eBay says Skype was not attacked

Published August 18th, 2007


Skype has not been attacked, eBay said Friday, dispelling rumors that Russian hackers took down its popular online telephony service.

For more than a day now, millions of Skype users have been knocked offline by a major service outage that has crippled the service. By Friday morning, things had improved for some users, but many were still unable to connect.

eBay attributes the outage to a problem in a Skype networking algorithm, but code has been posted to a Russian security discussion forum that could supposedly be used to knock the service offline in a DOS (denial of service) attack.

The code, which was published anonymously, appears to be capable of forcing Skype’s servers to freeze up, said the discussion forum site’s editor, Valery Marchuk, in a posting to the Full Disclosure security discussion list. “Reportedly, it must have caused Skype massive disconnections,” he wrote.

Not necessarily so, say researchers who looked at the code Friday.

The code is designed to repeatedly launch Skype and overwhelm the server with information, said Andrew Storms, director of security operations with nCircle Network Security. “But I couldn’t say if it would have this kind of potential DOS effect on all of Skype,” he said.

The code simply would not work as advertised, said Stefano Zanero, CTO with Secure Network SRL. “The attack code is fake, no doubt on that,” he said. “I don’t think this is the cause of whatever is happening to Skype.”





Related Articles
Skype 3.0 beta released
Skype to allow money transfers through eBay PayPal
Ebay Skype in online music deal?
eBay may sell off Skype
eBay Skype Launches Domestic Internet Call Plans