RE: Skype Network Remote DoS Exploit

看板Bugtraq作者時間18年前 (2007/08/21 06:47), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/2 (看更多)
Apologies if someone already posted the obvious question but: How come this Patch Tuesday was different for Skype?=20 Why didn't the last Patch Tuesday, which had the same rebooting requirements as any other Patch Tuesday, cause the same problem with Skype? What was different about this Patch Tuesday? Anyone seen Skype give an explanation of that yet, as I'm assuming someone already asked that question, hopefully. -Marc > -----Original Message----- > From: Steven M. Christey [mailto:coley@mitre.org]=20 > Sent: Monday, August 20, 2007 10:39 AM > To: tecklord@argocom.cv.ua; bugtraq@securityfocus.com > Subject: Re: Skype Network Remote DoS Exploit >=20 >=20 > The outage being experienced by Skype was apparently due to=20 > massive simultaneous reboots and reconnects after systems=20 > installed their Windows patches. >=20 > from=20 > http://heartbeat.skype.com/2007/08/what_happened_on_august_16.html: >=20 > The disruption was triggered by a massive restart of our users' > computers across the globe within a very short timeframe as they > re-booted after receiving a routine set of patches through Windows > Update. >=20 > The high number of restarts affected Skype's network resources. > This caused a flood of log-in requests, which, combined with the > lack of peer-to-peer network resources, prompted a chain reaction > that had a critical impact. >=20 > I wonder how many other services are impacted by simultaneous=20 > Windows scheduled updates. >=20 > Anyway... given that this was going on at the time the=20 > SecurityLab.ru exploit was released, and the exploit only=20 > claims a DoS (and only seems to make a series of requests to=20 > long URIs), was the exploit actually effective, or was the=20 > "DoS" just part of the larger outage? >=20 > - Steve >=20 >=20
文章代碼(AID): #16oXdp00 (Bugtraq)
文章代碼(AID): #16oXdp00 (Bugtraq)