Chinese authorities compromise millions in cyberattacks
On March 17th 2015, our websites and partner websites came under a DDoS attack. We had never been subjected to an attack of this magnitude before. This attack was unusual in nature as we discovered that the Chinese authorities were steering millions of unsuspecting internet users worldwide to launch the attack. We believe this is a major cyber-security and economic threat for the people of China.
After calling on the Internet community for help and assistance, independent researchers with access to our log files discovered the following facts:
-
Millions of global internet users, visiting thousands of websites hosted inside and outside China, were randomly receiving malicious code which was used to launch cyberattacks against GreatFire.org’s websites.
-
Baidu's Analytics code (h.js) was one of the files replaced by malicious code which triggered the attacks. Baidu Analytics, akin to Google Analytics, is used by thousands of websites. Any visitor to any website using Baidu Analytics or other Baidu resources would have been exposed to the malicious code. A list of Baidu resources known to be used for the attack appears in the report.
-
That malicious code is sent to “any reader globally” without distinguishing that user’s geographical location, meaning that the authorities did not just launch this attack using Chinese internet users - they compromised internet users and websites everywhere in the world.
-
The tampering takes places someplace between when the traffic enters China and when it hits Baidu’s servers. This is consistent with previous malicious actions and points to the Cyberspace Administration of China (CAC) being directly involved in these attacks.
More technical details of the attack can be read in a research report titled “Using Baidu to steer millions of computers to launch denial of service attacks”.
GitHub Suffers DDoS Attack
On March 25 the Chinese authorities used the same techniques to launch a DDoS attack on GitHub - our page was one of the main targets. To mitigate the DDoS attack, we mirrored content on our GitHub repository and asked users to access that page directly. The attackers then switched their attack to our GitHub page.
GitHub stated:
We are currently experiencing the largest DDoS (distributed denial of service) attack in github.com's history. The attack began around 2AM UTC on Thursday, March 26, and involves a wide combination of attack vectors. These include every vector we've seen in previous attacks as well as some sophisticated new techniques that use the web browsers of unsuspecting, uninvolved people to flood github.com with high levels of traffic. Based on reports we've received, we believe the intent of this attack is to convince us to remove a specific class of content.
We believe that “a specific class of content” refers to GreatFire.org’s GitHub page. To combat the DDoS attack from malicious JS code injected by CAC, GitHub modified https://github.com/greatfire/ to show a message to users: "WARNING: malicious javascript detected on this domain".
The URL to access our GitHub page ( https://github.com/greatfire/) is hard coded into the malicious JS. Our page is still accessible and only users who have been exposed to the malicious code will see the warning pop up message while browsing other websites. The GitHub attack is still ongoing and the malicious JS is still being injected for approximately 1% of foreign visitors to websites that are using elements from Baidu.
The Implications
When we first blogged about this attack we did not want to level accusations without evidence. Based on the technical forensic evidence provided above and the detailed research that has been done on the GitHub attack, we can now confidently conclude that the Cyberspace Administration of China (CAC) is responsible for both of these attacks.
Hijacking the computers of millions of innocent internet users around the world is particularly striking as it illustrates the utter disregard the Chinese authorities have for international as well as even Chinese internet governance norms. There was no way for an average internet user to prevent themselves from being exploited as part of this attack. This statement from Lu Wei, the head of the Cyberspace Administration of China, encapsulates our thoughts and concerns about these attacks:
We should establish an Internet order that helps maintain security. The Internet is a worldwide platform for sharing information. It is “a community of common interests”. No country is immune to such global challenges as cybercrime, hacking and invasion of privacy. In cyberspace, it is becoming increasingly difficult to uphold security for one’s own country by sacrificing that of others. It is also not practical to pursue one’s own interests by rejecting others’ needs. China is also a victim of hacking. We have always firmly opposed all forms of Internet attacks.
Inserting malicious code in this manner can only be done via the Chinese Internet backbone. Even if CAC did not launch the DDoS attack directly, they are responsible for managing the internet in China and it is not possible that they did not know what was happening. These attacks have occurred under CAC’s watch and would have needed the approval of Lu Wei.
Lu Wei and the Cyberspace Administration of China have clearly escalated the tactics that they use to control information. The Great Firewall has switched from being a passive, inbound filter to being an active and aggressive outbound one. This is a frightening development and the implications of this action extend beyond control of information on the internet. In one quick movement, the authorities have shifted from enforcing strict censorship in China to enforcing Chinese censorship on internet users worldwide. CAC can launch these attacks quickly and easily and they have the technical and financial resources behind them to continue to launch DDoS attacks against any website, anywhere in the world.
These attacks also illustrate the shortsighted nature of the Chinese authorities. Weaponizing Chinese internet services stifles global confidence in Chinese entrepreneurs and contributes to the fragmentation of the global internet. The SEC has already asked Weibo to explain how the censorship apparatus works - Baidu, a publicly-listed company in the US, may be called in to do the same.
We correctly predicted last year that China would increase their use of MITM attacks in an effort to censor encrypted websites. We now sadly predict that the DDoS attacks against us and GitHub are likely to signal a ramping up of attacks against foreign internet properties. These kinds of attacks should draw scorn and criticism from government officials of all countries around the world.
It is important to note that throughout this attack, our Android FreeBrowser app has not been impacted and is still helping thousands of Chinese internet users to bypass censorship and the great firewall every day.
On behalf of the millions of unsuspecting users manipulated by these actions, we call on Lu Wei and the Cyberspace Administration of China (CAC) to bring an end to these DDoS attacks immediately and to apologise for their blatantly disrespectful and dangerous actions.
Further Information
After the attacks started, many overseas Chinese saw these warning messages and started to post screenshots on social media.
One person uploaded a video to YouTube showing what happens when a user is injected with malicious JS in the GitHub DDoS attack. You can also see GitHub’s mitigation efforts in this video.
There are fascinating details about the attack on GitHub and changes made by the Cyberspace Administration of China to maintain the attack.
An earlier report about an unrelated GFW upgrade stated that “Every machine in China has the potential be a part of a massive DDOS attack on innocent sites,” and “They have weaponized their entire population.” That was too optimistic. Now CAC has weaponized the entire Internet population.
Comments
http://www.netaffiliate.in/vijayadashami-dussehra-songs-2015/vijayadasha...
http://appsdevotion.com/
very good http://www.happydiwalisms.net.in
very nce
very nice
http://www.happydiwalisms.net.in
http://www.diwalimessages.net.in
شركة تنظيف بالرياض
شركة تنظيف فلل بالرياض
شركة تنظيف خزانات بالرياض
شركة تنظيف منازل بالرياض
شركة نقل عفش بالرياض
شركة مكافحة حشرات بالرياض
شركة رش مبيدات بالرياض
شركة مكافحة حشرات بالدمام
شركة رش مبيدات بالدمام
Hate Story 3 Box Office Collection
http://www.hatestory3.net/
http://moviesboxofficial.com/
http://tune-pk.com/
http://watchfreemoviezonline.com/
http://www.stromanbieter.de.rs/ dfdf sd
http://www.stromanbieter.de.rs/ dfdf sd
nice..
http://dilwaleboxoffice.in/
nice..
http://dilwaleboxoffice.in/
nice...
http://dilwaleboxoffice.in/
With best compliments from
https://www.makingmove.com
Thank you for the post. It's really great t know about a event like this
super smash flash 2: http://supersmashflash2a.com/
gmail sign in: http://gmailsigninaz.com/
facebook login: http://facebookloginaz.com/
hotmail sign in: http://hotmailsigninaz.com/
hotmail: http://hotmailaz.com/
happy wheels az: http://happywheelsaz.net/
top unblocked games: http://topunblockedgames.com
lupus: http://lupuswiki.com/
http://www.simpygrewal.in/
http://www.nabihakhan.net.in/
http://www.poonamaggarwal.co.in/
http://www.trishagupta.org/
Golden Globe Awards 2016 Live Stream || @ On January 10, 2016 set the date for the 73rd Annual Golden Globe Awards by The Hollywood Foreign Press.
Golden Globe Awards 2016 Live Stream
http://goldenglobeawards2016livestream.com/
Justin Bieber Tickets Tours & Concert Updates
http://justinbieberconcert.co/
Knock! Knock! Knock!!! Hello……!!!! We are back with a big bang award show which is Golden Globe Award 2016. Great show, some great people, beautiful and spectacularly talented actresses/actors and lots of fun, entertainment, and suspense’re to be revealed.
This award has been continuing since 1943. Group of writers gathered together to frame the Hollywood Foreign Press Association and made liberally distributed award named Golden globe Award where they play momentous role in film making. The first award was being honored on best achievement in 1943 filmmaking and was held in January 1944, at the 20th Century –Fox studios. Successively, every year ceremonies were held in different venues for decades.
This is I was searching for: http://www.daysbeforevalentinesdays.com/
Thanks!
ohhhhhhhhhhhhhh hhhhhhhhhhhhhh hhhh gs y : http://www.daysbeforevalentinesdays.com/
شركة تنظيف بالرياض
شركة تنظيف فلل
بالرياض
شركة تنظيف خزانات بالرياض
شركة تنظيف منازل بالرياض
شركة مكافحة حشرات بالرياض
شركة رش مبيدات
بالرياض
شركة مكافحة حشرات بالدمام
شركة
كشف تسربات المياه بالرياض
شركة تنظيف بالدمام
شركة تنظيف شقق بالدمام
شركة تنظيف فلل بالدمام
شركة تنظيف بخميس مشيط
http://www.sattamatkak.in
Firmamız 2009 Yılından Buyana ADANA Kentinde Toner , Güvenlik Kamerası
Notebook Pc ve Tablet pc Onarımı , Notebook Ve Tablet Pc Yedek Parça ,
Alanlarında Hizmet vermekte Olup Profesyonel Ekibi ile Müşteri
Memnuniyeti Odaklı Çalışmaktadır. NFL : http://www.adanabilgisayartamiri.com
Thanks for all your information, Website is very nice and informative conten
شركة تنظيف بالدمام
شركة تنظيف شقق بالدمام
شركة تنظيف فلل بالدمام
شركة تنظيف بالطائف
شركة تنظيف بخميس مشيط
Danke für das Teilen mit mir einige Ihrer Ideen betreffend sind die Möglichkeit des Verminderns unserer gegenwärtigen Arbeitslosigkeit Mühen, indem Sie einen verkürzten Workweek einleiten.
loola-games.info juegosloola.us juegosdemafa.com yoobgamesfriv.com yoob2.com
Danke für diesen eindrucksvollen Bericht und das ehrliche Teilen, danke, dass wir zusammen stehen. Mariana, danke für das Teilen, danke in und bei uns zu sein; danke für deinen Unterricht, deine Bücher, deine Erinnerungen.
jogosdamafa.com loolafrozen.com juegosdeloola.com loola2015.com friv2016.info
Danke für das Teilen mit mir einige Ihrer Ideen betreffend sind die Möglichkeit des Verminderns unserer gegenwärtigen Arbeitslosigkeit Mühen, indem Sie einen verkürzten Workweek einleiten.
http://www.jogosdamafa.com
http://www.loolafrozen.com
http://www.juegosdeloola.com
http://www.loola2015.com
http://www.friv2016.info
This is a great article, that I really enjoyed reading. Thanks for sharing.
Netflix
This type of message always inspiring and I prefer to read quality content, so happy to find good place to many here in the post, the writing is just great, thanks for the post.
http://www.rajarakminimarket.com
http://www.rajaraktoko.com
http://www.rajaraksupermarket.com
Firstcab always ensures its users to get the best quality services along with the price as concern.That is the reason why we have choosen the best bangalore cabs/taxi service vendors from bunch of discrete cabs providers in the city - See more at: http://www.firstcab.in/
Your way of describing the whole thing in this paragraph is actually pleasant, all be able to without difficulty know it, Thanks a lot.
http://reet-result.in/
I was very happy to find this page. I need to thank you for ones time just for this wonderful read!! I definitely
loved every bit of it and i also have you book marked to look at new things on your site.
http://uptetresult2015-16.in/
http://www.expert5th.in/packers-and-movers-pune/
For Free Query Visit:-
Packers and Movers Chennai @ http://www.shiftingsolutions.in/packers-and-movers-chennai.html
Packers and Movers Hisar @ http://www.shiftingsolutions.in/packers-and-movers-hisar.html
Packers and Movers Panipat @ http://www.shiftingsolutions.in/packers-and-movers-panipat.html
Packers and Movers Sonipat @ http://www.shiftingsolutions.in/packers-and-movers-sonipat.html
Danke für das Teilen mit mir einige Ihrer Ideen betreffend sind die Möglichkeit des Verminderns unserer gegenwärtigen Arbeitslosigkeit Mühen, indem Sie einen verkürzten Workweek einleiten. mazzraasaida.blogspot.com
I was very happy to find this page. I need to thank you for ones time just for this wonderful read!! I definitely
loved every bit of it and i also have you book marked to look at new things on your site.
http://sscconstablegdresult.in/
شركة تنظيف بالطائف
شركة تنظيف ببيشة
شركة تنظيف بمكة
شركة تنظيف بجازان
شركة تنظيف بالقصيم
شركة تنظيف بحائل
شركة نقل اثاث بالدمام
شركة نقل اثاث بجدة
شركة نقل اثاث بمكة
شركة تنظيف بخميس مشيط
شركة تنظيف بالمدينة المنورة
شركة تنظيف بابها
This article is really fantastic and thanks for sharing the valuable post. Please Visit our wonderful and valuable website:
http://packers-and-movers-bangalore.in/
http://packers-and-movers-bangalore.in/packers-and-movers-bidari-bagalkot
http://packers-and-movers-bangalore.in/packers-and-movers-mahalakshmipur...
Packers And Movers Bangalore not only look after our perfection in Movers And Packers services but also ensure the satisfactory returned settlement of our client. Because one brings ten more to Movers And Packers Bangalore.
Nice article is provided by you admin, thanks for this article becoze it helped me lot and below we have some stuff which our topic to write article so please checkout them.
http://www.happyholi2016messagessms.in
http://www.womensday2016wishes.com
http://www.happyholi2016images.co.in
http://www.facebookwhatsappstatus.in
This article is really fantastic and thanks for sharing the valuable post. Please Visit our wonderful and valuable website:
http://al3ab-banat01.blogspot.com
I can't say a lot in regards to this thought, yet it's really intriguing exchange surely.
HR Homework Help
http://www.hrassignments.com
I can't say a lot in regards to this thought, yet it's really intriguing exchange surely.
Accounting Term Paper Help
http://www.accountingassignments.help
This is pleasant article. I might want to a debt of gratitude is in order for your endeavors and recommendations. I truly acknowledge to this article.
PHP Homework Help
http://www.phphelponline.com
I appreciate this work amazing post for us I like it.
Term Paper Writing Help
https://www.termpaperwriting.services
Our website is No. 1 in Academic Writing Service & Custom Term Paper Writing Service . Feel free to hire us for your academic needs. We are the perfect paper writers you will ever need.
term paper writer
https://www.academicpaperwriter.com/
This topic is interesting.
The messages that you have conveyed through your article is helpful to the public. It is essential to conduct an awareness program to inform the public about cyber attacks and all. Essay writing services is here to support you for starting fight against cyber attacks.
http://essayssos.com/
If you love bird watching then Corbett is virtual haven for such tourists. Corbett and its adjoining area is a home
to more than 650 species of residents and migratory birds. Particularly Dhikala is fine place to look for birds of
prey, more than over 50 species of raptors alone shows the healthy biodiversity of the area. Their multiplex
behavior is intriguing and their varied songs are very much pleasing to the ear. In a nutshell, this finest national
park of India is well known for rich and varied wildlife including royal Bengal tiger, elephant, four to five
species of deer and rich birdlife.
http://corbettresort.in/Marchula-46
http://corbettresort.in/JamunVillage-48
Pages
Add new comment