Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Analytics //

Security Monitoring

China Blames Massive Internet Blackout On Hackers

Evidence about the 45-minute outage points to botched censorship operation, not hackers, security experts say.

Chinese officials Wednesday blamed a country-wide Internet outage on a hack attack. But security and networking experts suspect that the country's Internet infrastructure was compromised when Chinese government censors inadvertently blocked every website in the world.

What's Chinese for schadenfreude?

The official story from China didn't involve stifling freedom of expression. Instead, government officials blamed a domain name system (DNS) malfunction Tuesday for leaving the country's nearly 600 million Internet users without access to websites for 45 minutes. "We have tracked and analyzed the DNS and found that at least two of the 13 root name servers around the world were affected," said Dong Fang, an Internet engineer at Chinese security product vendor Qihoo 360, according to the Xinhua News Agency, which is the Chinese government's official press agency.

DNS converts website names into IP addresses. Thus, during the supposed DNS outage, anyone who typed in the IP address for a website -- provided it wasn't being blocked by Chinese censors operating the so-called Great Firewall of China -- should have still been able to reach their desired site.

[Hacktivists have new tools in their arsenal. See Politically Motivated Cyberattackers Adopt New Tactics.]

Xinhua spun the apparent hack attack and resulting outage as a reason why China could no longer trust other countries to handle the DNS infrastructure. "All the root name servers are located in the United States, Japan, and European countries. A problem with them would affect all the domain name processes and website visits in China," Fang said. "Building root domain name servers in China should be completed as soon as possible."

But researchers at GreatFire.org, an anticensorship organization, disputed that version of events, saying in a blog post that the outage appeared to be caused by a government-initiated DNS poisoning attempt that went wrong. DNS poisoning refers to rerouting requests for certain websites to a different website, and is actively used by Chinese censors.

"We have conclusive evidence that this outage was caused by the Great Firewall," the researchers said. During the outage, notably, "we see that a lookup to 8.8.8.8, a public DNS operated by Google, returned bogus results if the lookup was done from China." Since that DNS wasn't one of the root name servers that was supposedly hacked, it should have resolved to the actual address.

Instead, even lookups to the Google-operated DNS resolved -- along with every other DNS attempt from inside China -- to 65.49.2.178, which is owned by Dynamic Internet Technology, which makes a censorship-circumvention tool called FreeGate. The site also contains a mirror of a news portal for practitioners of Falun Gong, which is banned in China.

"One hypothesis is that [the Great Firewall] might have intended to block the IP but accidentally used that IP to poison all domains," the GreatFire.org researchers said. According to the Pew Research Center, China has more Internet users than nearly all other countries -- baring India -- have people.

(Source: Pew Research.)
(Source: Pew Research.)

The result of the apparent DNS poisoning gone wrong was that the Dynamic Internet Technology site suffered the equivalent of a denial-of-service attack, as the site was flooded with access requests by every one of China's 591 million Internet users who attempted to access a website during the 45-minute Great Firewall meltdown.

That blip underscores the Chinese government's longstanding campaign to block access to any sites that it deems to be subversive, as well as sometimes even hacking into the systems of journalists to track their activities. Last year, for example, the Chinese government was cited as the culprit behind hacks into the email accounts of journalists at The New York Times and The Wall Street Journal who were covering China.

When it comes to blocking websites, Chinese censors typically only restrict access to Chinese-language sites, or else individual articles on foreign news sites. But this week, the government's censors took the unusual step of blocking access to some foreign news sites in their entirety, including the International Consortium of Investigative Journalists in Washington, D.C., and Britain's Guardian -- as well as a handful of sites in France, Germany, and Spain -- after they published a report into offshore tax havens created by the wealthy relatives of some of China's top leaders, including the brother-in-law of Chinese president Xi Jinping. Some of those news sites posted Chinese-language versions of their stories.

Mathew Schwartz is a freelance writer, editor, and photographer, as well the InformationWeek information security reporter.

Perimeter defense isn't rocket science, which may be the reason security pros often take it for granted. Without thoughtful and robust perimeter security measures, higher-level systems such as online security and application intelligence will be rendered almost worthless. This Dark Reading report, Building And Maintaining Effective Firewall Configurations report, recommends best practices for rooting out perimeter security issues and for configuring firewalls effectively in the first place. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Mathew
50%
50%
Mathew,
User Rank: Apprentice
1/24/2014 | 6:11:00 AM
Re: Why DIT
HCHENG085, Do you mean that DIT may have hacked the Great Firewall? That's also a possibility, but technically speaking probably would have been much more challenging. "User error" seems more likely.
HCHENG085
50%
50%
HCHENG085,
User Rank: Guru
1/23/2014 | 10:10:17 PM
Why DIT
All messages have been redirected back to DIT. That indicated that incidence was caused by the overthrowing-censorship tool by DIT. Perhaps, some freedom fighters were using DIT tools but failed to achieve its goal. 
RobPreston
100%
0%
RobPreston,
User Rank: Apprentice
1/23/2014 | 11:34:58 AM
Re: Burned
Mat, this line's a keeper: What's Chinese for schadenfreude?
Drew Conry-Murray
50%
50%
Drew Conry-Murray,
User Rank: Ninja
1/23/2014 | 10:40:19 AM
Re: Burned
I'll be here all week. Remember to tip your waitress.
Mathew
50%
50%
Mathew,
User Rank: Apprentice
1/23/2014 | 10:31:18 AM
Re: Burned
Nice. Very nice.
Drew Conry-Murray
100%
0%
Drew Conry-Murray,
User Rank: Ninja
1/23/2014 | 10:27:49 AM
Burned
I guess if you build a Great Firewall, sometimes you're going to get burned.
Whoopty
50%
50%
Whoopty,
User Rank: Ninja
1/23/2014 | 10:04:18 AM
UK
What's scary, is that the British Prime Minister, David Cameron, praises Chinese filter companies and wants to enact similar censorship here. It's already started with some ISPs, but they're so bad at it that they've been blocking sex education websites along with the pornography. 


Data Leak Week: Billions of Sensitive Files Exposed Online
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/10/2019
Intel Issues Fix for 'Plundervolt' SGX Flaw
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/11/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-5252
PUBLISHED: 2019-12-14
There is an improper authentication vulnerability in Huawei smartphones (Y9, Honor 8X, Honor 9 Lite, Honor 9i, Y6 Pro). The applock does not perform a sufficient authentication in a rare condition. Successful exploit could allow the attacker to use the application locked by applock in an instant.
CVE-2019-5235
PUBLISHED: 2019-12-14
Some Huawei smart phones have a null pointer dereference vulnerability. An attacker crafts specific packets and sends to the affected product to exploit this vulnerability. Successful exploitation may cause the affected phone to be abnormal.
CVE-2019-5264
PUBLISHED: 2019-12-13
There is an information disclosure vulnerability in certain Huawei smartphones (Mate 10;Mate 10 Pro;Honor V10;Changxiang 7S;P-smart;Changxiang 8 Plus;Y9 2018;Honor 9 Lite;Honor 9i;Mate 9). The software does not properly handle certain information of applications locked by applock in a rare condition...
CVE-2019-5277
PUBLISHED: 2019-12-13
Huawei CloudUSM-EUA V600R006C10;V600R019C00 have an information leak vulnerability. Due to improper configuration, the attacker may cause information leak by successful exploitation.
CVE-2019-5254
PUBLISHED: 2019-12-13
Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have an out-of-bounds read vulnerability. An attacker who logs in to the board m...