<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: tibet]]></title>
    <link>http://securityratty.com/tag/tibet</link>
    <description></description>
    <pubDate>Mon, 17 Mar 2008 10:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Chinese Cyber Attacks]]></title>
      <link>http://securityratty.com/article/6da7a571e68f430abd0a03fd33ea55f7</link>
      <guid>http://securityratty.com/article/6da7a571e68f430abd0a03fd33ea55f7</guid>
      <description><![CDATA[The popular media conception is that there is a coordinated attempt by the Chinese government to hack into U.S. computers -- military, government corporate -- and steal secrets. The truth is a lot...]]></description>
      <content:encoded><![CDATA[The popular media conception is that there is a coordinated attempt by the Chinese government to hack into U.S. computers -- military, government corporate -- and steal secrets. The truth is a lot more complicated.

There certainly is a lot of hacking coming out of China. Any company that does security monitoring sees it all the time.

These hacker groups seem not to be working for the Chinese government. They don't seem to be coordinated by the Chinese military. They're basically young, male, patriotic Chinese citizens, trying to demonstrate that they're just as good as everyone else. As well as the American networks the media likes to talk about, their targets also include pro-Tibet, pro-Taiwan, Falun Gong and pro-Uyghur sites.

The hackers are in this for two reasons: fame and glory, and an attempt to make a living. The fame and glory comes from their nationalistic goals. Some of these hackers are heroes in China. They're upholding the country's honor against both anti-Chinese forces like the pro-Tibet movement and larger forces like the United States.

And the money comes from several sources. The groups sell owned computers, malware services, and data they steal on the black market. They sell hacker tools and videos to others wanting to play. They even sell T-shirts, hats and other merchandise on their Web sites.

This is not to say that the Chinese military ignores the hacker groups within their country. Certainly the Chinese government knows the leaders of the hacker movement and chooses to look the other way. They probably buy stolen intelligence from these hackers. They probably recruit for their own organizations from this self-selecting pool of experienced hacking experts. They certainly learn from the hackers.

And some of the hackers are good. Over the years, they have become more sophisticated in both tools and techniques. They're stealthy. They do good network reconnaissance. My guess is what the Pentagon thinks is the problem is only a small percentage of the actual problem.

And they discover their own vulnerabilities. Earlier this year, one security company noticed a unique attack against a pro-Tibet organization. That same attack was also used two weeks earlier against a large multinational defense contractor.

They also hoard vulnerabilities. During the 1999 conflict over the two-states theory conflict, in a heated exchange with a group of Taiwanese hackers, one Chinese group threatened to unleash multiple stockpiled worms at once. There was no reason to disbelieve this threat.

If anything, the fact that these groups aren't being run by the Chinese government makes the problem worse. Without central political coordination, they're likely to take more risks, do more stupid things and generally ignore the political fallout of their actions.

In this regard, they're more like a non-state actor.

So while I'm perfectly happy that the U.S. government is using the threat of Chinese hacking as an impetus to get their own cybersecurity in order, and I hope they succeed, I also hope that the U.S. government recognizes that these groups are not acting under the direction of the Chinese military and doesn't treat their actions as officially approved by the Chinese government.


This essay <a href="http://dsc.discovery.com/technology/my-take/computer-hackers-china.html or http://tinyurl.com/5lv3ac">originally appeared</a> on the Discovery Channel website.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=LTtxsJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=LTtxsJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=3yfttJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=3yfttJ" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 14 Jul 2008 03:08:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/chinese">chinese</category>
      <category domain="http://securityratty.com/tag/chinese military ignores">chinese military ignores</category>
      <category domain="http://securityratty.com/tag/chinese military">chinese military</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/chinese government">chinese government</category>
      <category domain="http://securityratty.com/tag/military">military</category>
      <category domain="http://securityratty.com/tag/hacker tools">hacker tools</category>
      <category domain="http://securityratty.com/tag/hackers">hackers</category>
      <category domain="http://securityratty.com/tag/anti-chinese forces">anti-chinese forces</category>
      <source url="http://www.schneier.com/blog/archives/2008/07/chinese_cyber_a.html">Chinese Cyber Attacks</source>
    </item>
    <item>
      <title><![CDATA[TOP 10 - Hacks, more hacks, Ballmer on Yahoo, OLPC woes]]></title>
      <link>http://securityratty.com/article/fa194bd170d59f131c008ae495fdc8fd</link>
      <guid>http://securityratty.com/article/fa194bd170d59f131c008ae495fdc8fd</guid>
      <description><![CDATA[Those nasty JavaScript attacks that besieged thousands of Web sites from January until March started back up again this week, with the hackers setting up shop at a Chinese IP address. Meanwhile,...]]></description>
      <content:encoded><![CDATA[Those nasty JavaScript attacks that besieged thousands of Web sites from January until March started back up again this week, with the hackers setting up shop at a Chinese IP address. Meanwhile, security officials in China expressed worries that computer systems there will be hacked during the Olympics in August, even as hackers went after the CNN site and defaced a sports page with a message that Tibet is part of China, now and forever. Elsewhere, Steve Ballmer said Microsoft is prepared to carry on even if it does not succeed in buying Yahoo, OLPC head Nicholas Negroponte vexed open-source developers with his push to make the XO laptop interface Windows-compatible and a federal court said it's OK for customs agents to spark up our laptops and look over the contents, just because they can.]]></content:encoded>
      <pubDate>Thu, 24 Apr 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nasty javascript attacks">nasty javascript attacks</category>
      <category domain="http://securityratty.com/tag/cnn site">cnn site</category>
      <category domain="http://securityratty.com/tag/sports page">sports page</category>
      <category domain="http://securityratty.com/tag/yahoo">yahoo</category>
      <category domain="http://securityratty.com/tag/steve ballmer">steve ballmer</category>
      <category domain="http://securityratty.com/tag/security officials">security officials</category>
      <category domain="http://securityratty.com/tag/customs agents">customs agents</category>
      <category domain="http://securityratty.com/tag/laptop interface">laptop interface</category>
      <category domain="http://securityratty.com/tag/computer systems">computer systems</category>
      <source url="http://www.networkworld.com/news/2008/042508-top-10-hacks-more-hacks.html?fsrc=rss-security">TOP 10 - Hacks, more hacks, Ballmer on Yahoo, OLPC woes</source>
    </item>
    <item>
      <title><![CDATA[China worries hackers will strike during Beijing Olympics]]></title>
      <link>http://securityratty.com/article/0c8c5ff464604ac87dbd392e76308d89</link>
      <guid>http://securityratty.com/article/0c8c5ff464604ac87dbd392e76308d89</guid>
      <description><![CDATA[While CNN recently faced distributed denial-of-service attacks from Chinese hackers angry about the television network's coverage of a recent Chinese crackdown in Tibet, Chinese security officials...]]></description>
      <content:encoded><![CDATA[While CNN recently faced distributed denial-of-service attacks from Chinese hackers angry about the television network's coverage of a recent Chinese crackdown in Tibet, Chinese security officials remain worried hackers will strike while the Olympic Games are being held in Beijing.]]></content:encoded>
      <pubDate>Wed, 23 Apr 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hackers">hackers</category>
      <category domain="http://securityratty.com/tag/chinese hackers angry">chinese hackers angry</category>
      <category domain="http://securityratty.com/tag/recent chinese crackdown">recent chinese crackdown</category>
      <category domain="http://securityratty.com/tag/cnn recently faced">cnn recently faced</category>
      <category domain="http://securityratty.com/tag/television network">television network</category>
      <category domain="http://securityratty.com/tag/strike">strike</category>
      <category domain="http://securityratty.com/tag/olympic games">olympic games</category>
      <category domain="http://securityratty.com/tag/coverage">coverage</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <source url="http://www.networkworld.com/news/2008/042408-china-worries-hackers-will-strike.html?fsrc=rss-security">China worries hackers will strike during Beijing Olympics</source>
    </item>
    <item>
      <title><![CDATA[Chinese Hacktivists Waging People's Information Warfare Against CNN]]></title>
      <link>http://securityratty.com/article/05c9fa38479affa4d154230adf02a08e</link>
      <guid>http://securityratty.com/article/05c9fa38479affa4d154230adf02a08e</guid>
      <description><![CDATA[Empowering and coordinating script kiddies by releasing DIY DDoS tools (backdoored as well) during the DDoS attacks against Estonia for instance, is exactly what is happening in the time of blogging...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SA0mJdDpixI/AAAAAAAABmQ/Urb3lYBmDhU/s1600-h/hackcnn.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SA0mJdDpixI/AAAAAAAABmQ/Urb3lYBmDhU/s200/hackcnn.jpg" alt="" id="BLOGGER_PHOTO_ID_5191847889288661778" border="0" /></a>Empowering and coordinating script kiddies by <a href="http://ddanchev.blogspot.com/2007/10/empowering-script-kiddies.html">releasing DIY DDoS tools (backdoored as well)</a> during the <a href="http://ddanchev.blogspot.com/2007/08/your-point-of-view-requested.html">DDoS attacks against Estonia</a> for instance, is exactly what is happening in the time of blogging with a massive forum and IM coordination between Chinese netizens enticed to install a pre-configured to flood CNN.com piece of malware. Both of these coordinated incidents greatly illustrate what <a href="http://ddanchev.blogspot.com/2007/10/peoples-information-warfare-concept.html">people's information warfare, and the malicious culture of participation</a> is all about. The PSYOPS <span style="font-weight: bold;">anti-cnn.com</span> initiative is maturing into a central coordination point for recruiting DDoS participants on a nationalism level. Some info on <span style="font-weight: bold;">hackcnn.com</span>, the malware, internal commentary on behalf of the hacktivists, and who's behind it :<br /><br /><span style="font-weight: bold;">hackcnn.com</span> (58.49.59.253)<br />58.48.0.0-58.55.255.255 CHINANET-HB CHINANET Hubei province network China Telecom A12<br />Xin-Jie-Kou-Wai Street Beijing 100088,<br />China, Beijing 100000<br />tel:  101 1010000<br />fax:  101 1010000<br />china@hackcnn.com<br /><br />Upon execution of the tool, 18 TCP Connection Attempts to cnn.com (<span style="font-weight: bold;">64.236.91.24:80</span>) start, trying to access the following file at CNN.com :<br /><br />- Request: <span style="font-weight: bold;">GET /aux/con/com1/../../[LAG]../.%./../../../../fakecnn/redflag-stay-here.php.aspx.asp.cfm.jsp</span><br />Response: 400 "Bad Request"<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SA0pB9DpiyI/AAAAAAAABmY/2oFEElHWyFs/s1600-h/hackcnn_tool.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SA0pB9DpiyI/AAAAAAAABmY/2oFEElHWyFs/s200/hackcnn_tool.jpg" alt="" id="BLOGGER_PHOTO_ID_5191851058974526242" border="0" /></a>antiCnn.exe<br />Scanner results : 3% Scanner(1/36) found malware!<br />TROJAN.DOWNLOADER.GEN<br />File size: 174592 bytes<br />MD5...: c03abd4d871cd83fe00df38536f26422<br />SHA1..: 0502c74ee90e110ceed3cbb81b2ee53d26068691<br />Released by : Red Flag Cyber Operations nixrumor@gmail.com<br /><br />From a network reconnaissance perspective, the Chinese hacktivists didn't even bother to take care of Apache's /server status, and therefore we're easily able<br />to obtain such juicy inside information about hackcnn.com such as :<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SA0p_tDpizI/AAAAAAAABmg/8oIPp-wM404/s1600-h/sports_cnn_ddosed.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SA0p_tDpizI/AAAAAAAABmg/8oIPp-wM404/s200/sports_cnn_ddosed.jpg" alt="" id="BLOGGER_PHOTO_ID_5191852119831448370" border="0" /></a>Current Time: Tuesday, 22-Apr-2008 07:00:56<br />Restart Time: Monday, 21-Apr-2008 15:25:39<br />Parent Server Generation: 0<br />Server uptime: 15 hours 35 minutes 17 seconds<br />Total accesses: 291670 - Total Traffic: 533.8 MB<br />5.2 requests/sec - 9.7 kB/second - 1918 B/request<br />4 requests currently being processed, 246 idle workers<br /><br />Internal commentary excerpts regarding the motivation and their updates on the first DDoS round :<br /><br />"<span style="font-style: italic;">Our team of non-governmental organisations, We only private network enthusiasts. However, we have a patriotic heart, We will absolutely not permit any person to discredit our motherland under any name, We are committed to attack some spreading false information, and malicious slander, libel, support Tibet independence site.</span>"<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SA0t6dDpi0I/AAAAAAAABmo/oNfnCtMt6ns/s1600-h/sports_cnn_defaced_1.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SA0t6dDpi0I/AAAAAAAABmo/oNfnCtMt6ns/s200/sports_cnn_defaced_1.jpg" alt="" id="BLOGGER_PHOTO_ID_5191856427683646274" border="0" /></a>"<span style="font-style: italic;">User to a black CNN website suffer the same name. Yesterday, some Internet users attacked the domain name contains a "cnn" sports Web site, leaving protest speech, but reporters did not check the site found a relationship with CNN.</span>  <span style="font-style: italic;">Yesterday's attack was th</span><span style="font-style: italic;">e website with the domain name sports.si.cnn.com engaged in the work of the network of residents in Urumqi Mr. Chen, at about 2 pm, the attackers up a website hackcnn.com know, the "CNN sub-station" invasion and modify their pages. "Tug-of-war administrator and hackers," Mr. Chen said, after sports.si.cnn.com pages sometimes normal, and sometimes been modified. 16:50, the reporter saw on the pages left in bilingual text and flash animation, stressed that Tibet is a part of China, cnn protest against prejudice and false reports, the title page column was changed to "F * * kCNN!. "</span>  <span style="font-style: italic;">A few minutes later, the web site to enter a user ID and password before connecting, "evidently administrator of the authority." Chen analysis. Yesterday, the reporter tried to contact the attack, but received no response. Reporter verify that the contact address sports.si.cnn.com Pennsylvania in the United States, and the sports channel CNN web site is not the same, did not disclose information with the CNN.</span>"<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SA0uEtDpi1I/AAAAAAAABmw/eBx0cveCP5A/s1600-h/sports_cnn_defaced_2.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SA0uEtDpi1I/AAAAAAAABmw/eBx0cveCP5A/s200/sports_cnn_defaced_2.jpg" alt="" id="BLOGGER_PHOTO_ID_5191856603777305426" border="0" /></a>DDoS-ing is one thing, defacing is entirely another, try <a href="http://209.85.135.104/search?q=cache:bP4fl_vKGtwJ:sports.si.cnn.com/test.htm+%22fuck+cnn%22&amp;hl=en&amp;ct=clnk&amp;cd=8"><span style="color:black;"><span style="color:blue;">sports.si.cnn.com/test.htm</span></span></a> which was last defaced yesterday spreading "<span style="font-style: italic;">We are not against the western media, but against the lies and fabricated stories in the media</span>", "<span style="font-style: italic;">We are not against the western people, but against the prejudice from the western society.!</span>" messages.<br /><br />According to forum postings however, now that they've sent a signal, the attitude is shifting from attacking CNN to Western media in general. Thankfully, just like the case with <a href="http://ddanchev.blogspot.com/2007/11/electronic-jihad-v30-what-cyber-jihad.html">the  Electronic Jihad program</a>, they did not put a lot of efforts into ensuring the lifecycle of the tool will remain as long as possible, by introducing a way to automatically update the tool with new targets. In fact, in <a href="http://ddanchev.blogspot.com/2007/08/cyber-jihadist-dos-tool.html">the Electronic Jihad case</a>, the hardcoded update locations were all down priot to releasing the tool, making a bit more efforts cunsuming to finally manage to <a href="http://ddanchev.blogspot.com/2007/11/electronic-jihads-targets-list.html">obtain the targets list</a>.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Y8er0oG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Y8er0oG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=U8qwQ1G"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=U8qwQ1G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6x6u2fg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6x6u2fg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=z5wKCqg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=z5wKCqg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=lglljMG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=lglljMG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4Hn9S4G"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4Hn9S4G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UBIyLWg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UBIyLWg" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/275221877" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Apr 2008 22:25:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cnn">cnn</category>
      <category domain="http://securityratty.com/tag/cnn sub-station">cnn sub-station</category>
      <category domain="http://securityratty.com/tag/flood cnn">flood cnn</category>
      <category domain="http://securityratty.com/tag/sports web site">sports web site</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/psyops anti-cnn">psyops anti-cnn</category>
      <category domain="http://securityratty.com/tag/contact address sports">contact address sports</category>
      <category domain="http://securityratty.com/tag/contact">contact</category>
      <category domain="http://securityratty.com/tag/sports">sports</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/275221877/chinese-hacktivists-waging-peoples.html">Chinese Hacktivists Waging People's Information Warfare Against CNN</source>
    </item>
    <item>
      <title><![CDATA[China's CERT Annual Security Report - 2007]]></title>
      <link>http://securityratty.com/article/8eec1b2624eb89fa1310133e71a9abdb</link>
      <guid>http://securityratty.com/article/8eec1b2624eb89fa1310133e71a9abdb</guid>
      <description><![CDATA[Every coin has two sides, and while China has long embraced unrestricted warfare and people's information warfare for conducting cyber espionage, China's networked infrastructure is also under attack,...]]></description>
      <content:encoded><![CDATA[<a href="http://bp3.blogger.com/_wICHhTiQmrA/SAvJARnVfPI/AAAAAAAABlQ/7XmltP8sxhc/s1600-h/CN_CERT_2007.jpg"><img id="BLOGGER_PHOTO_ID_5191464002040200434" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SAvJARnVfPI/AAAAAAAABlQ/7XmltP8sxhc/s200/CN_CERT_2007.jpg" border="0" /></a>Every coin has two sides, and while China has long embraced <a href="http://ddanchev.blogspot.com/2007/12/combating-unrestricted-warfare.html">unrestricted warfare</a> and <a href="http://ddanchev.blogspot.com/2007/10/peoples-information-warfare-concept.html">people's information warfare</a> for conducting cyber espionage, China's networked infrastructure is also under attack, and is logically used as stepping stone to hit others country's infrastructures, thereby contributing to the possibility to engineer cyber warfare tensions.<br /><br /><div></div>A week ago, <a href="http://www.cert.org.cn/UserFiles/File/CNCERTCC2007AnnualReport_Chinese.pdf">China's CERT released their annual security report</a> (in Chinese for the time being), outlining the local threatscape with data indicating the increasing efficiency applied by Turkish web site defacement groups, in between the logical increases in spam/phishing and malware related incidents. Here's an excerpt from the report :<br /><br /><div>"<em>According CNCERT / CC monitoring found that in 2007 China's mainland are implanted into the host Trojans alarming increase in the number of IP is 22 times last year, the Trojans have become the largest Internet hazards. Underground black mature industrial chain for the production and the large number of Trojans wide dissemination provides a very convenient conditions, Trojan horses on the Internet led to the proliferation of a lot of personal information and the privacy of data theft, to the personal reputation and cause serious economic losses; In addition, the Trojans also increasingly being used to steal state secrets and secrets of the state and enterprises incalculable losses, the Chinese mainland are implanted into the Trojan Horse computer controlled source, the majority in China's Taiwan region, the phenomenon has been brought to the agency's attention. <strong>Zombie network is still the basic network attacks platform means and resources. 2007 CNCERT / CC sampling found to be infected with a zombie monitoring procedures inside and outside the mainframe amounted to 6.23 million, of which China's mainland has 3.62 million IP addresses were implanted zombie mainframe procedures, and more than 10,000 outside the control server to China Host mainland control.</strong> Zombie networks primarily be used launch denial of service (DdoS) attacks, send spam, spread malicious code, as well as theft of the infected host of sensitive information, issued by the zombie network flow, distributed DDOS attack is recognized in the world problems not only seriously affect the operation of the Internet business, but also a serious threat to China's Internet infrastructure in the safe operation. 2007 China's Internet domain name registration and the use of quantitative rapid growth, reaching 11.93 million, an annual growth rate of 190.4 percent, while hackers use of domain names has become a major tool. Use of domain names, the attackers could be flexible, hidden website linked to the implementation of large-scale horse zombie network control, network malicious activities such as counterfeiting. Fast-Flux domain names, such as dynamic analysis technologies, resulting in accordance with the IP to the attacks more difficult to trace and block; 2007 domain names which has been in use analytical services for the existence of security flaws, the public domain analysis of the server domain hijacking security incidents, a large number of users without knowing the circumstances of their fishing lure to the site or sites containing malicious code, such incidents very great danger. Therefore, the strengthening of the management of domain names and domain names analytic system's security protection is very important.</em>"</div><br />6.23 million botnet participating hosts according to their stats, where 3.62 million are Chinese IPs is a great example of how the Chinese Internet infrastructure's getting heavily abused by experienced malware and botnet masters, primarily taking advantage of what's old school social engineering, and outdated malware infection techniques, which undoubtedly will work given China's immature and inexperienced from a security perspective emerging Internet generation.<br /><div><br /></div><div><a href="http://bp1.blogger.com/_wICHhTiQmrA/SAvYUxnVfQI/AAAAAAAABlY/ZVoI70yVk68/s1600-h/chinese_defacer_nationalism.jpg"><img id="BLOGGER_PHOTO_ID_5191480846901935362" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp1.blogger.com/_wICHhTiQmrA/SAvYUxnVfQI/AAAAAAAABlY/ZVoI70yVk68/s200/chinese_defacer_nationalism.jpg" border="0" /></a>Getting back to the globalization and efficiency of Turkish web site defacement groups' worldwide web application security audit, indicated in the report, according to China's CERT these are the top 10 defacers, where 7 are well known Turkish ones, and 3 are interestingly Chinese :</div><br />sinaritx - 1731 defacements<br /><div>1923turk - 1417 defacements</div>the freedom - 1156 defacements<br /><div>aLpTurkTegin - 1052 defacements</div>Mor0Ccan Islam Defenders Team - 864 defacements<br /><div>iskorpitx - 761 defacements</div>lucifercihan - 525 defacements<br /><br /><div></div>It's also interesting to see pro-democratic Chinese hackers attacking homeland networks.<br /><p><a href="http://bp2.blogger.com/_wICHhTiQmrA/SAvigBnVfRI/AAAAAAAABlg/Gt4kn7d3LN8/s1600-h/anti_cnn_dot_com.jpg"><img id="BLOGGER_PHOTO_ID_5191492035291741458" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp2.blogger.com/_wICHhTiQmrA/SAvigBnVfRI/AAAAAAAABlg/Gt4kn7d3LN8/s200/anti_cnn_dot_com.jpg" border="0" /></a>Cyber warfare tensions engineering is only starting to take place, and state sponsored or perhaps even tolerated cyber espionage building capabilities in order for the state to later on acquire the already developed resources and capabilities in a cost-effective manner. However, <a href="http://bbs.gliet.edu.cn/bbs/index.php?s=40e077245937853cd6075b3d1cf365f2&amp;showtopic=157692&amp;st=0%EF%BF%BDentry2321659">considering</a> the <a href="http://www.upi.com/International_Security/Emerging_Threats/Analysis/2008/03/24/analysis_cyberattacks_on_tibet_groups/9260/print_view/">recent cyber attacks against "Free Tibet" movements</a>, as well as the <a href="http://asert.arbornetworks.com/2008/04/impending-cnncom-ddos/">DDoS attack attempts at CNN</a> due to <a href="http://www.thedarkvisitor.com/2008/04/breaking-upcoming-chinese-hacker-attack-on-cnn-building-steam/">CNN's coverage of Tibet</a>, Chinese cyber warriors continue demonstrating people's information warfare, and <a href="http://ddanchev.blogspot.com/2006/09/internet-psyops-psychological.html">Internet PSYOPs</a> by developing an <strong>anti-cnn.com</strong> (121.52.208.243) community, with some catchy altered images from the originals broadcasted worldwide, and with a special section to improve China's image across the world.</p>And logically, there's a <a href="http://ddanchev.blogspot.com/2006/09/internet-psyops-psychological.html">PSYOPs centered malware</a> released in the wild, a sample of which is basically embedding links to a non-existent domain, descriptive enough to point to <strong>TibetIsAPartOFChina.com</strong> :<br /><br /><p>%\CommonDocuments%\My Music\My Playlists\WWW.cgjSFGrz_TibetIsAPartOFChina.COM<br /></p><p>%CommonDocuments%\My Music\WWW.bimStzno_TibetIsAPartOFChina.COM<br /></p><p>%CommonDocuments%\My Videos\WWW.kUJs_TibetIsAPartOFChina.COM<br /></p><p>%CommonPrograms%\Accessories\Accessibility\WWW.RSulr_TibetIsAPartOFChina.COM<br /></p><p>%CommonPrograms%\Accessories\System Tools\WWW.aEGXBl_TibetIsAPartOFChina.COM</p>Now that's effective digital PSYOPs, isn't it? If you're visionary enough to tolerate the development of underground communities, whereas ensuring their nationalism level remain a priority for anything they do, you end up with a powerful cyber army whose every action perfectly fits with your political and military doctrine, without you even bothering to coordinate their efforts, thereby eliminating the need for a command and control structure.<br /><p>Related posts:</p><a href="http://ddanchev.blogspot.com/2007/09/chinas-cyber-espionage-ambitions.html">China's Cyber Espionage Ambitions</a><br /><a href="http://ddanchev.blogspot.com/2006/09/chinese-hackers-attacking-us.html">Chinese Hackers Attacking U.S Department of Defense Networks</a><br /><a href="http://ddanchev.blogspot.com/2007/12/inside-chinese-underground-economy.html">Inside the Chinese Underground Economy</a><br /><a href="http://ddanchev.blogspot.com/2007/10/chinas-cyber-warriors-video.html">China's Cyber Warriors - Video</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GC5DiiG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GC5DiiG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Vz3Pf1G"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Vz3Pf1G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GDo5aKg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GDo5aKg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dETNhLg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dETNhLg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7rxi57G"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7rxi57G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZpzUMXG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZpzUMXG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ScAQiNg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ScAQiNg" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/274516906" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 20 Apr 2008 22:34:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/china">china</category>
      <category domain="http://securityratty.com/tag/internet infrastructure">internet infrastructure</category>
      <category domain="http://securityratty.com/tag/chinese internet infrastructure">chinese internet infrastructure</category>
      <category domain="http://securityratty.com/tag/chinese">chinese</category>
      <category domain="http://securityratty.com/tag/zombie network flow">zombie network flow</category>
      <category domain="http://securityratty.com/tag/zombie network">zombie network</category>
      <category domain="http://securityratty.com/tag/interestingly chinese">interestingly chinese</category>
      <category domain="http://securityratty.com/tag/infrastructure">infrastructure</category>
      <category domain="http://securityratty.com/tag/chinese underground economy">chinese underground economy</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/274516906/chinas-cert-annual-security-report-2007.html">China's CERT Annual Security Report - 2007</source>
    </item>
    <item>
      <title><![CDATA[Chinese hackers poised for anti-CNN attack over the weekend]]></title>
      <link>http://securityratty.com/article/37619b9405190cf53d594938afd84f10</link>
      <guid>http://securityratty.com/article/37619b9405190cf53d594938afd84f10</guid>
      <description><![CDATA[An announced denial-of-service attack against CNN is allegedly planned by Chinese hackers incensed over world scrutiny of the crackdown in...]]></description>
      <content:encoded><![CDATA[An announced denial-of-service attack against CNN is allegedly planned by Chinese hackers incensed over world scrutiny of the crackdown in Tibet.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=TwFD9u"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=TwFD9u" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/272745694" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 18 Apr 2008 07:21:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/chinese hackers">chinese hackers</category>
      <category domain="http://securityratty.com/tag/world scrutiny">world scrutiny</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/cnn">cnn</category>
      <category domain="http://securityratty.com/tag/crackdown">crackdown</category>
      <category domain="http://securityratty.com/tag/tibet">tibet</category>
      <category domain="http://securityratty.com/tag/allegedly">allegedly</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/272745694/article.do">Chinese hackers poised for anti-CNN attack over the weekend</source>
    </item>
    <item>
      <title><![CDATA[Chinese hackers poised for anti CNN attack on April 19]]></title>
      <link>http://securityratty.com/article/c38a7854df70b7c9a0d083c76159dc94</link>
      <guid>http://securityratty.com/article/c38a7854df70b7c9a0d083c76159dc94</guid>
      <description><![CDATA[Chinese hackers appear to be readying for an attack on the West scheduled for April 19. It appears the basis of the attack is based on the recent, and very public, pro-Tibet coverage in Western media...]]></description>
      <content:encoded><![CDATA[Chinese hackers appear to be readying for an attack on the West scheduled for April 19. It appears the basis of the attack is based on the recent, and very public, pro-Tibet coverage in Western media organizations.]]></content:encoded>
      <pubDate>Thu, 17 Apr 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/chinese hackers">chinese hackers</category>
      <category domain="http://securityratty.com/tag/western media organizations">western media organizations</category>
      <category domain="http://securityratty.com/tag/pro-tibet coverage">pro-tibet coverage</category>
      <category domain="http://securityratty.com/tag/april">april</category>
      <category domain="http://securityratty.com/tag/west">west</category>
      <category domain="http://securityratty.com/tag/appears">appears</category>
      <category domain="http://securityratty.com/tag/basis">basis</category>
      <category domain="http://securityratty.com/tag/public">public</category>
      <source url="http://www.networkworld.com/news/2008/041808-chinese-hackers-poised-for-anti.html?fsrc=rss-security">Chinese hackers poised for anti CNN attack on April 19</source>
    </item>
    <item>
      <title><![CDATA[Espionage Against Pro-Tibet Groups, Others, Spurred Microsoft Patches]]></title>
      <link>http://securityratty.com/article/d4ffdd72706781e9653d1f7e0f536a05</link>
      <guid>http://securityratty.com/article/d4ffdd72706781e9653d1f7e0f536a05</guid>
      <description><![CDATA[A previously unexplained spike in security patches issued for Microsoft Office in 2006 and 2007 was spurred by sophisticated hack attacks against pro-Tibet organizations and U.S. defense contractors,...]]></description>
      <content:encoded><![CDATA[A previously unexplained spike in security patches issued for Microsoft Office in 2006 and 2007 was spurred by sophisticated hack attacks against pro-Tibet organizations and U.S. defense contractors, an insider claims.<br style="clear: both;"/>
      <a href="http://www.pheedo.com/click.phdo?s=bbe5c86f920984015cdd5c836df6080c"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=bbe5c86f920984015cdd5c836df6080c"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=bbe5c86f920984015cdd5c836df6080c" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=szPDbHG"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=szPDbHG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=jJZ9Bdg"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=jJZ9Bdg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=HlNVz6g"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=HlNVz6g" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=cKdn5fG"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=cKdn5fG" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=KLjS1XG"><img src="http://feeds.wired.com/~f/wired/politics/security?i=KLjS1XG" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=LXGc8Ig"><img src="http://feeds.wired.com/~f/wired/politics/security?i=LXGc8Ig" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=3UUWEBg"><img src="http://feeds.wired.com/~f/wired/politics/security?i=3UUWEBg" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Gm3t5mG"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Gm3t5mG" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/268036266" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/268036269" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 10 Apr 2008 18:40:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/insider claims">insider claims</category>
      <category domain="http://securityratty.com/tag/pro-tibet organizations">pro-tibet organizations</category>
      <category domain="http://securityratty.com/tag/microsoft office">microsoft office</category>
      <category domain="http://securityratty.com/tag/security patches">security patches</category>
      <category domain="http://securityratty.com/tag/defense contractors">defense contractors</category>
      <category domain="http://securityratty.com/tag/hack attacks">hack attacks</category>
      <category domain="http://securityratty.com/tag/previously">previously</category>
      <category domain="http://securityratty.com/tag/spike">spike</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/268036269/chinese_hackers">Espionage Against Pro-Tibet Groups, Others, Spurred Microsoft Patches</source>
    </item>
    <item>
      <title><![CDATA[Malware Targeted Against Pro-Tibet Groups]]></title>
      <link>http://securityratty.com/article/cf3ed990fd8e5534ca365b125dbf81d5</link>
      <guid>http://securityratty.com/article/cf3ed990fd8e5534ca365b125dbf81d5</guid>
      <description><![CDATA[My guess is that it's the Chinese...]]></description>
      <content:encoded><![CDATA[<p>My guess is <a href="http://www.f-secure.com/weblog/archives/00001406.html">that it's</a> the Chinese government.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=0Kj5UJF"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=0Kj5UJF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=O6SMOGF"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=O6SMOGF" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 27 Mar 2008 03:04:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/chinese government">chinese government</category>
      <source url="http://www.schneier.com/blog/archives/2008/03/malware_targete.html">Malware Targeted Against Pro-Tibet Groups</source>
    </item>
    <item>
      <title><![CDATA[Google News, YouTube blocked in China amid Tibet riots]]></title>
      <link>http://securityratty.com/article/bbf4f0c9aa6c1392f11f9c48ea2d7978</link>
      <guid>http://securityratty.com/article/bbf4f0c9aa6c1392f11f9c48ea2d7978</guid>
      <description><![CDATA[Chinese authorities have blocked Google News and YouTube in China amid protests in...]]></description>
      <content:encoded><![CDATA[Chinese authorities have blocked Google News and YouTube in China amid protests in Tibet.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=3LZgoD"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=3LZgoD" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/253066492" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 17 Mar 2008 10:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/google news">google news</category>
      <category domain="http://securityratty.com/tag/china amid protests">china amid protests</category>
      <category domain="http://securityratty.com/tag/youtube">youtube</category>
      <category domain="http://securityratty.com/tag/tibet">tibet</category>
      <category domain="http://securityratty.com/tag/chinese authorities">chinese authorities</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/253066492/article.do">Google News, YouTube blocked in China amid Tibet riots</source>
    </item>
  </channel>
</rss>
