Hello, 3APA3A,
Skype v. 5.x.x - information disclosure
2012-02-13
Skype is a proprietary voice-over-Internet Protocol service and
software application.
We have discovered improper chat logs handling, which cause in logs
accessibility even if user had enabled "no history" option in "Keep
history for" settings or even destroy it manually with "Clear history"
button.
2012-02-13: Β Β Public Disclosure
Published
Local
Low
As mentioned in the Skype FAQ
(https://support.skype.com/en-gb/faq/FA140/Managing-your-privacy-settings-Windows):
"You can choose how long to keep your conversation history for, or
delete it altogether.
This sounds safely, but in fact Skype stored all incoming and outgoing
chat messages into local sqlite3 DB (file main.db, table Messages), in
plain text. Even if "Keep history for"->"no history" option in
Settings->Security is enabled, Skype write all your data into Messages
table, but executes "delete * from Messages" Β after program exit. This
command will destroy messages at logical level in DB, but in fact, in
physical level all messages data stay alive (blocks in the DB file
only marks as destroyed), and simply can be recovered even with text
editor (as mentioned above, it is stored in plain text).
In Windows XP, go to "C:\Documents and Settings\%user
name%\Application Data\Skype\%Skype user name%" and open file main.db
with text editor. All the ducks inside.
Anonymous