Re: Skype API Ap2Ap Stream Creation Flaw



Other than the fact that this takes advantage of skype's built-in encryption, I don't see how this is that much different than any other network-capable application being built with backdoors and call-home capability.

vizig0thblitz@xxxxxxxxx wrote:
An application-to-application stream can be created between two Skype clients without having established normal communications between them and both Skype client's contact lists are empty. With this ability any Skype enabled application can create a convert communication stream to a central server. This can only occur, of course, if the user voluntarily installs the application. Therefore, the main attack vector for this functionality is to create a legitimate Skype-enabled application, have the user install the application, and once the user starts the application make a covert connection to a central server. Once the connection to the central server is made, additional software can be downloaded and installed on the target computer via the application-to-application stream.

Scenario Setup:

The following will be needed to recreate the scenario:

1.Two computers with Skype installed and two separate Skype Ids that have had no communication between them.

2.A copy of SkypeTracer installed on each computer.

Scenario Steps:
. . . . .

--
Stephen Samuel +1(778)861-7641 samnospam@xxxxxxxxxxx
http://www.bcgreen.com/
Powerful committed communication. Transformation touching
the jewel within each person and bringing it to light.



Relevant Pages

  • Re: Citrix
    ... The scenario involves reaching data stored on a network, ... connectivity there's really no need for the computers -- in our situation. ... data center with redundant everything. ... Why would home users needing the .Net framework be a problem? ...
    (microsoft.public.dotnet.languages.vb)
  • Re: Will Robots take over?
    ... Labeled "The Singularity" the speculation ... "The Biomedical Scenario: We directly increase our intelligence by ... Humanity, its networks, computers, and databases ... become sufficiently effective to be considered a superhuman being. ...
    (soc.retirement)
  • Re: Will Robots take over?
    ... Intelligent Machines ... "The AI Scenario: We create superhuman artificial intelligence in computers. ... We directly increase our intelligence by improving the neurological operation of our brains. ... Humanity, its networks, computers, and databases become sufficiently effective to be considered a superhuman being. ...
    (soc.retirement)
  • Re: 2005 car in 1955
    ... It was a very believable scenario. ... I do believe that an alien spaceship crashing today will not be easly ... Your idea of a "today's compatible" computer aboard the roswell ship is ... I does not believe that a crash would destroy all the computers, ...
    (rec.arts.sf.science)
  • Re: Where does Office 2003 validate over the Internet
    ... There are various scenarios for supplying updates for Office and it sounds as if you've investigated some of them. ... Office should not require reactivation unless you're deleting the Office Product Activation from the computers at some ... I'm not quite clear when you say you don't have direct internet for these computers but then that you are spending time putting them ... back on the internet, as to the scenario you're using, or the reason why using a proxy server would not work in your scenario, or ...
    (microsoft.public.office.setup)