ðòïåëôù 


  áòèé÷ 


Apache-Talk @lexa.ru 

Inet-Admins @info.east.ru 

Filmscanners @halftone.co.uk 

Security-alerts @yandex-team.ru 

nginx-ru @sysoev.ru 

  óôáôøé 


  ðåòóïîáìøîïå 


  ðòïçòáííù 



ðéûéôå
ðéóøíá














     áòèé÷ :: Security-alerts
Security-Alerts mailing list archive (security-alerts@yandex-team.ru)

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[security-alerts] Skype security research



In Blackhat Europe 2006 Philippe BIONDI presented his work on Skype.
Skype is famous for the level of obscurity taken to protect the code and
protocol from prying eyes.

This outstanding work unveils Skype's inner workings, reverse
engineering the application and the network protocol and provides code
samples.

The author poses and later answers three questions:

   1. Is Skype a backdoor?
   2. Can one detect and block Skype traffic?
   3. Is Skype safe enough for Business use?

Several security related issues are brought to light:

    * Several heap overflows were found during the research.
    * Skype can be DoSed by a single packet
    * Skype can be abused as anything from a port scanner to a botnet
and covert channels in P2P

For the rest of this excellent work get the full paper at:
http://www.blackhat.com/presentations/bh-europe-06/bh-eu-06-biondi/bh-eu
-06-biondi-up.pdf 




 




Copyright © Lexa Software, 1996-2009.