Safe and Secure

Read all 'Skype' posts in Safe and Secure
September 2, 2009 5:54 PM PDT

Symantec: Posted code enables VoIP spying

by Larry Magid
  • 23 comments

Along with keyloggers that track what you type, now we have to worry about malicious software that listens in on our voice over Internet Protocol conversations.

Gerry Egan

(Credit: Joris Evers/CNET)

A Symantec security blog on Thursday disclosed a new Trojan horse, Tojan.Peskyspy "that records VoIP communications, specifically targeting Skype." The posting, based on analysis from Symantec's Karthik Selvaraj, pointed out that "its existence isn't due to any problems with Skype itself" but that Skype may have been targeted "simply because it has such a large install base."

Gerry Egan, Symantec's director of security response, says the Trojan is capable of "hooking...through some Windows APIs into some audio streams" that "can be intercepted, turned into MP3 files, and then sent over a remote channel to a remote electronic eavesdropper."

A PC can be infected through the usual channels for malware, including an executable file in an e-mail you click on and a "drive by download" that's automatically triggered when you visit an infected Web site. The most recent trend, Egan said, "is a shift toward socially engineered attacks like a fake video site."

The code has been published on the Web by a Swiss researcher, Egan said, adding that "we've not seen any indications of it being used maliciously, but the published code opens up endless possibilities in the mind of a hacker."

The code would affect Skype or any other VoIP software on a Windows PC that uses an audio stream, Egan said.

Unlike most malware, Symantec does not anticipate the code being used to launch widespread attacks.

"To do this en masse really isn't practical," Egan said. Even if a "piece of malware gets on the machine of someone who is using (VoIP), and they are talking about interesting things, finding those interesting things among the many hundreds of thousands of hours of phone calls would be like trying to find a needle in a haystack." He said it might be more valuable in a targeted attack against a specific individual.

Eavesdropping is a risk, when it comes to industrial espionage, prying spouses or significant others, and political campaigns, as well as political dissidents. U.S. law requires a court order before a phone or a computer can be legally tapped by government or law enforcement officials.

The best way to avoid being infected with this or any other malware is to use good up-to-date security software and to be sure that your operating system and browser are updated. It's also a good idea to avoid clicking on e-mail attachments and consider using security software that warns you when you're about to visit a potentially malicious Web site.

You can listen to my interview with Gerry Egan here:

Listen now: Download today's podcast

January 9, 2009 10:26 PM PST

Podcast: Skype wins in a sinking economy

by Larry Magid
  • 1 comment

LAS VEGAS--At the CES show here, Skype Chief Operating Officer Scott Durchslag tells Larry Magid how the bad economy is actually good for Skype as people flock to value. He also talks about new Skype software and the explosion of video over his company's service.


Listen now: Download this podcast


Related stories:

Skype thrives amid tough economy

Skype Lite landing on Android phone, others too

See our complete news coverage from CES here

  • prev
  • 1
  • next
advertisement

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

About Safe and Secure

As founder of SafeKids.com and co-director of ConnectSafely.org, Larry Magid has a special interest in Internet safety, including debunking myths like a predator behind every screen and messages like "be afraid, very afraid."

Add this feed to your online news reader

Safe and Secure topics

More on Safe and Secure
Larry's For the Record podcast
Safekids.com
Connectsafely.org

Most Discussed

Inside CNET News

Scroll Left Scroll Right