Slashdot Log In
Cambridge Breached the Great Firewall of China
Posted by
Zonk
on Tue Jul 04, 2006 01:06 PM
from the didn't-work-against-the-mongol-spammers-either dept.
from the didn't-work-against-the-mongol-spammers-either dept.
Darren Rayes writes to mention a ZDNet article on Cambridge academics' claims that they have breached the great firewall of China. They also claim that by misusing the firewall they can launch DDoS attacks against IP addresses behind the wall. From the article: "The IDS uses a stateless server, which examines each data packet both going in and out of the firewall individually, unrelated to any previous request. By forging the source address of a packet containing a 'sensitive' keyword, people could trigger the firewall to block access between source and destination addresses for up to an hour at a time."
Related Stories
[+]
Comcast Forging Packets To Filter Torrents 413 comments
An anonymous reader writes "It's been widely reported by now that Comcast is throttling BitTorrent traffic. What has escaped attention is the fact that Comcast, like the Great Firewall of China uses forged TCP Reset (RST) packets to do the job. While the Chinese government can do what they want, it turns out that Comcast may actually be violating criminal impersonation statutes in states around the country. Simply put, while it's legal to block traffic on your network, forging data to and from customers is a big no-no."
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
Submit details! (Score:5, Funny)
Legal action against Cambridge? (Score:5, Insightful)
What about those inside China using those exploits for legitimate ends?
Is Cambridge indirectly helping the Chinese government to fix firewall issues?
Are Cambridge researchers after fame at the expense of the freedom of the Chinese people?
six of one... (Score:5, Insightful)
Certainly TFA suggests that the DoS attack could be used against chinese government computers, but this could also be used against chinese citizens. An exploit is, after all, an exploit. So I would suggest that in the case of the DoS attack, reporting it to the appropriate people - in this case the Chinese authorities - was the right thing to do.
Unfortunately, in this case, the very flaw that allows a DoS against machines within China also permits those inside the firewall to ignore the resets sent back, so by reporting the DoS, they've also reported how the censorship can be circumvented. (or, by discovering the censorship circumvention they've unfortunately stumbled upon a DoS attack).
In this case, I really don't think that there is a One True Answer.
Parent
Re:Legal action against Cambridge? (Score:5, Informative)
FYI, Cambridge isn't a U.S. university.
Parent
They're supposed to be helping them (Score:5, Interesting)
Their research is concerned with DRM ass hat tactics and such...pity!
Parent
Re:Legal action against Cambridge? (Score:4, Informative)
Parent
Re:Legal action against Cambridge? (Score:5, Informative)
Parent
Mongolians? (Score:5, Funny)
Solution? (Score:5, Insightful)
What does slashdot think about this?
Re:Tiannamen Where? (Score:5, Interesting)
Parent
I wonder... (Score:4, Interesting)
Re:I wonder... (Score:4, Interesting)
Parent
Re:I wonder... (Score:5, Interesting)
Falun Gong Is a Cult
www.china-embassy.org
Research Society of Falun Dafa and the Falun Gong organization under its control are held to be illegal
english.people.com.cn
Fifteen Falun Gong Cult followers attempted to sabotage cable TV network equipment
app1.chinadaily.com.cn
southcn:Falun Gong Cult OUTLAWED
www.newsgd.com
Here we should point out that the banning of "Falun Gong" by the Chinese government is also part of
www.chinaembassycanada.org
Falun Gong Practitioner Not Sorry for Killing Father, Wife
news.xinhuanet.com
Now compare all that to
http://www.google.com/search?q=Falun [google.com]
Now, if the Chinese Gov't is making Google filter based on English keywords, you think they're not going to do the same with their uber-firewall?
Many Chinese schools teach english. It isn't like they only speak various Chinese dialects over there.
Parent
That isn't technically a DDoS (Score:5, Informative)
Try the Saudi firewall (Score:5, Interesting)
National Security (Score:5, Insightful)
Couldn't the Chinese government view this as an act of terrorism? In the interest of national security the Chinese government will start an ambiguous "War on Terror" after the the US "War on Terror" and "War on Drugs" which are _also_ unwinnable and declared solely to keep the ruling party in power via fear.
Oblig. Monty Python (parody) - The Terrorist Song (Score:4, Insightful)
by Usurper_ii
(Sung to the tune of Python's The Lumber Jack Song)
I'm a terrorist and I'm OK
I read at night and I work all day.
The Government:
He's a terrorist and he's OK
He reads at night and he works all day.
I read a lot and I seek the truth
I go to the lavatory.
After OKC, I saw some things that didn't make sense to me.
The Government:
He doesn't believe our story about OKC,
We monitor when he goes to the lavatory.
On Wednesday night, he went to an unapproved web site.
Chorus:
He's a terrorist and he's OK
He reads at night and he works all day.
When, after 9-11 didn't all add up,
I met with others on the net, to talk it up.
The government:
He didn't believe our story about 9-11.
We followed him to unapproved web sites after hours.
In our report, well say he had bomb-making materials under his sink.
Chorus:
He's a terrorist and he's OK
He reads at night and he works all day.
I don't think a plane hit the Pentagon.
I think the World Trade Center buildings fell all wrong.
I wish I could convince my dear ol' mom!!
The government:
He's a terrorist and we're going to make him pay?!
We read his e-mail and didn't like what he had to say?!...
Just me:
I wish I'd been born, back when America was really free!!
The Government:
He's a terrorist and we're going to make him pay
He reads the Constitution and knows his rights.
He's just like McVeigh, Bin Laden, and al-Qaeda!!
Chorus:
He's a terrorist and he's OK
He reads at night and he works all day.
Parent
Cyber Attacks, a good thing?? (Score:5, Insightful)
Last weeks news - original post here (Score:5, Informative)
http://www.lightbluetouchpaper.org/2006/06/27/ign
And for all the details, the paper to be presented is here:
http://www.cl.cam.ac.uk/~rnc1/ignoring.pdf [cam.ac.uk]
I think the interesting thing is that by configuring our end to ignore the invalid resets from the Great Firewall of China we can aid the distribution of otherwise censored material.
DDoS attacks against the GFC seems not to be that easy, as the article mentions the GFC is not one giant router at the backbone, but rather smaller machines closer to the end stations - the firewall is distributed accross an unknown number of gateways.
Re:Congratulations (Score:4, Insightful)
Parent
Re:Congratulations (Score:5, Interesting)
It's not something that is trivial to fix. Others can do a better job of explaining why, but for now, suffice it to say that it'd require a significant effort on the part of the Chinese Gov't.
Maybe it can be fixed in The Great Firewall of China v2.0
Parent
Re:Congratulations; Same old tired argument. (Score:5, Interesting)
Well done on writting a 'how-to' on pointers to make the firewall better. Im sure people out there new these things, and used them to their advantage. Now all holes will be plugged and even more censorship will rein in China. You have now had your 15mins of fame.
This is the same old tired argument we hear here on Slashdot over and over again. Expose the flaws and you either 1) alert the hackers on how to expose them or 2) Allow the admins to patch them. It's funny how depending on your political ideology, people will swing either way. How about a consistent opinion in favor of revealing flaws? Those who favor security by obscurity deserve neither.
Parent
Re:Stateless? (Score:5, Informative)
Stateless != ruleless. For example, you could use OpenBSD's "pf" to create a stateless firewall that references an external rules file, then use a cron job to rewrite that rules file once an hour. That might be a pretty reasonable approach if you're filtering billions of packets per hour and can't afford to track state for each connection.
Parent
Actually it would have to work the other way round (Score:5, Interesting)
Not a big deal either. Just send the IP Address of any mailserver you want to protect with a packet containing something "sensitive".
Parent
Re:hard to believe (Score:4, Insightful)
Stateful firewalls scale poorly.
Parent