Hacked Skype IP address search launched

Powered by SC Magazine
 

Skype user locations, ISPs revealed.

An online search portal has been launched that reveals the IP addresses of any Skype user.

The portal requires a Skype username to be entered for it to produce local and remote IP addresses of users.

It then refers to a third party site to geo-locate users on a map and reveal further information.

 

 

The portal builds on a published flaw within Skype first detailed by an anonymous user on Pastebin who wrote that a hacked 'deofuscated' version of Skype would reveal the IP addresses of users, even those who had not been added to contact books.

But the operator of the Skype-IP-Finder portal claimed in a tweet that Skype would de-register any user who activated the hacked Skype version and logged in under their profile.

The search portal would avoid that risk.

Skype was investigating but noted the hack was an "ongoing, industry-wide issue faced by all peer-to-peer software companies".

"We are committed to the safety and security of our customers and we are takings measures to help protect them," the company said.

The hacked Skype application would capture IP addresses within the programs' logs when a user's contact card was opened – part of the process to send contact requests.

However the request need not be sent: Skype's debug logging function, activated using registry keys on github, would record IP addresses.

The Pastebin entry also included a Perl script to automate searching the logs for IP addresses.

Last year, researchers had exploited a Skype vulnerability to match IP addresses of Skype users to data gleaned from BitTorrent to discover file sharing information (pdf).

Copyright © SC Magazine, Australia


Hacked Skype IP address search launched
Tags
 
 
 
Top Stories
 
Beyond ACORN: Cracking the infosec skills nut
[Blog post] Could the Government's cybercrime focus be a catalyst for change?
 
The iTnews Benchmark Awards
Meet the best of the best.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  38%
 
Your insurance company
  4%
 
A technology company (Google, Facebook et al)
  8%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  3%
 
A Federal Government agency (ATO, Centrelink etc)
  19%
 
An Australian law enforcement agency (AFP, ASIO et al)
  14%
 
A State Government agency (Health dept, etc)
  6%
TOTAL VOTES: 1893

Vote
Do you support the abolition of the Office of the Information Commissioner?