Skype reads BIOS?

Malware, for "malicious software," is any program or file that is harmful to a computer user.

Skype reads BIOS?

Postby Spock » Sun 2007 Feb 11 1:56

Just found this on another forum:

The Windows version of the video and telephony software Skype reads and stores the BIOS data of a users computer. As a hacker with the pseudonym Myria reports in a blog entry, once the software is launched it saves an executable file called 1.com in the user's temporary folder. This file contains code that transmits the data found in the BIOS address area of the application to be launched. It is not yet clear what the Skype software does with the data, which may contain, among other things, the motherboard serial number. The mysterious .com file was only noticed because of an error message that Skype outputs when it is launched on systems running on 64-bit versions of Windows. 64-bit versions lack the "NT Virtual DOS Machine" (NTVDM), which allows direct access to BIOS memory pages and is required to execute the program. Since myria's blog entry is dated February the 6th 2007 presumably Skype added the BIOS reading code to their applications relatively recently.

Interestingly, the Skype software apparently also attempts to prevent the contents of .com file that it has created, from being examined. Myria writes that the file could only be opened after the system had been rebooted because of a forced kernel panic. As the comments on this blog entry reveal, such actions make users quite suspicious of the Skype vendor. At the beginning of 2006, in its antitrust dispute with Intel, AMD accused Skype of having tailored the conference function of its telephone software specificaly to Intel processors. At the time the function would not run on AMD based systems.

http://www.heise-security.co.uk/news/84973/from/atom10
User avatar
Spock
Forum Admin
Forum Admin
 
Posts: 2417
Joined: Tue 2005 Jan 18 10:47
Location: MD, USA

Return to Malware

Who is online

Users browsing this forum: No registered users and 1 guest

cron