Chinese authorities compromise millions in cyberattacks
On March 17th 2015, our websites and partner websites came under a DDoS attack. We had never been subjected to an attack of this magnitude before. This attack was unusual in nature as we discovered that the Chinese authorities were steering millions of unsuspecting internet users worldwide to launch the attack. We believe this is a major cyber-security and economic threat for the people of China.
After calling on the Internet community for help and assistance, independent researchers with access to our log files discovered the following facts:
-
Millions of global internet users, visiting thousands of websites hosted inside and outside China, were randomly receiving malicious code which was used to launch cyberattacks against GreatFire.org’s websites.
-
Baidu's Analytics code (h.js) was one of the files replaced by malicious code which triggered the attacks. Baidu Analytics, akin to Google Analytics, is used by thousands of websites. Any visitor to any website using Baidu Analytics or other Baidu resources would have been exposed to the malicious code. A list of Baidu resources known to be used for the attack appears in the report.
-
That malicious code is sent to “any reader globally” without distinguishing that user’s geographical location, meaning that the authorities did not just launch this attack using Chinese internet users - they compromised internet users and websites everywhere in the world.
-
The tampering takes places someplace between when the traffic enters China and when it hits Baidu’s servers. This is consistent with previous malicious actions and points to the Cyberspace Administration of China (CAC) being directly involved in these attacks.
More technical details of the attack can be read in a research report titled “Using Baidu to steer millions of computers to launch denial of service attacks”.
GitHub Suffers DDoS Attack
On March 25 the Chinese authorities used the same techniques to launch a DDoS attack on GitHub - our page was one of the main targets. To mitigate the DDoS attack, we mirrored content on our GitHub repository and asked users to access that page directly. The attackers then switched their attack to our GitHub page.
GitHub stated:
We are currently experiencing the largest DDoS (distributed denial of service) attack in github.com's history. The attack began around 2AM UTC on Thursday, March 26, and involves a wide combination of attack vectors. These include every vector we've seen in previous attacks as well as some sophisticated new techniques that use the web browsers of unsuspecting, uninvolved people to flood github.com with high levels of traffic. Based on reports we've received, we believe the intent of this attack is to convince us to remove a specific class of content.
We believe that “a specific class of content” refers to GreatFire.org’s GitHub page. To combat the DDoS attack from malicious JS code injected by CAC, GitHub modified https://github.com/greatfire/ to show a message to users: "WARNING: malicious javascript detected on this domain".
The URL to access our GitHub page ( https://github.com/greatfire/) is hard coded into the malicious JS. Our page is still accessible and only users who have been exposed to the malicious code will see the warning pop up message while browsing other websites. The GitHub attack is still ongoing and the malicious JS is still being injected for approximately 1% of foreign visitors to websites that are using elements from Baidu.
The Implications
When we first blogged about this attack we did not want to level accusations without evidence. Based on the technical forensic evidence provided above and the detailed research that has been done on the GitHub attack, we can now confidently conclude that the Cyberspace Administration of China (CAC) is responsible for both of these attacks.
Hijacking the computers of millions of innocent internet users around the world is particularly striking as it illustrates the utter disregard the Chinese authorities have for international as well as even Chinese internet governance norms. There was no way for an average internet user to prevent themselves from being exploited as part of this attack. This statement from Lu Wei, the head of the Cyberspace Administration of China, encapsulates our thoughts and concerns about these attacks:
We should establish an Internet order that helps maintain security. The Internet is a worldwide platform for sharing information. It is “a community of common interests”. No country is immune to such global challenges as cybercrime, hacking and invasion of privacy. In cyberspace, it is becoming increasingly difficult to uphold security for one’s own country by sacrificing that of others. It is also not practical to pursue one’s own interests by rejecting others’ needs. China is also a victim of hacking. We have always firmly opposed all forms of Internet attacks.
Inserting malicious code in this manner can only be done via the Chinese Internet backbone. Even if CAC did not launch the DDoS attack directly, they are responsible for managing the internet in China and it is not possible that they did not know what was happening. These attacks have occurred under CAC’s watch and would have needed the approval of Lu Wei.
Lu Wei and the Cyberspace Administration of China have clearly escalated the tactics that they use to control information. The Great Firewall has switched from being a passive, inbound filter to being an active and aggressive outbound one. This is a frightening development and the implications of this action extend beyond control of information on the internet. In one quick movement, the authorities have shifted from enforcing strict censorship in China to enforcing Chinese censorship on internet users worldwide. CAC can launch these attacks quickly and easily and they have the technical and financial resources behind them to continue to launch DDoS attacks against any website, anywhere in the world.
These attacks also illustrate the shortsighted nature of the Chinese authorities. Weaponizing Chinese internet services stifles global confidence in Chinese entrepreneurs and contributes to the fragmentation of the global internet. The SEC has already asked Weibo to explain how the censorship apparatus works - Baidu, a publicly-listed company in the US, may be called in to do the same.
We correctly predicted last year that China would increase their use of MITM attacks in an effort to censor encrypted websites. We now sadly predict that the DDoS attacks against us and GitHub are likely to signal a ramping up of attacks against foreign internet properties. These kinds of attacks should draw scorn and criticism from government officials of all countries around the world.
It is important to note that throughout this attack, our Android FreeBrowser app has not been impacted and is still helping thousands of Chinese internet users to bypass censorship and the great firewall every day.
On behalf of the millions of unsuspecting users manipulated by these actions, we call on Lu Wei and the Cyberspace Administration of China (CAC) to bring an end to these DDoS attacks immediately and to apologise for their blatantly disrespectful and dangerous actions.
Further Information
After the attacks started, many overseas Chinese saw these warning messages and started to post screenshots on social media.
One person uploaded a video to YouTube showing what happens when a user is injected with malicious JS in the GitHub DDoS attack. You can also see GitHub’s mitigation efforts in this video.
There are fascinating details about the attack on GitHub and changes made by the Cyberspace Administration of China to maintain the attack.
An earlier report about an unrelated GFW upgrade stated that “Every machine in China has the potential be a part of a massive DDOS attack on innocent sites,” and “They have weaponized their entire population.” That was too optimistic. Now CAC has weaponized the entire Internet population.
Comments
My spouse and I absolutely love your blog and find the majority of your post's to be exactly I'm looking
for. Does one offer guest writers to write content to suit your needs?
I wouldn't mind producing a post or elaborating on most of
the subjects you write about here. Again, awesome website!
My webpage ... photo retouching service
把墙拆了,本站自然也就关闭了,不知道耗费大量物力财力搞ddos攻击有何意义
They did not weaponise their own population, they weaponised foreigners (particularly overseas Chinese). By doing so, they do not have to pay the cost of the traffic traversing their backbone network.
The attack was injected at the inbound link of the international gateway, ultimately making this an untrustworthy provider.
If baidu (or any other network service provider) is to be trusted outside China, they must now bypass the CCP controlled international links.
I am a professional writer having good experience as well as qualifications.
http://www.writeversity.com
my secret blog is down , all attack IP is from China , seems I need to block the Chinese IP myself..
Thanks for post this helpful post - Please visit for More information about -
http://www.expert5th.in/packers-and-movers-hyderabad/
http://packersmoverspune.top3rd.in/
http://www.expert5th.in/packers-and-movers-mumbai/
http://www.expert5th.in/packers-and-movers-chennai/
We're a group of volunteers and opening a brand new scheme in our community.
Your web site provided us with helpful info
to work on. You've performed a formidable process and our entire community might be grateful to you.
Feel free to visit my blog - tłumaczenia przysięgłe gdańsk
ohhhh
copa libertadores 2015 semi final
Happy Diwali 2015
Happy New Year 2016
Happy Ganesh Chaturthi 2015
Happy Diwali 2015
Whats app status
Tamasha full movie
Bajirao mastani full movie
Hera pheri 3 full movie
Dilwale full movie
Baahubali full movie
Fan full movie
You can learn tto make tеn different types of paper airplanes օn this free website.Αѕ he is also tҺe President of the Japan Origami
Airplane Association, Һe apparently decided to makе a гun at 27.
The more recent variations օf this recreation incluɗe way more missions ɑnd
objectives.
mү site: www.printonet.pl
Thanks for sharing this nice post - For more info: -
Packers and Movers Gurgaon @ http://getpackers.in/packers-and-movers-gurgaon.html
Packers and Movers Delhi @ http://getpackers.in/packers-and-movers-delhi.html
Packers and Movers Pune @ http://getpackers.in/packers-and-movers-pune.html
Packers and Movers Bangalore @ http://getpackers.in/packers-and-movers-bangalore.html
Thanks for sharing this nice post - For more info: -
Packers and Movers Mumbai @ http://getpackers.in/packers-and-movers-mumbai.html
Packers and Movers Hyderabad @ http://getpackers.in/packers-and-movers-hyderabad.html
Packers and Movers Kolkata @ http://getpackers.in/packers-and-movers-kolkata.html
Packers and Movers Chennai @ http://getpackers.in/packers-and-movers-chennai.html
Taking after this strategy, you ought to deal with tasks in place of slightest troublesome and speediest to hardest and most lengthy. You will then permit yourself to commit the greater part of your time to the tasks that require the most time, effort, and focus , without different other tasks abating furious as a background process in the mind. It would be enjoyable to work on monstrous 10-15 page paper without more diminutive assignments annoying at you. If not, you may be forced to seek help from any custom essay writing service http://essayacademia.com to finish the larger task on time.
You must download lagu for this site, its awesome.
Brothers Full Movie
Brothers box office collection
Thanks for all your information, Website is very nice and informative content.
http://healthydrugz.com/
http://www.menspowerx.com/
niceeeee
xiaomi mi note pro
raees full movie download box office collection
Download lagu
niceeeeeeeeee
dddddfan movie trailer
amazon prime
usps tracking by tracking number
bean bad bedddddddddd
http://www.teachersday2015speech.in/
http://www.rakhirakshabandhan2015.in/
here we are giving you must check these all links >>
Hey check out these
Gandhi jayanti 2015 sms
Gandhi jayanti 2015 Images
Gandhi jayanti 2015 Hd Wallpapers
Gandhi jayanti 2015 Speech
Gandhi jayanti 2015 Wishes
Gandhi jayanti 2015 Patriotic Songs
Gandhi jayanti 2015 Quotes
Gandhi jayanti 2015 Poems
Also check these Muharram 2015 :-
10th Muharram 2015 Images
Muharram 2015 Greeting Cards
Muharram 2015 Matam Videos
Muharram 2015 Wishes
Muharram 2015 Sms
Muharram 2015 Duas Sms
Muharram 2015 Quotes
Or Must See These :-
Dhanteras Puja 2015
Dhanteras Puja Vidhi 2015
Dhanteras 2015 Wishes
Dhanteras 2015 Kavita
Dhanteras 2015 Quotes
Dhanteras 2015 Sms
Dhanteras 2015 Images
Dhanteras Puja Songs 2015
Dhanteras 2015 Gift Ideas
Dhanteras Puja Mantra
Dhanteras Puja Muhurat
Raksha Bandhan 2015 Wishes
Raksha Bandhan Sms
Raksha Bandhan Status
Rakshabandhan 2015 Shubh Muhurat Timing
Happy New Year 2016 Quotes
Happy New Year 2016 Wishes
Happy New Year 20-16 Images
Happy New Year Eve 2016
Happy New Year 2016 Status
Happy New Year 2016 Greeting Cards
See more for navratri
Happy Navratri 2015 Status
Happy Navratri 2015 Durga Mata Photos
Happy Navratri 2015 Sms
Navratri Shubh Muhurat
Navratri Vrat Vidhi
See Our diwali stuff click on these links
Happy Diwali 2015 Sms
Happy Diwali 2015 Facebook Cover Images
Happy Diwali HD 3D Images
It is appropriate time to make some plans for the future and it is time to be happy. I’ve read this post and if I could I desire to suggest you few interesting things or tips. Maybe you can write next articles referring to this topic. I desire to read more things about it.
http://www.advancehappynewyear2016.com
http://www.advancehappynewyear2016.com
Future yeah because it's very fashionable people and be turned the activity experience non led by opportunity to ghetto the net I organized on last evening and really in Feb me count happen actually in
happy new year 2016 images pictures photos wallpapers
happy new year 2016 Quotes wishes messages sms greetings
Packers and Movers Bangalore Or http://www.top5th.co.in/packers-and-movers-bangalore/
Packers and Movers Chennai Or http://www.top5th.co.in/packers-and-movers-chennai/
Packers and Movers Hyderabad Or http://www.top5th.co.in/packers-and-movers-hyderabad/
Packers and Movers Mumbai Or http://www.top5th.co.in/packers-and-movers-mumbai/
Packers and Movers Noida Or http://www.top5th.co.in/packers-and-movers-noida/
Packers and Movers Pune Or http://www.top5th.co.in/packers-and-movers-pune/
Packers and Movers Chandigarh Or http://www.top5th.co.in/packers-and-movers-chandigarh/
Packers and Movers Delhi Or http://www.top5th.co.in/packers-and-movers-delhi/
Packers and Movers Gurgaon Or http://www.top5th.co.in/packers-and-movers-gurgaon/
Raksha Bandhan Quotes
Teachers Day
Check out our latest collection of Rakhi HD Images 2015, Rakhi Live Wallpapers, Rakhi Bollywood Songs, Send Rakhi Online, Rakhi Making, Rakhi sms messages in Hindi and English for brothers and sisters, Raksha Bandhan Images 2015, Rakhi Gifts for Sisters, Raksha Bandhan Quotes - 2015
==> http://www.rakshabandhanimages2015.net/ <==
Check out our latest collection of Rakhi HD Images 2015, Rakhi Live Wallpapers, Rakhi Bollywood Songs, Send Rakhi Online, Rakhi Making, Rakhi sms messages in Hindi and English for brothers and sisters, Raksha Bandhan Images 2015, Rakhi Gifts for Sisters, Raksha Bandhan Quotes - 2015 :
==> Raksha Bandhan Images 2015 <==
==> Raksha Bandhan Special Bollywood Songs 2015 <==
Thank you for such a well written article. It’s full of insightful information and entertaining descriptions. Your point of view is the best among many.
http://www.mayfairservicedapartments.com/
It is appropriate time to make some plans for the future and it is time to be happy. I’ve read this post and if I could I desire to suggest you few interesting things or tips.
thanks by stallion business
Packers and Movers Pune, http://www.best7th.in/packers-and-movers-pune/
Packers and Movers Gurgaon, http://www.best7th.in/packers-and-movers-gurgaon/
Packers and Movers Chennai, http://www.best7th.in/packers-and-movers-chennai/
Packers and Movers Mumbai, http://www.best7th.in/packers-and-movers-mumbai/
Packers and Movers Bangalore, http://www.top6pm.in/packers-and-movers-bangalore.html
Packers and Movers Gurgaon, http://www.top6pm.in/packers-and-movers-gurgaon.html
Packers and Movers Mumbai, http://www.top6pm.in/packers-and-movers-mumbai.html
Packers and Movers Delhi, http://www.top6pm.in/packers-and-movers-delhi.html
Packers and Movers Pune, http://www.top6pm.in/packers-and-movers-pune.html
What an article i just loved it amazing awesome. i will love to listen more on this.
You can also check these
http://www.happydiwali2015cards.com
would love to listen more on this great !
Thanks
I know that would be fine if i say i need to make :
http://conceptive.in/gandhi-jayanti-2015/gandhi-jayanti-images/
would love to listen more on this great !
Thanks
Thanks for post this helpful post - Please visit for More information about -
Packers and Movers in Chennai @
http://www.expert5th.in/packers-and-movers-chennai/
Packers and Movers in Hyderabad @
http://www.expert5th.in/packers-and-movers-hyderabad/
Packers and Movers in Pune @
http://www.expert5th.in/packers-and-movers-pune/
Packers and Movers in Mumbai @
http://www.expert5th.in/packers-and-movers-mumbai/
This article is really fantastic and thanks for sharing the valuable post.
Packers and Movers in Gurgaon @
http://www.expert5th.in/packers-and-movers-gurgaon/
Packers and Movers in Delhi @
http://www.expert5th.in/packers-and-movers-delhi/
Packers and Movers in Bangalore @
http://www.expert5th.in/packers-and-movers-bangalore/
Thanks for all your information, Website is very nice and informative content.
Packers and Movers in Faridabad @
http://www.expert5th.in/packers-and-movers-faridabad/
Packers and Movers in Noida @
http://www.expert5th.in/packers-and-movers-noida/
Packers and Movers in Thane @
http://www.expert5th.in/packers-and-movers-thane/
Packers and Movers in Navi Mumbai @
http://www.expert5th.in/packers-and-movers-navimumbai/
Packers and Movers in Ghaziabad @
http://www.expert5th.in/packers-and-movers-ghaziabad/
Thanks for post this helpful post - Please visit for More information about -
Packers and movers in Gurgaon @
http://www.dteller.in/packers-and-movers-gurgaon/
Packers and Movers in Bangalore @
http://www.dteller.in/packers-and-movers-bangalore/
Packers and Movers in Hyderabad @
http://www.dteller.in/packers-and-movers-hyderabad/
Packers and Movers in Pune @
http://www.dteller.in/packers-and-movers-pune/
They did not weaponise their own population, they weaponised foreigners (particularly overseas Chinese). By doing so, they do not have to pay the cost of the traffic traversing their backbone network
http://conceptive.in/
Nice and informative article thanks to share with us.
http://edugeeksalert.in/
Does one offer guest writers to write content to suit your needs?
I wouldn't mind producing a post or elaborating on most of
the subjects you write about here. Again, awesome website!
My webpage , thanks alote by http://www.indiantrio.com
http://kuchtohhaiteremeredarmiyaan.com/
http://pyarkohojaanedo.com/
http://aajkiraathaizindagi.net/
http://www.hatestory3.in/
http://biggboss92015.in/
wow thanks for share great info here i really like it your site and you can check http://www.hatestory3boxofficecollection.in/
http://www.hatestory3movie.in/
http://www.netaffiliate.in/vijayadashami-dussehra-images/vijayadashami-d...
Pages
Add new comment