<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: tensions]]></title>
    <link>http://securityratty.com/tag/tensions</link>
    <description></description>
    <pubDate>Tue, 29 Apr 2008 07:16:44 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The DDoS Attack Against Bobbear.co.uk]]></title>
      <link>http://securityratty.com/article/290801c330ee41caec63af5966719ea1</link>
      <guid>http://securityratty.com/article/290801c330ee41caec63af5966719ea1</guid>
      <description><![CDATA[When you get the &quot;privilage&quot; of getting DDoS-ed by a high profile DDoS for hire service used primarily by cybercriminals attacking other cybercriminals, you're officially doing hell of a good job...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SSNmn4J-fjI/AAAAAAAACeM/iaTooLo_YGA/s1600-h/ddos_for_hire_bobbear.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SSNmn4J-fjI/AAAAAAAACeM/iaTooLo_YGA/s200/ddos_for_hire_bobbear.png" /></a>When you get the "privilage" of <a href="http://blogs.zdnet.com/security/?p=2188">getting DDoS-ed by a high profile DDoS for hire service</a> used primarily by cybercriminals attacking other cybercriminals, you're officially doing hell of a good job exposing <a href="http://www.bobbear.co.uk/">money laundering scams</a>.<br />
<br />
The attached screenshot demonstrates how even the relatively more sophisticated countersurveillance approaches taken by a high profile DDoS for hire service can be, and were in fact bypassed, ending up in a real-time peek at how they've dedicated 4 out of their 10 BlackEnergy botnets to Bobbear exclusively.<br />
<br />
Perhaps for the first time ever, I come across a related DoS service offered by the very same vendor - <b>insider sabotage on demand given they have their own people in a particular company/ISP in question</b>. Makes you think twice before considering a minor network glitch what could easily turn into a coordinated insider attack requested by a third-party. Moreover, now that I've also established the connection between this DDoS for hire service and one of the command and control locations (all active and online) of one of the botnets used in the <a href="http://blogs.zdnet.com/security/?p=1670">Russia vs Georgia cyberattack</a>, the <a href="http://ddanchev.blogspot.com/2008/02/malware-infected-hosts-as-stepping.html">concept of engineering cyber warfare tensions</a> once again proves to be <a href="http://ddanchev.blogspot.com/2008/08/whos-behind-georgia-cyber-attacks.html">a fully realistic one</a>. <br />
<br />
<b>Related posts:</b><br />
<a href="http://blogs.zdnet.com/security/?p=1095">A U.S military botnet in the works</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/ddos-attack-graphs-from-russia-vs.html">DDoS Attack Graphs from Russia vs Georgia's Cyberattacks</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/botnet-on-demand-service.html">Botnet on Demand Service</a><br />
<a href="http://ddanchev.blogspot.com/2007/04/osint-through-botnets.html">OSINT Through Botnets</a><br />
<a href="http://ddanchev.blogspot.com/2007/05/corporate-espionage-through-botnets.html">Corporate Espionage Through Botnets</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/ddos-attack-against-cnncom.html">The DDoS Attack Against CNN.com</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/new-ddos-malware-kit-in-wild.html">A New DDoS Malware Kit in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/electronic-jihad-v30-what-cyber-jihad.html">Electronic Jihad v3.0 - What Cyber Jihad Isn't</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vAULN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vAULN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ReZlN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ReZlN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Xyy4n"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Xyy4n" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jkNqn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jkNqn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=R21XN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=R21XN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vKYRN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vKYRN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Mwlxn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Mwlxn" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/458461988" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 19 Nov 2008 05:35:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ddos">ddos</category>
      <category domain="http://securityratty.com/tag/ddos attack">ddos attack</category>
      <category domain="http://securityratty.com/tag/ddos-ed">ddos-ed</category>
      <category domain="http://securityratty.com/tag/ddos malware kit">ddos malware kit</category>
      <category domain="http://securityratty.com/tag/ddos attack graphs">ddos attack graphs</category>
      <category domain="http://securityratty.com/tag/hire service">hire service</category>
      <category domain="http://securityratty.com/tag/profile ddos">profile ddos</category>
      <category domain="http://securityratty.com/tag/botnets">botnets</category>
      <category domain="http://securityratty.com/tag/blackenergy botnets">blackenergy botnets</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/458461988/ddos-attack-against-bobbearcouk.html">The DDoS Attack Against Bobbear.co.uk</source>
    </item>
    <item>
      <title><![CDATA[Who's Behind the Georgia Cyber Attacks?]]></title>
      <link>http://securityratty.com/article/5b529a9f3815b10331813e58bacf8129</link>
      <guid>http://securityratty.com/article/5b529a9f3815b10331813e58bacf8129</guid>
      <description><![CDATA[Of course the Klingons did it, or you were naive enough to even think for a second that Russians were behind it at the first place? Of the things I hate most, it's lowering down the quality of the...]]></description>
      <content:encoded><![CDATA[<a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SKQoGBB38zI/AAAAAAAACCU/WYu9dc61zMQ/s1600-h/georgia_ddos8.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img height="51" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SKQoGBB38zI/AAAAAAAACCU/1TazKONjKVw/s200-R/georgia_ddos8.JPG" style="border: 0pt none ;" width="200" /></a>Of course the Klingons did it, or you were naive enough to even think for a second that Russians were behind it at the first place? Of the things I hate&nbsp; most, it's lowering down the quality of the discussion I hate the most. Even if you're excluding all the factual evidence (<a href="http://blogs.zdnet.com/security/?p=1670">Coordinated Russia vs Georgia cyber attack in progress</a>), common sense must prevail.<br />
<br />
Sometimes, the degree of incompetence can in fact be pretty entertaining, and greatly explains why certain countries are lacking behind others with years in their inability to understand the rules of information warfare, or the basic premise of unrestricted warfare, that there are no rules on how to achieve your objectives.<br />
<br />
So who's behind the Georgia cyber attacks, encompassing of plain simple ping floods, web site defacements, to sustained DDoS attacks, which no matter the fact that Geogia has switched hosting location to the U.S remain ongoing? It's <a href="http://computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=cybercrime_and_hacking&amp;articleId=9112443&amp;taxonomyId=82&amp;intsrc=kc_top">Russia's self-mobilizing cyber militia, the product of a collectivist society</a> having the capacity to wage cyber wars and literally dictating the rhythm in this space. What is militia anyway : <br />
<br />
<a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SKQqNt95RjI/AAAAAAAACCc/hxG1PZAcltY/s1600-h/information_warfare.1.gif" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://2.bp.blogspot.com/_wICHhTiQmrA/SKQqNt95RjI/AAAAAAAACCc/B0-V902UtRA/s200-R/information_warfare.1.gif" style="border: 0pt none ;" /></a>"<i>civilians trained as soldiers but not part of the regular army; the entire body of physically fit civilians eligible by law for military service; a military force composed of ordinary citizens to provide defense, emergency law enforcement, or paramilitary service, in times of emergency; without being paid a regular salary or committed to a fixed term of service; an army of trained civilians, which may be an official reserve army, called upon in time of need; the national police force of a country; the entire able-bodied population of a state; or a private force, not under government control; An army or paramilitary group comprised of citizens to serve in times of emergency</i>"<br />
<br />
Next to the "blame the Russian Business Network for the lack of large scale implementation of DNSSEC" mentality, certain news articles also try to wrongly imply that <a href="http://arstechnica.com/news.ars/post/20080813-georgian-attacks-might-not-be-russians-after-all.html%20">there's no Russian connection in these attacks</a>, and that the attacks are not "state-sponsored", making it look like that there should be a considerable amount of investment made into these attacks, and that the Russian government has the final word on whether or not its DDoS capabilities empowered citizens should launch any attacks or not. In reality, the only thing the Russian government was asking itself during these attacks was "why didn't they start the attacks earlier?!".<br />
<br />
Thankfully, there are some visionary folks out there understanding the situation. Last year, I asked the following question - <a href="http://www.imedialearn.com/imediapoll/poll.php?code=f1156c39d3c972139c62bc91c17e2c53">What is the most realistic scenario on what exactly happened in the recent DDoS attacks aimed at Estonia, from your point of view?</a> and some of the possible answers still fully apply in this situation :<br />
<br />
- It was a Russian government-sponsored hacktivism, or shall we say a government-tolerated one<br />
<br />
- Too much media hype over a sustained ICMP flood, given the publicly obtained statistics of the network traffic<br />
<br />
- Certain individuals of the collectivist Russian society, botnet masters for instance, were automatically recruited based on a nationalism sentiments so that they basically forwarded some of their bandwidth to key web servers<br />
<br />
- In order to generate more noise, DIY DoS tools were distributed to the masses so that no one would ever know who's really behind the attacks<br />
<br />
- Don't know who did it, but I can assure you my kid was playing !synflood at that time<br />
<br />
- Offended by the not so well coordinated removal of the Soviet statue, Russian oligarchs felt the need to send back a signal but naturally lacking any DDoS capabilities, basically outsourced the DDoS attacks<br />
<br />
- A foreign intelligence agency twisting the reality and engineering cyber warfare tensions did it, while taking advantage of the momentum and the overall public perception that noone else but the affected Russia could be behind the attacks<br />
<br />
- I hate scenario building, reminds me of my academic years, however, yours are pretty good which doesn't necessarily mean I actually care who did it, and pssst - it's not cyberwar, as in cyberwar you have two parties with virtual engagement points, in this case it was bandwidth domination by whoever did it over the other. A virtual shock and awe<br />
<br />
- I stopped following the news story by the time every reporter dubbed it the first cyber war, and started following it again when the word hacktivism started gaining popularity. So, hacktivists did it to virtually state their political preferences <br />
<br />
Departamental cyber warfare would never reach the flexibity state of people's information warfare where everyone is a cyber warrior given he's empowered with access to the right tools at a particular moment in time.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/10/peoples-information-warfare-concept.html">People's Information Warfare Concept</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/combating-unrestricted-warfare.html">Combating Unrestricted Warfare</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/cyber-storm-ii-cyber-exercise.html">The Cyber Storm II Cyber Exercise</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/chinese-hacktivists-waging-peoples.html">Chinese Hacktivists Waging People's Information Warfare Against CNN</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/ddos-attack-against-cnncom.html">The DDoS Attacks Against CNN.com</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/chinas-cyber-espionage-ambitions.html">China's Cyber Espionage Ambitions</a><br />
<a href="http://ddanchev.blogspot.com/2006/07/north-koreas-cyber-warfare-unit-121.html">North Korea's Cyber Warfare Unit 121</a><br />
<div><a href="http://ddanchev.blogspot.com/2006/09/chinese-hackers-attacking-us.html">Chinese Hackers Attacking U.S Department of Defense Networks</a></div><div><a href="http://ddanchev.blogspot.com/2007/11/electronic-jihad-v30-what-cyber-jihad.html">Electronic Jihad v3.0 - What Cyber Jihad Isn't</a></div><div><a href="http://ddanchev.blogspot.com/2007/11/electronic-jihads-targets-list.html">Electronic Jihad's Targets List</a></div><div><a href="http://ddanchev.blogspot.com/2007/11/teaching-cyber-jihadists-how-to-hack.html">Teaching Cyber Jihadists How to Hack</a></div><div><a href="http://ddanchev.blogspot.com/2007/10/empowering-script-kiddies.html">Empowering the Script Kiddies</a></div><div><a href="http://ddanchev.blogspot.com/2007/04/osint-through-botnets.html">OSINT Through Botnets</a></div><div><a href="http://ddanchev.blogspot.com/2007/05/corporate-espionage-through-botnets.html">Corporate Espionage Through Botnets</a></div><div><a href="http://ddanchev.blogspot.com/2008/02/malware-infected-hosts-as-stepping.html">Malware Infected Hosts as Stepping Stones</a></div><div><a href="http://ddanchev.blogspot.com/2006/07/hacktivism-tensions-israel-vs.html">Hacktivism Tensions - Israel vs Palestine Cyberwars</a></div><div><a href="http://ddanchev.blogspot.com/2006/05/current-emerging-and-future-state-of.html">The Current, Emerging, and Future State of Hacktivism</a></div><div><a href="http://ddanchev.blogspot.com/2006/09/internet-psyops-psychological.html">Internet PSYOPS - Psychological Operations</a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Tcck1K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Tcck1K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=X9Eb0K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=X9Eb0K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sJIFNk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sJIFNk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dY7m7k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dY7m7k" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rRiYlK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rRiYlK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XCeTAK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XCeTAK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IYEN6k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IYEN6k" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/364867192" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 06:16:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/georgia cyber attacks">georgia cyber attacks</category>
      <category domain="http://securityratty.com/tag/warfare">warfare</category>
      <category domain="http://securityratty.com/tag/departamental cyber warfare">departamental cyber warfare</category>
      <category domain="http://securityratty.com/tag/cyber warfare tensions">cyber warfare tensions</category>
      <category domain="http://securityratty.com/tag/information warfare concept">information warfare concept</category>
      <category domain="http://securityratty.com/tag/information warfare">information warfare</category>
      <category domain="http://securityratty.com/tag/russian">russian</category>
      <category domain="http://securityratty.com/tag/russian oligarchs">russian oligarchs</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/364867192/whos-behind-georgia-cyber-attacks.html">Who's Behind the Georgia Cyber Attacks?</source>
    </item>
    <item>
      <title><![CDATA[Coordinated Cyber Attacks Hit Websites Due To Russian-Georgian Conflict]]></title>
      <link>http://securityratty.com/article/279d4af57bc5882f3e7a45cba9760f7d</link>
      <guid>http://securityratty.com/article/279d4af57bc5882f3e7a45cba9760f7d</guid>
      <description><![CDATA[Conflict between Georgia and Russia on the ground has been accompanied by the relaunch of cyber-attacks against Georgian government websites. The Georgian presidential (www.president.gov.ge) and other...]]></description>
      <content:encoded><![CDATA[Conflict between Georgia and Russia on the ground has been accompanied by the relaunch of cyber-attacks against Georgian government websites. The Georgian presidential (www.president.gov.ge) and other government websites (such as www.parliament.ge) were left inaccessible by assaults over the weekend, in a repeat of attacks in late July before tensions over the breakaway region of South [...]]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 11:05:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/georgian government websites">georgian government websites</category>
      <category domain="http://securityratty.com/tag/government websites">government websites</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/conflict">conflict</category>
      <category domain="http://securityratty.com/tag/breakaway region">breakaway region</category>
      <category domain="http://securityratty.com/tag/georgian presidential">georgian presidential</category>
      <category domain="http://securityratty.com/tag/cyber-attacks">cyber-attacks</category>
      <category domain="http://securityratty.com/tag/russia">russia</category>
      <category domain="http://securityratty.com/tag/weekend">weekend</category>
      <source url="http://cyberinsecure.com/coordinated-cyber-attacks-hit-websites-due-to-russian-georgian-conflict/">Coordinated Cyber Attacks Hit Websites Due To Russian-Georgian Conflict</source>
    </item>
    <item>
      <title><![CDATA[The Ayyildiz Turkish Hacking Group VS Everyone]]></title>
      <link>http://securityratty.com/article/e5949393a0e7be6e2ea6b20dadaba58c</link>
      <guid>http://securityratty.com/article/e5949393a0e7be6e2ea6b20dadaba58c</guid>
      <description><![CDATA[Certain hacktivist groups often come and go by the time the momentum of their particular cause is long gone. Excluding the hardcore hacktivists who are obliged to defend their country's infrastructure...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><div style="text-align: left;"></div><div class="" style="clear: both;"><a href="http://bp0.blogger.com/_wICHhTiQmrA/SH-6Lbjq6XI/AAAAAAAAB7M/dn0skav9XIg/s1600-h/AYYILDIZ_TEAM.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SH-6Lbjq6XI/AAAAAAAAB7M/mYlVgqX-mVU/s200-R/AYYILDIZ_TEAM.jpg" style="border: 0pt none ;" /></a>Certain hacktivist groups often come and go by the time the momentum of their particular cause is long gone. Excluding the hardcore hacktivists who are obliged to defend their country's infrastructure and reputation on the international scene, smart enough to do on one front, there are certain hacktivist groups who ensure their future existence by declaring war and every single country that has ever made statements in contradiction with their vision. Quite a stimulating factor for ensuring the future of your script kiddies group, isn't it?<br />
<br />
One of these groups is the AYYILDIZ TEAM, a group of Turkish script kiddies who've been pretty active as of recently, targeting everyone, everywhere, leaving statements like the following :</div><br />
"<i>Me, as AYT-Admin Barbaros, swear to everything which is lovely and holy to me, that you will pay for your actions. We, AYT, as a Cyber Attacking Army will make it sure. Read right, what will we do:<br />
<br />
* The government websites will be inaccessible an all lawsuits will be manipulated</i><br />
<i>* We will infiltrate the server of inland revenues for the manipulation of the data which are there.</i><br />
<i>* At the same time we will insist into the server of banks and will care for chaos</i><br />
<i>* Websites of the press will be extinguished.</i><br />
<i>* If the offence of our prophet (s.a.v.) called your press freedom, we will show you this press freedom</i><br />
<i>* Websites of divers shops will be hacked. Databank information's and the dates which are there, for example credit card dates, will be policed in this page. (Don't worry, we wouldn't taste one cent of your moneys, we aren't thieves like you. However we don't take care of what happens, if other hackers see this dates and empty your account)</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp0.blogger.com/_wICHhTiQmrA/SIBtXRQhuII/AAAAAAAAB7U/WwX3npoBZvI/s1600-h/SQL_turkz.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SIBtXRQhuII/AAAAAAAAB7U/saIYE3fxpdA/s200-R/SQL_turkz.JPG" style="border: 0pt none ;" /></a>While this may sound inspiring, <b>some of the group's members are also involved in SQL injections in between the web site defacements</b>, which are naturally done by exploiting web application vulnerabilities. For instance, right after the defacement messages, they are also injecting the following fast-fluxed domains, part of the latest wave of SQL injections attacks.<b></b><br />
<br />
<b>bkpadd.mobi /ngg.js<br />
usaadw.com /ngg.js<br />
cliprts.com /ngg.js</b><br />
<br />
They are monetizing their defacements by either compiling lists of sites known to be SQL injectable since they've managed to defaced them, then reselling these to the SQL injectors, or are in fact part of the whole process in this scammy ecosystem. Speaking of SQL injections, here's the most recent list of fast-fluxed SQL injected domains participating in the last wave that I've been keeping track of for a while :<br />
<br />
<b>pyttco .com/ngg.js<br />
butdrv .com/ngg.js<br />
gitporg .com/ngg.js<br />
brcporb .ru/ngg.js<br />
korfd .ru/ngg.js<br />
adwnetw .com/ngg.js<br />
wowofmusiopl .com.cn/456.js<br />
adwbn .ru/ngg.js<br />
btoperc .ru/ngg.js<br />
nudk .ru/ngg.js<br />
bkpadd .mobi/ngg.js<br />
cliprts .com/ngg.js<br />
adwr .ru/ngg.js<br />
bnrc .ru/ngg.js<br />
adpzo .com/ngg.js<br />
iogp .ru/ngg.js<br />
lodse .ru/ngg.js<br />
usabnr .com/ngg.js<br />
vcre .ru/ngg.js<br />
sdkj .ru/ngg.js<br />
rcdplc .ru/ngg.js<br />
7maigol .cn/ri.js<br />
j8heisi .cn/ri.js<br />
usaadp .com/ngg.js<br />
gbradp .com/ngg.js<br />
cdrpoex .com/ngg.js<br />
rrcs .ru/ngg.js<br />
gbradw .com/ngg.js<br />
hiwowpp .cn/ri.js<br />
cdport .eu/ngg.js<br />
nopcls .com/ngg.js<br />
loopadd .com/ngg.js<br />
tertad .mobi/ngg.js<br />
gbradde .tk/ngg.js<br />
tctcow .com/ngg.js<br />
ausbnr .com/ngg.js<br />
movaddw .com/ngg.js<br />
grtsel .ru/ngg.js<br />
sslwer .ru/ngg.js<br />
destad .mobi/ngg.js<br />
hdrcom .com/ngg.js<br />
addrl .com/ngg.js<br />
porttw .mobi/ngg.js<br />
bnsdrv .com/ngg.js<br />
drvadw .com/ngg.js<br />
crtbond .com/ngg.js<br />
usaadw .com/ngg.js</b><br />
<br />
What used to be plain simple cooperating among every single participant in the underground marketplace, seems to be evolving into long-term business relationships.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/monetizing-compromised-web-sites.html">Monetizing Compromised Web Sites</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/monetizing-web-site-defacements.html">Monetizing Web Site Defacements</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/underground-multitasking-in-action.html">Underground Multitasking in Action</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/right-wing-israeli-hackers-deface.html">Right Wing Israeli Hackers Deface Hamas's Site</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/pro-serbian-hacktivists-attacking.html">Pro-Serbian Hacktivists Attacking Albanian Web Sites</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/rise-of-kosovo-defacement-groups.html">The Rise of Kosovo Defacement Groups</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/commercial-web-site-defacement-tool.html">A Commercial Web Site Defacement Tool</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/phishing-tactics-evolving.html">Phishing Tactics Evolving</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/web-site-defacement-groups-going.html">Web Site Defacement Groups Going Phishing</a><br />
<a href="http://ddanchev.blogspot.com/2006/02/hacktivism-tensions.html">Hacktivism Tensions</a><br />
<a href="http://ddanchev.blogspot.com/2006/07/hacktivism-tensions-israel-vs.html">Hacktivism Tensions - Israel vs Palestine Cyberwars</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/mass-defacement-by-turkish-hacktivists.html">Mass Defacement by Turkish Hacktivists</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/overperforming-turkish-hacktivists.html">Overperforming Turkish Hacktivists</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=727PxJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=727PxJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JwIAWJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JwIAWJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RvHRWj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RvHRWj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZamBlj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZamBlj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=YzU9yJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=YzU9yJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2kBf4J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2kBf4J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LV5ldj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LV5ldj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/338894561" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 18 Jul 2008 01:48:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/comngg">comngg</category>
      <category domain="http://securityratty.com/tag/sql injections attacks">sql injections attacks</category>
      <category domain="http://securityratty.com/tag/sql injections">sql injections</category>
      <category domain="http://securityratty.com/tag/rungg">rungg</category>
      <category domain="http://securityratty.com/tag/sql">sql</category>
      <category domain="http://securityratty.com/tag/web sites">web sites</category>
      <category domain="http://securityratty.com/tag/web site defacement">web site defacement</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/338894561/ayyildiz-turkish-hacking-group-vs.html">The Ayyildiz Turkish Hacking Group VS Everyone</source>
    </item>
    <item>
      <title><![CDATA[Links List 7.11.08]]></title>
      <link>http://securityratty.com/article/b2a7be57e50c0f7ba8f0bfa37e32e334</link>
      <guid>http://securityratty.com/article/b2a7be57e50c0f7ba8f0bfa37e32e334</guid>
      <description><![CDATA[The big news this week is of course Diane Greenes surprising ousting as CEO of virtualization giant VMware. There was a lot of speculation about the reasoning behind this decision from stock prices...]]></description>
      <content:encoded><![CDATA[<p class="MsoNormal"><span style="font-size: 11pt; font-family: Calibri;">The big news this week is of course <a href="../diane-greene-ousted-from-vmware/07/2008">Diane Greene’s surprising ousting</a> as CEO of virtualization giant VMware. There was a <a href="http://gigaom.com/2008/07/08/vmware-ceo-diane-greene-quits-stock-tanks-30/">lot of speculation</a> about the reasoning behind this decision – from stock prices dropping for VMware and parent EMC to fighting Microsoft with Microsoft (new CEO Paul Maritz is an old MS exec) to tensions between VMware and EMC (communications, culture, tie-in to EMC storage/sales) to a possible cloud computing future for VMware that Maritz is better positioned to drive. </span></p>
<p class="MsoNormal"><span style="font-size: 11pt; font-family: Calibri;">But in the end, it seems like Tucci didn’t have faith that Greene had the chops to run the successfully growing company anymore. So she could build it to the stature it has now but just as MS comes out of the gates, all of a sudden she’s no good? Boy, I can’t wait for Greene’s book on this. CEOs, take heed – don’t be too successful or the board will fire you. (Or alternatively don’t let the guy who doesn’t like you stack the board!) </span></p>
<p class="MsoNormal"><span style="font-size: 11pt; font-family: Calibri;">So <a href="http://www.eweek.com/c/a/Virtualization/VMware-EMC-Where-Does-Virtualization-Go-From-Here/">where does VMware go from here</a>? Rachel Chalmers, Research Director for Infrastructure Management at The 451 Group, places a bet on cloud computing – saying that VMware plans to offer a new suite of cloud computing at the next VMworld Conference. And here’s a nice piece on the Burton Group’s Data Center Strategies Blog that suggests another <a href="http://dcsblog.burtongroup.com/data_center_strategies/2008/07/vmware-welcome.html">multi-pronged winning strategy</a>.</span></p>
<p class="MsoNormal"><span style="font-size: 11pt; font-family: Calibri;">Oh no. The virtualization management space, if it didn’t before, is beginning to remind me of the Internet boom time when everyone and their brother (literally, ask me about it sometime) got into the act. Introducing, DynamicOps and their product, <a href="http://www.eweek.com/c/a/Infrastructure/Credit-Suisse-Spins-Off-VM-Control/">Virtual Resource Manager</a> (VRM). The two-week old company and product are spinouts from Credit Suisse, where the original solution was home-grown and in production for more than 2 years, managing thousands of virtual machines.<span> </span>I’m really interested in taking a closer look at it and seeing just what VRM does differently to meet the unique requirements of virtualization management at such a scale.</span></p>
<p class="MsoNormal"><span style="font-size: 11pt; font-family: Calibri;">Forrester Research released a research report on “<a href="http://blogs.zdnet.com/projectfailures/?p=903">the Five Essential Metrics for Managing IT</a>.” The study relates the “Operational Health” metric to the measuring of IT failures. Dave will be happy to note that the report uses one of his favorite phrases – talking about the “dial-tone reliability of IT services”. </span></p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Links+List+7.11.08&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Flinks-list-71108%2F07%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Fri, 11 Jul 2008 19:48:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/virtualization giant vmware">virtualization giant vmware</category>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/vmware plans">vmware plans</category>
      <category domain="http://securityratty.com/tag/virtualization management">virtualization management</category>
      <category domain="http://securityratty.com/tag/emc storagesales">emc storagesales</category>
      <category domain="http://securityratty.com/tag/emc">emc</category>
      <category domain="http://securityratty.com/tag/ceo paul maritz">ceo paul maritz</category>
      <category domain="http://securityratty.com/tag/maritz">maritz</category>
      <category domain="http://securityratty.com/tag/virtualization management space">virtualization management space</category>
      <source url="http://blog.sciencelogic.com/links-list-71108/07/2008">Links List 7.11.08</source>
    </item>
    <item>
      <title><![CDATA[Lithuania Attacked by Russian Hacktivists, 300 Sites Defaced]]></title>
      <link>http://securityratty.com/article/2d3be07cf61adc6c866a5aad79d898ed</link>
      <guid>http://securityratty.com/article/2d3be07cf61adc6c866a5aad79d898ed</guid>
      <description><![CDATA[Last week's mass defacement of over 300 Lithuanian sites hosted on the same ISP, an upcoming attack that was largely anticipated due to the on purposely escalated online tensions out of Lithuan's...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp3.blogger.com/_wICHhTiQmrA/SG_Da11zxkI/AAAAAAAAB30/hOMBHxBYeFc/s1600-h/info_war_slides.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SG_Da11zxkI/AAAAAAAAB30/5pqzMZ2AxxE/s200-R/info_war_slides.jpg" style="border: 0pt none ;" /></a>Last week's <a href="http://blogs.zdnet.com/security/?p=1408">mass defacement of over 300 Lithuanian sites</a> hosted on the same ISP, an upcoming attack that was largely anticipated due to the on purposely escalated online tensions out of Lithuan's accepted legislation banning communist symbols across the counry, once again demonstrates information warfare building capabilities in action.<br />
<br />
Moreover, the attack is again relying on common prerequisites for a successful information warfare campaign, used in the <a href="http://en.wikipedia.org/wiki/Cyberattacks_on_Estonia_2007">Russia vs Estonia cyberattack</a> last year. These very same <a href="http://ddanchev.blogspot.com/2006/09/internet-psyops-psychological.html">Internet PSYOPS tactics</a> ensure the success of the information warfare as a whole :<br />
<br />
- start publicly justifying upcoming attacks based on nationalism sentions, which in a bandwidth empowered (botnets) collectivist society ensures a decent degree of cyber mobilization. In Lithuania's case, the discussions across web forums were on purposely escalated to the point where "if you don't take action, you're not loyal to your country"<br />
<br />
-&nbsp; the media as the battleground for winning the hears and minds of the bandwidth empowered botnet masters, and position the insult against loyal nationalists next to the daily basis, thereby putting the nationalists in a "stand by" mode prompting them to take actions and to break even. In Estonia's case for instance, news broadcasts of the riots on the streets were on purposely broadcast as often as possible, mostly emphasizing on the nationalist sentiments within the crowds<br />
<br />
- prioritizing the attack targets, distributing the targets list and ensuring the coordination in terms of the exact time and data for the attacks to take place is something that didn't happen in the public domain for the mass defacement of Lithuanian sites, the way it happened in the Estonia attack<br />
<br />
- utilizing a <a href="http://ddanchev.blogspot.com/2007/10/peoples-information-warfare-concept.html">people's information warfare</a> tactic known as the malicious culture of participation, when everyone's consciously contributing bandwidth to be used/abused by those coordinating the attacks<br />
<br />
Also, it's important to point out that by the time they announced their ambitions to attack Lithuania and other countries such as Latvia, Ukraine, and again Estonian sites, they literally put these countries in a "stay tune" mode. <a href="http://www.baltic-course.com/eng/baltics_cis/?doc=2699">Here's a translated statement</a> :<br />
<br />
"<i>All the hackers of the country have decided to unite, to counter the impudent actions of Western superpowers. We are fed up with NATO's encroachment on our motherland, we have had enough of Ukrainian politicians who have forgotten their nation and only think about their own interests. And we are fed up with Estonian government institutions that blatantly re-write history and support fascism," says the appeal that is being circulated on Russian Internet forums.</i>" <br />
<br />
But why did they signalled their intentions, compared to keeping them quiet and attack Lithuania surprisingly? Another relevant use of <a href="http://ddanchev.blogspot.com/2006/09/internet-psyops-psychological.html">PSYOPS</a>, namely the biased exclusiveness and keeping a non-existent status bar for the upcoming attacks. And since they can launch a coordinated attack at the country at any time without warning about it, this warning was aiming to cause confusion prompting country officials to make public statements that could later on be analyzed and a better attack strategy formed on the basis of what they said they've done to ensure the attacks don't succeed. <br />
<br />
If they did launch DDoS attacks compared to <a href="http://blog.washingtonpost.com/securityfix/2008/07/lithuania_weathers_cyber_attac_1.html">defacing over 300 sites hosted on a single ISP</a>, and had warned about the upcoming attacks about a week earlier, successfully shutting down the country's Internet infrastructure would have achieved a double effect, since they did warn them about the attacks, and despite that&nbsp; they countries couldn't prepate to fight back even though fighting back was futile right from the very beginning.<br />
<br />
At least, that's the level of confidence they've build into capabilities.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/06/right-wing-israeli-hackers-deface.html">Right Wing Israeli Hackers Deface Hamas's Site</a><b></b><br />
<a href="http://ddanchev.blogspot.com/2008/06/monetizing-web-site-defacements.html">Monetizing Web Site Defacements</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/pro-serbian-hacktivists-attacking.html">Pro-Serbian Hacktivists Attacking Albanian Web Sites</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/rise-of-kosovo-defacement-groups.html">The Rise of Kosovo Defacement Groups</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/commercial-web-site-defacement-tool.html">A Commercial Web Site Defacement Tool</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/phishing-tactics-evolving.html">Phishing Tactics Evolving</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/web-site-defacement-groups-going.html">Web Site Defacement Groups Going Phishing</a><br />
<a href="http://ddanchev.blogspot.com/2006/02/hacktivism-tensions.html">Hacktivism Tensions</a><br />
<a href="http://ddanchev.blogspot.com/2006/07/hacktivism-tensions-israel-vs.html">Hacktivism Tensions - Israel vs Palestine Cyberwars</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/mass-defacement-by-turkish-hacktivists.html">Mass Defacement by Turkish Hacktivists</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/overperforming-turkish-hacktivists.html">Overperforming Turkish Hacktivists</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZLhnoJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZLhnoJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IHUziJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IHUziJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ajtYuj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ajtYuj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=yElfaj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=yElfaj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=oii31J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=oii31J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3e804J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3e804J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kBFw0j"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kBFw0j" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/328628825" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 06 Jul 2008 21:19:13 +0000</pubDate>
      <category domain="http://securityratty.com/tag/lithuania">lithuania</category>
      <category domain="http://securityratty.com/tag/attack lithuania surprisingly">attack lithuania surprisingly</category>
      <category domain="http://securityratty.com/tag/estonia">estonia</category>
      <category domain="http://securityratty.com/tag/estonia attack">estonia attack</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/attack strategy">attack strategy</category>
      <category domain="http://securityratty.com/tag/attacks based">attacks based</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/328628825/lithuania-attacked-by-russian.html">Lithuania Attacked by Russian Hacktivists, 300 Sites Defaced</source>
    </item>
    <item>
      <title><![CDATA[Right Wing Israeli Hackers Deface Hamas's Site]]></title>
      <link>http://securityratty.com/article/71489cb3d193dd4338009c34bae2a95e</link>
      <guid>http://securityratty.com/article/71489cb3d193dd4338009c34bae2a95e</guid>
      <description><![CDATA[Compared to historical hacktivism tensions between different nations, Israeli and Palestinian hacktivists seem to be most sensitive to &quot;virtual fire exchange&quot; like this one, and consequently, just...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SGPh9XRJWOI/AAAAAAAAB2c/i3FUgSZgHWg/s1600-h/hamas_hacked.png"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SGPh9XRJWOI/AAAAAAAAB2c/i3FUgSZgHWg/s200/hamas_hacked.png" alt="" id="BLOGGER_PHOTO_ID_5216261237759367394" border="0" /></a>Compared to historical hacktivism tensions between different nations, <a href="http://ddanchev.blogspot.com/2006/07/hacktivism-tensions-israel-vs.html">Israeli and Palestinian hacktivists</a> seem to be most sensitive to "virtual fire exchange" like this one, and consequently, just like in real-life, always look and find for an excuse to engage in a conflict. <a href="http://www.ynetnews.com/articles/0,7340,L-3560756,00.html">Israeli hackers penetrate Hamas website</a> :<br /><br />"<span style="font-style: italic;">Israeli hackers boasted Thursday about breaking into the website of Izz al-Din al-Qassam, Hamas’ military wing, which now displays a white screen and words in Arabic announcing technical difficulties. The hacker group, which calls itself Fanat al-Radical (the fanatical radicals), also said that it broke into additional terror organizations’ sites and those of various leftist movements.  In a Ynet interview, a group representative who refused to reveal his name said, “We searched for relevant sites with the criteria we look for, whether leftist or anti-Zionist, and looked for loopholes. Our emphasis was always on the al-Qassam site. "The criteria are defined as anti-Zionist or anti-Jewish sites that support or assist in harming Zionism and the existence of Israel as a Zionistic, Jewish state.</span>"<br /><br />The message they left :<br /><br />"<span style="font-style: italic;">Hacked by XcxooXL and FENiX from Fanat Al Radical Greets: Sn4k3 Contact: Fanat.al.Radical@gmail.com </span>"<br /><br />These script kiddies using SQL injection vulnerabilities within the affected sites, since they indeed managed to deface several other as well, seem to have also participated in the 2006 cyber conflict sparkled due to the <a href="http://www.mfa.gov.il/MFA/MFAArchive/2000_2009/2004/1/Israeli%20MIAs">the kidnapping of three soldiers</a>. One of their defacements remains still active (<span style="font-weight: bold;">aviv.perffect-x.net/deface.html</span>)<br /><br />"<span style="font-style: italic;">We will stand against the Islam until the kidnapped soldiers, Gilad Shalit, Eldad Regev and Ehod Goldvaser will be return, We will attack arabic servers and site which support the Islam and protest against the zionism</span>"<br /><br />What if every script kiddie with a SQL injection scanners goes into politics? It's a mess already.<br /><br /><span style="font-weight: bold;">Related posts:</span><br /><a href="http://ddanchev.blogspot.com/2008/06/monetizing-web-site-defacements.html">Monetizing Web Site Defacements</a><br /><a href="http://ddanchev.blogspot.com/2008/05/pro-serbian-hacktivists-attacking.html">Pro-Serbian Hacktivists Attacking Albanian Web Sites</a><br /><a href="http://ddanchev.blogspot.com/2008/04/rise-of-kosovo-defacement-groups.html">The Rise of Kosovo Defacement Groups</a><br /><a href="http://ddanchev.blogspot.com/2008/04/commercial-web-site-defacement-tool.html">A Commercial Web Site Defacement Tool</a><br /><a href="http://ddanchev.blogspot.com/2008/04/phishing-tactics-evolving.html">Phishing Tactics Evolving</a><br /><a href="http://ddanchev.blogspot.com/2008/04/web-site-defacement-groups-going.html">Web Site Defacement Groups Going Phishing</a><br /><a href="http://ddanchev.blogspot.com/2006/02/hacktivism-tensions.html">Hacktivism Tensions</a><br /><a href="http://ddanchev.blogspot.com/2006/07/hacktivism-tensions-israel-vs.html">Hacktivism Tensions - Israel vs Palestine Cyberwars</a><br /><a href="http://ddanchev.blogspot.com/2007/11/mass-defacement-by-turkish-hacktivists.html">Mass Defacement by Turkish Hacktivists</a><br /><a href="http://ddanchev.blogspot.com/2007/11/overperforming-turkish-hacktivists.html">Overperforming Turkish Hacktivists</a><br /><a href="http://ddanchev.blogspot.com/2007/11/overperforming-turkish-hacktivists.html"></a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ryWbnI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ryWbnI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=frccjI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=frccjI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Yec9Yi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Yec9Yi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZdpmYi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZdpmYi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BOanxI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BOanxI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XjskfI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XjskfI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MXrvxi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MXrvxi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/320791816" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 26 Jun 2008 11:36:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/israeli">israeli</category>
      <category domain="http://securityratty.com/tag/israeli hackers">israeli hackers</category>
      <category domain="http://securityratty.com/tag/anti-jewish sites">anti-jewish sites</category>
      <category domain="http://securityratty.com/tag/al-qassam site">al-qassam site</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/web site defacement">web site defacement</category>
      <category domain="http://securityratty.com/tag/hacktivism tensions">hacktivism tensions</category>
      <category domain="http://securityratty.com/tag/historical hacktivism tensions">historical hacktivism tensions</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/320791816/right-wing-israeli-hackers-deface.html">Right Wing Israeli Hackers Deface Hamas's Site</source>
    </item>
    <item>
      <title><![CDATA[Monetizing Web Site Defacements]]></title>
      <link>http://securityratty.com/article/9c0b522d99880bbb79d7258c5f16975f</link>
      <guid>http://securityratty.com/article/9c0b522d99880bbb79d7258c5f16975f</guid>
      <description><![CDATA[What used to be a harmless web site defacements back in the old school days, is today's ongoing monetization of defaced web sites, a logical development given the consolidation between different...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SFKBgjBBwkI/AAAAAAAAByo/TVBWvnlCxq8/s1600-h/africa_fund_defaced.png"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SFKBgjBBwkI/AAAAAAAAByo/TVBWvnlCxq8/s200/africa_fund_defaced.png" alt="" id="BLOGGER_PHOTO_ID_5211370114976432706" border="0" /></a>What used to be a harmless web site defacements back in the old school days, is today's ongoing monetization of defaced web sites, a logical development given the consolidation between different underground parties, evidence of which can be seen in the majority of incidents I've been analyzing recently.<br /><br /><a href="http://africammfund.com">The Africa Middle Market Fund</a>' site is the latest example of a web site defacer is abusing the access to the web server to generate and locally host blackhat SEO pages, which when once access only by searching for the keywords and consequently returning 404 if traffic isn't coming from a search engine, redirect to known rogue security software, in this case, the <a href="http://ddanchev.blogspot.com/2008/05/got-your-xpshield-up-and-running.html">XP antivirus protection</a> (<span style="font-weight: bold;">securityscannersite.com</span>) which you must be familiar with if you were following the <a href="http://ddanchev.blogspot.com/2008/03/massive-iframe-seo-poisoning-attack.html">assessments</a> of the <a href="http://ddanchev.blogspot.com/2008/03/rogue-rbn-software-pushed-through.html">massive IFRAME</a> SEO <a href="http://ddanchev.blogspot.com/2008/03/more-cnet-sites-under-iframe-attack.html">poisoning attacks</a> that took place during March this year. More about the found :<br /><br />"<span style="font-style: italic;">The Africa Middle Market Fund is a private capital fund that invests in small and medium sized African businesses who need from $500,000 up to $2 million to grow and succeed to their full potential. We are a "double bottom-line" or "impact investment" fund, meaning that we care equally about financial performance and social benefit. We are for-profit and insist on our investees employing world standards of financial and business management to maximize their chances of success</span>"<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_wICHhTiQmrA/SFKLPBOgSkI/AAAAAAAAByw/N8jiOnSohiw/s1600-h/africa_fund_blackhat_seo.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp0.blogger.com/_wICHhTiQmrA/SFKLPBOgSkI/AAAAAAAAByw/N8jiOnSohiw/s200/africa_fund_blackhat_seo.JPG" alt="" id="BLOGGER_PHOTO_ID_5211380808964655682" border="0" /></a>Most of the outgoing links from a sample of over 50 blackhat SEO pages at the site point to <span style="font-weight: bold;">23search.org</span>, which is an invitation-only affiliate based network for traffic exchange, connecting different malicious parties together :<br /><br />"<span style="font-style: italic;">What is this site? This site helps webmasters to earn money with their sites. How it works? Our program generate traffic from search engines and display advertising. What shell I do to start with you? Signup, get php file from member area, put file into your website directory, modify or create .htaccess in the same directory, and receive money!</span>"<br /><br />The session is then redirected to <span style="font-weight: bold;">drivemedirect.com/soft.php?aid=0195&amp;d=3&amp;product=XPA,</span> as well as to<span style="font-weight: bold;"> drivemedirect.com/soft.php?aid=0263&amp;d=2&amp;product=XPC </span>to ultimately redirect the user to<span style="font-weight: bold;"> online-xpcleaner.com/2/freescan.php?aid=880263<br /><br /></span>Moreover, the majority of blackhat SEO campaigns are also starting to apply evasive techniques to make it harder to analyze them. In this particular campaign for instance, only traffic comming from search engines would get the chance to see the SEO page due to the use of document.referrer tags. Here are some sample monitization practices from what I've seen between the lines of recently defaced sites :<br /><br />- installing web backdoors and reselling the access to phishers, spammers and malware authors who would have full control over the content, and can therefore do whatever they to with the web server<br /><br />- installing web based spamming tools that later on will be either used directly by the defacers, or access to the tools sold to those interested in using them<br /><br />- participating in an affiliate based blackhat SEO networks, where revenue coming of the victims w<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SFKcYCaWu9I/AAAAAAAABy4/X2y_2cplAoE/s1600-h/africa_fund_blackhat_visualized.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SFKcYCaWu9I/AAAAAAAABy4/X2y_2cplAoE/s200/africa_fund_blackhat_visualized.JPG" alt="" id="BLOGGER_PHOTO_ID_5211399655599291346" border="0" /></a>ho installed the rogue software is shared among the defacer and the affiliate based network, which doesn't really care how and where is all the traffic coming from<br /><br />- forwarding the responsibility of hosting phishing pages to the legitimate site by hosting them locally in between sending the phishing emails again using the same host<br /><br />- selling the access by promoting it based on its page rank<br /><br />Web site defacements in times when <a href="http://blogs.zdnet.com/security/?p=1200">traffic suppliers are efficiently coordinating campaigns with traffic seekers</a>, will mature into a tool for providing malicious infrastructure on demand, just like botnets did. Then again, the endless possibilities provided by insecure web applications are already blurring the lines between web site defacements and SQL injections.<br /><br /><span style="font-weight: bold;">Related posts:</span><br /><a href="http://ddanchev.blogspot.com/2008/05/pro-serbian-hacktivists-attacking.html">Pro-Serbian Hacktivists Attacking Albanian Web Sites</a><br /><a href="http://ddanchev.blogspot.com/2008/04/rise-of-kosovo-defacement-groups.html">The Rise of Kosovo Defacement Groups</a><br /><a href="http://ddanchev.blogspot.com/2008/04/commercial-web-site-defacement-tool.html">A Commercial Web Site Defacement Tool</a><br /><a href="http://ddanchev.blogspot.com/2008/04/phishing-tactics-evolving.html">Phishing Tactics Evolving</a><br /><a href="http://ddanchev.blogspot.com/2008/04/web-site-defacement-groups-going.html">Web Site Defacement Groups Going Phishing</a><br /><div><a href="http://ddanchev.blogspot.com/2006/02/hacktivism-tensions.html">Hacktivism Tensions</a></div> <div><a href="http://ddanchev.blogspot.com/2006/07/hacktivism-tensions-israel-vs.html">Hacktivism Tensions - Israel vs Palestine Cyberwars</a></div> <div><a href="http://ddanchev.blogspot.com/2007/11/mass-defacement-by-turkish-hacktivists.html">Mass Defacement by Turkish Hacktivists</a></div> <a href="http://ddanchev.blogspot.com/2007/11/overperforming-turkish-hacktivists.html">Overperforming Turkish Hacktivists</a><br /><a href="http://ddanchev.blogspot.com/2008/05/blackhat-seo-campaign-at-millennium.html">Blackhat SEO Campaign at The Millennium Challenge Corporation</a><br /><a href="http://ddanchev.blogspot.com/2008/03/massive-iframe-seo-poisoning-attack.html">Massive IFRAME SEO Poisoning Attack Continuing</a><br /><a href="http://ddanchev.blogspot.com/2008/02/massive-blackhat-seo-targeting-blogspot.html">Massive  Blackhat SEO Targeting Blogspot</a><br /><a href="http://ddanchev.blogspot.com/2008/01/invisible-blackhat-seo-campaign.html">The  Invisible Blackhat SEO Campaign</a><br /><a href="http://ddanchev.blogspot.com/2007/01/attack-of-seo-bots-on-edu-domain.html">Attack  of the SEO Bots on the .EDU Domain</a><br /><a href="http://ddanchev.blogspot.com/2007/11/p0rngov-ongoing-blackhat-seo-operation.html">p0rn.gov  - The Ongoing Blackhat SEO Operation</a><br /><a href="http://ddanchev.blogspot.com/2008/02/continuing-gov-blackat-seo-campaign.html">The Continuing .Gov Blackat SEO Campaign</a><br /><a href="http://ddanchev.blogspot.com/2008/02/continuing-gov-blackat-seo-campaign_25.html">The Continuing .Gov Blackhat SEO Campaign - Part Two</a><br /><a href="http://ddanchev.blogspot.com/2007/10/compromised-sites-serving-malware-and.html">Compromised Sites Serving Malware and Spam</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NKDexI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NKDexI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hZINeI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hZINeI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3PrFbi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3PrFbi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nDo4mi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nDo4mi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jT9iqI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jT9iqI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=YLiNQI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=YLiNQI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sAhmSi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sAhmSi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/311270173" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 13 Jun 2008 07:54:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/web site defacements">web site defacements</category>
      <category domain="http://securityratty.com/tag/site helps webmasters">site helps webmasters</category>
      <category domain="http://securityratty.com/tag/web site defacement">web site defacement</category>
      <category domain="http://securityratty.com/tag/web sites">web sites</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/traffic exchange">traffic exchange</category>
      <category domain="http://securityratty.com/tag/traffic">traffic</category>
      <category domain="http://securityratty.com/tag/traffic suppliers">traffic suppliers</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/311270173/monetizing-web-site-defacements.html">Monetizing Web Site Defacements</source>
    </item>
    <item>
      <title><![CDATA[Pro-Serbian Hacktivists Attacking Albanian Web Sites]]></title>
      <link>http://securityratty.com/article/9cd351092492f0dea72819f3f21ac7aa</link>
      <guid>http://securityratty.com/article/9cd351092492f0dea72819f3f21ac7aa</guid>
      <description><![CDATA[The rise of pro-kosovo web site defacement groups was marked in April, 2008, with a massive web site defacement spreading pro-kosovo propaganda. The ongoing monitoring of pro-kosovo hacktivists...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SDMw8XtDXBI/AAAAAAAABuQ/91twMWhzoeQ/s1600-h/vulnerable_albanian_sites.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SDMw8XtDXBI/AAAAAAAABuQ/91twMWhzoeQ/s200/vulnerable_albanian_sites.JPG" alt="" id="BLOGGER_PHOTO_ID_5202555808256318482" border="0" /></a>The rise of <a href="http://ddanchev.blogspot.com/2008/04/rise-of-kosovo-defacement-groups.html">pro-kosovo web site defacement groups</a> was marked in April, 2008, with a massive web site defacement spreading pro-kosovo propaganda. The ongoing monitoring of pro-kosovo hacktivists indicates an ongoing cyberwar between pro-serbian supporting hacktivists successfully defacing Albanian sites, and building up capabilities by releasing a list of vulnerable Albanian sites (remote SQL injections for remote file inclusion, defacements or <a href="http://ddanchev.blogspot.com/2007/04/compilation-of-web-backdoors.html">installing web shells/backdoors</a>) to assist supports into importing the list within their <a href="http://ddanchev.blogspot.com/2008/04/commercial-web-site-defacement-tool.html">do-it-yourself web site defacement tools</a>.<br /><br />Go through the complete post - <a href="http://blogs.zdnet.com/security/?p=1145">Pro-Serbian hacktivists attacking albanian web sites</a>.<br /><br /><span style="font-weight: bold;">Related posts:</span><br /><div><a href="http://ddanchev.blogspot.com/2006/02/hacktivism-tensions.html">Hacktivism Tensions</a></div><div><a href="http://ddanchev.blogspot.com/2006/07/hacktivism-tensions-israel-vs.html">Hacktivism Tensions - Israel vs Palestine Cyberwars</a></div><div><a href="http://ddanchev.blogspot.com/2007/11/mass-defacement-by-turkish-hacktivists.html">Mass Defacement by Turkish Hacktivists</a></div><div><a href="http://ddanchev.blogspot.com/2007/11/overperforming-turkish-hacktivists.html">Overperforming Turkish Hacktivists</a><br /></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2XYKFH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2XYKFH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=INk15H"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=INk15H" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=qd1S7h"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=qd1S7h" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mzdRFh"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mzdRFh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dH27YH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dH27YH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=soMCMH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=soMCMH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GOjVNh"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GOjVNh" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/294535899" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 20 May 2008 11:21:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hacktivists">hacktivists</category>
      <category domain="http://securityratty.com/tag/pro-kosovo hacktivists">pro-kosovo hacktivists</category>
      <category domain="http://securityratty.com/tag/pro-serbian">pro-serbian</category>
      <category domain="http://securityratty.com/tag/pro-serbian hacktivists">pro-serbian hacktivists</category>
      <category domain="http://securityratty.com/tag/turkish hacktivists">turkish hacktivists</category>
      <category domain="http://securityratty.com/tag/albanian web sites">albanian web sites</category>
      <category domain="http://securityratty.com/tag/albanian sites">albanian sites</category>
      <category domain="http://securityratty.com/tag/vulnerable albanian sites">vulnerable albanian sites</category>
      <category domain="http://securityratty.com/tag/hacktivism tensions">hacktivism tensions</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/294535899/pro-serbian-hacktivists-attacking.html">Pro-Serbian Hacktivists Attacking Albanian Web Sites</source>
    </item>
    <item>
      <title><![CDATA["The Kite Runner" will change how you think about Afghanistan]]></title>
      <link>http://securityratty.com/article/68351bd69c1abb7087d3ca708851899c</link>
      <guid>http://securityratty.com/article/68351bd69c1abb7087d3ca708851899c</guid>
      <description><![CDATA[My wife Bonnie and I don't get out to the movies as much as we used to. When we do it is often with the kids, so we miss out on many of the adult (no, I don't mean those kind of adult) themed movies...]]></description>
      <content:encoded><![CDATA[<p><img style="max-width: 800px; float: left; margin-top: 10px; margin-bottom: 10px; margin-right: 10px;" src="http://www.stillsecureafteralltheseyears.com/ashimmy/kite%20runner.jpg" width="200" height="295"></img>My wife Bonnie and I don't get out to the movies as much as we used to.  When we do it is often with the kids, so we miss out on many of the adult (no, I don't mean those kind of adult) themed movies that come out.  We wait for the DVD, but even than I miss many.  I compensate by watching movies on planes a lot.  Recently I caught The Kingdom with Jaime Fox and We Own the Night with Marc Wahlberg and Joaquin Phoenix.  Both good, powerful movies.  However, last night on my way out to Vegas for Interop I watched a movie that will change my life.  It is the <a href="http://en.wikipedia.org/wiki/The_Kite_Runner_%28film%29">Kite Runner</a>, based on the book of the same title by Khaled Hosseini.<br><br>The movie tells the story of two boys growing up in pre-Soviet invasion Kabul, Afghanistan all the way up to the year 2000, with a pre-9/11 Taliban regime in charge.  You can read the Wikipedia article I linked to or better yet go rent the movie or read the book (I am going to read it next) for all of the dramatic details.  However, let me talk a bit about my take away from this film.  First of all, like many Americans I had a pre-concieved notion of Afghanistan as a poor, backwater, backwards place that welcomed a repressive regime like the Taliban to power and were part of the Muslim world that runs from the Med through to Pakistan. Nothing distinctive and in fact lets face it, I am not sure we humanize the people who live in that part of the world, as we do Europeans or our fellow Americans.  I knew little to nothing of  Afghan history or lifestyle. Our American view of the world makes it hard for us to remember that children are children the world over and their lives are special.  Whether it be something as simple as flying a kite or aspiring to be a writer, all children share the same dreams, hopes and challenges.  Yes, in a place like Afghanistan with its ethnic tensions, there is room for a level of violence we don't often see here (but even that is BS, me living in Boca doesn't see it, but live in an inner city bad neighborhood in the US and is life any better for a child?). But parents are parents the world over and they love their children and have hopes for their children the same way you and I do.  People have values they believe in and may not be the most religous, but are never the less good people. <br><br>The movie made me think about my role as a father, husband and American. The whole American immigration experience is such a great influence on the world. We have the ability to take people from anywhere and they become Americans.  The father in the movie goes from being a man of power and wealth in Kabul, to working in a gas station here.  The father-in-law was a general in Afghanistan, but just a lower middle class worker here.  But they don't lose their identity or the pride and sense of who they are and most of all their values. They don't lose their identity into the melting pot, but we add their identities to our tapestry of life here in this country.  That is the real special sauce in what makes America <br><br>That part of the world is not just full of religous extremists.  There are real live human beings there who think and feel very much like we do.  Yes there are incredible challenges with religous extremism to overcome, but there is a core of real people who are worthy of our efforts. At the end of the day, that is what the movie has succeeded in doing for me. It has made the Afghan people real. <br></p>
<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=8yjBdY"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=8yjBdY" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=cDCwfG"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=cDCwfG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=VLqZTG"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=VLqZTG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=0tIasG"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=0tIasG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=TKrcYG"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=TKrcYG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=NDb2ig"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=NDb2ig" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=CQiE8g"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=CQiE8g" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/280180761" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 29 Apr 2008 07:16:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/afghan people real">afghan people real</category>
      <category domain="http://securityratty.com/tag/muslim world">muslim world</category>
      <category domain="http://securityratty.com/tag/world">world</category>
      <category domain="http://securityratty.com/tag/afghanistan">afghanistan</category>
      <category domain="http://securityratty.com/tag/movie tells">movie tells</category>
      <category domain="http://securityratty.com/tag/movie">movie</category>
      <category domain="http://securityratty.com/tag/kite runner">kite runner</category>
      <category domain="http://securityratty.com/tag/american view">american view</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/280180761/the-kite-runner.html">"The Kite Runner" will change how you think about Afghanistan</source>
    </item>
  </channel>
</rss>
