It's even worse! Their website is so broken you can't change your password (new password fields are disabled) and you can't set a new email address as primary (the "make primary" button only appears when the new email address field is empty). Also, if you first add a new email address, save, then set it to primary, it disappears. Wtf. I see no recourse other than closing my account, if that's still possible. [edit] N…
Skype vulnerability allowing hijacking of an account if you know just the email
31–40 of 124 posts
Re: Skype vulnerability allowing hijacking of an account if you know just the email
#32It's even worse! Their website is so broken you can't change your password (new password fields are disabled) and you can't set a new email address as primary (the "make primary" button only appears when the new email address field is empty). Also, if you first add a new email address, save, then set it to primary, it disappears. Wtf. I see no recourse other than closing my account, if that's still possible. [edit] N…
Re: Skype vulnerability allowing hijacking of an account if you know just the email
#33I think it's a good practice to always use unique, unpredictable email addresses when signing for online services. 1. Most people use the same or similar password, so once one account gets hacked, the attacker is probably able to use many other accounts on different services with the same email address/password combo. 2. It's easier to spot services that spam, or that leak your email address (I became aware of a leak…
Are you suggesting to have a different email address for every online service we use? Today I manage about 100 different unique passwords for every online service. This is already very inconvenient. Adding as well as having different bogus email addresses would be at least 2 times more difficult! I think something is really broken in today's web authentication scheme. I think there is really huge need for some indepe…
Re: Skype vulnerability allowing hijacking of an account if you know just the email
#34It's even worse! Their website is so broken you can't change your password (new password fields are disabled) and you can't set a new email address as primary (the "make primary" button only appears when the new email address field is empty). Also, if you first add a new email address, save, then set it to primary, it disappears. Wtf. I see no recourse other than closing my account, if that's still possible. [edit] N…
After adding the email address and clicking save, logging out, and logging in, I found the email address was successfully added. At this point I could change it to the primary one, click save, paste my password, and click the button on the password prompt to successfully change my primary email address. If I tried to add the email and make it primary in one session, it would not work. If I entered my password and hit enter, it would not work.
Re: Skype vulnerability allowing hijacking of an account if you know just the email
#35I confirm. Just tested on Win7, Skype 6.0.0.120 The notification about the password reset token does appear in the Skype client, but no reset code is shown at first. Then I've pressed Ctrl+F5 on the home screen, skipped the Facebook thing, and here they are! http://www.xiag.ch/share/2012-11-14_1021.png On OSX doesn't work, though. The password token notification doesn't come.
Re: Skype vulnerability allowing hijacking of an account if you know just the email
#36It's even worse! Their website is so broken you can't change your password (new password fields are disabled) and you can't set a new email address as primary (the "make primary" button only appears when the new email address field is empty). Also, if you first add a new email address, save, then set it to primary, it disappears. Wtf. I see no recourse other than closing my account, if that's still possible. [edit] N…
Character not recognized. Please choose a mix of letters and numbers.
...
Re: Skype vulnerability allowing hijacking of an account if you know just the email
#37After successfully exploited this on my own account, tried again with my SO's account and https://login.skype.com/account/password-reset-request has been blocked. Pretty good emergency reaction. It should be noted that after my account password is changed, I tried to login with the old password, the Windows Skype app told me the username and password combination is wrong but it still let me logged in. This may be a d…
Re: Skype vulnerability allowing hijacking of an account if you know just the email
#38I confirm. Just tested on Win7, Skype 6.0.0.120 The notification about the password reset token does appear in the Skype client, but no reset code is shown at first. Then I've pressed Ctrl+F5 on the home screen, skipped the Facebook thing, and here they are! http://www.xiag.ch/share/2012-11-14_1021.png On OSX doesn't work, though. The password token notification doesn't come.
also it seems the password reset link, is not working for me.
Re: Skype vulnerability allowing hijacking of an account if you know just the email
#39 George A: Hello! Welcome to Skype Live Support! My name is George. How
may I help you?
me: Recently I have received an email welcoming me to Skype (not
phishing, I verified). The problem is that I didn't create the account
mentioned in the email. The account name was "[NEW SKYPE ACCOUNT]" and
my email is [MY EMAIL 1], so I think that user mistyped his email
address, and then Skype sent a welcome message to me. Doesn't skype
verifies email addresses before sending a welcome message?
George A: I understand that you are concerned about your email address
being used to setup a Skype account, I'll be happy to help you with
that. May I please have your Skype Name?
me: [MY SKYPE ACCOUNT]
George A: I would also need the email address, please.
me: [MY EMAIL 1]. let me check that this address in on my Skype
account... ok, my email on file in Skype is [MY EMAIL 2]. and a few
other too, all mine :)
George A: Well, I see that there is only Skype Name registered under
that email address, the Skype Name is [NEW SKYPE ACCOUNT]
me: Yes, for my account ([MY SKYPE ACCOUNT]) the primary email is [MY
EMAIL 2], but other emails on profile are [MY EMAIL 1], [MY EMAIL 2],
[MY EMAIL 3].
George A: May I please ask you to confirm which Skype Name that you do
not authorize?
me: Does Skype sends verification message before assigning the email
to account? The Skype name which I didn't create is [NEW SKYPE
ACCOUNT]
George A: May I also have the email address that was used?
me: [MY EMAIL 1]
George A: Well, I would need to send you a confirmation to that email
address. I would kindle need you to reply back to that email.
me: Please do
George A: Then, we will be able to delete that Skype Name for you.
me: thank you
George A: You are most welcomed, please expect me email within 10
minutes. Is there anything else I can help you with today?
me: Could you tell me if email accounts that are registered with Skype
are being verified by sending a message to them? If so, maybe there's
bug in your system?
George A: We send a welcome email to the registered email address
whenever a new account is set up using that email.
me: OK, that's what I received. And then you also send other emails
with offers to the same account. So, basically, anyone can create an
account for any email. Why don't you verify emails?
George A: Please understand that all of us here at Skype take our
customers' privacy and confidentiality very seriously
me: OK. Thank you.
George A: You are most welcomed. It's been a pleasure speaking with
you today. Thank you for contacting Skype Live Support, have a great
day. We value your feedback. Please be aware that we will ask you a
few questions after closing the chat window about your experience with
us today. Once you are ready please click on the "Exit" button.
me: I suggest adding a link to Welcome email that says "I didn't
create this account". Bye!
Realizing that there's nothing this support person can do about this, I sent email to their "security" people. I received no reply.And now this failure to verify emails leads to the linked vulnerability. Nice.
Re: Skype vulnerability allowing hijacking of an account if you know just the email
#40I think it's a good practice to always use unique, unpredictable email addresses when signing for online services. 1. Most people use the same or similar password, so once one account gets hacked, the attacker is probably able to use many other accounts on different services with the same email address/password combo. 2. It's easier to spot services that spam, or that leak your email address (I became aware of a leak…
ksekryrpiedge0@mydomain.com
then I have a catch-all on the domain, and lower the priority of emails that aren't to my normal address, but any important emails get their own forwarder to forward into my main inbox, so I will get the emails on my mobile devices.
quite effective actually.