32 ms·
GitHub hit by DDoS attack
- jdsnape 12y agoLooks like another case of Chinese traffic being tampered with to load resources from another domain - in this case Baidu searches: http://insight-labs.org/?p=1682 http://insight-labs.org/?p=1682
- nickysielicki 12y agoThis is far more interesting than the OP. Thanks for sharing.
- plq 12y agoYou mean TFA.
- fibo 12y agoSad but true, it is better to use tcpwrappers to block China bot nets, see for example http://g14n.info/2015/03/server-hardening-tips/#restrict-ssh-access http://g14n.info/2015/03/server-hardening-tips/#restrict-ssh...
- nickodell 12y agoSo who's doing this? The Chinese government? Baidu themselves?
- toong 12y agoI was going to make point that Baidu should serve his analytics-js over https only. But thinking about it, there are fails on so many levels.
- _RPM 12y agodef noticed this like 5 minutes ago. DNS completely failed for a second.
- ptr 12y agoStill getting lots of instability in spite of the status page.
- jhildings 12y agoA good warning sign for companies that only have their codebase at Github which seem more common to me nowdays. If you run your own server at least you can like physicaly restrict the access to local network only.
- reidrac 12y agoI'm not sure if I understand what you're saying. They're using git, don't they? Obviously you miss the web interface to issues, pull requests, etc; but if you don't have git repositories distributed in your own infrastructure you're doing it wrong.
- inglor 12y agoWhy though? The whole point of git is that it's distributed source control - you _always_ have a local copy of the source and the history. That's one of the biggest wins in using git and not a centralised source control in the first place..
- butwhy 12y agoBut you don't necessarily have an up to date copy. If you had a local mirror, you could queue collective commits until the github server becomes available again.
- hayd 12y agoYou have your own local branches...
- ademarre 12y ago> But you don't necessarily have an up to date copy. You would if you designed your build process that way. I think it's a good idea to eliminate all third party build-time dependencies. In practice this means keeping a Git clone of everything to use for official builds, or anything that can't risk a third-party being unavailable when you need it most.
- 12y ago
- alexchamberlain 12y agoMaking the not unrealistic assumption that the data is _not_ normally distributed, mean is a useless average here. You should be looking at median, which will be much less distorted by the long tail.
- hayd 12y agoWould be interesting to see the 10/90% too.
- TeMPOraL 12y agoThis, or if you are evil and know that your competitor has a stupidly-designed build process that depends on GitHub being available - by DDoSing GitHub itself you'll make your competition unable to work.
- MollyR 12y agoSome smaller companies depend on github. I think its stupid, but I know of at least one ivy league university subgroup who depend on github for everything. Management wanted to outsource everything they could, they just saw developers and IT as cost sinks.
- edwintorok 12y agothe page says that everything is operating normally, but the main github.com page doesn't even load for me... Edit: works again now
- mwadams 12y agoIt seems fine for me - and http://www.downforeveryoneorjustme.com/github.com http://www.downforeveryoneorjustme.com/github.com
- mwadams 12y agoHowever, I still prefer http://gitlab.com http://gitlab.com :-)
- singlefailpoint 12y agoCrappy startup: "we put all our code into one place, depend on all our code from place, and only hire people when we can see their code examples in that same one place, Github." Experienced better tech person: "Good luck with your single point of failure!" (walks away laughing).
- Gigablah 12y agoWise and mature tech person: "Here's what you can do to mitigate it." (Gives some helpful advice).
- toong 12y agoYou would have made a valid point if git wasn't fully distributed. But it is. And every dev has full copy of the repository. This is only a temp DDoS situation ? And you can host your code repository elsewhere. You can even use multiple remotes simultaneously. Not that it's convenient (that's why we use Github), but hell, you just create some ssh-accounts for your colleges and host the repository on your laptop ? Sorry, who was laughing and why ?
- mikekchar 12y agoIt's a very good point. I had a slight inconvenience today because I was missing one commit on a branch that I wanted. But I could easily get it from my colleague. If my colleague wasn't available, then I've only missed one commit. It's not a massive issue to just redo the work. When I get access to the commit I'm missing I can even diff my changes against it and choose which one I like better. Even if Github went away completely, we wouldn't have that much of a problem. It is important to have systems that maintain a copy of old projects, though. It would be easy to think, "Oh it's in Github. I don't have to worry about it." But that's stupid, of course (not that it will stop people from doing it...)
- dagw 12y agoThe real problem that I can see is not for developing, but all the build and deployment systems that are hard coded to pull in dependencies from github.
- dengnan 12y agoThis is an article [0] summarizes what happened. It is however in Chinese. So let me put a simple summary here: Baidu has Baidu Analytics, a service similar to Google Analytics. In short, a website includes a javascript file from Baidu and Baidu will report some basic analytics to the site manager like how many visitors per day, how much time they spent on average per page etc. Someone in the middle between a client outside China and Baidu, allegedly it should be the Great Fire Wall, changed the javascript file from Baidu and added some code so that any client executing the javascript file will periodically access https://github.com/greatfire/ https://github.com/greatfire/ and https://github.com/cn-nytimes/ https://github.com/cn-nytimes/. This means any user who is accessing a site using Baidu Analytics will be an attacker to github. Here is a simple solution: Block any javascript from Baidu if you do not use it. For chrome users, add the pattern [*.]baidu.com. See here[1]. Edit 1: Added a solution. Edit 2: Format. Edit 3: Oh, it's not only Baidu Analytics. Baidu Ads' javascript is also being hijacked and changed [2]. Imagine that all sites containing Google Ads use their visitors as attackers to attack github. Now it is literally what is happening to Baidu and its customers (and their customers' visitors.) The javascript is only changed for visitors outside China. This is why people believe that is done by Chinese government --- the only entity who has total access to all out-going routers in China. Since many Chinese users use VPN or other types of proxy to access Internet, they are all considered as visitors outside China. 0. http://drops.wooyun.org/papers/5398 http://drops.wooyun.org/papers/5398 1. http://www.howtogeek.com/tips/how-to-block-javascript-and-ads-for-a-single-site-in-chrome/ http://www.howtogeek.com/tips/how-to-block-javascript-and-ad... 2. http://www.solidot.org/story?sid=43489 http://www.solidot.org/story?sid=43489
- im2w1l 12y agoWow this must be a major blow to Baidu. This time their scripts was hijacked to DDoS, not that bad. Since we all know that the Chinese government would never do a thing like this, it must mean that there is a very powerful hacker group behind this. And they are probably DDoSing for profit. Who knows what they may do for profit next? Spy on users? Steal passwords? Credit cards? Impersonating users? Until Baidu implements a secure crypto solution that can prevent this malevolent hacker gang from sending corrupted scripts, it would be very irresponsible to use baidu analytics!
- r3bl 12y agoWhy the hell would anyone launch a DDoS attack against GitHub? Seriously, the only point I see in DDoS-ing GitHub is to prove yourself that you can DDoS it.
- brador 12y agoThere is the Github you see and use, then there is the Github you don't see. It's a service that allows files/information to be uploaded, downloaded, shared, by pretty much anyone. That's something some governments sadly don't like.
- deleted 12y ago[deleted]
- rodgerd 12y agoNote that it seems to be attacking two specific projects, according to the details above, one of which is to get around the restrictions of the Great Firewall of China. It's most likely an threat about the advisability of hosting something unapproved-of.
- mirhagk 12y agoInterestingly enough they have succeeded in pulling those projects down.
- dagw 12y agoGiven that the DDoS wasn't targeted at "https://github.com/" https://github.com/" but rather "https://github.com/greatfire/" https://github.com/greatfire/" and "https://github.com/cn-nytimes/" https://github.com/cn-nytimes/", two projects that can reasonably be described as not being pro Chinese government, it seems that github was targeted for hosting anti-Chinese 'propaganda'.
- r3bl 12y agoThanks for the clarification!
- mitkok 12y agoHow is this news ?
- bitinn 12y agoI have written a brief summary of issues, as a tweetstorm: https://twitter.com/bitinn/status/581350026217013248 https://twitter.com/bitinn/status/581350026217013248
- tsheeeep 12y agoWe use bower and npm for our project. Every couple of months github is under attack by a DDoS or not working correctly leaving us with broken deploy scripts. What is the best way to fix this? We don't like the idea of commiting the node_modules or bower_components folder. Is there a tool which will cache the npm and bower sources so they only have to be downloaded if something changes?
- kowdermeister 12y agoCommitting downloaded packages is not a bad practice. Yes, it can be a bit big, but otherwise I don't see much problem with it. You will be always sure that the installed packages are compatible with each other.
- tsheeeep 12y agoTo be sure everything that we know works together we use things like npm-shrinkwrap files. We don't like it because it makes the git changelogs a lot bigger and almost unreadable if you want to compare a pull request.
- Already__Taken 12y agoYes the way you should do it is with shrinwrap to ensure the consistency of your dependencies. As for the actual files if you depend on it you should have your own npm repo caching them that you deploy from and have that mirror the public one. but for small projects or quick deploys absolutely just go ahead and commit the modules.
- __david__ 12y agoYou could commit them to their own repository so they don't taint your main repo. Then use a submodule to pull that repo in to the main repo...
- STRML 12y agoTry https://github.com/uber/npm-shrinkwrap https://github.com/uber/npm-shrinkwrap, it produces deterministic shrinkwrap files that actually diff properly.
- rdl 12y agoSomeone turning a widely-used third-party-hosted JS into "evil" seems like an incredibly difficult layer 7 DDoS to address. Assuming you have great capacity to filter on the edge (CloudFlare, being Google, etc.), but a limited backend, it's still very hard to identify legit vs. non-legit traffic and do filtering. (Obviously if the attack is against, say, Chinese users, and your site's legitimate users are mainly in Estonia, you can do filtering, or if the attack only hits an obscure URL, but the attack doesn't have to be weak in that way.) There are a bunch of potential ways to address it, but they all work best if you have a site with a defined community of users. If you're a large public site, without login, it's hard. Some of the better techniques are in-browser challenges (JS, CAPTCHA, etc.), but it's conceivable with enough endpoint with real browsers and real humans on them, these could get defeated.
- nickodell 12y agoGitHub seems to have done just this. Both attack URLs return >alert("WARNING: malicious javascript detected on this domain") They can probably serve that without hitting their database servers.
- zhufenggood 12y agoBaidu's javascript cdn is being Hack by national firewall, inject these JS attack script. If other webseit include some javascript library from Baidu's javascript CDN will automatically run JS script that will DDOS attack Github. The attack JS script is here: https://gist.github.com/zhufenggood/7bb040b1effb71d14bcc https://gist.github.com/zhufenggood/7bb040b1effb71d14bcc Here is deobfuscate version using http://jsbeautifier.org/ http://jsbeautifier.org/ https://gist.github.com/zhufenggood/6a38c2a2b2185977b3cb https://gist.github.com/zhufenggood/6a38c2a2b2185977b3cb Github notice that, it replace that DDOS http request respond with a alert("WARNING: malicious javascript detected on this domain"). That is why some Chinese guy gets a weird pop-up with English text when visiting Chinese websites.
- deleted 12y ago[deleted]
- deleted 12y ago[deleted]
- talnet 12y agoclever move we should say ? or any better idea ?
- andao 12y agomaybe the point is to scare people into preemptively blocking Chinese IPs so the Chinese gov doesn't have to swat flies with the Great Firewall. it's good marketing too: "look at all those foreigners who refuse to let us access the free internet!" "anti-Chinese prejudice!" etc etc
- dEnigma 12y agoIf that is their plan it seems to be working, judging by some of the comments here.
- mahouse 12y agoI wonder what's the positive effect of sharing the same Internet with the chinese. I never visit nor I know someone who visits sites from China. Major ISPs from the west should definitely consider blackholing all traffic coming from there to avoid DoS attacks, spam, etc. – From my experience, this would mitigate spam by a 50% or even more.
- danuker 12y agoI assume Github could block it themselves if it were that simple.
- chrisBob 12y agoSo you agree with the Chinese government and think we should just censor the Internet for all Chinese citizens?
- deleted 12y ago[deleted]
- s_kilk 12y agoI wonder what's the positive effect of sharing the same Internet with the French? Or the Americans? How about the Scottish? I know I personally want rid of the Irish from the internet, so we should black-hole all traffic from there too while we're at it. /s
- GeneralMayhem 12y agoNot that I agree with the parent, but you're being disingenuous. The Americans, Sottish, French, and Irish are not actively trying to wreck the Internet, certain US Congress members notwithstanding. There's a difference between throwing someone out of your store because you don't like the look of them and throwing someone out of your store because they shit on the floor every time they come in.
- dEnigma 12y ago
- hokutosei 12y agooh boy, think we have to go home early today and its tgif.
- vinceyuan 12y agoFxxx GFW!
- mirekrusin 12y agoCould github whitelist ip addresses who did commit to protect normal users from DDoS effects (splitting traffic to two sets of servers during DDoS etc)?
- zer0defex 12y agoSeems like a reasonable strategy to me, but probably very infeasible for an attack already in progress if this tactic weren't planned and ready to go in advance. It would be something I'd investigate post-attack however to see if it's a viable strategy for mitigating future attacks.
- dataker 12y agoIs it confirmed the Chinese government is behind this? Could it be possible to also be a competing company?
- mikekchar 12y agoGiven Snowden's recent allegations that the Canadian government is engaging in false flag operations (causing havoc and placing the blame on other nations), it could even be another country that just wants to make China look bad. To be honest, I would expect an attack from China to be a little bit more subtle... Of course it could be a double bluff... but then... Basically, it's pretty hard to know what the heck is going on.
- mwadams 12y agoApologies - it seems my earlier comment was made during a brief respite.
- teknologist 12y agoAnd we're down again
- yAnonymous 12y agoThey should redirect the attack to the server hosting the script as a friendly encouragement to use encryption.
- Ethan_Mick 12y agoWhat we really need is a free and open source distributed version control system.
- sreya 12y agoIf someone wouldn't mind explaining, what could the motive possibly be for the Chinese government to be doing this?
- touristtam 12y agoMaybe because the github repo is for this website: https://zh.greatfire.org/ https://zh.greatfire.org/ ?
- sgarrity 12y agoThis is a reminder that having a single service, like Google Analytics or Google Fonts, injected into just about every major site on the web might not be a great idea.
- omgitstom 12y agoThis! Even though I don't think this would have proactively helped this DDoS, but it can't be closer to the truth. CDNs hosting libraries / fonts / resources for the web are going to be targeted more and more, it is just too attractive to malicious people.
- kalleboo 12y agoThis is why I wish we could have a file hash attribute added to certain tags (such as script). It could improve caching across domains and validate the content you're serving up. I proposal was posted here a while ago.
- JeremyBanks 12y agoSubresource Integrity - W3C Editor's Draft http://w3c.github.io/webappsec/specs/subresourceintegrity/ http://w3c.github.io/webappsec/specs/subresourceintegrity/
- b123400 12y agoDid Baidu or its employee said anything about their script being used to attack Github? Would like to know how they think about it
- TACIXAT 12y agoThe internet is so cool. I hope no one ever fixes the ability for shit to go crazy online. It makes me so happy to be alive in the age of data leaks, ddosses, and malware. It's all the more awesome that it isn't just individuals but entire nation states fucking shit up. This is a really neat attack. I hadn't thought of a MITM being used on a such a massive scale, and to leverage uninfected computers as a botnet is pretty great. Props to China. 很好!
- jmakov 12y agoWhat I think is most interesting of all is not that a foreign country is attacking a US company nor that the company has no support from the wast pool of three letter agencies but the fact that github as a company designed their architecture in such a way that a sub site is allowed to eat all of the resources bringing the whole company down. Kudos to all the engineers and architects with +100k salary over there.
- jeremybass 12y agoQuestion, way can't `code.jquery.com` help here? or has the attack moved passed this MIM attack?
- Irish 12y agoAnyone in europe having trouble with github this morning? I cant get bower to install and it fails with cannot connect to github error, status page seems to suggest everything is working