Great Cannon brings down Github and GreatFire.org

China's new cyber weapon has been designed to stop its citizens reading articles it doesn't agree with

China is testing its new cyberweapon, taking down Github and GreatFire.org to demonstrate how it can be used to attack websites it doesn't want its residents to read.

The, tool which has been called the Great Cannon, targets web servers with enormous amounts of traffic in a distributed denial of service (DDoS) attack. However, researchers at the University of Toronto's Citizen Lab, the International Computer Science Institute, the University of California-Berkeley and Princeton University said it could be tweaked to distribute malware or infect any computer anywhere in the world that visits a Chinese server.

John Scott-Railton, a researcher at the Citizen Lab, Munk School of Global Affairs, University of Toronto said: "This is a powerful attack capability, and we are curious about the risk and benefit analysis that led the Chinese government to reveal it with this highly visible denial of service attack."

Great Cannon works by targeting traffic between a limited number of web addresses, rather than everything going in and out of China like the Great Firewall does. It then uses web traffic unrelated to the source to build an attack against the source site. So, for example, users of Baidu, one of China's biggest web services could be inadvertently attacking an external website.

Although the way it works is very different to the Great Firewall, the researchers were able to relate it back to China because it's hosted in the same network space, and has the same infrastructure and similar coding as the Great Firewall.

It isn't particularly surprising that GreatFire.org was the first website to be taken down by Great Cannon, because it is run by Chinese expats and is used to monitor which websites Chinese citizens are accessing.

Github was reportedly taken down because it is linked to GreatFire, hosting two repositories used by the site to help Chinese citizens to get around the country's firewall to read the New York Times in Chinese.

Featured Resources

Four cyber security essentials that your board of directors wants to know

The insights to help you deliver what they need

Download now

Data: A resource much too valuable to leave unprotected

Protect your data to protect your company

Download now

Improving cyber security for remote working

13 recommendations for security from any location

Download now

Why CEOS should care about the move to SAP S/4HANA

And how they can accelerate business value

Download now

Recommended

DeviceSHIELD combats rising cyber attacks and online fraud amid COVID-19
Security

DeviceSHIELD combats rising cyber attacks and online fraud amid COVID-19

24 Nov 2020
350,000 Spotify users hacked in credential stuffing attack
Security

350,000 Spotify users hacked in credential stuffing attack

24 Nov 2020
WAPDropper malware hooks you up to premium telecoms services
Security

WAPDropper malware hooks you up to premium telecoms services

24 Nov 2020
VMware sounds alarm over zero-day flaws in multiple products
Security

VMware sounds alarm over zero-day flaws in multiple products

24 Nov 2020

Most Popular

macOS Big Sur is bricking some older MacBooks
operating systems

macOS Big Sur is bricking some older MacBooks

16 Nov 2020
46 million Animal Jam accounts leaked after comms software breach
Security

46 million Animal Jam accounts leaked after comms software breach

13 Nov 2020
How computing has revolutionised Formula 1
Sponsored

How computing has revolutionised Formula 1

11 Nov 2020