Users of Skype that run 64-bit versions of Windows like me probably have noticed that when starting Skype, the following dialog box appears:
The program or feature “\??\C:\Documents and Settings\Myria\Local Settings\Temp\12\1.com” cannot start or run due to incompatibility with 64-bit versions of Windows. Please contact the software vendor to ask if a 64-bit Windows compatible version is available.
Well, that’s weird. Skype’s trying to run a .com file, which won’t work on Win64 because there’s no NTVDM. Let’s try opening it in Hex Workshop. Access denied? OK, I’ll terminate Skype to read it. Still can’t?! This thing is really starting to annoy me. I’ll use WinDbg to terminate winlogon.exe to force a kernel panic. I reboot and NOW I can read the damn file.
An unreadable executable file coming from Skype sounds interesting, so I look at it. It’s 46 bytes long. For copyright reasons I can’t post the file or a complete disassembly. However, I can describe the program in terms of 16-bit DOS C:
int main(void)
{
fwrite((const void far*) 0xF0000000, 1, 0xFFFF, stdout);
fwrite((const void far*) 0xF000FFFF, 1, 1, stdout);
return 0;
}
It’s dumping your system BIOS, which usually includes your motherboard’s serial number, and pipes it to the Skype application. I have no idea what they’re using it for, or whether they send anything to their servers, but I bet whatever they’re doing is no good given their track record.
In 32-bit Windows NT, including Vista, the kernel permits NTVDM to make a read-only mapping of the BIOS at address 000F0000. This allows DOS programs running under NTVDM to make use of the BIOS. That’s how this 46-byte program is capable of sending the BIOS to the Skype application, and also explains why they use this mechanism to begin with.
If they hadn’t been ignorant of Win64′s lack of NTVDM, nobody would’ve noticed this happening.
[...] klientas? SusidomÄjusiems â Firefox profilo skaitymas nÄra vienetinis atvejis. Skype aktyviai nuskaito BIOS nustatymus, kurie apskritai neturÄtĹł turÄti naudingos informacijos tokiai programai, kaip Skype. Skype [...]
[...] Skype Reads Your BIOS and Motherboard Serial Number – СаПоŃка в йНОго, ŃаСОйНаŃаŃŃĐ°Ń ĐźĐ°Ń Đ¸Đ˝Đ°Ńии, ŃĐşŃŃŃĐž ĐżŃОдоНŃваоПŃĐľ Skype, ŃиŃаŃŃиП BIOS и ŃĐľŃиКнŃĐš Đ˝ĐžĐźĐľŃ ĐźĐ°ŃĐľŃинŃкОК пНаŃŃ: http://www.pagetable.com/?p=27. [...]
ĐŃĐ¸Đ˛ĐľŃ Đ˛ŃоП!
РпОŃĐľĐźŃ ŃОйŃŃвоннО ĐľŃНи ĐżŃОгŃаППа вŃŃиŃĐťŃĐľŃ Đ°Đ´ŃĐľŃа йиОŃа и Đ´ŃŃгио паŃаПоŃŃŃ ŃиŃŃĐľĐźŃ ĐžĐ˝Đ° вŃодиŃŃ ŃОйиŃаоŃŃŃ? Đна ĐźĐžĐśĐľŃ Đ´ĐľĐťĐ°ŃŃ ĐžĐąŃаŃĐ˝ŃŃ ŃŃĐźĐźŃ Đ¸Đˇ ŃаŃŃи йиОŃа (напŃ. 1024йаКŃа) – Он Đ˛ĐľĐ´Ń Đ˝Đľ иСПонŃĐľŃŃŃ ĐżŃОгŃаППнО (Đ˝Ń Đ¸ĐťĐ¸ пОŃŃи) – пОŃоПŃ-ĐąŃ Đ˝Đľ иŃпОНŃСОваŃŃ ŃŃи даннŃĐľ Đ´ĐťŃ Đ°ŃŃонŃиŃикаŃии ŃникаНŃнОгО кНŃŃа кОŃĐžŃŃĐš иŃпОНŃСŃĐľŃŃŃ Đ´ĐťŃ ŃиŃŃОваниŃ.
[...] and apparently, Skype Reads Your BIOS and Motherboard Serial Number upon startup. Now thats a nasty backdoor and privacy threat. What better way to catalog the [...]
Đни ПОгŃŃ Đ˝Đ°ĐşĐ°ĐżĐťĐ¸Đ˛Đ°ŃŃ Đ˛ ŃвОоК йаСо ŃĐľŃиКник ваŃоК ПаПки + ŃвОК НОгин. РСнаŃĐ¸Ń ŃНодиŃŃ ĐşĐ°ĐşĐ¸Đľ ĐťĐžĐłĐ¸Đ˝Ń Đ¸ŃпОНŃСОваНиŃŃ Đ˝Đ° ОднОП кОПпо.
ХаП ŃĐ°ĐşŃ ĐşĐ°ĐşĐžĐłĐž-ŃĐž пОŃŃĐžŃОнногО кОда ŃМо пОдОСŃиŃоНон.. ЧŃĐž-ŃĐž СдоŃŃ Đ˝Đľ ŃĐž!
ĐŃикОНŃĐ˝ŃĐš ĐąĐ¸ĐžŃ ĐżĐžĐťŃŃаоŃŃŃ!
Yea and itunes installed something similar. I bet everything does
I bet everything does.Yea and itunes installed something similar. I bet everything does
Thankfully this was solved a while back, but it could be re-engineered elsewhere. Nice post!
[...] Skype Reads Your BIOS and Motherboard Serial Number – ??????? ? ?????, ????????????? ?????????, ?????? ????????????? Skype, ???????? BIOS ? ???????? ????? ??????????? ?????: http://www.pagetable.com/?p=27. [...]
I;d rather they didn’t do this, but here:
http://blogs.skype.com/security/2007/02/skype_extras_plugin_manager.html
they explain why. Still, the Privacy Agreement is met…
“Of course, in line with our Privacy Agreement, Skype does not retrieve any of this data. It is only used by the EasyBits software to ensure that plug-in use complies with the appropriate license token or key.”
mean games…
[...]Skype Reads Your BIOS and Motherboard Serial Number « pagetable.com[...]…
hacker hack hackers security…
[...]Skype Reads Your BIOS and Motherboard Serial Number « pagetable.com[...]…
Really i am impressed from this post….the person who created this post is a genious and knows how to keep the readers connected..thanks for sharing this with us.i found it informative and interesting. Looking forward for more updates..
In this day and age its always good to be on the alert. We all benefit in some way when knowledge is power. Power to people i say! It will always keep these huge companys on the alert, instead of big brother watching us, its our turn to keep watch on them. Good post!
Teper’ skajp sam sebia obnovliaet, neobxodim DotNet.4 i kak minimum Vista, dla poiska. inache voobshe fignia na ekrane.
Podozrevaju 4to on eshe i proveriaet vxodiashie magnet linki – tipa torrenta itd.
Scabi very good site and I want to subscribe to
200
62326?+65
3+
5++
965
[...] (Quelle: http://www.pagetable.com/?p=27) [...]