pressed Ctrl+F5 on the home screen, skipped the Facebook thing, and here they are! http://www.xiag.ch/share/2012-11-14_1021.png On OSX doesn't work, though. The password token notification doesn't come.

also it seems the password reset link, is not working for me.

MS is fixing the problem right now. They turned off password recovery form few minutes ago.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#39
In August I received an email from Skype thanking me for registering an account. But I already had an account, I didn't register this one. After comparing the new account name with part of my email, I came to the conclusion that someone mistyped their email address, and registered an account on my address. I contacted their live support, here's the conversation:

    George A: Hello! Welcome to Skype Live Support! My name is George. How
    may I help you?

    me: Recently I have received an email welcoming me to Skype (not
    phishing, I verified). The problem is that I didn't create the account
    mentioned in the email. The account name was "[NEW SKYPE ACCOUNT]" and
    my email is [MY EMAIL 1], so I think that user mistyped his email
    address, and then Skype sent a welcome message to me. Doesn't skype
    verifies email addresses before sending a welcome message?

    George A: I understand that you are concerned about your email address
    being used to setup a Skype account, I'll be happy to help you with
    that.  May I please have your Skype Name?

    me: [MY SKYPE ACCOUNT]

    George A: I would also need the email address, please.

    me: [MY EMAIL 1]. let me check that this address in on my Skype
    account... ok, my email on file in Skype is [MY EMAIL 2].  and a few
    other too, all mine :)

    George A: Well, I see that there is only Skype Name registered under
    that email address, the Skype Name is [NEW SKYPE ACCOUNT]

    me: Yes, for my account ([MY SKYPE ACCOUNT]) the primary email is [MY
    EMAIL 2], but other emails on profile are [MY EMAIL 1], [MY EMAIL 2],
    [MY EMAIL 3].

    George A: May I please ask you to confirm which Skype Name that you do
    not authorize?

    me: Does Skype sends verification message before assigning the email
    to account? The Skype name which I didn't create is [NEW SKYPE
    ACCOUNT]

    George A: May I also have the email address that was used?

    me: [MY EMAIL 1]

    George A: Well, I would need to send you a confirmation to that email
    address. I would kindle need you to reply back to that email.

    me: Please do

    George A: Then, we will be able to delete that Skype Name for you.

    me: thank you

    George A: You are most welcomed, please expect me email within 10
    minutes.  Is there anything else I can help you with today?

    me: Could you tell me if email accounts that are registered with Skype
    are being verified by sending a message to them? If so, maybe there's
    bug in your system?

    George A: We send a welcome email to the registered email address
    whenever a new account is set up using that email.

    me: OK, that's what I received. And then you also send other emails
    with offers to the same account. So, basically, anyone can create an
    account for any email. Why don't you verify emails?

    George A: Please understand that all of us here at Skype take our
    customers' privacy and confidentiality very seriously

    me: OK. Thank you.

    George A: You are most welcomed. It's been a pleasure speaking with
    you today. Thank you for contacting Skype Live Support, have a great
    day. We value your feedback. Please be aware that we will ask you a
    few questions after closing the chat window about your experience with
    us today.  Once you are ready please click on the "Exit" button.

    me: I suggest adding a link to Welcome email that says "I didn't
    create this account". Bye!

Realizing that there's nothing this support person can do about this, I sent email to their "security" people. I received no reply.

And now this failure to verify emails leads to the linked vulnerability. Nice.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#40

I think it's a good practice to always use unique, unpredictable email addresses when signing for online services. 1. Most people use the same or similar password, so once one account gets hacked, the attacker is probably able to use many other accounts on different services with the same email address/password combo. 2. It's easier to spot services that spam, or that leak your email address (I became aware of a leak…

what I do is intersperse the site name with my username at my domain e.g. for skype:

ksekryrpiedge0@mydomain.com

then I have a catch-all on the domain, and lower the priority of emails that aren't to my normal address, but any important emails get their own forwarder to forward into my main inbox, so I will get the emails on my mobile devices.

quite effective actually.

Post reply on HN