China's man-on-the-side attack on GitHub
Summary
Netresec analyses injected JavaScript traffic that caused browsers to send masses of requests to GitHub. The attack targeted GitHub in March 2015. Manipulated Baidu scripts generated repeated requests.
Ideas
- A network observer copies packets and answers faster than the real server.
- Unencrypted HTTP allows content to be injected unnoticed on the way.
- Other people's browsers became participants in a DDoS attack.
- Packet characteristics reveal differences between genuine and forged responses.
Insights
- Encryption protects not only secrets but also the integrity of content.
- A position in the network can turn passive surveillance into active manipulation.
- Third-party content transfers the security risk of its transport paths to every page that embeds it.
Facts
- Netresec compared the TTL and TCP characteristics of the packets.
Recommendations
- Only load active third-party content over HTTPS.
- Use packet captures to separate origin from injection.
References
Links to the original source and the Web Archive open in a new tab.