Cambridge Breached the Great Firewall of China
Darren Rayes writes to mention a ZDNet article on Cambridge academics' claims that they have breached the great firewall of China. They also claim that by misusing the firewall they can launch DDoS attacks against IP addresses behind the wall. From the article: "The IDS uses a stateless server, which examines each data packet both going in and out of the firewall individually, unrelated to any previous request. By forging the source address of a packet containing a 'sensitive' keyword, people could trigger the firewall to block access between source and destination addresses for up to an hour at a time."
How exactly does a stateless IDS block connections for up to an hour? Are there other components to the firewall I'm not aware of, or does stateless mean something else these days?
...what would happen if I sent some packets from google.com to google.cn, containing words like 'democracy' and 'Falun Gong'.
As far as I understood it, the point is that the wall blocks out IPs outside of China that try to send "sensitive" data into China.
Not a big deal either. Just send the IP Address of any mailserver you want to protect with a packet containing something "sensitive".
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
Chinese firewall is nothing - try getting through the Saudi firewall. As I understand it, the Chinese are at least a bit less modest about what is banned, so you should be able to at least get some legit porn sites through Chinese internet. However Saudi internet would block not just porn sites, but womens rights websites, womens magazines websites, even medical sites - anything that would display a photograph or illustration of a naked woman or man was stricly banned. Even it was just part of a human body, i.e. shoulders up.
It's not something that is trivial to fix. Others can do a better job of explaining why, but for now, suffice it to say that it'd require a significant effort on the part of the Chinese Gov't.
Maybe it can be fixed in The Great Firewall of China v2.0
[Fuck Beta]
o0t!
Their research is concerned with DRM ass hat tactics and such...pity!
Well done on writting a 'how-to' on pointers to make the firewall better. Im sure people out there new these things, and used them to their advantage. Now all holes will be plugged and even more censorship will rein in China. You have now had your 15mins of fame.
This is the same old tired argument we hear here on Slashdot over and over again. Expose the flaws and you either 1) alert the hackers on how to expose them or 2) Allow the admins to patch them. It's funny how depending on your political ideology, people will swing either way. How about a consistent opinion in favor of revealing flaws? Those who favor security by obscurity deserve neither.
Me too, it was an incredible symbol. The story of one of the photographers who captured that image is pretty amazing as well.
I'm a nature photographer.