bk99.de entertain the web since 1997

China's man-on-the-side attack on GitHub

Summary

Netresec analyses injected JavaScript traffic that caused browsers to send masses of requests to GitHub. The attack targeted GitHub in March 2015. Manipulated Baidu scripts generated repeated requests.

Ideas

  • A network observer copies packets and answers faster than the real server.
  • Unencrypted HTTP allows content to be injected unnoticed on the way.
  • Other people's browsers became participants in a DDoS attack.
  • Packet characteristics reveal differences between genuine and forged responses.

Insights

  • Encryption protects not only secrets but also the integrity of content.
  • A position in the network can turn passive surveillance into active manipulation.
  • Third-party content transfers the security risk of its transport paths to every page that embeds it.

Facts

  • Netresec compared the TTL and TCP characteristics of the packets.

Recommendations

  • Only load active third-party content over HTTPS.
  • Use packet captures to separate origin from injection.

References

Read the original article

Search the Web Archive