Home > Security News > Skype Trojan: Much ado about nothing?
Security News:
EMAIL THIS
COLUMN

Skype Trojan: Much ado about nothing?

By Bill Brenner
22 Dec 2006 | SearchSecurity.com


Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Security experts are becoming increasingly concerned about voice over Internet protocol (VoIP) threats. So when researchers came across a Trojan horse that tries to penetrate the popular Skype program, it was bound to get plenty of headlines.

But some security bloggers aren't so sure this particular malware is worth the hype.

Websense Inc. initially raised the red flag in its blog, warning that Skype users may receive a message asking them to download a file containing a password-stealing Trojan. While other security vendors entered the fray with their own alerts, some -- particularly F-Secure Corp. and CA¬ -- offered a milder assessment of the threat.

"There is something spreading on Skype, but only in limited numbers," F-Secure Corp. Chief Research Officer Mikko Hypponen wrote in the company's blog. "There is no massive outbreak going on. It is not exploiting a vulnerability in Skype, but simply sending chat messages asking you to download and run the infected executable."

CA Senior Researcher Hamish O'Dea wrote in his company's blog that the Trojan is capable of stealing passwords, credit card numbers and other sensitive information. But it appears to need the help of the user in order to spread. Calling it a hyped Trojan that is relatively harmless, O'Dea cautioned users of mistaking the Trojan with a separate, older Skype worm.
About Security Blog Log:
Senior News Writer Bill Brenner peruses security blogs each day to see what's got the information security community buzzing. In this column he lists the weekly highlights. If you'd like to comment on the column or bring new security blogs to his attention, contact him at bbrenner@techtarget.com.

Recent columns:

Schneier: UCLA breach barely newsworthy

Zero-Day Tracker a hit, but IT shops need better strategy

Oracle answers its security critics

Pete Cashmore, keeper of Mashable, a blog about social networking programs, acknowledged that he received a copy of the malware.

"Since I have about 300 friends on Skype, it was pretty likely that I'd be sent the file," he wrote. "In fact, the dialog to download sp.exe started to arrive about a week ago." But he added that users must manually click a button to get infected, and that tech savvy users would know better.

Skype expert Andrew Hansen, owner of Virtual Communications Ltd, wrote in his blog that all the chatter about the Skype malware is "complete FUD," or fear, uncertainty, and doubt.

"There are several reports … on a Skype-based worm," he wrote. "This is complete and utter nonsense … Skype, much like Windows' built-in firewall, forces users to make a decision on whether or not to allow a program to access the Skype API. If you didn't install an application that is supposed to work with Skype there is no way to hijack the IM channel in Skype."

The Skype blog acknowledged the malware's existence, but sought to assure users that the threat is minimal. Effective Dec. 20, sites distributing the malware had been taken offline, "effectively stopping further spread of the malware," the blog said.

Maybe the threat has been overly hyped. But that's no cause for people to dismiss the wider concerns that security experts have expressed about VoIP.

Stephen Northcutt, director of training and certification at the SANS Institute, said in a recent interview that VoIP presents a significant security risk.

"If I had my way, I would have the creators of VoIP stop everything and redesign this with security in mind from the get-go," he said.

Seemingly lightweight threats like the Skype Trojan are usually the bad guys' way of experimenting with new attack vectors. There could be more damaging attacks in the future, and IT administrators would be wise to prepare for them.

At the least, the Skype Trojan should serve as a wake-up call.

Tags: IM Security Issues, Risks and ToolsMalware, Viruses, Trojans and SpywareVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
IM Security Issues, Risks and Tools
What are effective ways to stop instant messaging (IM) spam?
Secure messaging complications result in limited protection
Is it possible to ban chat programs on an enterprise LAN?
How to lock down instant messaging in the enterprise
AOL closes AIM attack vector, but risks remain
Researcher says AIM still vulnerable, AOL insists it's fixed
Serious security flaw in AOL Instant Messenger
Security flaws found in AOL, Yahoo IM programs
Flaw found in MSN Messenger
AOL, Yahoo, Trillian IM applications under threat

Malware, Viruses, Trojans and Spyware
Schneier-Ranum Face-Off: Is antivirus dead?
Modern malware, stealthy botnets, adapt quickly, expert says
Computer worm infections up, scareware antivirus down, Microsoft says
Web-based attacks skyrocket, pirating sites surge, security firms say
Mini guide: How to remove and prevent Trojans, malware and spyware
Kaspersky system analyzes malicious URLs on Twitter for malware
Silon malware intercepts Internet Explorer sessions, steals credentials
Breach forces payroll service provider PayChoice to shut down again
RSA research underscores problem tracking cybercriminals
Conficker analysis finds P2P coding limited, less sophisticated

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
greynet  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts