Advertisement
Promo

Security threats Toolkit

China orders plug for hole in Green Dam

Tom Espiner ZDNet.co.uk

Published: 16 Jun 2009 15:42 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The Chinese government has ordered the makers of the Green Dam Youth Escort censorware to rush out a patch.

The censorship software has been downloaded over 3.5 million times since August 2008, according to its makers Jinhui Computer System Engineering. However, researchers from the University of Michigan revealed in a paper last week that the program contains gaping security flaws, which could lead to users' systems being compromised, and the creation of a massive botnet.

Jinhui on Monday told the People's Daily, an officially sanctioned Chinese publication, that the company had been ordered by a government agency to produce a patch.

"The Ministry of Industry and Information Technology told us to make the software safer as soon [as] a series of security vulnerabilities were found," said Zhang Chenmin, general manager Jinhui, on Sunday.

The Green Dam software is billed by the Chinese government as a pornography filter, primarily for use in schools.

In their paper, the University of Michigan researchers the software could allow malicious code to be uploaded to a PC, if the user visited a malicious website. In addition, they said the filter contains a backdoor that could allow the software's manufacturer or a third party to remotely install malware.

Jinhui plans to take legal action against the University of Michigan researchers for revealing the flaws, Zhang told the People's Daily.

"It is not responsible to crack somebody's software and publish the details, which are commercial secrets, on the internet. [The researchers] have infringed the copyright of our product," said Zhang.

According to the University of Michigan paper, the Green Dam software includes a number of blacklists from the CyberSitter web-filter program, which is produced by California-based Solid Oak. On Saturday, the US software publisher alleged that Green Dam features Solid Oak's proprietary code, and said it will seek an injunction to prevent US companies from shipping computers with the filtering software.

Zhang said while there may be similarities in the sites blocked by the two filters, Jinhui had not infringed copyright.

"I cannot deny that the two filters' databases of blacklisted URL addresses might share similarities," Zhang told the People's Daily. "After all, they are all well known international pornographic websites that all porn filters are meant to block. But we didn't steal their programming code."

The software has been mandated by the Ministry of Industry and Information Technology to be pre-installed on all new computers from the 1 July, while the initiative has been agreed by Lenovo, according to Jinhui.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
3 out of 3 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Malicious Mobile Apps a Growing Concer...

Malicious Mobile Apps a Growing Concern Author: Eric Everson, MBA, MSIT-SE The phrase “mobile security” does not usually mean much to anyone, until of course they encounter their... More

Post a comment

Malicious Mobile Code: What You Need t...

Malicious Mobile Code: What You Need to Know. Author: Eric Everson, MBA, MSIT-SE The thought of someone hacking into your mobile phone to steal your personal data added to the growing... More

1 comment

Bletchley Park calls for operators for...

The home of World War II codebreaking has called for engineers to operate an electro-mechanical machine developed by mathematician Alan Turing. The Turing Bombe was a brute-force... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters