2015年3月28日星期六

Baidu Analytics' JavaScript was "hijacked" to fire-up DDoS attack against Github

Github claimed on Twitter, that Github.com/ny-times and Github.com/greatfire are under massive DDoS attack. It is found that the attack source is from everywhere around the globe. And many netizens pointed out that the attack is becaused of a malicious JS, which is hosted on Baidu.

Why? 

Because so many websites in Chinese use Baidu Analytics or Baidu Adsense (substitution of Google Analytics and Google Adsense), then those websites all contains JavaScript from Baidu in order to funtions properly. And then the javascript was hi-jacked. I don't know whether is hi-jacked or not. I mean, I don't know the malicious JS is deployed by either a hacker or actually Baidu itself. Anyway, since the JS is malicious, when a user open such a webpage, and load the JS background automatically, then the user's PC is fire up a DDoS attack against Github.

It is not the first time Github's the victim. Github has been under DDoS attack originated from China for many times, and Github has been under MITM Attack for at least one time. The reason is that, there are projects and webpages hosted on Github, either to help Chinese netizens get aware of China Internet Censorship, or reveal news which is banned in China, or teach them how to bypass the censorship firewall (called GFW).

Github is kind of like Wikipedia. They consider freedom of speech as a basic human right. And they don't want to modify the Terms of Use to forbit these usage, even these projects are only cared by Chinese netizens or actually irrelevant for software development, even these projects and webpages result in A LOT OF attack against Github.

And it is not the first time Baidu was used as attack source. Back in 2005, the same trick, malicious JS, which is used by numerous websites using Baidu Analytics/Adsense, and DDoS, against 8848.com .Of course, Baidu denied the accusation, they said they did not envolved in the attack.

Just several days before, Google posted a blog that they've caught CNNIC generating fake digital certificate which can be used for MITM attack. And according to Wikipedia, CNNIC is a NGO. But who will buy it? Obviously CNNIC is not NGO, it is under administrartion of Internet Security and Informatization Leading Group Office of CPC and National Internet & Information Technology Office. And this so called NGO, as the Internet Authority of China, is responsible for the Notorious Malware Chinese Web Browsing Helper, which is usually installed on PC's without awareness of user and is very hard to uninstall. Even CNNIC claims himself as NGO and its Root CA is pre-installed on most Operating Systems and Browsers, I WILL NEVER EVER BUY IT. I DO NOT TRUST CNNIC.

At last, I recommend a website, which can allow netizens to observe the DDoS attack war all around the globe. That is http://www.digitalattackmap.com/

Below is a living demo showing the war record of Sep.15th,2014. (Maybe 14th because of timezone.) BTW, China is acting more as attack source than as attack victim.

2015年3月18日星期三

New Domain for my Blog: joeyao.chou.space

Today I register a domain called chou.space.
So from now on, joeyao.chou.space becomes new home for my blog.
Of course, the blog is still hosted on Blogger.

So kind is Google, as a free user of Blogger, I can add HTML/Java Widget, use my own domain name. But since Google Reader and Google Code are all shut down, I'm a little afraid that one day, Blogger will be shut down. If that comes true, we will lose a wonderful free blog hosting service.

Go go go, Google!

今天新注册了域名 chou.space
然后呢,joeyao.chou.space 成为目前此Blogger博客的地址。
话说Google真也大方,Blogger允许添加Java组件,允许使用自己的域名,而且这一切都是免费的。考虑到Google Reader和Google Code都被关闭了,我还真是担心万一有一天Google也要关闭Blogger呢。那样的话恐怕天底下再找不到一个这个好的免费博客站点了。

为什么我说Blogger好?
1、免费
2、可以添加Java组件,免费
3、可以使用自己的域名,免费

当然了缺点也是有的,模板太少,不好看。写文章不如Wordpress。
Wordpress.com提供免费博客空间,但使用自己的域名是要收费的,而且不支持Java组件。

目前域名只是一时脑热买下来的。
暂时没什么好想法把网站做成什么样子。
所以目前只是作为博客的个性域名。