dslreports logo
uniqs
402

FunnyBones
Premium Member
join:2004-01-22
usa

FunnyBones

Premium Member

Whistleblower releases Skype snooping code

The source code for a Windows Trojan capable of recording Skype calls as MP3 files has been released in a move that spells bad news for VoIP confidentiality.
»www.theregister.co.uk/20 ··· ce_code/

Hmm and I see new development's on the way soon enough to attack skype and maybe even a few others..

Cudni
La Merma - Vigilado
MVM
join:2003-12-20
Someshire

Cudni

MVM

"..
The approach involves tricking users into getting infected and hoping the any security defences they have in place don't detect the threat. Not detecting a threat as part of a gentleman's agreement between a software vendor and a law enforcement agency could risk alienating customers and would be difficult, if not impossible to conceal, for any length of time.
.."

as always, be vigilant

Cudni
SUMware2
Premium Member
join:2002-05-21

1 edit

SUMware2 to FunnyBones

Premium Member

to FunnyBones
Thanks for the article link.

A few more excerpts:
quote:
Symantec warns that the public availability of the code (dubbed Peskyspy) is likely to spur the development of "customised" threats.

The source code includes backdoor functionality, according to preliminary analysis by anti-virus firm F-Secure.

Leaked documents have previously suggested that Bavarian authorities commissioned a firm called DigiTask to create a similar Trojan.* Law enforcement agencies in the US and Europe, most vocally those in Germany, have long complained that Skype has become a barrier to investigations and called for changes in the law that would allow them to plant Trojans on suspects PCs.

That's just one reason why the whole law enforcement Trojan plan has long struck us as both unworkable and plain wrong-headed. The trade craft of a serious criminal or terror suspect would have to be really sloppy to get caught. Simply using a Mac or, better, Linux would defeat any law enforcement Trojan targeted at Windoze users, for example.
* Skype and SSL Interception letters - Bavaria - Digitask

sivran
Vive Vivaldi
Premium Member
join:2003-09-15
Irving, TX

sivran to FunnyBones

Premium Member

to FunnyBones
So... this trojan records skype calls taking place on the infected pc?

This doesn't show anything revolutionary, just that malware on your system can record audio being recorded/played by your PC. Big deal! Once you're on the PC, anything's fair game. Intercept, decode and record Skype's encrypted peer-to-peer stream "on the wire" and then I'll be impressed.

The whole bit about law enforcement using trojans is far more disturbing than a trojan that can record skype calls.