Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The man on the side they're performing, according to analysis, seems to be letting the initial SYN through to the original server, you get the SYN-ACK back from the actual Baidu server. Then after your ACK and HTTP GET, the other packets are injected. If they wanted to make the attack more subtle, messing with the timing to make it match the original SYN-ACK pair and keeping the right TTL values would make it much harder to detect.

http://www.netresec.com/?month=2015-03&page=blog&post=china%...



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: