Why Baidu Has Been Hijacked to Attack GitHub
archive.today
archive.today
Edit: ooh, take a look at the more detailed look from insight-labs: http://insight-labs.org/?p=1682
It's XMLHttpRequest ($.ajax), but with dataType: "script". Looking at the jQuery docs (http://api.jquery.com/jquery.ajax/):
"script": Evaluates the response as JavaScript and returns it as plain text. Disables caching by appending a query string parameter, "_=[TIMESTAMP]", to the URL unless the cache option is set to true. Note: This will turn POSTs into GETs for remote-domain requests.
Oh dear. If GitHub can detect this, GitHub can basically XSS all sites using Baidu's analytics.
Edit 2: Oh, the insight-labs article says the attack has stopped.
alert("WARNING: malicious javascript detected on this domain")
when you're trying to reach: https://github.com/greatfire/ or https://github.com/cn-nytimes/
That's why other people have started to notice it (as the article describes).Timeline of the attack looks something like this:
1. The Chinese firewall hijacks requests to http://hm.baidu.com/h.js and sends back a script that attacks GH instead.
2. Github notices that a huge amount of people are trying to reach https://github.com/greatfire/ and https://github.com/cn-nytimes/
3. GH figures out what's happening and starts replying with the alert javascript snippet.
4. Users are now getting noticed by the alert every time their browser runs the hijacked javascript.
5. The person that wrote this article writes this article after investigating what the alert message is about.
A attack reflection of sort.
Edit: You're technically not attacking you're reflecting if the attack stops there's nothing to reflect.
Just like in martial arts you don't just take a beating you defend and return the opponents attack back at them. Seems fair to me.
You can always fight, even if you believe you will lose.
If that were the case, I don't think they would have backed down and allowed access to Github again.
I sincerely doubt github is at all important to China.
On the other hand, the capitalists running the communist party might scoff at the idea of software that everyone is allowed to copy, because that offers no advantage to the unscrupulous. At least I'd imagine they would scoff at copyleft, just like Github does.
Why only one? :)
An eye for an eye would leave two people blind: the person who blinded the other, and the one that was blinded.
Once people start seeing the severe consequence of blinding someone (getting blinded back), they and everyone else would most likely stop, not continue blinding more people.
Such errors result in people who shouldn't be blinded themselves being blinded, and are themselves the subject of retaliation by the same error-prone process.
Well under your reading wouldn't it just leave them each without one eye. They may be blind but in most cases they will still have one other functioning eye. /pedantry
"Who paid retribution for the second blinding? The second paid for the first, I demand a third eye" ... ergo the aphorism.
alert('......'); r_send = function(){}
What would be much more interesting is replacing <body> with a multi-lingual message explaining what's happening and how to block the Baidu script.
Edit: Google cached it here: http://webcache.googleusercontent.com/search?q=cache:CeVJaTq...
Edit 2: Here's an archive.today of Google's cache: https://archive.today/KtgpS
They must believe that GitHub will bow to their will
[...] That seems incredibly naive.
Plenty of technology companies would. Of course, they would call it "complying with local laws in all countries in which we operate".The only way to find out if Github is such a company is a few months of successful attacks.
If 'I was following orders.' isn't an excuse when you are in the military where disobeying orders can get you jailed if not killed, then no one should accept such reasoning when the pentalty is merely being unable to do business in an area.
Github is powerful and funded enough that they won't succumb. Its all the smaller websites who might male changes because of this.
Well, yes? Extraterritorial law enforcement works fine for the US, they're quite happy to shut down gambling, copyright infringement, and so on regardless of where you are in the world.
In this case, it's git. It's inherently distributed. It's fairly easy to force Chinese users onto a local equivalent and block all those suspicious outgoing https/ssh connections to github.
An American concept. Foreign to Chinese Legalism. Do note that "Free Speech" doesn't exist over there as a concept.
I think you're rather overstating that.
1. Free speech as a right isn't critical to the Streisand effect, and
2. "Free speech" as a concept certainly exists in China. The formal orientation of the government with respect to the concept (and quite possibly the public perception of the value of the concept) is very different than in Western liberal democracies, but the concept certainly exists, just as the concept of, say, "theocracy" exists in most places, even the places that don't practice it.
Countries are different beasts.
Do you have any source on that?
http://tech.slashdot.org/story/13/12/14/1618239/github-takes...
https://pipedot.org/story/2014-10-04/github-staff-jake-boxer...
There's several more sources regarding this, but I'm on a terrible mobile connection at the moment. Googling around will get you a bit more info for the story.
[1] https://www.bis.doc.gov/index.php/enforcement/oac#whatsprohi...
[1]: http://webcache.googleusercontent.com/search?q=cache:X_4LmyL...
[2]: https://github.com/cn-nytimes/mirrors [3]: https://dtl1al4e74u07.cloudfront.net/
alert(
"The site you are visiting contains malicious JavaScript.\n" +
"Your computer is currently being used to attack Github.com."
)
or something..."[...] Github.com, and more specifically the tools allowing to easily bypass the chinese government censorship."
I wonder what would happen with such a message.
alert("The site you are visiting contains malicious JavaScript. It uses your machine as part of a cyber attack. You must immediately alert owners of this website to remove Baidu analytics which distributes the malware.")
Okay, I'm guessing this isn't on Baidu so much as the Chinese governments, but incentivizing Chinese corporations to object to government attacks isn't a terrible idea.
He is certainly one of them, and perhaps the most influential, but he is certainly not powerful enough to be "the ruler".
Github's data is difficult to cache and many pages load piecemeal using turbolinks which itself creates lots of un-cacheable requests (cacheable only until someone pushes a new commit).
So it would appear to be next to impossible to stop a distributed attack.
It doesn't exploit anything GitHub-specific! The way it's done is applicable to any site. The reason is that it uses the <script> loophole around the Same Origin Policy (<script> can be loaded cross-domain, thanks Eich...). They basically just inject this every two seconds:
<script src="http://github.com/greatfire/"></script>
The browser will request that page expecting a script. And it'll get HTML, but that's not valid JS and just ignore it, but the DDOS is successful.However, this also makes all sites with the malicious JS vulnerable to an XSS attack by GitHub, like GitHub is currently doing. If you visit that URL, you get this:
alert("WARNING: malicious javascript detected on this domain")
Though I think the same trick could be done with, say, <img> or <style>, and those wouldn't allow XSS (though <style> could fuck with the page, certainly). Sloppy coding, Chinese Government employee...Then the answer from my server will be 400 because I don't have a javascript representation of this url.
I imagine github can do this at the reverse proxy level, instead of doing 20 queries to mysql and overload the ruby application.
Isn't that the difficult part, ie. to intercept a request to a server and inject malicious code. In this case as all request goes through the great firewall, the hack was trivial.
The retaliation from GitHub is quite clever although not great for the user or Baidu.
Um, sure. But that's not GitHub-specific, which is what they were asking about...
You can XSS with SVG "images" [1]. Though up-to-date browsers should be patched against this.
The other option is having an image which said the same as the alert() message. Again, using SVG, this needn't be much bigger file size than the JS response [2]
[1] https://www.owasp.org/images/0/03/Mario_Heiderich_OWASP_Swed...
I use those two specific examples (ad and tracking) because that seems to be the two instances in which this JS was MITM'ed.
They look real time now, but that is best effort: they don't have to be. Nobody will lament Github suddenly saying "we're under heavy load, changes will take a minute to propagate and real time notifications are turned off".
Note that this attack is read-only; there's no creating new issues or PRs or any other write operation (that would be different).
It's comparable to Wikipedia, which has close to 100% cache hits on popular pages. (sorry can't find the source for this right now)
The git repositories are another story, but that's not so easily attacked through JS.
Still, with an attack of this magnitude, no matter how cacheable, you're going to feel it.
PS: I forgot about one thing; their HTTP interface to diffs. That's a huge surface of fresh data to request which will have to go to the backend. Like you could do with Wikipedia history diffs. Perhaps they would have to cut that off for users who do not have a cookie set from a project or user home page... Okay, I spoke too soon. Github has a huge amount of fresh data to request and a targeted attack on things like git diffs (let every user request a different diff) can't just be solved by HTTP caches.
Right -- pretty much any page that uses pjax / turbolinks to load segments of the page: each is an expensive query going to the backend.
GH recently added a timeout for the diff page if it's too large which probably also caches the "too large" status. The sweet spot for an attack would be the pages that don't time out but still create a 95th percentile request.
Seems like these groups hosted content that the Chinese government didn't approve of, and tried to put it on github to avoid it being blocked. The Chinese government responded by DDoS-ing the two repositories to bend github itself into removing/blocking the content.
China is just as reliant on the West as the West is reliant on China. The use of that as leverage doesn't have to be limited to one side of that equation.
Let us hope that day never ever happens. It would be awful for both sides no matter the "winner". As I learned from spending a year as a UAV Pilot in Iraq from 2003-2004, in war, as soon as a single person on either side is injured, both sides permanently lose. There is no real "winner". Just one side that loses less.
My manager speaks a dialect that's pronounced differently, but has a grammar close to Mandarin. The majority of people here in Hong Kong speak Cantonese, which is grammatically more different and uses a lot more slang and references to popular culture. I'm told that growing up here, leaving at age 15, and coming back at 25 makes it very difficult to follow daily conversations and read certain types of publications for the first few months because of the amount of slang used and how rapidly Cantonese changes.
Baidu could make a switch to only support HTTPS though. That would require a more elaborate attack.
https://github.com/blog/1452-new-github-pages-domain-github-...
Obviously the link above might not work at the moment.
"19:23 UTC The on-going DDoS attack now includes GitHub Pages. We are working to mitigate any service disruption."
Could that be the real aim here?
Additionally, how can a site like Amazon.com run non-ssl protected pages and prevent mitm-ing? (e.g. http://www.amazon.com/dp/B00TYBBNAW/ doesn't redirect to https, but only when ordering, etc.)
The Chinese government is telling the world with this attack that, if you choose to interfere with Chinese sovereignty by means of the Internet, or to enable those who would do that, then there’s a cost.
Note the way the attack is targeted. It’s not just an indiscriminate DDoS of Github, although that’s been the effect — instead, they’re aiming specifically at two repos whose content, being designed and built with the aim of circumventing the technical means by which are implemented a significant goal of China's domestic policy, enables no more or less than a direct attack on the sovereignty of the Chinese government.
To use that content is to say: "You may not run your country in the fashion you choose, because it does not suit me that you should do so."
To host that content is to say: "In this matter, we take the side of those attacking the sovereignty of the Chinese government, by making it easy for them to share and improve the tools with which they do so."
What you're seeing, then, is the quite reasonable response of the Chinese government to these statements. Yes, it's annoying for those of us who use Github, and no doubt it's much worse than merely annoying for those who administer Github. That is the point. Github is being encouraged to consider how much it's worth to them to maintain the stance they've implicitly taken in this matter. I'm looking forward to seeing how they respond.
As one of the billion people who live inside the Intranet "protected" by the GFW, I guess I can say I'm quite aware about how and why this happened. Let's start from the beginning.
For those who host things Chinese govt doesn't like, it usually just block the website altogether (Twitter, FB, and recently Google). But it had tried to block Github, twice. Each time there is a huge response from the Chinese webizens (mainly programmers) calling to unblock it.
Another way to block certain content from a website is to filter by keyword (like Wikipedia). But GH is encrypted so that's a no. The govt even tried to use some fake SSL certificates to MITM it. So some "smart" guys exploited this feature and created the repo greatfire/wiki and things like this.
Then some evil guys from GFW thought of this way, directing the attack at these user accounts, to warn GH to remove these accounts.
What I don't agree with you is the word "reasonable" (and the "no"). First, it's never "reasonable" to DDoS attack a website. Second, if you can't block the content, you have a choice to block the website and take the bitter from every single webizen against you. Finally, I believe it's the website owner's choice to choose who / what they want to use their website. Since GH is a U.S. company (I guess), it doesn't have to listen to a sh*t from the Chinese govt.
And of course it's up to the website owner whose content they host. They don't have to take down those repositories. But, unless the DDoS stops, they have to choose between taking down those repos and continuing to stand the gaff.
If I were to stand on a sidewalk outside of a church with signs saying "You're God is false, Heaven doesn't exist, you're going to die and disappear forever," and a parishioner decided to punch me in the face to stop me, they would be in the wrong, not me.
How totalitarian.
None of these thoughts is tremendously controversial in its own right, save where they conflict with cherished beliefs which I do not happen to share.
Reality is that political power extends from the barrel of a gun. But we also dream bigger and imagine better.
Github is a US company that hosts their service in US, Chinese government cannot possibly have sovereignty over that. If you believe there is righteous reason behind it, then you are supporting internet terrorism.
(The problem with rhetoric is that it can point both ways. Study the definitions of "sovereignty" and "terrorism" in international law, then try again.)
Yeah that's my thinking on it. They're being handed traffic, or more correctly having it thrown at them maliciously, which they could in turn redirect back at some point in the Chinese infrastructure.
I must be misunderstanding - is there a salient piece of info missing?
It makes no sense for the Chinese government to attempt to foil censor bypassing by sending all users of Baidu a link to a project on GitHub that enable censor bypassing.
As an outcome is to inform all affected Baidu users of bypass tools and a non-government controlled newspaper this looks more likely to be a rogue element to me.
It doesn't even look like what I'd call DDoS - sending genuine users to your site who might be interested in your product, isn't that an unpaid affiliate scheme?!?
The Great Firewall intercepts requests to Baidu's CDN from outside China, specifically HTTP requests for Baidu's analytics scripts.
Users from outside China who visit web properties that use Baidu's analytics get malicious JS that injects <script> tags every two seconds to spam github.com with requests.
Nobody would notice that attack, except GitHub cottoned onto this and replaced the github pages with JS that spawns a little alert() popup.
That puts the blame strictly on the Chinese government. And specifically the military that controls the firewall.
Sounds to me like an act of aggression by a state army against a non-combatant on foreign soil. What if a helicopter with a red star on it flew into California in the middle of the night and set fire to Github's offices? What's the difference?
Furthermore, only people outside of China are affected by this -- Chinese citizens don't have this code injected.
[1]: Actually there is a mistake in the injected code that causes the result of the XHR request to be interpreted as JavaScript, and then executed. Hence GitHub has tried to mitigate the attack by replying 'alert("WARNING: malicious javascript detected on this domain")' to notify the user that this is happening.
That's not a mistake. GitHub, like 99.99% of the Internet, doesn't allow cross-origin XHR for their pages (that's a security vulnerability). So they have to use <script> which doesn't follow the Same Origin Policy.
Though that's a bit silly, given they could've also used <img> which wouldn't be vulnerable to XSS.
So the text I quoted should say something like [with appropriate expansion and fact checking]:
"Requests from other countries to Baidu's CDN in China are intercepted by the government firewall - the returned web pages load content from GitHub or NYT that is hidden from the user. Each affected Baidu user outside China's browser sends content requests to those content suppliers whenever they follow a link in Baidu's search results. With Baidu's immense popularity this is causing a DDoS of the content suppliers servers preventing genuine user's browser requests from being handled."
What's the actual injected code? Presumably one can get it by requesting a link on a Baidu SERP?