Top Banner
The Great Firewall & The Great Cannon 1 Ivan Ortega @ivanortegaalba Slides: http://es.slideshare.net/IvanOrtega14 1
29

Great Firewall & Great cannon

Jan 22, 2017

Download

Technology

Ivan Ortega
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Great Firewall & Great cannon

The Great Firewall &The Great Cannon

1

Ivan Ortega@ivanortegaalba

Slides:http://es.slideshare.net/IvanOrtega14

1

Page 2: Great Firewall & Great cannon

The Great Firewall

2

Page 3: Great Firewall & Great cannon

China and their censure policy

Until now China has been using its system:

Great Firewalla part of

Golden Shield Project

3

Page 4: Great Firewall & Great cannon

Great Firewall

30.000 - 50.000 police agents involved.

800.000.000 $ invested

8 years

All this to censor the Internet as we know it

4

Page 5: Great Firewall & Great cannon

How do Great Firewall block sites?

5

Page 6: Great Firewall & Great cannon

How do Great Firewall block sites?

1. The Great Firewall search in DNS servers if the domain is censored

6

Page 7: Great Firewall & Great cannon

How do Great Firewall block sites?

1. The Great Firewall search in DNS servers if the domain is censored

2. If IP is obtained, Great Firewall search if this IP is saved as blocked

7

Page 8: Great Firewall & Great cannon

How do Great Firewall block sites?

1. The Great Firewall search in DNS servers if the domain is censored

2. If IP is obtained, Great Firewall search if this IP is saved as blocked

3. The Great Firewall analyse the URL to find word forbidden

8

Page 9: Great Firewall & Great cannon

How do Great Firewall block sites?

1. The Great Firewall search in DNS servers if the domain is censored

2. If IP is obtained, Great Firewall search if this IP is saved as blocked

3. The Great Firewall analyse the URL to find word forbidden

4. The Great Firewall search text forbidden that is sowed as text plain

9

Page 10: Great Firewall & Great cannon

How do Great Firewall block sites?

1. The Great Firewall search in DNS servers if the domain is censored

2. If IP is obtained, Great Firewall search if this IP is saved as blocked

3. The Great Firewall analyse the URL to find word forbidden

4. The Great Firewall search text forbidden that is sowed as text plain

10

Page 11: Great Firewall & Great cannon

How do Great Firewall block sites?

1. The Great Firewall search in DNS servers if the domain is censored

2. If IP is obtained, Great Firewall search if this IP is saved as blocked

3. The Great Firewall analyse the URL to find word forbidden

4. The Great Firewall search text forbidden that is sowed as text plain

11

Page 12: Great Firewall & Great cannon

How do Great Firewall block sites?

1. The Great Firewall search in DNS servers if the domain is censored

2. If IP is obtained, Great Firewall search if this IP is saved as blocked

3. The Great Firewall analyse the URL to find word forbidden

4. The Great Firewall search text forbidden that is sowed as text plain

12

Page 13: Great Firewall & Great cannon

Forbidden sites

13

Page 14: Great Firewall & Great cannon

Forbidden sites

14

Page 15: Great Firewall & Great cannon

Alternatives

15

Page 16: Great Firewall & Great cannon

Alternatives

16

Page 17: Great Firewall & Great cannon

What is the Great Cannon?

17

Page 18: Great Firewall & Great cannon

A Great Firewall with a Great Cannon

18

Page 19: Great Firewall & Great cannon

A Great Firewall with a Great Cannon

19

Page 20: Great Firewall & Great cannon

A Great Firewall with a Great Cannon

20

Page 21: Great Firewall & Great cannon

A Great Firewall with a Great Cannon

21

Page 22: Great Firewall & Great cannon

1. China establish IP targets to be attacked.

Mirror & Forbidden sites:

22

Page 23: Great Firewall & Great cannon

2. China ear the traffic from outside of China Network to Baidu

23

Page 24: Great Firewall & Great cannon

3. China reroute a percent of this traffic and inject a malicious JS

24

Page 25: Great Firewall & Great cannon

4. This malicious JS will do request constantly to target server

25

Page 26: Great Firewall & Great cannon

Great Cannon discovered

Great cannon was discovered as result of DDoS on Github repositories when a lot page was allocated as mirror of forbidden sites.

https://www.fayerwayer.com/2015/04/asi-es-como-china-ataco-y-tumbo-github-con-su-gran-canon/ 26

Page 27: Great Firewall & Great cannon

Conclusion

China have a new weapon to censor by force

China goverment don’t recognize this attack and The Great Cannon but all investigation point to this, so all this is a augmented supposition

It’s effective? Now, Chinese people are seeing the same pages attacked

27

Page 29: Great Firewall & Great cannon

Thank you!Questions?

Ivan Ortega@ivanortegaalba

Slides:http://es.slideshare.net/IvanOrtega14 29