Home / Software & Gaming / Security / Skype exploit lets you steal anyone’s account

Skype exploit lets you steal anyone’s account

Update: Skype has now disabled the password reset link, though there is another one that's supposedly active.

Original Story: A new exploit for VOIP software client, Skype, has been discovered that has the potential to allow anyone to steal anyone else's account, if they have the person's login email. Fortunately there's a few simplesteps you can take to protect yourself.

The vulnerability showed up late yesterday on Russian website Habrahabr, where it was detailed how to gain control of a user's skype account. Fortunately there's an English translation with better explanation over at Pixus. All a person needs to do is to make a new account using an email that's already in use and use the password recovery system to change the password.

Hack Any Account
With great power comes great responsibility...

To make sure you're protected while Microsoft works on a fix, the best bet is to change your primary email address. However you don't want to use one that is publicly known or used on any other service, so the simple thing to do for now would be to make a new account with one of the free services and use that as a temporary placeholder email for Skype only.

Once you have a newly created email, go to the Skype profile management service here, and login with your current information. Head to your profile and add your new email, then click “add email,” again and change your primary address to the new one. Hit save and then remove all other emails but the newly created one. Hit save again and input your password to confirm – make sure you click save, don't hit Enter or it will not save the information and you'll have to do it all over again.

KitGuru Says: This should keep your accounts safe for now, but hopefully Skype staffers will have this fixed soon, or the popular client could see a lot of people migrating to competing services.

Become a Patron!

Check Also

Marvel Rivals has a major security issue enabling Remote Code Execution

A Remote Code Execution exploit has been discovered in Marvel Rivals, allowing hackers to remotely spread malware through the game.

We've noticed that you are using an ad blocker.

Thank you for visiting KitGuru. Our news and reviews teams work hard to bring you the latest stories and finest, in-depth analysis.

We want to be as informative as possible – and to help our readers make the best buying decisions. The mechanism we use to run our business and pay some of the best journalists in the world, is advertising.

If you want to support KitGuru, then please add www.kitguru.net to your ad blocking whitelist or disable your adblocking software. It really makes a difference and allows us to continue creating the kind of content you really want to read.

It is important you know that we don’t run pop ups, pop unders, audio ads, code tracking ads or anything else that would interfere with the KitGuru experience. Adblockers can actually block some of our free content, such as galleries!