<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Dark Visitor &#187; Hackers Talking</title>
	<atom:link href="http://www.thedarkvisitor.com/category/hackers-talking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thedarkvisitor.com</link>
	<description></description>
	<lastBuildDate>Wed, 08 Jun 2011 03:15:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Hackbase: Alert Guinness</title>
		<link>http://www.thedarkvisitor.com/2009/09/hackbase-alert-guinness/</link>
		<comments>http://www.thedarkvisitor.com/2009/09/hackbase-alert-guinness/#comments</comments>
		<pubDate>Mon, 07 Sep 2009 09:13:44 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Evil and/or Stupid]]></category>
		<category><![CDATA[Hacker History]]></category>
		<category><![CDATA[Hackers Talking]]></category>
		<category><![CDATA[Hacking for money]]></category>
		<category><![CDATA[Other attacks]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=2051</guid>
		<description><![CDATA[Someone may want to alert Guinness that a new spin record was just set in China: Despite its suspicious name, hackbase.com&#8217;s operators want to let people know it is a legitimate computer school for defensive purposes and not an illegal hacking school. &#8220;We don&#8217;t train hackers, instead we provide professional training for Internet security. It&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>Someone may want to alert <em>Guinness</em> that a <a href="http://news.alibaba.com/article/detail/technology/100167419-1-don%25EF%25BF%25BD%25EF%25BF%25BD%25EF%25BF%25BDt-call-students-hackers%252C-says.html">new spin record</a> was just set in China:</p>
<blockquote><p>Despite its suspicious name, hackbase.com&#8217;s operators want to let people know it is a legitimate computer school for defensive purposes and not an illegal hacking school.</p>
<p>&#8220;We don&#8217;t train hackers, instead we provide professional training for Internet security. It&#8217;s up to the trainees whether they want to be a hacker or network administrator,&#8221; said Chen Qian, director of the training department.</p>
<p>The online classes are given in the evening and cover topics such as computer maintenance, anti-virus, data recovery, code protection and network attack and defense.</p>
<p>The courses, which cost between 398 to 1,998 yuan ($58- 292), are &#8220;easy&#8221; and aimed at everyone, even those without a college background or without English language skills, Chen said.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/09/hackbase-alert-guinness/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Former Chinese nationalist hacker causes international incident</title>
		<link>http://www.thedarkvisitor.com/2009/08/fomer-chinese-nationalist-hacker-causes-international-incident/</link>
		<comments>http://www.thedarkvisitor.com/2009/08/fomer-chinese-nationalist-hacker-causes-international-incident/#comments</comments>
		<pubDate>Fri, 21 Aug 2009 00:25:02 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[China internet]]></category>
		<category><![CDATA[Evil and/or Stupid]]></category>
		<category><![CDATA[Hacker History]]></category>
		<category><![CDATA[Hackers Talking]]></category>
		<category><![CDATA[India Attacks]]></category>
		<category><![CDATA[Nationalism]]></category>
		<category><![CDATA[US attacks]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1977</guid>
		<description><![CDATA[Kang Lingyi According to reports, in 1999, Kang Lingyi participated in hacking the US Embassy and the White House over the accidental bombing of the Chinese Embassy in Belgrade.   He then went on to fame founding several nationalist websites. An international controversy has broken out over an article he published on one of his websites called, [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><a rel="attachment wp-att-1978" href="http://www.thedarkvisitor.com/2009/08/fomer-chinese-nationalist-hacker-causes-international-incident/kanglingyi/"><img class="size-full wp-image-1978 alignnone" title="kanglingyi" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/08/kanglingyi.JPG" alt="kanglingyi" width="232" height="230" /></a></p>
<p style="text-align: center;">Kang Lingyi</p>
<p style="text-align: left;"><a href="http://74.125.155.132/search?q=cache:Lxo1y4T25AoJ:archive.dwnews.com/gb/MainNews/Forums/BackStage/2005/06/24/2005_6_24_16_7_34_30.html+%E9%BB%91%E5%AE%A2+kang+lingyi&amp;cd=1&amp;hl=en&amp;ct=clnk&amp;gl=us">According to reports</a>, in 1999, Kang Lingyi participated in hacking the US Embassy and the White House over the accidental bombing of the Chinese Embassy in Belgrade.   He then went on to fame <a href="http://www.time.com/time/magazine/article/0,9171,1074115-1,00.html">founding several nationalist websites</a>.</p>
<p style="text-align: left;">An <a href="http://www.2point6billion.com/2009/08/14/chinese-essay-saying-dismember-india-creates-uproar-1789.html">international controversy</a> has broken out over an article he published on one of his websites called, the <em>China International Strategy Net</em>.  In the article, Kang suggests that India can be removed as a competitor by intentionally encouraging separatists to bring about the collapse of the state.  The statements caused such an uproar that the Indian government was forced to issue a statement saying that the relationship between China and India was peaceful.</p>
<p style="text-align: left;">As of this writing, Kang&#8217;s website has a message up saying that the site is currently under maintenance.  It has been up all day so let the wild speculations begin:</p>
<p style="text-align: center;"><a rel="attachment wp-att-1981" href="http://www.thedarkvisitor.com/2009/08/fomer-chinese-nationalist-hacker-causes-international-incident/kangyishutdown/"><img class="aligncenter size-medium wp-image-1981" title="Kangyishutdown" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/08/Kangyishutdown-300x157.jpg" alt="Kangyishutdown" width="300" height="157" /></a></p>
<p style="text-align: left;">1) Beijing took it down as a concession</p>
<p style="text-align: left;">2) Indian hackers</p>
<p style="text-align: left;">3) The boring option of site maintenance          </p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/08/fomer-chinese-nationalist-hacker-causes-international-incident/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>China starting to worry about its own hackers</title>
		<link>http://www.thedarkvisitor.com/2009/08/china-starting-to-worry-about-its-own-hackers/</link>
		<comments>http://www.thedarkvisitor.com/2009/08/china-starting-to-worry-about-its-own-hackers/#comments</comments>
		<pubDate>Wed, 05 Aug 2009 05:39:46 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Hacker History]]></category>
		<category><![CDATA[Hacker Organization]]></category>
		<category><![CDATA[Hackers Talking]]></category>
		<category><![CDATA[Hacking for money]]></category>
		<category><![CDATA[Leaders]]></category>
		<category><![CDATA[US attacks]]></category>
		<category><![CDATA[Janker]]></category>
		<category><![CDATA[Lonely Swordsman]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1875</guid>
		<description><![CDATA[The picture seen above is an advertisement for a Chinese hacker training course.  Now I know many of you are struggling to process this information;  something seems wrong with the picture.  The reason your brain is having trouble with the image,  is that it is located in a place called, the &#8220;outdoors&#8221;.  Like me, many [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="aligncenter size-full wp-image-1876" title="hackertrainingposter" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/08/hackertrainingposter.JPG" alt="hackertrainingposter" width="298" height="431" /></p>
<p style="text-align: left;">The picture seen above is an advertisement for a Chinese hacker training course.  Now I know many of you are struggling to process this information;  something seems wrong with the picture.  The reason your brain is having trouble with the image,  is that it is located in a place called, the &#8220;outdoors&#8221;.  Like me, many of you spend way too much time online and this poster is horribly out of place.</p>
<p>The following report from <em>China Daily</em> talks about the growing public concern over <a href="http://www.chinadaily.com.cn/china/2009-08/04/content_8513977.htm">hacking and online hacking courses</a>.  It also interviews Wang Xianbing, a consultant for <em>hackbase.com</em>:</p>
<blockquote><p>&#8220;Lots of hacker schools only teach students how to hack into unprotected computers and steal personal information,&#8221; said Wang Xianbing, a security consultant for hackerbase.com. &#8220;They then make a profit by selling users&#8217; information.&#8221;</p>
<p>For investing hundreds of yuan in hacker school, students could obtain the skills to make a fortune, Wang said.</p>
<p>&#8220;Hacker school is a bit like driving school &#8211; they teach you how to drive but it&#8217;s up to you if you are going to drive safely or kill someone,&#8221; said Wang.</p></blockquote>
<p>What the article doesn&#8217;t tell you is that Wang Xianbing is also known as <a href="http://www.thedarkvisitor.com/2007/12/the-lonely-swordsman/">Janker and the Lonely Swordsman</a>; one of China&#8217;s first generation of hackers and the leader of online conflicts with the US and Japan.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/08/china-starting-to-worry-about-its-own-hackers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Chinese hacker, now just phoning it in</title>
		<link>http://www.thedarkvisitor.com/2009/07/chinese-hacker-now-just-phoning-it-in/</link>
		<comments>http://www.thedarkvisitor.com/2009/07/chinese-hacker-now-just-phoning-it-in/#comments</comments>
		<pubDate>Tue, 28 Jul 2009 02:18:10 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Hackers Talking]]></category>
		<category><![CDATA[Nationalism]]></category>
		<category><![CDATA[Other attacks]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1855</guid>
		<description><![CDATA[The Chinese hacker who defaced the Melbourne Film Festival website signed his message of protest with the sid Oldjun.  To obscure his online identity, he named his personal website&#8230;Oldjun.com.  Some people just don&#8217;t care about their chosen profession and it shows. Even the people who have stopped by Oldjun&#8217;s blog are dismayed by his total [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><a rel="attachment wp-att-1856" href="http://www.thedarkvisitor.com/2009/07/chinese-hacker-now-just-phoning-it-in/oldjun-2/"><img class="aligncenter size-medium wp-image-1856" title="oldjun" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/07/oldjun1-300x193.jpg" alt="oldjun" width="300" height="193" /></a></p>
<p>The Chinese hacker who defaced the Melbourne Film Festival website signed his message of protest with the sid Oldjun.  To obscure his online identity, he named his personal website&#8230;Oldjun.com.  Some people just don&#8217;t care about their chosen profession and it shows.</p>
<p>Even the <a href="http://www.oldjun.com/blog/index.php/archives/48/#comment">people who have stopped by Oldjun&#8217;s blog are dismayed</a> by his total disregard for anonymity.   They point out that his personal info is all over Baidu and his blog site.   It gives away his surname, age, where he went to school and ID number.  They joke telling him to run and hide.</p>
<p><a href="http://bbs.huanqiu.com/viewthread.php?action=printable&amp;tid=237147">Huanqiu.com tracked Oldjun down</a> using a Whois lookup on the website and got him to confess:</p>
<blockquote><p>After tracing the domain name Oldjun, The Sunday Age spoke to Zhou Yu, 24, an IT professional from Nanjing, who admitted hacking the site after learning about the controversy from the internet.</p>
<p>Mr Zhou denied acting on behalf of the Chinese Government, stating he acted &#8216;because I am Chinese. I’m very angry — not only me, but I think all of the Chinese people— about this.&#8217;</p></blockquote>
<p>As an added bonus, our <a href="http://www.thedarkvisitor.com/2007/11/peoples-armed-police-officer-hacking/">old friend Sunwear</a> shows up in the comments section.  My theory still holds that if Sunwear is present, <a href="http://www.thedarkvisitor.com/2008/06/sunwear-hacks-metasploitcom/">something bad is happening</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/07/chinese-hacker-now-just-phoning-it-in/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Leader of Chinese hacker group that planned DDoS attack on CNN identified</title>
		<link>http://www.thedarkvisitor.com/2009/07/leader-of-chinese-hacker-group-that-planned-ddos-attack-on-cnn-identified/</link>
		<comments>http://www.thedarkvisitor.com/2009/07/leader-of-chinese-hacker-group-that-planned-ddos-attack-on-cnn-identified/#comments</comments>
		<pubDate>Sun, 19 Jul 2009 13:03:53 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Hacker History]]></category>
		<category><![CDATA[Hacker Hunting]]></category>
		<category><![CDATA[Hacker Organization]]></category>
		<category><![CDATA[Hackers Talking]]></category>
		<category><![CDATA[Nationalism]]></category>
		<category><![CDATA[Tibet]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1805</guid>
		<description><![CDATA[In April of 2008, we reported Revenge of the Flame&#8216;s plan to carry out a DDoS attack on the CNN website.  A series of events during that time period enraged the Chinese online community: European nations harshly criticized China&#8217;s response to the Tibetan uprising; pro-Tibetan independence protesters in Paris tried to snatch the Olympic torch [...]]]></description>
			<content:encoded><![CDATA[<p>In April of 2008, we reported <a href="http://www.thedarkvisitor.com/2008/04/breaking-anti-cnns-call-for-european-protests-spreading-onlinebreaking-cnn-possible-target-of-chinese-hacker-attack-on-19-april-what-beijing-police-supplied-eggs-to-protesters-during-anti-japan/"><em>Revenge of the Flame</em>&#8216;s plan to carry out a DDoS attack</a> on the <em>CNN</em> website.  A series of events during that time period enraged the Chinese online community: European nations harshly criticized China&#8217;s response to the Tibetan uprising; pro-Tibetan independence protesters in Paris tried to snatch the Olympic torch from the hands of a wheelchair-bound Chinese female athlete; and Jack Cafferty, a CNN commentator, referred to Chinese products as &#8220;junk&#8221; and called the Chinese government &#8220;goons and thugs.&#8221;   In response to these insults, <em>Anti-CNN</em> called for overseas Chinese in Europe to wave the Chinese flag and raise their voice to the sky.</p>
<p>In response to these same events, a hacker, using the online name cn_magistrate, formed a group called Revenge of the Flame and announced his plan to carry out a DDoS attack on<em> the  CNN</em> website.  We <a href="http://www.thedarkvisitor.com/2008/04/breaking-upcoming-chinese-hacker-attack-on-cnn-building-steam/">followed the events</a> as calls went out for Chinese netizens to join the action.  We were there when cn_magistrate <a href="http://www.thedarkvisitor.com/2008/04/chinese-hacker-group-identified-as-revenge-of-the-flame-calls-off-attack-on-cnntoo-many-people-know/">called off the attack</a> and <a href="http://www.thedarkvisitor.com/2008/04/revenge-of-the-flame-disbands-denies-all-responsibility-for-attack-on-cnnand-kills-website/">disbaned the organization</a>.  Then he vanished&#8230;</p>
<p style="text-align: center;"><a rel="attachment wp-att-1806" href="http://www.thedarkvisitor.com/2009/07/leader-of-chinese-hacker-group-that-planned-ddos-attack-on-cnn-identified/cnmagistrate/"><img class="aligncenter size-thumbnail wp-image-1806" title="cnmagistrate" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/07/cnmagistrate-150x150.jpg" alt="cnmagistrate" width="150" height="150" /></a></p>
<p style="text-align: center;">cn_magistrate</p>
<p style="text-align: left;"><strong>Cold Case</strong>:  Yeah, we keep looking.  Finally <a href="http://hi.baidu.com/hack666/profile">located him</a> through a combination of e-mail address, website and online name.   Below are the results of a Whois search we conducted on the associated website during the time of the attack (Notice the website name and e-mail address):</p>
<p style="text-align: left;">Domain Name: <span style="color: #ff0000;">hacksa.cn<strong style="color: #333333;"> </strong></span><br />
ROID: 20070811s10001s50288265-cn<br />
Domain Status: ok<br />
Registrant Organization: 判官<br />
Registrant Name: 判官<br />
Administrative Email: <span style="color: #ff0000;">Kenan2677@126.com</span><br />
Sponsoring Registrar: 北京万网志成科技有限公司<br />
Name Server:ns1.okidc.com Name Server:ns2.okidc.com<br />
Registration Date: 2007-08-11 11:59<br />
Expiration Date: 2008-08-11 11:59</p>
<p style="text-align: left;">
<p style="text-align: center;"><a rel="attachment wp-att-1807" href="http://www.thedarkvisitor.com/2009/07/leader-of-chinese-hacker-group-that-planned-ddos-attack-on-cnn-identified/cnmagistrate2/"><img class="size-thumbnail wp-image-1807 aligncenter" title="cnmagistrate2" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/07/cnmagistrate2-150x150.jpg" alt="cnmagistrate2" width="150" height="150" /></a></p>
<p style="text-align: center;">Hacksa.cn website letter</p>
<p style="text-align: left;">The image seen above was taken from cn_magistrate&#8217;s <a href="http://hi.baidu.com/hack666/album/item/76ab0f2ed5d95a584ec22600.html#IMG=7afdc950c42ede511038c2e8">current blog</a> showing the old URL  hacksa.cn,  which was <a href="http://www.thedarkvisitor.com/2008/04/495/">associated with the <em>CNN</em> attack</a>.</p>
<p style="text-align: left;">
<p style="text-align: left;">
<p style="text-align: left;"><a rel="attachment wp-att-1809" href="http://www.thedarkvisitor.com/2009/07/leader-of-chinese-hacker-group-that-planned-ddos-attack-on-cnn-identified/cnmagistrate4-2/"><img class="aligncenter size-medium wp-image-1809" title="cnmagistrate4" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/07/cnmagistrate41-300x30.jpg" alt="cnmagistrate4" width="300" height="30" /></a></p>
<p style="text-align: left;">This <a href="http://hi.baidu.com/hack666/blog/item/ed31f11360dd07015aaf53ce.html">reply from cn_magistrate</a> in the comments section of his blog shows the e-mail address  Kenan2677@126.com, used to register <em>hacksa.cn</em>.</p>
<p style="text-align: left;">SURPRISE&#8230;</p>
<p style="text-align: left;"><a rel="attachment wp-att-1812" href="http://www.thedarkvisitor.com/2009/07/leader-of-chinese-hacker-group-that-planned-ddos-attack-on-cnn-identified/cnmagistrate3/"><img class="aligncenter size-full wp-image-1812" title="cnmagistrate3" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/07/cnmagistrate3.JPG" alt="cnmagistrate3" width="284" height="289" /></a></p>
<p style="text-align: left;">He claims to be a Taiwanese citizen&#8230;</p>
<p style="text-align: left;">I&#8217;ve written to cn_magistrate and asked if he will talk to us about the incident.  Off topic, did anyone hear the news about Taiwan and the US coming closer to an <a href="http://www.chinapost.com.tw/taiwan/foreign-affairs/2009/05/28/209871/Ma-pitches.htm">extradition agreement</a>?  That would be cool.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/07/leader-of-chinese-hacker-group-that-planned-ddos-attack-on-cnn-identified/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>New leader of the Red Hacker Alliance?</title>
		<link>http://www.thedarkvisitor.com/2009/07/new-leader-of-the-red-hacker-alliance/</link>
		<comments>http://www.thedarkvisitor.com/2009/07/new-leader-of-the-red-hacker-alliance/#comments</comments>
		<pubDate>Thu, 02 Jul 2009 10:34:57 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Hacker History]]></category>
		<category><![CDATA[Hacker Organization]]></category>
		<category><![CDATA[Hackers Talking]]></category>
		<category><![CDATA[Leaders]]></category>
		<category><![CDATA[Nationalism]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1691</guid>
		<description><![CDATA[During the Olympics Games, a secret organization was formed by a Chinese hacker named Wang Zi to protect Olympic websites against foreign hackers and while they won&#8217;t say, reprisals were probably taken against offenders. This article, from the People&#8217;s Daily, details Wang Zi&#8217;s efforts to bring back the patriotic spirit of the Red Hacker Alliance. [...]]]></description>
			<content:encoded><![CDATA[<p>During the Olympics Games, <a href="http://english.people.com.cn/90001/90782/6691378.html">a secret organization was formed</a> by a Chinese hacker named Wang Zi to protect Olympic websites against foreign hackers and while they won&#8217;t say, reprisals were probably taken against offenders.</p>
<p>This article, from the <em>People&#8217;s Daily, </em>details Wang Zi&#8217;s efforts to bring back the patriotic spirit of the Red Hacker Alliance.</p>
<blockquote><p>&#8220;The Tao that can be described in words is not the true Tao. The Name that can be named is not the true Name,&#8221; – the first two sentences of Tao Te Ching are the slogan of hong ke that appear on the new union&#8217;s new homepage.</p>
<p>After the Olympics, Wang Zi&#8217;s group retired from the web for a short time, and then on the first day of this year, the group made a bold new announcement.</p>
<p>The blurb on their newly-launched website reads, &#8220;Hong ke culture is back. We will hold and transmit hong ke spirit focusing on justice, pioneering and love for the motherland.&#8221;</p></blockquote>
<p>Lin Lin, the leader of <em>Evil Octal</em> (another Chinese hacker organization), refutes Wang Zi&#8217;s claim to the title of new leader:</p>
<blockquote><p>&#8220;Lion is the spiritual leader of the hong ke union,&#8221; Lin Lin, a leader of hacker group Eviloctal Security Team, told the Global Times. &#8220;And without him, no hong ke organization can be regarded as a reorganization of the original.</p></blockquote>
<p>The article goes to great lengths to distance the organization from being government sanctioned:</p>
<blockquote><p>Wang Zi says his union is a purely non-governmental organization. They could not register the union&#8217;s name with the Ministry of Industry and Information Technology until they deleted &#8220;Zhongguo&#8221; (China) from it.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/07/new-leader-of-the-red-hacker-alliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>It&#8217;s a man baby!</title>
		<link>http://www.thedarkvisitor.com/2009/05/its-a-man-baby/</link>
		<comments>http://www.thedarkvisitor.com/2009/05/its-a-man-baby/#comments</comments>
		<pubDate>Sat, 09 May 2009 03:02:54 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Evil and/or Stupid]]></category>
		<category><![CDATA[Hackers Talking]]></category>
		<category><![CDATA[Yingcracker]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1565</guid>
		<description><![CDATA[UPDATED: Webshell, in the comments, may be saying that Yingcracker (also fixed, I had typed in yinghacker) is a female.  Anyway, finally located his/her website.  If it is a guy, he is very much in touch with his feminine side. In the last few days, the story of Yingcracker, &#8220;the most beautiful female hacker in [...]]]></description>
			<content:encoded><![CDATA[<p><strong>UPDATED</strong>: Webshell, in the comments, may be saying that Yingcracker (also fixed, I had typed in yinghacker) is a female.  Anyway, finally located his/her <a href="http://user.qzone.qq.com/709193296">website</a>.  If it is a guy, he is very much in touch with his feminine side.</p>
<p>In the last few days, the story of Yingcracker, &#8220;the most beautiful female hacker in China,&#8221; has been making the rounds  in Chinese news outlets and blogs.  Her exploits and earnings, in this male dominated society, have been posted by  numerous online sources.  The number of male friends added to her blog since the story first appeared have been impressive.</p>
<p><strong>Problem:</strong> <a href="http://www.hackbase.com/news/2009-05-09/25851.html">Yingcracker is a man baby</a>! He thinks it&#8217;s kinda funny to pretend to be a MM (girl) online.  <a href="http://www.thedarkvisitor.com/2008/05/chinese-female-hacker-group/">Xiao Tian</a> e-mails me this:</p>
<p style="text-align: center;"><a rel="attachment wp-att-1697" href="http://www.thedarkvisitor.com/2009/05/its-a-man-baby/xiaotian3-2/"><img class="size-full wp-image-1697  aligncenter" title="xiaotian3" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/05/xiaotian3.JPG" alt="xiaotian3" width="398" height="669" /></a><a rel="attachment wp-att-1566" href="http://www.thedarkvisitor.com/2009/05/its-a-man-baby/xiaotian3/"></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/05/its-a-man-baby/feed/</wfw:commentRss>
		<slash:comments>16</slash:comments>
		</item>
		<item>
		<title>Hackers: the China Syndrome by Mara Hvistendahl</title>
		<link>http://www.thedarkvisitor.com/2009/04/hackers-the-china-syndrome-by-mara-hvistendahl/</link>
		<comments>http://www.thedarkvisitor.com/2009/04/hackers-the-china-syndrome-by-mara-hvistendahl/#comments</comments>
		<pubDate>Fri, 24 Apr 2009 11:12:48 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Hacker History]]></category>
		<category><![CDATA[Hacker Hunting]]></category>
		<category><![CDATA[Hacker Organization]]></category>
		<category><![CDATA[Hackers Talking]]></category>
		<category><![CDATA[Leaders]]></category>
		<category><![CDATA[Nationalism]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1549</guid>
		<description><![CDATA[Best hobby in the world. It was absolutely my privilege to  spend a few days talking with Mara Hvistendahl on the subject of Chinese hackers.  She is such a fantastic lady and I couldn&#8217;t have enjoyed our time more. While linking to our interview may seem a bit of shameless self-promotion, I mainly wanted it [...]]]></description>
			<content:encoded><![CDATA[<p>Best hobby in the world.</p>
<p><span class="author">It was absolutely my privilege to  spend a few days talking with <a href="http://www.marahvistendahl.com/bio.cfm">Mara Hvistendahl</a> on the subject of Chinese hackers.  She is such a fantastic lady and I couldn&#8217;t have enjoyed our time more. </span></p>
<p><span class="author">While linking to our interview may seem a bit of shameless self-promotion, I mainly wanted it on record that Mara called me, &#8220;</span>a <strong>trim</strong> 46-year-old.&#8221;  I pushed for other words like swashbuckling, ruggedly handsome and athletic until Mara started mentioning other adjectives such as weird, strange and goofy.</p>
<p><strong>&#8230;TRIM!</strong></p>
<p><a href="http://www.popsci.com/scitech/article/2009-04/hackers-china-syndrome"><em>Hackers: the China Syndrome</em></a> by Mara Hvistendahl</p>
<p><span class="author"><br />
</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/04/hackers-the-china-syndrome-by-mara-hvistendahl/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>CasperNet gets punked</title>
		<link>http://www.thedarkvisitor.com/2009/04/caspernet-gets-punked/</link>
		<comments>http://www.thedarkvisitor.com/2009/04/caspernet-gets-punked/#comments</comments>
		<pubDate>Sat, 04 Apr 2009 13:37:33 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Hacker Hunting]]></category>
		<category><![CDATA[Hackers Talking]]></category>
		<category><![CDATA[India Attacks]]></category>
		<category><![CDATA[CasperNet]]></category>
		<category><![CDATA[lost33]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1497</guid>
		<description><![CDATA[Remember the fable about the Scorpion and the Frog?  Well, we got stung&#8230; Lost33 did not make contact with Jumper last night.  In fact, it seems he spent the night changing his QQ number and deleting all info from his blog. The website is now completely empty, except for a change to his personal data.  [...]]]></description>
			<content:encoded><![CDATA[<p>Remember the fable about the <a href="http://en.wikipedia.org/wiki/The_Scorpion_and_the_Frog">Scorpion and the Frog</a>?  Well, we got stung&#8230;</p>
<p>Lost33 did not make contact with Jumper last night.  In fact, it seems he spent the night changing his QQ number and deleting all info from <a href="http://hi.baidu.com/damnfootman">his blog</a>. The website is now completely empty, except for a change to his personal data.  Lost33 changed his current residence from Sichuan to Beijing:</p>
<p style="text-align: center;"><a rel="attachment wp-att-1638" href="http://www.thedarkvisitor.com/2009/04/caspernet-gets-punked/capsernetpunk1-2/"><img class="aligncenter size-medium wp-image-1638" title="CapserNetPunk1" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/04/CapserNetPunk1-300x205.jpg" alt="CapserNetPunk1" width="300" height="205" /></a></p>
<p>We retained a full copy of the previous night&#8217;s conversation with Lost33 but have decided to only release two sections.  The first section is being reprinted to prove the connection between Lost33 and the losttemp33 hotmail account:</p>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; color: #008242; text-align: center;">jumper_tdv 2009-04-02 23:57:28</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; text-align: center;">Do you have the email address <a href="mailto:losttemp33@hotmail.com">losttemp33@hotmail.com</a>?</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; color: #0000ff; text-align: center;"><span style="font-family: STHeiti Light; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal;">周小屁</span> 2009-04-02 23:57:30</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: 'Lucida Grande'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; text-align: center;">Sorry for my english too</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; color: #0000ff; text-align: center;"><span style="font-family: STHeiti Light; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal;">周小屁</span> 2009-04-02 23:58:11</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: 'Lucida Grande'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; text-align: center;">yes ,but i never use it.</div>
<p>The second section is being released&#8230;well, to be honest, just because I think it is funny. I can practically see Jumper&#8217;s expression as he types, &#8220;Yes, really.&#8221;</p>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; color: #008242; text-align: center;">jumper_tdv 2009-04-03 00:05:29</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; text-align: center;">The problem is that your lost33 email is used to register DNS names for hackers</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; color: #0000ff; text-align: center;"><span style="font-family: STHeiti Light; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal;">周小屁</span> 2009-04-03 00:05:43</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: 'Lucida Grande'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; text-align: center;"><span style="font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 12px; line-height: normal; font-size-adjust: none; font-stretch: normal;"> </span> really?</div>
<p style="text-align: center;">
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; color: #008242; text-align: center;">jumper_tdv 2009-04-03 00:05:51</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; text-align: center;">Yes, really</div>
<p>Are we surprised, shocked, or angry over Lost33 punking us&#8230;</p>
<p>-Hey, it&#8217;s just his nature.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/04/caspernet-gets-punked/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Children of a lesser malware</title>
		<link>http://www.thedarkvisitor.com/2009/04/children-of-a-lesser-malware/</link>
		<comments>http://www.thedarkvisitor.com/2009/04/children-of-a-lesser-malware/#comments</comments>
		<pubDate>Fri, 03 Apr 2009 20:51:20 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Hacker Hunting]]></category>
		<category><![CDATA[Hackers Talking]]></category>
		<category><![CDATA[India Attacks]]></category>
		<category><![CDATA[CasperNet]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1494</guid>
		<description><![CDATA[UPDATE: Added further comment by Nart Villeneuve at the bottom (Great guy!) Yep, that would be us&#8230; According to researchers at IWM, Lost33&#8242;s information was only included in the GhostNet report because his malware was found on two computers associated with the Dalai Lama&#8217;s network.  However, it was different from the remote control access tool [...]]]></description>
			<content:encoded><![CDATA[<p><strong>UPDATE:</strong> Added further comment by Nart Villeneuve at the bottom (Great guy!)</p>
<p>Yep, that would be us&#8230;</p>
<p>According to researchers at IWM, Lost33&#8242;s information was only included in the GhostNet report because his malware was found on two computers associated with the Dalai Lama&#8217;s network.  However, it was different from the remote control access tool<span class="body"> gh0stRAT that made up the backbone of GhostNet.</span></p>
<p><span class="body">From the <a href="http://www.securityfocus.com/brief/940">report</a> by Robert Lemos at <em>Security Focus</em>:</span></p>
<blockquote><p>However, the e-mail address was found only on two of the computers analyzed for the investigation, said Nart Villeneuve, a researcher at the CitizenLab and one of the authors of the GhostNet report. Both computers had been infected with a second piece of malware, separate from the gh0st remote access tool (gh0stRAT) that formed the backbone of the surveillance network, he said.</p>
<p>&#8220;That is a valid piece of malware but it is not the one related to the malware that connected to the admin interface for the gh0stRAT,&#8221; Villeneuve said.</p></blockquote>
<p>So it looks like we are now investigating a massive network intrusion of two computers.  One, two.  We will call our project CasperNet.</p>
<p style="text-align: center;"><a href="http://doopy1956.com/graphics/casper.jpg"><img class="aligncenter" src="http://doopy1956.com/graphics/casper.jpg" alt="" width="350" height="271" /></a></p>
<p>Spoke with Jumper earlier today and he still feels it is worthwhile to pursue.  So, he will continue his conversation with Lost33 tonight.</p>
<p><strong>UPDATE:</strong> Wanted to add this comment left by <a href="http://www.nartv.org/">Nart Villeneuve</a> because I thought it was super nice of him.  I botched up his report but he was still kind enough to stop by and offer these words of encouragement:</p>
<p>&#8220;I wouldn’t say lesser at all — just different. The CasperNet (www.lookbytheway.net/www.macfeeresponse.org) which sounds way better than what I’ve been calling it (CGI after their use of CGI scripts) was the one that was found to be retrieving a sensitive document related to the Dalai Lama’s negotiating position. In addition to being found at the OHHDL it was also found at the Tibetan NGO Drewla.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/04/children-of-a-lesser-malware/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

