5 ms·
I wonder how GitHub mitigated the attack so successfully. I can't find any baidu scripts using the injected code anymore (in fact the original tracking scripts
by e79 12y ago
I wonder how GitHub mitigated the attack so successfully. I can't find any baidu scripts using the injected code anymore (in fact the original tracking scripts on baidu's own domain return nothing), and GitHub is now serving the two repos that were originally targeted.
What happened? Whatever it is, I'm glad they were able to mitigate the attacks.
- clippit 12y agoThe injection has been stopped and Baidu's script checks if there exists a referer.
- deleted 12y ago[deleted]
- zaroth 12y agoWhat do you mean "has been" stopped? There's no definitively stopping this without HTTPS, which I'm pretty sure hasn't magically "happened" in China in the last couple days. The GFW may have ceased its attack, but there's no check you can possibly add into an asset delivered over HTTP which can't be undone by the GFW. As long as there's a script being delivered over HTTP, the GFW can intercept that script request and replace with a script of its own.
- lgas 12y agoThere don't even have to be scripts being served -- as long as HTML is being served over HTTP they can inject their own scripts.
- clippit 12y agoI mean the Javascript hijacking has been stopped. This DDoS mixes several ways and during the js hijacking period, GitHub returns `alert()` on specific url for blocking browsers sending ajax requests. For now, the infected urls are back to normal.
- pmontra 12y agoThe attack is still going on. Details at https://status.github.com/messages https://status.github.com/messages They describe what they're doing to mitigate it. The latest message is 0:09 UTC Hour 118: Mitigation remains effective and service is stable.
- e79 12y agoYes but they don't explain what the mitigation is.
- dandelany 12y agoDuring an ongoing attack? I wonder why not...
- e79 12y agoRight. Not looking for specifics. My curiosity would be satisfied by something like "we've reached out to Baidu and they've done X and Y. Meanwhile, traffic has decreased so we've unblocked the affected repos." Just a bit more transparency on the situation.
- enraged_camel 12y agoThey might release a post-mortem once it's over, but I wouldn't expect any transparency during the attack itself.
- mkesper 12y agoIt's not baidu.com that serves that malicious code, it gets inserted on its way through the Great Fire Wall.