Archive for December, 2007



2010 Guo Degang crosstalk Session: http://u.115.com/file/t777fcfb55
Yu Qian Guo Degang Carnival 2010 Session: http://u.115.com/file/t7b6eec9ee

January 12 evening news, the experience of failure 11 hours after the visit, Baidu began in most countries and regions, gradually returning to normal. The domain name was hijacked by the failure was caused by Baidu was founded, suffered the longest, most heavily attacked by hackers, it reflected the DNS domain name out of safety is neglected and weak.
Baidu experienced unprecedented 11 hours

"Baidu has been hacked!" Around 7:00 this morning from friends began to pass each other words. The background of this statement is included successively in Beijing, Liaoning, Jiangsu, Sichuan, Anhui, Guangdong, Wuhan and more found in parts of Baidu users can not open the page appears in part to open the Yahoo page, but to jump to the English, or with the Iranian flag the situation of the page.

Exception to this visit very suddenly, then call Baidu Sina science and technology and Internet experts, stakeholders, there is no clear answer to explain the anomalies of the visit. However, users have carefully broke the news to the SAN, domain name server Baidu (DNS) is modified to Yahoo, the domain name is resolved to the IP on the Netherlands, have been deduced Baidu DNS hacking.

After 4 hours of silence, Baidu at 11:10 for the first time confirmed the above statement, the disclosure as www.baidu.com domain name registrar office in the United States illegally tampered with, resulting in page can not normally access. Baidu said it is actively seized of the case, but did not give details of recovery schedule.

12:30 Baidu about web pages and WAP access gradually began to recover, but still unstable. Baidu made after an hour at noon in Beijing announced that service back to normal, but some users a message that Beijing can not access.

18:00 or so, Baidu said in a statement issued in most countries and regions have already returned to normal access, this Baidu's biggest ever hacker attack suffered by storm, and finally in 11 hours and then gradually restore calm.
Baidu Chinese hackers counter triggered by the black

"I made a plan, Baidu search through a lot of detailed information, this morning I had no way to work." Baidu little high because of a sudden can not access the abnormal depression. As the largest Chinese search engine Baidu has thousands of users affected by black Internet applications.

Baidu CEO Robin Li even in the access fault occurred 6 hours after the paste it in issue "an unprecedented, unprecedented Yeah!" Exclamation. Robin Li paste it in the back of the thread, the users or the majority of support and understanding attitude, while the focus and target of the attack behind the Baidu.
User inference is one of hackers based in part Baidu visit a Web page sharp green, white and red flags, website in Persian language, and write a "IRANIAN CYBER
ARMY (Army of Iran Network) "words. Last year on Dec. 18, the famous micro-blog website TWITTER also been hacking almost the same, their home once tampered with, hackers also claimed the network forces from Iran.

Although not a conclusive evidence of the above reasoning is correct, but angry Chinese hacker "Baidu Home by Iranian hackers", the beginning of the counter-measures against Iran. According to a "observe China's Internet," the international news website of Iran before and after an educational institution iribu.ir noon was "black" and the screen appears "Long live the People" slogan.

According to Beijing News, the embassy's press counselor of the Iranian interview Zha Ayi, Zha Ayi did not know this clearly, but stressed that even if this is true, it does not mean the Iranian government and official conduct, while condemning such incidents. Foreign Ministry Spokesperson Jiang Yu's Regular Press Conference today said the media inquiry, yet to see the matter, but has consistently opposed, including cyber crime including hacking.

Baidu said in a statement later to see some righteous anger on the Chinese netizens, but also tried to retaliatory attacks on other foreign sites, but "does not encourage such practices, please remain calm and restraint."
Other search engine Baidu failure due to benefit
Although the event was attacked, many netizens expressed understanding of Baidu, but can not avoid is that the incident reflected the "world's largest Chinese language search site," Baidu's negligence.

Research Center of Chinese search engine, e-commerce analyst Pu Zi Qin pointed out that the Internet company Baidu as China's representative, the recovery time is longer, reflects Baidu technical input on safety and emergency preparedness is obviously inadequate. "Hackers see Baidu so fragile, may lead to larger domestic network attacks."

For the current business model is still produced hits pay Baidu, its hundreds of thousands of corporate customers and small and medium sized sites will face losses and negative impacts. Some webmasters that visit the failures Baidu 50% flow reduction, indirect economic losses of up to several hundred dollars to several thousand dollars, hoping Baidu to pay damages.

Baidu does not mention the impact of issues, also did not give compensation for claims. The legal profession have an interview that although the cause is not from the outside from Baidu, but Baidu customers as a network service provider should assume legal responsibility.

But other search engine Baidu's visit was because of failure to benefit. According to Bu Zi Qin observation, Baidu can not visit, Google, Love asked, tactics, search search, China Yahoo and other search engine traffic is surging, and is expected on January 12 "search list" share or ranking will change significantly.
Experts called attention to DNS security issues

Baidu today is the fault of DNS was hijacked, hijacking DNS servers by means of some means of getting control over the domain name resolution records, and then modify the current domain of the analytical results, leading to visits by the original IP address of domain name transfer to a modified the specified IP.

"The result is a right given the URL can not access or access to the yes Jia Web site to achieve the theft of information or Pohuaiyuanyou normal service objectives." Duba Anquanzhuanjia Li Tiejun said is a hacker's attack the most common way of Zhiyi .

Rising security experts believe that the root causes of the attack occurred, is currently managing the Internet domain name server DNS security has not been given due attention. At present, most domain name similar security risks exist, so there are many security risks DNS.

In fact this is not the first DNS failures caused by security weaknesses. Since 2009, DNS experienced hackers, video storm has triggered off a massive network of events, there were many security experts to call for the DNS security technology and Internet companies to wake-up call.

Baidu regard frankly, this incident did not attack the criminals Baidu server, but select the U.S. as a target for domain name registration business, this is a new object worthy of Internet companies wary. Baidu also called DNS vendors to enhance network security building.

At the same time Baidu self-interest of those malicious tampering, the behavior of Web site attacks strongly condemned "this act is morally and legally, if not to stop the level, damage may be Baidu today, tomorrow may be damaged any other legitimate websites, but the final analysis, damage the interests of all Internet users. "

Rising to remind the major Internet companies, experts and relevant domain name authorities, should take measures to prevent: use of safe and reliable DNS server to manage their own domain name and pay attention to loopholes in the relevant follow-up DNS information, update the latest patch, reinforcement server. Important to protect your confidential information safe from theft domain administrative privileges.