The other thing that stood out was that these sites did not appear to be the Voice of America. And they are not. You can lookup the registrar here. The Registrant Name is 慢速英语 which babel translates as "Slow English" which gave me a chuckle.
I did some more tweaking and voanews.com.cn is being subjected to a form of DNS tampering because it has "voanews.com" in it. It looks like China is bringing back an improved version of their old DNS spoofing. Rather than messing around with individual DNS servers, China has implemented a system which appears to operate like the RST/Keyword filtering system (see this paper for technical details).
DNS lookups for voanews.com (or voanews.com.cn) will return one or more of the following 4 IP's:
voanews.com has address 213.169.251.35
voanews.com has address 209.36.73.33
voanews.com has address 72.14.205.99
voanews.com has address 72.14.205.104The last two by the way are google IP addresses. Weird.
But if you sniff the connection you'll see that what happens is after the request is made 4 spoofed results are received although eventually the correct result is received. But by the time the true result is received applications relying on a dns lookup (e.g. a web browser) have already accepted the initial spoofed result.
ME -> CN DNS Standard query ANY voanews.com
CN -> ME DNS Standard query response A 72.14.205.99
...
CN -> ME DNS Standard query response SOA auth00.ns.uu.net MX 20 ibb2.ibb.gov MX 30 ibb1.ibb.gov MX 10 voa2.voa.gov A 128.11.143.113 NS auth00.ns.uu.net NS auth100.ns.uu.net
Domain Name System (response)
voanews.com: type SOA, class IN, mname auth00.ns.uu.net
voanews.com: type MX, class IN, preference 20, mx ibb2.ibb.gov
voanews.com: type MX, class IN, preference 30, mx ibb1.ibb.gov
voanews.com: type MX, class IN, preference 10, mx voa2.voa.gov
voanews.com: type A, class IN, addr 128.11.143.113
voanews.com: type NS, class IN, ns auth00.ns.uu.net
voanews.com: type NS, class IN, ns auth100.ns.uu.net
ME -> CN ICMP Destination unreachable (Port unreachable)
A variety of other domain names are affected, not just voanews.com.
In order to perpetuate the Party's rule China is moving towards a Western-oriented, free market economy. "Communist" China is an anachronism. Free communications and free markets do not inherently go hand in hand.
ReplyDeleteفیلتر شکن بفرست متشکرم
ReplyDeleteاين آدرسي كه فرستاديد سايت شما را باز نميكند و مخابرات نكبت بار جمهوري اسلامي ميگويد كه دسترسي به اين سايت امكانپذير نميباشد
ReplyDelete[...] Meanwhile another more concrete piece of evidence has just emerged to link the Internet filtering initiative, or the Great Fire Wall of China, directly to a type of cyber-crime known as DNS (Domain Name System) hijacking. DNS hijacking involves converting legitimate domain names of websites into IP addresses of malicious websites using a rogue DNS server. So when a user of an infected computer visits a certain legitimate domain name, he is sent to a bogus website instead. An expatriate in Shanghai published a blog post a couple of weeks ago about how he accidentally discovered this criminal practice of the GFW. Since then, another blogger has also come forward to share his findings. [...]
ReplyDelete