Archive for November, 2007

Nov 29 2007

The Return of Goodwell (龚蔚)

CAUTION: I usually do not link directly to hacker websites for one reason, I don’t want people getting something nasty uploaded to their machines. This is that don’t try this at home warning. I am going to link directly to Goodwell’s blog but I still do not suggest you follow it unless you are sure you know what you are doing.

Reported several days ago about Goodwell’s online gaming in Worlds of Warcraft and figured that might be the end of it. However, got a visit on the website from isbase.net and decided to see what was up:

greenarmylogo.JPG

Logo for the Green Army Corps

The site’s BBS has a large number of participants; the screenshot below does not even capture the full membership. Only copied out the two columns that show the TOPICS and the number of POSTS to give you an idea of the size:

greentopicsposts.JPG

Scrolled down the BBS a little farther and there was a blog listed for…drum roll…

Continue Reading »

No responses yet

Nov 29 2007

Less than 24hrs later…

Published by Heike under Hacking for money

NEW CHRISTMAS ATTACK with tens of thousands of domain names mostly registered in China.

Does this mean I was right…sadly, no! But, I am feeling strangely happy about the whole prediction thing.

Just read it. 

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]

No responses yet

Nov 28 2007

United Nations Site Hacked by Self-Appointed Chinese Loophole Finder

 

 

unhacktom.JPG

        Located this screenshot on 7747.net and it seemed a little unusual. Our Chinese hacker, named ?Tom?, has hacked the UN Statistics Division website and failed to leave any sort of patriotic message. Over at his website hacker.zcuu.com:

zcuuwhois.JPG

        Tom Dong, headquarters located in Shenyang, holds the record as far as I can tell for the boldest Chinese hacker on the web. He doesn’t stop there, he is a man on a mission. It seems Tom and his group perform spot inspections on different groups in the Red Hacker Alliance and other Chinese websites to see if they can find problems.

tomspotinspections.JPG

This list indicates they conducted security inspections on:

  1. China Black Hawk Union
  2. The Red Wolf Network Security Organization
  3. Hacker Animation
  4. The New Century Network
  5. Online Download Net
  6. CCTV

There were more Red Hacker Alliance sites listed but I decided to look at the one marked Online Download Net since it had been checked by Tom and wow… Continue Reading »

6 responses so far

Nov 28 2007

Developing….Chinese hackers preparing Xmas attacks?

Published by Heike under US attacks

Looks like we all might be getting coal this year. Post later today.

UPDATE: Looks like the story has devolved and only I will be getting coal this year.  The post I was originally following about a new Christmas virus posted on November 17th of this year, was actually a reprint of the Chinese Christmas e-mail virus that was released last year in a flash animation.   Bottom line…I blew it.

However, I will go out on a limb and say it is only a matter of weeks before I post another story about a new Chinese Christmas virus, since they have basically released one every year for the last several.

Posted under: Wrong, dumb, stupid, premature and I got no friends.

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]

No responses yet

Nov 27 2007

Evolution of the Chinese Hacker Green Army

Published by Heike under Hacker Organization, Leaders

        March of 2000 witnessed the breakup of the Green Army, the organization that started the Chinese Red Hacker movement. In July, cooperation between controlling parties deteriorated and their commercial enterprise ended up in court with both parties suing. The legal battle also saw mutual hacking attacks against one another. In August, the legal case was decided in favor of the Beijing Green Alliance and Shen Jiye. The Shanghai Green Alliance, led by founder Goodwill, owed the Beijing faction 300,000 Yuan (approximately US $36,720) and was forced to turn over the domain isbase.com. Regarding the cause of the break-up, there are two versions of the story.

green-army.JPG

        The first version is that Beijing Green Alliance was well along in commercialization and did not want to turn back to freelance hacking that was advocated by members of the Green Army of the Shanghai Green Alliance. Apparently, Goodwill wanted to be the first non-profit network security organization in China but others (probably Shen Jiye), saw it as a commercial venture. Eventually, the profit motive won out. Continue Reading »

No responses yet

Nov 27 2007

What’s in a name…Well, it get’s your damn website hacked that’s what!

Published by Heike under Uncategorized

        Hackers eating hackers! Great stuff. In May of this year, one Chinese hacker guy wanted to register with www.chinahacker.com as the “Professional Pervert”. Site admin was having none of it and told him that the name “Professional Pervert” was not allowed. Well Mr. Arrogant chinahacker.com, kiss your website goodbye in… 5,4,3,2,1:

pervert.JPG

        Moral of the story, never piss off a guy who’s mad computer hacking skills are better than yours. The rest of the article is an interview with “Professional Pervert” explaining how he was able to deface the site. He explains in step-by-step detail how he accomplished this using a MAC ARP (Address Resolution Protocol) attack. Not a clue. Antionline may have summed it up here, or posted a chicken soup recipe for all I know…didn’t understand their stuff either.

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]

7 responses so far

Nov 25 2007

People’s Armed Police Officer Hacking?

Published by Heike under Hacker Hunting, Nationalism

The following is the defacement of the Japanese site nishimatsu.co by a Chinese hacker named Sunwear. He used English on some lines and Chinese on others, but here is the translation with one line omitted :

(English) Hi

(Chinese) You Japanese pigs

(English) Fuck All Japan Gril (18-20)

(Chinese) I represent all the PRC men who fuck all your pretty Japanese girls from ages (18-20).

(This line illegible)

(Chinese) You all took over 300 slaves from China. I Sunwear swear that I will hack 3000 Japanese websites

(English) Destroy Japan!!!!!!

(English) By China Sunwear E-Mail btwlu@163.com (Chinese) Chinese people look, if you have a patriotic heart add my QQ 625185 and later when there is a site to hack I will give you a call.

sunwear.JPG

Tracked down his website at http://hi.baidu.com/patricksunwear and did some checking around. There are only six personal pictures on the site and all appear to be the same male. Two pictures drew my attention:

sunwear2.JPG

sunwear3.JPG

The uniform he is wearing is that of the People’s Armed Police; a quasi military organization, protection of the party, and has recently started moving into anti-terror stuff. Hard to see detail but the rank insignia seems to be that of a 2nd Lieutenant.

sunwear4.JPG

My guess is that it is not his official duty to hack into Japanese websites, just a 2nd Lt doing what they all do… getting into more trouble than they can get out of.

UPDATE 26 Nov: After looking at the two pictures and thinking about it some more, he just may be trying on the uniform of his buddy. I don’t know, that haircut just has me thinking not in regs.

 

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]

10 responses so far

Nov 24 2007

Russia, China espionage in Germany

Published by Heike under China Russia Links

This article kind of hints around at a subject Jumper and I have been having on the link between Chinese and Russian hackers. The recent move of the Russian Hacker mob to China, along with this article showing both Chinese and Russian espionage in Germany, continues to suggest they are dancing around each other but never quite linked together.  For me it is just a gut feeling that they are linked. I haven’t found anything that shows the groups working together but…

Russia, China espionage in Germany

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]

No responses yet

Nov 23 2007

Feel Really Good About Your CAPTCHA Security…Don’t!

Published by Heike under Hacking for money

Hat-tip again to Jumper!

Jeff Atwood, at Coding Horror, has an excellent post on CAPTCHA tech and how it is implemented. He includes a section on a Chinese hacker who has posted a price list based on the probability of breaking different encoding. Well worth the read here.

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]

No responses yet

Nov 23 2007

The News with Mei Li

Published by Heike under Mei Li's reports

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]

No responses yet

Nov 21 2007

Cyber Hissy-Fit

Published by Heike under US attacks

In an article posted today (21 Nov 07) on cnhacker.com, a Chinese hacker going by the pseudonym“Name81″ apparently had an online breakdown after suffering Taiwanese Independence Syndrome. The combination of Chen Suibian’s moves to join the UN and US arms sales to Taiwan caused him to hack 32 websites in the United States. Here is his blog site:

name81.JPG

No mention as to which websites were hacked but he did have a nice little anti-US rant on his blog.

UPDATE: Kept looking a little more and these seem to be the sites he claims to have hacked

UPDATE: All hacks have the same IP address 209.225.105.101 and location Racine Wisconsin.

Continue Reading »

13 responses so far

Nov 20 2007

Best (maybe only) English Language Video on Chinese Hackers

Published by Heike under Chinese hacker video

Best (maybe only) English Language Video Documentary on Chinese Hackers

Hat-tip to Jumper

This video was produced by iDefense; these guys are the best in the business when it comes to research on Chinese hackers. It also features Lion (Lin Yong) leader of the Honker Union of China.

Hat-tip again to Jumper

He informs me that it was produced by Discovery…still great video!

 

 

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]

2 responses so far

Nov 19 2007

Top 10 Chinese Hacker Sites According to Alexa

Published by Heike under Hacker Organization

Top 10 Chinese Hacker Sites According to Alexa

      While I’m not sure I agree with these sites being the most popular overall, they are according to Alexa search.

top10.JPG

In case you have trouble reading the list (had to modify it to fit) the list was as follows:

  1. cnhacker.com
  2. hackbase.com
  3. hackerxfiles.net
  4. juntuan.net
  5. forum.eviloctal.com
  6. bbs.7747.net
  7. hhacker.com
  8. nsfocus.net
  9. netxeyes.com
  10. chinaeagle.org
[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]

No responses yet

Nov 17 2007

Chinese Hacker Documentary

Published by Heike under Chinese hacker video

Chinese Hacker Documentary

        The documentary below was posted on Youku (Chinese Youtube) in May of 2007. It is a CCTV 10 documentary that features Wan Tao, the leader of China Eagle, covering the history of the Red Hacker Alliance. The clip is 36 minutes long, so I’m not going to translate it but I did want to post it to show an example of what we can learn using open source information. All of the history that he talks about here is covered in my book but it is interesting to note how open they are about the subject. You can see just about all the defacements seen in the video at the my Flickr site located on the right in the navigation buttons.

        If you are just interested in seeing an honest to goodness famous Chinese hacker, Wan Tao begins speaking at 2 minutes 24 seconds into the video and then throughout. Warning, it loads really slow. One of the other reasons I don’t want to spend a lot of time translating.


 

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]

No responses yet

Nov 17 2007

More…Where are they now?

Published by Heike under Leaders

More…Where are they now?

 

lion1.JPG

 

        Meet Lion (true name Lin Yong), a Chinese hacker who at the age of 22, established the Honker Union of China in 2000. At that time, he had only a little over one year of Internet experience. After leading his faction in many cyber conflicts, he would disband his organization in 2004. He was also responsible for coining the word “Honker” as a term to identify the group to Westerners. So, where is he today? Couldn’t find him on World of Warcraft like his buddy Goodwell but I did check out a few links on his old blog and it looks like he was still working at XSec (We are Red Hat) as late as December of 2006. Lion also used the online name of nop, that I believe stands for “no operation” in computer programmer ease. In this screenshot (modified to fit better), we can see nop’s posts on the site:

xsec.JPG

The site also left an e-mail address for him at nop@xsec.org

 

lionemail.JPG

    Couldn’t find anything more recent. Guess I could drop him an e-mail and ask what he was up to but…I don’t think I would dare open up any reply he sent. Oh well.

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]

No responses yet

Next »