Courses:

Offensive Countermeasures: The Art Of Active Defense: SANSFIRE June 15-16, Blackhat USA July 27-28 & 29-30


Defensive Countermeasures: Foundations for Becoming A Devious Defender: Blackhat USA July 27-28 & 29-30


Conferences:

Check out the entire PaulDotCom crew at BsidesRI June 14-15th!



Subscribe:

Blog:
Videos:
Podcast:


PaulDotCom EspaƱol


Hack Naked TV


Hack Naked At Night


Stogie Geeks


Sponsored By:


www.coresecurity.com


www.tenablesecurity.com


www.sans.org



Follow Us On:


twitter.com/pauldotcom

PaulDotCom YouTube Channel


Great Firewall of China = Pwn3d

| | Comments (1)

Researchers at the University of Cambridge discovered a way to DoS users in China using China's own firewall/filter against them.

To quote the article (linked below), "the Chinese firewall can be used to launch denial-of-service attacks against specific IP addresses within China, including those of the Chinese government itself.

The IDS uses a stateless server, which examines each data packet both going in and out of the firewall individually, unrelated to any previous request. By forging the source address of a packet containing a "sensitive" keyword, people could trigger the firewall to block access between source and destination addresses for up to an hour at a time."

Nice.

 The article goes on to say that Internet access could be denied by using this method to individual members of covernment.  I say, however that any bot herder with a political agenda on human rights, could potentially deny internet access for ALL of China.

The researchers did send their findings to the Chinese CERT. 

Human rights issues aside, it looks like they may need to rethink how they apply the technology, and we can learn a lesson as well.  Apparently, the Chinese firewall is not mindful of state - if the firewall can be fooled by just one spoofed packet, it is clear that it has no concept of state   Sure, statefull inspection at a scale this large would require massive computing power - but understand the technology and design your systems appropriatley!

- Larry

Academics break the Great Firewall of China

University of Cambridge computer experts say they breached firewall and can use it to launch denial-of-service attacks.

1 Comments

Wouldn't a DoS attack that took down the Internet for all of China simply give that corrupt Communist government exactly what they want?

[Michael, I don't disagree with you in the least on that one, but I'm going to leave those Human Rights issues alone. I'm a security guy, not a politics guy, and noone need to hear me rant on it. - Larry]