I posted some comments about Skype not listing published vulnerabilities on their "security advisory" webpage, as well as some cheesy debugger trickery they're doing to another list, see the following: http://seclists.org/lists/security-basics/2005/Aug/0524.html http://seclists.org/lists/security-basics/2005/Aug/0551.html Thanks, --scm