Stuart covered the ‘SkypeKiller’earlier this week here. The SkypeKiller application is meant to sow more fear, uncertainty and doubt in to the hearts of Skype users. IT Managers already know how to perform this task.
SkypeKiller is an application written by some folks in Herdon, VA. (the heart of the US 3 letter agencies) that goes out on a company network and deletes Skype from a computer. You may be wondering “How can I avoid this?”.
Well, like any technology that tries to delete something there is a way around it, or a way to avoid it. First and foremost your company should have a Security policy about applications like Skype and their proper use. So do not go and violate company policy after the IT folks go and delete Skype from your system or you could be terminated.
With that said, now how can I avoid an accidental deletion of Skype from my system. Well there are several ways. If the person using SkypeKiller does not have administrator access to your system, they cannot access it and therefore can not delete Skype. So if your administrative accounts have different passwords than they expect, the IT staff will not be able to gain access. Many companies have this issue, we refer to it as “unmanaged” systems and they account for 20% of systems in most companies. An IT staff should have some sort of admin access to all systems it manages if not by a Domain admin account, then by a local admin account. You would also violate company policy by changing these accounts passwords or deleting the accounts by the way, so don’t do this.
The best way to avoid SkypeKiller is to use the F1K Flash Phone by MPlat for around US $47 that has everything you need loaded on the Flash Drive so that nothing is installed on your computer. Now you can not use any old Flash Drive as it has to be designed for Skype as the F1K is. If you install Skype to another location on your system, SkypeKiller deletes the default install file location and the registry entries which only seem to affect when you logon to Skype removing your auto-logon settings. Plus it would be trivial to scan the computer for where Skype is actually loaded other than the default and I would expect SK would do this in the next release, I am surprised it is not in this release. The F1K Flash drive has a built-in audio device and by using a standard 2.5mm headset just like your cell phone uses, you can plug this puppy into a USB slot of any Windows computer and make your Skype calls, File Transfers and chat right from the flash drive. The F1K also saves all your contacts and chat history to the Flash Drive and you even have around 90Meg of storage for file transfers!
Another method to avoid SkypeKiller is use a Pocket PC device with WiFi. Of course you need open WiFi to use it, but many companies have WiFi these days. Another way is to use a fully Skype enabled device like the new Accton WiFi phone that does not use a computer. Also, you can install VMWare or Virtual PC and create a ‘virtual pc’ on your computer to run programs like Skype and avoid scans and deletion. SkypeKiller is not the panacea of avoiding Skype on your network, a good Security Policy and detection process is needed, not just a tool that misses many instances of Skype, but of course it does do the 80/20 rule. In my business, the 20% is what I worry about.
Michael Gough is a regular contributor to the Skype Journal on matters of Skype Security and Skype Tips. He is also author of “Skype Me” a book published by Syngress and available in early December.
TrackBack URL for this entry:
http://www.skypejournal.com/cgi-bin/mt/mt-tb.cgi/1711
Comments
Posted by: Robert at November 20, 2005 4:38 PM
Greetings Bill and Michael:
Well it looks like Skype does have a strong competitor. I just happened to find this website from France. Seems that this Open Source program has a video feature too. Oh, and you can buy a monthly unlimited service plan too.
I haven't put this software to the extreme test yet, but my first tests seem intersting.
Here is the link:http://openwengo.com/
Posted by: philippe at November 21, 2005 8:43 AM
seems that this skypekiller is not from Virginia, but from the french pyrenean mountains : here is the result for a whois on isdecisions, the company behind Skypekiller :
Registrant:
AMIGORENA FRANCOIS
Errota Xaharra
AHETZE 64210
FR
far less trouble to just add the following to your proxy config
acl numeric_IPs url_regex [0-9]+\.[0-9]+\.[0-9]+\.[0-9]+
http_access deny CONNECT numeric_IPs all
if your having trouble with skype going through your company webproxy(there is a slightly different one around the web but it does work fo r me)
Posted by: Jules le Renard at February 19, 2006 2:27 PM
SkypeKiller is an application written by some folks in Herdon, VA. (the heart of the US 3 letter agencies)
Oh dear. Don't look just now, but I think there's a black helicopter just above your head. they're watching you. Some say they can even read your mind!
Skypekiller is French. They make no mystery about it, and it's stated clearly on their front page http://www.skypekiller.com/
I thought the big thing with blogs is that unlike the evil Big Media, bloggers edited their stuff want it turned out to be wrong. Oh well...
Posted by: nick at April 20, 2006 10:20 AM
Windows: OpenWengo or Gizmo.
Linux: Ekiga.
Skype: Finished.
HAHAHAHAHAHA bye bye skype it was fun while it lasted.
SkypeKiller is an application written by some folks in Herdon, VA. (the heart of the US 3 letter agencies)
Oh dear. Don't look just now, but I think there's a black helicopter just above your head. they're watching you. Some say they can even read your mind!
Skypekiller is French. They make no mystery about it, and it's stated clearly on their front page http://www.skypekiller.com/
I thought the big thing with blogs is that unlike the evil Big Media, bloggers edited their stuff want it turned out to be wrong. Oh well...
far less trouble to just add the following to your proxy config
acl numeric_IPs url_regex [0-9]+\.[0-9]+\.[0-9]+\.[0-9]+
http_access deny CONNECT numeric_IPs all
if your having trouble with skype going through your company webproxy(there is a slightly different one around the web but it does work fo r me)
seems that this skypekiller is not from Virginia, but from the french pyrenean mountains : here is the result for a whois on isdecisions, the company behind Skypekiller :
Registrant:
AMIGORENA FRANCOIS
Errota Xaharra
AHETZE 64210
FR
Well it looks like Skype does have a strong competitor. I just happened to find this website from France. Seems that this Open Source program has a video feature too. Oh, and you can buy a monthly unlimited service plan too.
I haven't put this software to the extreme test yet, but my first tests seem intersting.
Here is the link:http://openwengo.com/