

News Archive
March 2012
February 2012
January 2012
December 2011
November 2011
October 2011
September 2011
August 2011
July 2011
June 2011
May 2011
April 2011
March 2011
February 2011
January 2011
December 2010
November 2010
October 2010
September 2010
August 2010
July 2010
June 2010
May 2010
April 2010
March 2010
February 2010
January 2010
December 2009
November 2009
October 2009
September 2009
August 2009
July 2009
June 2009
May 2009
April 2009
March 2009
February 2009
December 2008
November 2008
October 2008
September 2008
August 2008
July 2008
June 2008
May 2008
April 2008
March 2008
February 2008
January 2008
December 2007
November 2007
October 2007
September 2007
August 2007
July 2007
June 2007
May 2007
April 2007
March 2007
February 2007
Were Googlers Involved in Chinese Cyber Attack?
January 18, 2010, 7:17 amReuters is reporting that Google is now investigating the possibility that one or more Google employees could have been involved in the recent attack in China, but is not offering comment on any details. The news agency reports:
Security analysts told Reuters the malicious software (malware) used in the Google attack was a modification of a Trojan called Hydraq. A Trojan is malware that, once inside a computer, allows someone unauthorized access. The sophistication in the attack was in knowing whom to attack, not the malware itself, the analysts said.
Local media, citing unnamed sources, reported that some Google China employees were denied access to internal networks after January 13, while some staff were put on leave and others transferred to different offices in Google's Asia Pacific operations.
Regardless of whether or not insiders were involved, it's important to note that "Operation Aurora", as the attacks have been dubbed, stem from a particular vulnerability in Micosoft's Internet Explorer. Security giant McAfee has a page set up with information on protection. The company explains:
McAfee Labs identified a zero-day vulnerability in Microsoft Internet Explorer that was used as an entry point for “Operation Aurora” to exploit Google and at least 30 other companies. Microsoft has issued a security advisory and McAfee is working closely with them on this matter. “Operation Aurora” was a coordinated attack, which included a piece of computer code that exploits a vulnerability in Internet Explorer to gain access to computer systems. This exploit is then extended to download and activate malware within the systems. The attack, which was initiated surreptitiously when targeted users accessed a malicious Web page (likely because they believed it to be reputable), ultimately connected those computer systems to a remote server. That connection was used to steal company intellectual property and, according to Google, additionally gain access to user accounts.

The company's "Security Insights" blog has been updated continuously, and may be a good spot to keep in mind for the latest developments on Operation Aurora.
The attack on Google has of course led to Google stopping the censoring of its search results in China, which could in turn lead to the company having to shut down its Chinese operations. Philipp Lenssen at Blogoscoped points to some other instances where Google is censoring results.
More WPN articles on the Google/China story here.
Related Articles:
> China Responds To Google Situation
> Baidu's Stock Soars Following China News




