20 Dec 2006
Security firm Websense has downgraded a security threat to internet telephony application Skype that it warned about earlier this week.
Websense Security Labs reported on its blog on Monday that there was a potential worm propagating via Skype. On closer inspection the firm has discovered that this is not a self-propagating worm at all and is actually a Trojan horse.
"After discussions with the very helpful Skype security team, the behavior of this Trojan using the Skype API is as per the specifications of the API," said Websense.
"The end user who is running Skype does get notified that a program is attempting to access it and must acknowledge it."
Skype users would receive a message via Skype Chat to download and run a file with a filename of sp.exe. If the file is run it appears to drop, and runs a password stealing Trojan horse. But the user must choose to run the program.
"There is no vulnerability in Skype at this time that has been uncovered," the company said.
The threat may already be abating anyway. Websense confirmed today that the websites that were used to download the Skype API code and the site that is used to download new copies of the Trojan were both down.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Principal Development Engineer Lead- London - Smart TV...
Development Engineer - London - Smart TV, Gaming, Tablets...
Principal Development Engineer - London - Smart TV, Gaming...
Test Engineer -London - Smart TV, Gaming, Tablets, PC...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?