<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Mohammed CHERIFI &#187; trojan skype</title>
	<atom:link href="http://www.mcherifi.org/tag/trojan-skype/feed" rel="self" type="application/rss+xml" />
	<link>http://www.mcherifi.org</link>
	<description>Another Web Developper Blog!</description>
	<lastBuildDate>Tue, 31 Jan 2012 18:42:15 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Le code source du trojan Skype Peskyspy publié sous liscence GPL</title>
		<link>http://www.mcherifi.org/hacking/le-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html</link>
		<comments>http://www.mcherifi.org/hacking/le-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html#comments</comments>
		<pubDate>Sun, 06 Sep 2009 06:31:58 +0000</pubDate>
		<dc:creator>Mohammed CHERIFI</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[peskyspy]]></category>
		<category><![CDATA[ruben unteregge]]></category>
		<category><![CDATA[skype]]></category>
		<category><![CDATA[trojan skype]]></category>
		<category><![CDATA[voip]]></category>

		<guid isPermaLink="false">http://www.mcherifi.org/?p=145</guid>
		<description><![CDATA[TweetRuben Unteregger vient de publier le code source de Peskyspy, un cheval de troie pour Skype, le trojan permet le monitoring de tout appel entrant ou sortant d&#8217;une machine infectée, d&#8217;enregistrer ces conversations et les convertir au format MP3, puis les crypter et les envoyer au serveur de le l&#8217;attaquant!
Pendant 7 ans, Ruben Unteregger travaillait [...]]]></description>
			<content:encoded><![CDATA[<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.mcherifi.org/hacking/le-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html" data-text="Le code source du trojan Skype Peskyspy publié sous liscence GPL" data-count="horizontal">Tweet</a><div id="attachment_146" class="wp-caption alignleft" style="width: 151px"><img class="size-full wp-image-146" title="Ruben Unteregger" src="http://www.mcherifi.org/wp-content/uploads/2009/09/Megapanzer-Ruben-Unteregger.jpg" alt="Ruben Unteregger" width="141" height="210" /><p class="wp-caption-text">Ruben Unteregger</p></div>
<p><strong>Ruben Unteregger</strong> vient de publier le code source de <strong>Peskyspy</strong>, un cheval de troie pour Skype, le trojan permet le monitoring de tout appel entrant ou sortant d&#8217;une machine infectée, d&#8217;enregistrer ces conversations et les convertir au format MP3, puis les crypter et les envoyer au serveur de le l&#8217;attaquant!</p>
<p>Pendant 7 ans, Ruben Unteregger travaillait en tant qu&#8217;ingénieur logiciel pour une société suisse (ERA IT Solutions) , son job était de programmer un malware pour pénétrer des ordinateurs privés et espionner les communications VOIP, étant couvert par le gouvernement suisse, Ruben Unteregger est légalement resté le propriétaire des droits du code source du trojan, et a décidé de le rendre publique.</p>
<p><strong>Comment </strong><strong>Peskyspy </strong><strong>procède-t&#8217;il?</strong></p>
<p>Une fois exécuté sur la machine, PeSkyspy injecte un composant (Skype-TAP)  dans Skype, ce composant utilise les API Windows qui se chargent de la gestion des entrées/sorties audio, ainsi ce dernier peut capturer l&#8217;ensemble des données audio transitant entre le processus Skype.exe et les périphériques audio sous-jacents, ces données seront extraites au format PCM (Pulse Code Modulation) puis convertis au format MP3, et finalement transmises au serveur de l&#8217;attaquant, ce dernier se connectera à son serveur et récupèra les fichiers MP3 de toutes les conversations enregistrées!</p>
<p>En effectuant l&#8217;écoute directement sur les périphériques audio du système d&#8217;exploitation, la capture des données audio reste indépendante du protocole utilisé par Skype, même si ce dernier change de méthode de cryptage de conversation le trojan reste toujours fonctionnel ;)</p>
<p><strong>Code Source :</strong></p>
<p>Entièrement codé en C++,  le code source de PeSkyspy a été publié sur le site <a href="http://www.megapanzer.com">megapanzer</a>. Comme a précisé son auteur, le code est d&#8217;une extrême simplicité et reste une bonne référence pour les apprentis! cependant sa publication peut représenter un danger réel pour les entreprises utilisant Skype comme moyen de communication avec l&#8217;extérieur, notamment les société d&#8217;off-shoring!</p>
<p>Voilà! je vous laisse avec le code source de PeSkyspy, bonne lecture !</p>
<p><a href="http://www.megapanzer.com/wp-content/uploads/SkypeTrojan.zip">Télécharger ici le code source de PeSkyspy</a></p>
<p><a href="http://www.mcherifi.org/data/peskypy/SkypeTrojan.zip">Lien alternative</a></p>



Partager cet article:


	<a rel="nofollow"  target="_blank" href="http://www.mcherifi.org/wp-content/plugins/sociable/awesmate.php?c=twitter&t=http%3A%2F%2Fwww.mcherifi.org%2Fhacking%2Fle-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html&d=http://twitter.com/home?status=Le%20code%20source%20du%20trojan%20Skype%20Peskyspy%20publi%C3%A9%20sous%20liscence%20GPL%20-%20TARGET" title="Twitter"><img src="http://www.mcherifi.org/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.mcherifi.org/wp-content/plugins/sociable/awesmate.php?c=facebook-post&t=http%3A%2F%2Fwww.mcherifi.org%2Fhacking%2Fle-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html&d=http://www.facebook.com/share.php?u=TARGET%26t=Le%20code%20source%20du%20trojan%20Skype%20Peskyspy%20publi%C3%A9%20sous%20liscence%20GPL" title="Facebook"><img src="http://www.mcherifi.org/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.mcherifi.org%2Fhacking%2Fle-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html&amp;title=Le%20code%20source%20du%20trojan%20Skype%20Peskyspy%20publi%C3%A9%20sous%20liscence%20GPL&amp;annotation=%0D%0A%0D%0ARuben%20Unteregger%20vient%20de%20publier%20le%20code%20source%20de%20Peskyspy%2C%20un%20cheval%20de%20troie%20pour%20Skype%2C%20le%20trojan%20permet%20le%20monitoring%20de%20tout%20appel%20entrant%20ou%20sortant%20d%27une%20machine%20infect%C3%A9e%2C%20d%27enregistrer%20ces%20conversations%20et%20les%20convertir%20au%20format%20MP3%2C%20" title="Google Bookmarks"><img src="http://www.mcherifi.org/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fwww.mcherifi.org%2Fhacking%2Fle-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html&amp;title=Le%20code%20source%20du%20trojan%20Skype%20Peskyspy%20publi%C3%A9%20sous%20liscence%20GPL&amp;notes=%0D%0A%0D%0ARuben%20Unteregger%20vient%20de%20publier%20le%20code%20source%20de%20Peskyspy%2C%20un%20cheval%20de%20troie%20pour%20Skype%2C%20le%20trojan%20permet%20le%20monitoring%20de%20tout%20appel%20entrant%20ou%20sortant%20d%27une%20machine%20infect%C3%A9e%2C%20d%27enregistrer%20ces%20conversations%20et%20les%20convertir%20au%20format%20MP3%2C%20" title="del.icio.us"><img src="http://www.mcherifi.org/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.netvibes.com/share?title=Le%20code%20source%20du%20trojan%20Skype%20Peskyspy%20publi%C3%A9%20sous%20liscence%20GPL&amp;url=http%3A%2F%2Fwww.mcherifi.org%2Fhacking%2Fle-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html" title="Netvibes"><img src="http://www.mcherifi.org/wp-content/plugins/sociable/images/netvibes.png" title="Netvibes" alt="Netvibes" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.viadeo.com/shareit/share/?url=http%3A%2F%2Fwww.mcherifi.org%2Fhacking%2Fle-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html&title=Le%20code%20source%20du%20trojan%20Skype%20Peskyspy%20publi%C3%A9%20sous%20liscence%20GPL&urllanguage=fr" title="viadeo FR"><img src="http://www.mcherifi.org/wp-content/plugins/sociable/images/viadeo.png" title="viadeo FR" alt="viadeo FR" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mcherifi.org%2Fhacking%2Fle-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html&amp;title=Le%20code%20source%20du%20trojan%20Skype%20Peskyspy%20publi%C3%A9%20sous%20liscence%20GPL&amp;bodytext=%0D%0A%0D%0ARuben%20Unteregger%20vient%20de%20publier%20le%20code%20source%20de%20Peskyspy%2C%20un%20cheval%20de%20troie%20pour%20Skype%2C%20le%20trojan%20permet%20le%20monitoring%20de%20tout%20appel%20entrant%20ou%20sortant%20d%27une%20machine%20infect%C3%A9e%2C%20d%27enregistrer%20ces%20conversations%20et%20les%20convertir%20au%20format%20MP3%2C%20" title="Digg"><img src="http://www.mcherifi.org/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.mcherifi.org%2Fhacking%2Fle-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html&amp;title=Le%20code%20source%20du%20trojan%20Skype%20Peskyspy%20publi%C3%A9%20sous%20liscence%20GPL&amp;source=Mohammed+CHERIFI+Another+Web+Developper+Blog%21&amp;summary=%0D%0A%0D%0ARuben%20Unteregger%20vient%20de%20publier%20le%20code%20source%20de%20Peskyspy%2C%20un%20cheval%20de%20troie%20pour%20Skype%2C%20le%20trojan%20permet%20le%20monitoring%20de%20tout%20appel%20entrant%20ou%20sortant%20d%27une%20machine%20infect%C3%A9e%2C%20d%27enregistrer%20ces%20conversations%20et%20les%20convertir%20au%20format%20MP3%2C%20" title="LinkedIn"><img src="http://www.mcherifi.org/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://slashdot.org/bookmark.pl?title=Le%20code%20source%20du%20trojan%20Skype%20Peskyspy%20publi%C3%A9%20sous%20liscence%20GPL&amp;url=http%3A%2F%2Fwww.mcherifi.org%2Fhacking%2Fle-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html" title="Slashdot"><img src="http://www.mcherifi.org/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fwww.mcherifi.org%2Fhacking%2Fle-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html" title="Sphinn"><img src="http://www.mcherifi.org/wp-content/plugins/sociable/images/sphinn.png" title="Sphinn" alt="Sphinn" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.mixx.com/submit?page_url=http%3A%2F%2Fwww.mcherifi.org%2Fhacking%2Fle-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html&amp;title=Le%20code%20source%20du%20trojan%20Skype%20Peskyspy%20publi%C3%A9%20sous%20liscence%20GPL" title="Mixx"><img src="http://www.mcherifi.org/wp-content/plugins/sociable/images/mixx.png" title="Mixx" alt="Mixx" class="sociable-hovers" /></a>
	<a  target="_blank" href="http://blogplay.com" title="Blogplay"><img src="http://www.mcherifi.org/wp-content/plugins/sociable/images/blogplay.png" title="Blogplay" alt="Blogplay" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://identi.ca/notice/new?status_textarea=http%3A%2F%2Fwww.mcherifi.org%2Fhacking%2Fle-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html" title="Identi.ca"><img src="http://www.mcherifi.org/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fwww.mcherifi.org%2Fhacking%2Fle-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html&amp;partner=sociable" title="Print"><img src="http://www.mcherifi.org/wp-content/plugins/sociable/images/printfriendly.png" title="Print" alt="Print" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.mcherifi.org/wp-content/plugins/sociable/awesmate.php?c=pingfm&t=http%3A%2F%2Fwww.mcherifi.org%2Fhacking%2Fle-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html&d=http://ping.fm/ref/?link=TARGET%26title=Le%20code%20source%20du%20trojan%20Skype%20Peskyspy%20publi%C3%A9%20sous%20liscence%20GPL%26body=%0D%0A%0D%0ARuben%20Unteregger%20vient%20de%20publier%20le%20code%20source%20de%20Peskyspy%2C%20un%20cheval%20de%20troie%20pour%20Skype%2C%20le%20trojan%20permet%20le%20monitoring%20de%20tout%20appel%20entrant%20ou%20sortant%20d%27une%20machine%20infect%C3%A9e%2C%20d%27enregistrer%20ces%20conversations%20et%20les%20convertir%20au%20format%20MP3%2C%20" title="Ping.fm"><img src="http://www.mcherifi.org/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.mcherifi.org/wp-content/plugins/sociable/awesmate.php?c=mailto&t=http%3A%2F%2Fwww.mcherifi.org%2Fhacking%2Fle-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html&d=mailto:?subject=Le%20code%20source%20du%20trojan%20Skype%20Peskyspy%20publi%C3%A9%20sous%20liscence%20GPL%26body=TARGET" title="email"><img src="http://www.mcherifi.org/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fwww.mcherifi.org%2Fhacking%2Fle-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html&amp;title=Le%20code%20source%20du%20trojan%20Skype%20Peskyspy%20publi%C3%A9%20sous%20liscence%20GPL&amp;selection=%0D%0A%0D%0ARuben%20Unteregger%20vient%20de%20publier%20le%20code%20source%20de%20Peskyspy%2C%20un%20cheval%20de%20troie%20pour%20Skype%2C%20le%20trojan%20permet%20le%20monitoring%20de%20tout%20appel%20entrant%20ou%20sortant%20d%27une%20machine%20infect%C3%A9e%2C%20d%27enregistrer%20ces%20conversations%20et%20les%20convertir%20au%20format%20MP3%2C%20" title="Posterous"><img src="http://www.mcherifi.org/wp-content/plugins/sociable/images/posterous.png" title="Posterous" alt="Posterous" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mcherifi.org%2Fhacking%2Fle-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html&amp;title=Le%20code%20source%20du%20trojan%20Skype%20Peskyspy%20publi%C3%A9%20sous%20liscence%20GPL" title="Reddit"><img src="http://www.mcherifi.org/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://buzz.yahoo.com/submit/?submitUrl=http%3A%2F%2Fwww.mcherifi.org%2Fhacking%2Fle-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html&amp;submitHeadline=Le%20code%20source%20du%20trojan%20Skype%20Peskyspy%20publi%C3%A9%20sous%20liscence%20GPL&amp;submitSummary=%0D%0A%0D%0ARuben%20Unteregger%20vient%20de%20publier%20le%20code%20source%20de%20Peskyspy%2C%20un%20cheval%20de%20troie%20pour%20Skype%2C%20le%20trojan%20permet%20le%20monitoring%20de%20tout%20appel%20entrant%20ou%20sortant%20d%27une%20machine%20infect%C3%A9e%2C%20d%27enregistrer%20ces%20conversations%20et%20les%20convertir%20au%20format%20MP3%2C%20&amp;submitCategory=science&amp;submitAssetType=text" title="Yahoo! Buzz"><img src="http://www.mcherifi.org/wp-content/plugins/sociable/images/yahoobuzz.png" title="Yahoo! Buzz" alt="Yahoo! Buzz" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fwww.mcherifi.org%2Fhacking%2Fle-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html&amp;partner=sociable" title="PDF"><img src="http://www.mcherifi.org/wp-content/plugins/sociable/images/pdf.png" title="PDF" alt="PDF" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.mcherifi.org/feed" title="RSS"><img src="http://www.mcherifi.org/wp-content/plugins/sociable/images/rss.png" title="RSS" alt="RSS" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.diigo.com/post?url=http%3A%2F%2Fwww.mcherifi.org%2Fhacking%2Fle-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html&amp;title=Le%20code%20source%20du%20trojan%20Skype%20Peskyspy%20publi%C3%A9%20sous%20liscence%20GPL" title="Diigo"><img src="http://www.mcherifi.org/wp-content/plugins/sociable/images/diigo.png" title="Diigo" alt="Diigo" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://cgi.fark.com/cgi/fark/farkit.pl?h=Le%20code%20source%20du%20trojan%20Skype%20Peskyspy%20publi%C3%A9%20sous%20liscence%20GPL&amp;u=http%3A%2F%2Fwww.mcherifi.org%2Fhacking%2Fle-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html" title="Fark"><img src="http://www.mcherifi.org/wp-content/plugins/sociable/images/fark.png" title="Fark" alt="Fark" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.blogospherenews.com/submit.php?url=http%3A%2F%2Fwww.mcherifi.org%2Fhacking%2Fle-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html&amp;title=Le%20code%20source%20du%20trojan%20Skype%20Peskyspy%20publi%C3%A9%20sous%20liscence%20GPL" title="Blogosphere News"><img src="http://www.mcherifi.org/wp-content/plugins/sociable/images/blogospherenews.png" title="Blogosphere News" alt="Blogosphere News" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://cimlap.blogter.hu/index.php?action=suggest_link&amp;title=Le%20code%20source%20du%20trojan%20Skype%20Peskyspy%20publi%C3%A9%20sous%20liscence%20GPL&amp;url=http%3A%2F%2Fwww.mcherifi.org%2Fhacking%2Fle-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html" title="blogtercimlap"><img src="http://www.mcherifi.org/wp-content/plugins/sociable/images/blogter.png" title="blogtercimlap" alt="blogtercimlap" class="sociable-hovers" /></a>


<br/><br/>
<p class="FacebookLikeButton"><fb:like href="http%3A%2F%2Fwww.mcherifi.org%2Fhacking%2Fle-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html" layout="standard" show_faces="true" width="450" action="like" colorscheme="light"></fb:like></p>
]]></content:encoded>
			<wfw:commentRss>http://www.mcherifi.org/hacking/le-code-source-du-trojan-skype-peskyspy-publie-sous-liscence-gpl.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

