Live data from Hacker News

China's Man-On-the-Side Attack on GitHub

netresec.com

241–250 of 323 posts

Re: China's Man-On-the-Side Attack on GitHub

#241

Earlier quoted context omitted.

> information about and software for circumventing the Chinese government's internet censorship systems -- which, among many other things, blocks access to, eg, Google, and The New York Times. The actual impact of the attack was to have thousands of news outlets and discussion forum sites mention and link to the github repos that offer circumvention. Further, by attacking Github, it's guaranteed that many of the most…

> Of course the Chinese government knows this and was likely not responsible for the attack. This is an example of the logical fallacy of "argumentum ad stultum", or "appeal to stupidty". It goes like this: - X would be stupid. - No one would ever do anything stupid. : Therefore no one would ever do X. There are so many counter-examples to this argument that they hardly bear mentioning. People do stupid things every…

> People do stupid things every day of the week and twice on Sundays.

While you are correct in pointing out the logical fallacy, there have been several examples of highly likely false-flag cyber attacks lately. The Sony hack is another example, the result of which was the exact opposite of what the state actor alleged to have done the attack wanted.

"Cyber attacks" are a great platform for false flag attacks because it's easy to obtain servers or DDOS drones in any country.

I'd say a good indicator of strategy like this going on is when a defacing attack is accompanied by targeted data breach. Chances are the data breach was the goal, and the defacing the smoke screen.

Many HN readers could stage a cyber attack that would be initially linked to North Korea or China with a few hours of reading/research.

Re: China's Man-On-the-Side Attack on GitHub

#242
post #224

Earlier quoted context omitted.

> Another is that you should never ever have any webpage configured to load any resources from a server hosted within China IP address space as it is vulnerable to this sort of attack by the Chinese government. Yep. Baidu are a NASDAQ listed company, while they may not be the malicious actor here, they still have a responsibility to ensure their networks are not used to attack others - which they don't seem to be tak…

Does that mean we should drop everything coming from US prefixes also because the NSA uses them for man-on-the-side attacks?

Replying to myself as HN won't let me reply to the post by 'nailer

> If there is a specific network being leveraged by the US government to attack someone else, and the owner of the network is not taking steps to prevents its misuse, then yes, of course.

We have documented evidence of GCHQ doing man-on-the-side attacks against visitors of LinkedIn and slashdot.org. So are you currently blocking the prefixes of LinkedIn and SourceForge, Inc. on your networks? Or are you aware of any specific acts of these companies to prevent this from being possible in the future?

I worry about mass surveillance and national firewalls no matter where they come from, but I don't think balkanising the internet is a good response.

Re: China's Man-On-the-Side Attack on GitHub

#243

Earlier quoted context omitted.

It's an identical setup to the NSA QUANTUM infrastructure, just in China instead of scattered around the western internet system. So I guess it's probably been used offensively in a more targeted approach for a while.

you mean in principle or in the actual detail/technology?

The actual detail/technology, more or less. There's nothing China did this last couple of weeks that the Five Eyes' QUANTUM setups aren't already tooled to do: QUANTUMINSERT can be used to inject the JavaScript, just change the selectors and the payload. Indeed, I believe this capability has already been privately trialled by GCHQ. (QUANTUMSLAMMER, was it?)

It is not advanced technology: TCP just has no protection here. Anyone capable of in-path packet surveillance and in-/by-path packet injection on a significant link can pull off this exact same attack. You could co-opt a router to do it: GCHQ have.

We're going to need pervasive (authenticated) encryption to defeat it.

Re: China's Man-On-the-Side Attack on GitHub

#244

Since the question of "why" and "how" is coming up again, here's a quick summary I posted on reddit: From a few different analysis on HN and elsewhere... Baidu has an analytics product and an ads product, much like Google Analytics and Google AdSense, which are used on all kinds of websites via Javascript. China has set the Great Firewall of China to modify some of Baidu's assets so that any non-Chinese IP gets a mod…

actually both projects are still online on github. https://github.com/cn-nytimes https://github.com/greatfire

There still seems to be some special handling of them. Accessing these two projects through tor fails with an angry-looking unicorn and the message "Something went wrong and we cannot service your request". All other github projects seem accessible.

Re: China's Man-On-the-Side Attack on GitHub

#245

Since the question of "why" and "how" is coming up again, here's a quick summary I posted on reddit: From a few different analysis on HN and elsewhere... Baidu has an analytics product and an ads product, much like Google Analytics and Google AdSense, which are used on all kinds of websites via Javascript. China has set the Great Firewall of China to modify some of Baidu's assets so that any non-Chinese IP gets a mod…

I think you got it wrong. The Baidu analytics code is not on the pages that are on GitHub. It is all over the place, and the Great Firewall occasionally swaps it out for the malicious script. There is no malicious code on the GitHub pages.

Re: China's Man-On-the-Side Attack on GitHub

#246

For me the most interesting thig about this incident is how the GFW is being used offensively. Most other governments so far have protested online censorship from a kind of moral standpoint, but not from a security standpoint per se. Now it's quite clear the GFW is being leveraged offensively - did anyone spot this capability previously?

It seems the only solution might be to block all content from China? Great - now they have the firewall working both ways.

Re: China's Man-On-the-Side Attack on GitHub

#247

Since the question of "why" and "how" is coming up again, here's a quick summary I posted on reddit: From a few different analysis on HN and elsewhere... Baidu has an analytics product and an ads product, much like Google Analytics and Google AdSense, which are used on all kinds of websites via Javascript. China has set the Great Firewall of China to modify some of Baidu's assets so that any non-Chinese IP gets a mod…

I think you got it wrong. The Baidu analytics code is not on the pages that are on GitHub. It is all over the place, and the Great Firewall occasionally swaps it out for the malicious script. There is no malicious code on the GitHub pages.

You must have misread because they never said anything like what you're claiming they said here.

Re: China's Man-On-the-Side Attack on GitHub

#248

Earlier quoted context omitted.

you mean in principle or in the actual detail/technology?

The actual detail/technology, more or less. There's nothing China did this last couple of weeks that the Five Eyes' QUANTUM setups aren't already tooled to do: QUANTUMINSERT can be used to inject the JavaScript, just change the selectors and the payload. Indeed, I believe this capability has already been privately trialled by GCHQ. (QUANTUMSLAMMER, was it?) It is not advanced technology: TCP just has no protection he…

I believe this is precisely the method GCHQ used to compromise Belgacom, for the purposes of spying on the EU. They used QUANTUMINSERT to inject an exploit payload into connections from belgacom employees to LinkedIn and slashdot.

Re: China's Man-On-the-Side Attack on GitHub

#249
post #181

Earlier quoted context omitted.

You are right. The degree and sophistication of media manipulation is profoundly greater in the west. While the Chinese block a lot of media, the manipulation is minimal. Most Chinese are very cynical and know exactly what is going on. The west, or at least the US, traps people in a matrix of sorts where they don't even see the manipulation. The narrative is exquisitely framed and guided to leave people with a sense…

If you want to publish your own newspaper, you can. Nobody will stop you. Start your own online video news service, weblog or nes site - nobody will stop you. Post whatever you like to Reddit, or any other discussion platform. In China and Russia you cannot do these things. Published mdeia are strictly monitored and censored. The state employs thousands of astroturfers to flood social media with pro-government messag…

> [...] is strong evidence for freedom of expression in the west.

Unfortunately there are less and less white spots in "the west."

https://index.rsf.org/

Re: China's Man-On-the-Side Attack on GitHub

#250
post #233

Earlier quoted context omitted.

> The response is altered as the trafic goes out of China. By locating their network inside China, Baidu is allowing a malicious actor to leverage their network traffic - which indeed is a 'use' of Baidu's network. > The only thing they can do is hosting http://hm.baidu.com in another country. Most likely, yes. And until they do so, or come to another solution, their traffic should be blocked.

So what's the rule then? Block all packets coming out of countries with governments that do MITM attacks? Blame the companies for not locating their servers in other countries? Companies like GitHub? This is so hypocritical.

> So what's the rule then? Block all packets coming out of countries with governments that do MITM attacks?

Block packets from any company that does not take reasonable steps to stop its network from being used to attack others.

This has been networking rule for a long time.

- We block open mail relays

- we block hacked Windows XP machines

- we should block a company who's in a hacked data center where their upstream adds malicious JavaScript.

Edit: 'we' = network administrators.

Post reply on HN