A security researcher has found it’s possible to reveal a Skype app user’s IP address without the target needing to even click a link. Microsoft said the vulnerability does not need immediate attention.

  • jrest18n@lemm.ee
    link
    fedilink
    English
    arrow-up
    21
    ·
    1 year ago

    When Skype was still in common use, this was a very known issue. I’m in lots of gaming communities, and you had to be careful about who knew your username because you could have your IP exposed then get DDoS.

    Possibly they patched it and this is a new instance of this, but it was like this for years and years before.

  • BradleyUffner@lemmy.world
    link
    fedilink
    English
    arrow-up
    41
    arrow-down
    6
    ·
    1 year ago

    Ohh no, someone on the Internet might have my IP address! The horror! What if they try to ping me?!

    • RheingoldRiver@kbin.social
      link
      fedilink
      arrow-up
      8
      arrow-down
      1
      ·
      edit-2
      1 year ago

      People used to use this attack in League of Legends a decade ago. If they’re losing, they guess someone might have Skype open; and moreover, that their Skype is the same as their summoner name. Then they get an ip address and ddos the entire lobby, causing the game to crash (I think it happened in one of my games maybe once, but I didn’t really play ranked other than team ranked).

      Also, since all pro & semipro players had each other added, this was possible to do at any time during online tournaments (which was most tournaments - TSM invitational etc). So there were always rules that ddossing was disallowed. But it did happen.

      Known ddossers were more hated in the community than known flamers, but a few people who did it “reformed” and went on to be pro players anyway.

  • Filipdaflippa@lemmy.ml
    link
    fedilink
    English
    arrow-up
    26
    arrow-down
    2
    ·
    1 year ago

    Wait you can still do this? I was booting people off games when they would use the same user as their Skype over 10 years as a script kiddie, how is it not patched by now

    • Redditiscancer789@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      1
      ·
      edit-2
      1 year ago

      Lol I love how behind the times academics can be. This literally was a big thing used to ddos streamers back in the day like 2010s-2015s. All that needed to happen was they accepted a call and since Skypes peer to peer the hacker instantly got their IP. I remember Destiny being targeted for a while by it.

  • Swim@lemmy.ca
    link
    fedilink
    English
    arrow-up
    15
    arrow-down
    1
    ·
    1 year ago

    This is soo old that’s how they would ddos clan leaders and shot callers back in the acheage days

  • Franzia@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    15
    arrow-down
    2
    ·
    1 year ago

    What the fuck. What percentage of people uses skype? I’d really rather see coverage of the exploits found in discord, zoom, slack, etc.

  • howrar@lemmy.ca
    link
    fedilink
    English
    arrow-up
    15
    arrow-down
    3
    ·
    1 year ago

    If you connect to anything on the internet, you’re giving out your IP address. Why would this be any more of a concern?

      • Sethayy@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        3
        ·
        1 year ago

        At this point Microsoft is a suspicious server, and any data they could get from this they could just like… pay for from one of our overlords

    • LinusSexTips@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      1 year ago

      Was common practice in procurement for me and my team, still have contacts at ASRock / Keychron / Logitech / SteelSeries / Beacn / HYTE / Maxsun and many more.

      Was a platform that was used early on and has carried through. Factories in China will commonly use WeChat but many of the more mainstream western brands will default to Skype.

  • smoothbrain coldtakes@lemmy.ca
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    1
    ·
    1 year ago

    Huh, the time machine must be off. This was news from a decade ago.

    It’s actually one of the main reasons we switched off Skype to Discord for most gaming socialization.