Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In 2015, AlienVault researchers reported that attackers had inserted JavaScript into compromised Chinese-language community websites. The script queried JSONP endpoints at other services; when a visitor was logged in to one of those services, its response could reveal account identifiers and, depending on the endpoint, other profile details. The episode showed how a site could expose identity information even when a visitor used Tor or a VPN to hide their network route.

How the watering-hole attack worked

A watering-hole attack compromises a website that a particular group is likely to visit, rather than attacking each person directly. Contemporary reports described affected sites associated with NGOs, Uyghur communities, and Islamic associations. Attackers injected JavaScript into a compromised site, where it ran in visitors’ browsers.

The script then made requests to JSONP endpoints on popular Chinese services. If a visitor had an active authenticated session with a service, the endpoint could return information associated with that account. The malicious script could read the executable response and send collected data to infrastructure controlled by the attackers. The visitor did not need to submit a form or deliberately disclose account details on the compromised site.

Why JSONP could expose data across sites

Browsers normally restrict a page from reading responses from another website under the same-origin policy. JSONP was a technique for requesting cross-domain data by loading a response as a script, which browsers permit. The service wrapped its response in a JavaScript callback; when the browser executed it, the requesting page could access the returned data.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That behavior becomes dangerous when a JSONP endpoint returns sensitive, user-specific information based on the visitor’s logged-in session. In that case, the endpoint itself intentionally supplies data in a form that a page on another origin can execute and read. As AlienVault chief scientist Jaime Blasco explained in Infosecurity Magazine’s June 16, 2015 report, JSONP can bypass the same-origin policy, but that can create information leakage when the response contains user data.

What information could have been exposed

The information depended on the service endpoint and whether the visitor was authenticated there. Contemporary accounts described possible exposure ranging from user IDs and usernames to nicknames, real names, mobile numbers, birth dates, gender, and other profile details. The academic study of the RSF-Chinese.org compromise described attempts to collect personal information including name, date of birth, address, and phone number.

These reports do not establish that every listed field was obtained from every visitor. They describe what endpoints could return and what the attackers’ scripts sought; exposure varied by service and account state.

What Tor or a VPN could—and could not—hide

Tor and VPNs can obscure or change the apparent network route between a visitor and a website. They do not prevent another service from returning identity data to a page when the visitor is logged in to that service and its endpoint exposes that data. An account identifier or username may also help connect activity to a person across services.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

AlienVault researchers Eddie Lee and Jaime Blasco wrote that even a user ID for one website could help pinpoint targets for espionage within China’s Great Firewall. That was the researchers’ assessment of the identifier’s potential value, not evidence that every visitor was identified or that a particular person was tracked.

Targets and reported timeline

AlienVault’s 2015 reporting described compromises of Chinese-language websites connected to NGOs, Uyghur communities, and Islamic associations. Infosecurity Magazine summarized the report as identifying more than 15 Chinese websites whose JSONP endpoints were vulnerable at that time. That figure is a historical report, not a measure of present-day exposure.

The academic paper Catching Predators at Watering Holes: Finding and Understanding Strategically Compromised Websites discusses RSF-Chinese.org, associated with Reporters Without Borders in China. It reports that the compromise was detected in January 2015 and lasted six months before cleanup after notification. The Uyghur Human Rights Project later cited the incident in its November 28, 2017 report on harassment and monitoring of overseas Uyghur communities, as an example of cyberattacks used to identify visitors to community sites.

What is known about attribution

AlienVault researchers assessed that the campaign could help Chinese authorities identify people trying to hide their identity online, and contemporary coverage reported that assessment. The sources cited in those reports do not conclusively establish that a government actor carried out or directed the attacks. It is more accurate to describe the campaign as one researchers suspected could support identification of visitors than to state government responsibility as proven.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How services can reduce JSONP information leakage

The mitigations attributed to AlienVault focus on service and application design, not on a user installing a generic security product. Engineering teams reviewing cross-origin data access should consider these controls:

  • Use CORS rather than JSONP where appropriate, and limit which origins may read a response.
  • Do not return personal or otherwise sensitive information in JSONP responses.
  • Do not customize JSONP responses based on authentication cookies.
  • Include a random value in JSONP requests, as recommended in AlienVault’s reporting.
  • Test endpoints for cross-origin information disclosure, including whether an authenticated session changes the data returned to a requesting page.

The central design issue is whether a cross-origin request can cause a service to return executable, user-specific data. Browser protections cannot prevent disclosure when the service deliberately makes that data available through JSONP.

Are the services named in the 2015 report still vulnerable?

The 2015 reports establish what researchers said about the named services at that time; they do not establish whether those endpoints remain available, vulnerable, or unchanged. No current status is verified here, so the historical list should not be treated as a present-day warning about any named service.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.