Nov
29
2007
CAUTION: I usually do not link directly to hacker websites for one reason, I don’t want people getting something nasty uploaded to their machines. This is that don’t try this at home warning. I am going to link directly to Goodwell’s blog but I still do not suggest you follow it unless you are sure you know what you are doing.
Reported several days ago about Goodwell’s online gaming in Worlds of Warcraft and figured that might be the end of it. However, got a visit on the website from isbase.net and decided to see what was up:

Logo for the Green Army Corps
The site’s BBS has a large number of participants; the screenshot below does not even capture the full membership. Only copied out the two columns that show the TOPICS and the number of POSTS to give you an idea of the size:

Scrolled down the BBS a little farther and there was a blog listed for…drum roll…
Continue Reading »
Nov
28
2007

Located this screenshot on 7747.net and it seemed a little unusual. Our Chinese hacker, named ?Tom?, has hacked the UN Statistics Division website and failed to leave any sort of patriotic message. Over at his website hacker.zcuu.com:

Tom Dong, headquarters located in Shenyang, holds the record as far as I can tell for the boldest Chinese hacker on the web. He doesn’t stop there, he is a man on a mission. It seems Tom and his group perform spot inspections on different groups in the Red Hacker Alliance and other Chinese websites to see if they can find problems.

This list indicates they conducted security inspections on:
- China Black Hawk Union
- The Red Wolf Network Security Organization
- Hacker Animation
- The New Century Network
- Online Download Net
- CCTV
There were more Red Hacker Alliance sites listed but I decided to look at the one marked Online Download Net since it had been checked by Tom and wow… Continue Reading »
Nov
27
2007
March of 2000 witnessed the breakup of the Green Army, the organization that started the Chinese Red Hacker movement. In July, cooperation between controlling parties deteriorated and their commercial enterprise ended up in court with both parties suing. The legal battle also saw mutual hacking attacks against one another. In August, the legal case was decided in favor of the Beijing Green Alliance and Shen Jiye. The Shanghai Green Alliance, led by founder Goodwill, owed the Beijing faction 300,000 Yuan (approximately US $36,720) and was forced to turn over the domain isbase.com. Regarding the cause of the break-up, there are two versions of the story.

The first version is that Beijing Green Alliance was well along in commercialization and did not want to turn back to freelance hacking that was advocated by members of the Green Army of the Shanghai Green Alliance. Apparently, Goodwill wanted to be the first non-profit network security organization in China but others (probably Shen Jiye), saw it as a commercial venture. Eventually, the profit motive won out. Continue Reading »
Nov
25
2007
The following is the defacement of the Japanese site nishimatsu.co by a Chinese hacker named Sunwear. He used English on some lines and Chinese on others, but here is the translation with one line omitted :
(English) Hi
(Chinese) You Japanese pigs
(English) Fuck All Japan Gril (18-20)
(Chinese) I represent all the PRC men who fuck all your pretty Japanese girls from ages (18-20).
(This line illegible)
(Chinese) You all took over 300 slaves from China. I Sunwear swear that I will hack 3000 Japanese websites
(English) Destroy Japan!!!!!!
(English) By China Sunwear E-Mail btwlu@163.com (Chinese) Chinese people look, if you have a patriotic heart add my QQ 625185 and later when there is a site to hack I will give you a call.

Tracked down his website at http://hi.baidu.com/patricksunwear and did some checking around. There are only six personal pictures on the site and all appear to be the same male. Two pictures drew my attention:


The uniform he is wearing is that of the People’s Armed Police; a quasi military organization, protection of the party, and has recently started moving into anti-terror stuff. Hard to see detail but the rank insignia seems to be that of a 2nd Lieutenant.

My guess is that it is not his official duty to hack into Japanese websites, just a 2nd Lt doing what they all do… getting into more trouble than they can get out of.
UPDATE 26 Nov: After looking at the two pictures and thinking about it some more, he just may be trying on the uniform of his buddy. I don’t know, that haircut just has me thinking not in regs.
chinese hackers
Nov
21
2007
In an article posted today (21 Nov 07) on cnhacker.com, a Chinese hacker going by the pseudonym“Name81″ apparently had an online breakdown after suffering Taiwanese Independence Syndrome. The combination of Chen Suibian’s moves to join the UN and US arms sales to Taiwan caused him to hack 32 websites in the United States. Here is his blog site:

No mention as to which websites were hacked but he did have a nice little anti-US rant on his blog.
UPDATE: Kept looking a little more and these seem to be the sites he claims to have hacked
UPDATE: All hacks have the same IP address 209.225.105.101 and location Racine Wisconsin.
Continue Reading »
Nov
20
2007
Best (maybe only) English Language Video Documentary on Chinese Hackers
Hat-tip to Jumper
This video was produced by iDefense; these guys are the best in the business when it comes to research on Chinese hackers. It also features Lion (Lin Yong) leader of the Honker Union of China.
Hat-tip again to Jumper
He informs me that it was produced by Discovery…still great video!
Nov
17
2007
Chinese Hacker Documentary
The documentary below was posted on Youku (Chinese Youtube) in May of 2007. It is a CCTV 10 documentary that features Wan Tao, the leader of China Eagle, covering the history of the Red Hacker Alliance. The clip is 36 minutes long, so I’m not going to translate it but I did want to post it to show an example of what we can learn using open source information. All of the history that he talks about here is covered in my book but it is interesting to note how open they are about the subject. You can see just about all the defacements seen in the video at the my Flickr site located on the right in the navigation buttons.
If you are just interested in seeing an honest to goodness famous Chinese hacker, Wan Tao begins speaking at 2 minutes 24 seconds into the video and then throughout. Warning, it loads really slow. One of the other reasons I don’t want to spend a lot of time translating.
Nov
17
2007
More…Where are they now?

Meet Lion (true name Lin Yong), a Chinese hacker who at the age of 22, established the Honker Union of China in 2000. At that time, he had only a little over one year of Internet experience. After leading his faction in many cyber conflicts, he would disband his organization in 2004. He was also responsible for coining the word “Honker” as a term to identify the group to Westerners. So, where is he today? Couldn’t find him on World of Warcraft like his buddy Goodwell but I did check out a few links on his old blog and it looks like he was still working at XSec (We are Red Hat) as late as December of 2006. Lion also used the online name of nop, that I believe stands for “no operation” in computer programmer ease. In this screenshot (modified to fit better), we can see nop’s posts on the site:

The site also left an e-mail address for him at nop@xsec.org

Couldn’t find anything more recent. Guess I could drop him an e-mail and ask what he was up to but…I don’t think I would dare open up any reply he sent. Oh well.