4 ms·
If I understand correctly, there is almost no way to stop this attack because it uses client side JavaScript code. If Baidu doesn't remove this malicious js fro
by roylez 12y ago
If I understand correctly, there is almost no way to stop this attack because it uses client side JavaScript code. If Baidu doesn't remove this malicious js from its http response, github will continue to suffer.
- Pirate-of-SV 12y agoBaidu is not doing anything wrong. The HTTP requests/responses are hijacked. Baidu could make a switch to only support HTTPS though. That would require a more elaborate attack.
- louis-paul 12y agoGitHub just needed to add code in their application to return a very simple snippet of Javascript on the /greatfire route, instead of trying to process the whole request and generate content for users. Since it's very lightweight, they are probably able to handle hundreds of thousands requests per second if it's implemented properly.