10 ms·
This is an article [0] summarizes what happened. It is however in Chinese. So let me put a simple summary here: Baidu has Baidu Analytics, a service similar to
by dengnan 12y ago
This is an article [0] summarizes what happened. It is however in Chinese. So let me put a simple summary here:
Baidu has Baidu Analytics, a service similar to Google Analytics. In short, a website includes a javascript file from Baidu and Baidu will report some basic analytics to the site manager like how many visitors per day, how much time they spent on average per page etc.
Someone in the middle between a client outside China and Baidu, allegedly it should be the Great Fire Wall, changed the javascript file from Baidu and added some code so that any client executing the javascript file will periodically access https://github.com/greatfire/ https://github.com/greatfire/ and https://github.com/cn-nytimes/ https://github.com/cn-nytimes/. This means any user who is accessing a site using Baidu Analytics will be an attacker to github.
Here is a simple solution: Block any javascript from Baidu if you do not use it. For chrome users, add the pattern [*.]baidu.com. See here[1].
Edit 1: Added a solution.
Edit 2: Format.
Edit 3: Oh, it's not only Baidu Analytics. Baidu Ads' javascript is also being hijacked and changed [2]. Imagine that all sites containing Google Ads use their visitors as attackers to attack github. Now it is literally what is happening to Baidu and its customers (and their customers' visitors.) The javascript is only changed for visitors outside China. This is why people believe that is done by Chinese government --- the only entity who has total access to all out-going routers in China. Since many Chinese users use VPN or other types of proxy to access Internet, they are all considered as visitors outside China.
0. http://drops.wooyun.org/papers/5398 http://drops.wooyun.org/papers/5398
1. http://www.howtogeek.com/tips/how-to-block-javascript-and-ads-for-a-single-site-in-chrome/ http://www.howtogeek.com/tips/how-to-block-javascript-and-ad...
2. http://www.solidot.org/story?sid=43489 http://www.solidot.org/story?sid=43489
- im2w1l 12y agoWow this must be a major blow to Baidu. This time their scripts was hijacked to DDoS, not that bad. Since we all know that the Chinese government would never do a thing like this, it must mean that there is a very powerful hacker group behind this. And they are probably DDoSing for profit. Who knows what they may do for profit next? Spy on users? Steal passwords? Credit cards? Impersonating users? Until Baidu implements a secure crypto solution that can prevent this malevolent hacker gang from sending corrupted scripts, it would be very irresponsible to use baidu analytics!
- hk__2 12y ago> Since we all know that the Chinese government would never do a thing like this Why?
- teknologist 12y agoThey've mobilised the Troll Department
- tothepixel 12y agoI'm kind of amazed that these trolls are so obvious. It makes me wonder how much user generated content is really government generated content that we miss because it's not as apparent.
- mikeash 12y agoWhat if it's all government generated content? Maybe there are no real users online at all.
- nothrabannosir 12y agoWow, this one has >100 karma and his other comments are actually reasonable.. Normally they're new accounts. Maybe this is just a regular nut?
- pjc50 12y agoI'd assumed it was sarcasm, but clearly Poe's law applies here.
- emodendroket 12y agoThe much-vaunted principle of non-interference in other countries' internal affairs, of course.
- Perdition 12y agoI think that was sarcasm.
- orf 12y agoAccording to this[1] post GitHub (or someone else in between) started changing the responses to alert("Malicious Script Detected")[2]. That's an awesome counterattack - this stops the script from looping indefinitely and annoys the users. 1. http://insight-labs.org/?p=1682 http://insight-labs.org/?p=1682 2. https://github.com/greatfire/ https://github.com/greatfire/
- dengnan 12y agoFor github, this is a smart move. But, really, you can hardly negotiate with Chinese government. I'm pretty sure that they will deny this attack and re-emphasize their so-called Internet policy. If I were github, instead of a warning message, I would redirect the workload to some Chinese government's website and let them suffer what they've created. Let's face it, they are waging a war on the Internet first. Edit: Disclaimer: I know that my post is quite biased, especially this one. I'm not suggesting that people should wage a war to Chinese government. Please take my words just as a (biased?) sample from an ordinary Chinese citizen who is really tired of the government's censorship.
- j4sonstath 12y agoI think you are wrong here. Everyone is innocent until proven guilty! Also I don't think its hard to negotiate with the Chinese government unless you are an ambassador and had previous experience with them before? And any government would deny an attack under any circumstances... if not that leaves them exposed!
- toxicFork 12y agoAsked in another thread but it went down because the post linked was taken down it seems[0]: Would it have been prevented if Baidu served the .js files only over https? Are there any reasons of using http for anything that Baidu serves? [0] https://news.ycombinator.com/item?id=9275201 https://news.ycombinator.com/item?id=9275201
- dengnan 12y agoProbably, yes. But considering that CNNIC, a root CA from China, is issuing unauthorized certificates [0], I cannot help to connect these two events together. I won't be surprised that Chinese government is using unauthorized certificates to initiate MITM attack specifically targeting TLS traffics. If that is the case, there will be really bad days for the whole Internet. 0. http://googleonlinesecurity.blogspot.com/2015/03/maintaining-digital-certificate-security.html http://googleonlinesecurity.blogspot.com/2015/03/maintaining...
- toxicFork 12y agoWell, that sucks. That effectively makes HTTPS worthless there doesn't it? Also on the other link I have seen another relevant article [0] on how BitTorrent could be used for attacks from China. Scary stuff. [0] http://furbo.org/2015/01/22/fear-china/ http://furbo.org/2015/01/22/fear-china/
- mikeash 12y agoCAs aren't geographically limited. Any CA trusted by your computer is trusted for any domain anywhere (with the exception of certificate pinning, which isn't commonly used). That means that a single rogue CA is enough to make HTTPS worthless everywhere.
- bbatsell 12y agoMozilla actually has done this (sort of), once. They restricted French agency ANSSI's root CA to only be valid for TLDs ending in .fr, .gp, .gf, .mq, .re, .yt, .pm, .bl, .mf, .wf, .pf, .nc, .tf. https://wiki.mozilla.org/CA:IncludedCAs https://wiki.mozilla.org/CA:IncludedCAs
- teknologist 12y agoWhat I don't get is why they didn't inject a script into all html passing through the firewall. That would have achieved a much greater effect if they really wanted to take out GitHub - the Baidu Analytics tracker is just a single script.
- dengnan 12y agoEasy to implement? This is just my theory: I think that GFW is currently entering its next stage, which probably includes MITM attack to TLS traffic and some attack specific to websites outside China. I suppose that since everything now is in a "research" stage, they are just trying to see if the technique works and how much it could go. Disclaimer: I was an user inside China and being blocked from the real Internet. So please take my words with a grain of salt.
- nothrabannosir 12y agoThis is actually the most plausible explanation I have seen so far: they just finished implementing this new injection feature and they needed something to test it on. For lack of a better target, they chose those two github projects. Everybody's talking about how this is a targeted attack against GH, but I'm starting to think you might just have hit the nail on the head...
- sthreet 12y agoWhat is GFW?
- vinceyuan 12y agoCan we report it to Baidu and ask Baidu to clean up the scripts immediately?
- hk__2 12y agoIf that’s a MITM attack they can’t do anything I guess.
- coldpie 12y ago"Gee coldpie, why do you use NoScript? All you're doing is breaking every website you visit!" Shoe's on the other foot now, hahaha! :)
- jdjb 12y agoI use NoScript as well (and I wish more people would) but to be fair I doubt the users who were part of the botnet even noticed it at all. It's only github who would've benefited from these users running NoScript.
- coldpie 12y agoYeah, it was obviously a lighthearted comment, but the larger issue is that every web user is running someone else's untrusted code on every website they visit. Frankly I'm surprised these kinds of attacks aren't more common. NoScript helps mitigate this issue, and while it has lots of other incidental bonuses that a nerd like myself cares about, I freely admit it results in a worse end-user experience for almost everyone else.
- eli 12y agoThey could have done a similar attack with an <IMG> tag. Or do you block images too?
- therealidiot 12y agoSomething like Request Policy could cover this
- repsilat 12y agoErm, you don't? I suggest you read the Basilisk FAQ before you get into real trouble... http://ansible.uk/writing/c-b-faq.html http://ansible.uk/writing/c-b-faq.html
- teknologist 12y agoHaving no sites on the internet actually work finally paid off huh
- teknologist 12y agoUsing jQuery to send this request is really kind of amateur. They could just append a <script> tag to the page which is effectively what that $.ajax call is doing.