6

I am curious about something; let's say someone randomly added me to Skype and tried to initiate a chat with me and I want to know more about them but I am worried if they can do some damage.

My question is, how dangerous would it be to have a voice call with someone you don't know on Skype ?
What can a potential attacker do?
If anything, how far can they go?

Fingolfin
  • 175
  • 6
  • They can easily get your IP address. Even not being in a call, with your username (if they get it) they sometimes can obtain your IP. Also, there were a few skype exploits or bugs, one of them was to crash everyone on skype (i believe it's fixed now, public one's are always fixes quickly.) – SomeNickName Jan 10 '14 at 15:40
  • @SomeNickName - You forgot to mention the fact that a malicious person having just your ip address is not a threat. They would also need to know they can compromise using a known vulnerability with software on the machine. In most cases any attack like this can be blocked by a router. – Ramhound Jan 11 '14 at 01:51
  • Yes, but these days there are free DDoser's perfectly capable of keeping down your home connection. Anything else and you're right, there's nothing more they can do with your IP, besides tring to somehow doxing you. – SomeNickName Jan 11 '14 at 02:20

2 Answers2

7

They may be able to gather some details about your connection since I believe that Skype at least used to go direct from one user to the other when in a voice call, so they could potentially identify your IP address, however they would be limited to what Skype allows them to do or any bugs in Skype allow for. If Skype is bug free, they shouldn't be able to do much of anything, but if someone found an exploit in Skype, then it could be anything. It's probably not super likely that someone has an exploit for Skype that is being used in the wild a lot that hasn't been detected yet, but it's always a possibility.

AJ Henderson
  • 41,816
  • 5
  • 63
  • 110
  • +1 Skype works peer to peer and in my experience I've always been able to see the hostname the ISP assigned to the person on the other end. ( For group calls you can see that of the host of the group call. ) – Philipp Gayret Jan 10 '14 at 14:55
  • Funny thing, it seems I've been attacked using skype lately. At least it seems so: suddenly my browser opens advertising pages until skype crashes. Not very reassuring :/ – Sam Nov 28 '15 at 11:18
0

If anything, how far can they go?

So far, that they can get your IP address. And that they can get without being so suspicious. I don't know if it still exists, but Skype had a bug which allowed revealing users IP just by knowing his skype username.

I don't think there is any other possible exploit that would allow him some access.

balex
  • 272
  • 1
  • 11