China vs. Google
Google a anuntat pe 12 ianuarie un atac provenind din China.
Conform blogului Google, nu este prima oara cand este detectat un atac din China:
“Like many other well-known organizations, we face cyber attacks of varying degrees on a regular basis. In mid-December, we detected a highly sophisticated and targeted attack on our corporate infrastructure originating from China that resulted in the theft of intellectual property from Google. However, it soon became clear that what at first appeared to be solely a security incident–albeit a significant one–was something quite different.”
Atacurile au urmarit accesarea conturilor Gmail ale unor activisti pentru drepturile omului. Doar doua conturi au fost accesate:
“We have evidence to suggest that a primary goal of the attackers was accessing the Gmail accounts of Chinese human rights activists. Based on our investigation to date we believe their attack did not achieve that objective. Only two Gmail accounts appear to have been accessed, and that activity was limited to account information (such as the date the account was created) and subject line, rather than the content of emails themselves.”
O analiza a incidentului recomandata de Google este cea facuta de Nart Villeneuve:
“iDefense has stated that they were able to investigate these attack since some of their customers were also hit:
IDefense was called in to help some of the victim companies that Google had uncovered. According to Jellenc, the hackers sent targeted e-mail messages to victims that contained a malicious attachment containing what’s known as a zero-day attack. These attacks are typically not detected by antivirus vendors because they exploit a previously unknown software bug.
“There is an attack exploiting a zero-day vulnerability in one of the major document types,” Jellenc said. “They infect whichever users they can, and leverage any contact information or any access information on the victim’s computer to misrepresent themselves as that victim.” The goal is to “infect someone with administrative access to the systems that hold the intellectual property that they’re trying to obtain,” he added.
The attack vector is very similar to GhostNet, but, it is a very common form of attack. Mikko Hypponen (who is awesome) told the BBC:
“This wasn’t in my opinion ground-breaking as an attack. We see this fairly regularly. said Mikko Hypponen, of security firm F-Secure.
“Most companies just never go public,” he added.
“Human-rights activists are the biggest target,” said Mr Hypponen. “Everyone from Freedom for Tibet to Falun Gong supporters and those involved in Liberation of Taiwan are hit.”
I tend to agree. It is not the method of attack that is the story here, its the high profile of the victims and public disclosure by Google as well as Google decision to challenge China’s censorship that have made it so interesting. Really, we investigate these kind of attacks (usually on human rights activists) all the time.”
Am mai gasit una foarte buna facuta de Sam si Sydney Liles:
There are a variety of examinations on details within the attack. The path to an attack is fairly simple to discuss and much harder to actually do;
- Determine a scope and objective for the attack.
- Create an acquisition mechanism.
- Determine a delivery and propagation mechanism.
- Using a varied path (heterogeneous) select targets of opportunity.
- Place the exploit code into the wild with the propagation and acquisition mechanism in place.
- Diversity of the delivery mechanism across the largest target population is important.
- Exfiltration of information and tuning of the attack after contact with targets increases the risk substantially.
One Response to China vs. Google
Leave a Reply Cancel reply
Facebook
Arhiva
- January 2012
- December 2011
- November 2011
- October 2011
- September 2011
- August 2011
- July 2011
- June 2011
- May 2011
- April 2011
- March 2011
- February 2011
- January 2011
- December 2010
- November 2010
- October 2010
- September 2010
- August 2010
- July 2010
- June 2010
- May 2010
- April 2010
- March 2010
- February 2010
- January 2010
- December 2009
- November 2009
- October 2009
- September 2009
- August 2009
- July 2009
- June 2009
- May 2009
- April 2009
- March 2009
- February 2009
- January 2009
- December 2008
- November 2008
- October 2008
- September 2008
- August 2008
- July 2008
- June 2008
- May 2008






[...] fine, China, un jucator foarte activ pe internet, a ales alte mijloace mai agresive: a atacat recent mai multe conturi e-mail Google si a lansat o clona Google numita Goojje si o clona Youtube numita You Tubecn, in ceea ce [...]