<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Dark Visitor &#187; Taiwan</title>
	<atom:link href="http://www.thedarkvisitor.com/category/taiwan/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thedarkvisitor.com</link>
	<description></description>
	<lastBuildDate>Wed, 08 Jun 2011 03:15:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Chinese hackers: We are not mentally handicapped</title>
		<link>http://www.thedarkvisitor.com/2009/09/chinese-hackers-we-are-not-mentally-handicapped/</link>
		<comments>http://www.thedarkvisitor.com/2009/09/chinese-hackers-we-are-not-mentally-handicapped/#comments</comments>
		<pubDate>Wed, 09 Sep 2009 09:10:04 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Hacker Organization]]></category>
		<category><![CDATA[Nationalism]]></category>
		<category><![CDATA[Taiwan]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=2057</guid>
		<description><![CDATA[The article from Alibaba reports that the website was down on Tuesday but as of a few moments ago when I checked, it was back up and running: The post-90 generation teens that run 2009.90admin. com, wrote on their website, &#8220;We are not Internet attackers, we are just a group of computer fans; we are [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-2058" href="http://www.thedarkvisitor.com/2009/09/chinese-hackers-we-are-not-mentally-handicapped/90admin/"><img class="aligncenter size-medium wp-image-2058" title="90admin" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/09/90admin-300x130.jpg" alt="90admin" width="463" height="178" /></a></p>
<p>The <a href="http://news.alibaba.com/article/detail/technology/100168523-1-teen-hackers-vow-prove-patriotism.html">article</a> from <em>Alibaba</em> reports that the website was down on Tuesday but as of a few moments ago when I checked, it was back up and running:</p>
<blockquote><p>The post-90 generation teens that run 2009.90admin. com, wrote on their website, &#8220;We are not Internet attackers, we are just a group of computer fans; we are not mentally handicapped kids, we are the real patriotic youth. We&#8217;ll target anti-China websites across the nation and send it as a birthday gift to our country.&#8221;</p>
<p>The site was the subject of hot debate on the Chinese version of twitter but could not be viewed Tuesday. Efforts to reach the site&#8217;s operators were unsuccessful.</p>
<p>The 500-word statement appeared over a red and black background decorated with a flying national flag.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/09/chinese-hackers-we-are-not-mentally-handicapped/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
		<item>
		<title>And now the Taiwanese film festival</title>
		<link>http://www.thedarkvisitor.com/2009/09/and-now-the-taiwanese-film-festival/</link>
		<comments>http://www.thedarkvisitor.com/2009/09/and-now-the-taiwanese-film-festival/#comments</comments>
		<pubDate>Tue, 08 Sep 2009 11:44:48 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Censorship]]></category>
		<category><![CDATA[Nationalism]]></category>
		<category><![CDATA[Taiwan]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=2055</guid>
		<description><![CDATA[Taiwanese organizers in Kaohsiung, Taiwan&#8217;s second largest city, plan to show the controversial film, &#8220;Ten Conditions of Love&#8221; next month, sparking outrage in the Chinese hacker community once again.  Given the fact that it is Taiwan, it is doubly outrageous.  The film&#8217;s showing in Melbourne last month sent Chinese hackers on a mini-rampage, see here, here, [...]]]></description>
			<content:encoded><![CDATA[<p>Taiwanese organizers in Kaohsiung, Taiwan&#8217;s second largest city, plan to show the controversial film, &#8220;Ten Conditions of Love&#8221; next month, sparking outrage in the Chinese hacker community once again.  Given the fact that it is Taiwan, it is doubly outrageous. </p>
<p>The film&#8217;s showing in Melbourne last month sent Chinese hackers on a mini-rampage, see <a href="http://www.thedarkvisitor.com/2009/07/chinese-hackers-unfamiliar-with-traditional-method-of-film-review/">here</a>, <a href="http://www.thedarkvisitor.com/2009/07/chinese-hacker-now-just-phoning-it-in/">here</a>, <a href="http://www.thedarkvisitor.com/2009/08/sold-out-chinese-hackers-hold-all-the-tickets/">here</a> and <a href="http://www.thedarkvisitor.com/2009/08/swing-and-a-miss/">here</a>.</p>
<p>Now all eyes turn to the <a href="http://politics.inquirer.net/view.php?db=1&amp;article=20090908-224235">Taiwanese film festival</a>:</p>
<blockquote><p>Anonymous hackers have attacked a Taiwan film festival over plans to screen a documentary on the US-based leader of China&#8217;s predominantly Muslim Uighur minority, festival organizers said Tuesday.</p>
<p>A message, posted on a blog run by one of the organizers of the Kaohsiung Film Festival, blamed Rebiya Kadeer for recent bloody unrest in northwest China&#8217;s Xinjiang region, which is home to the Turkic-speaking Uighurs.</p>
<p>&#8220;I don&#8217;t know if you heard about the violence (in Xinjiang) and if you know how many people were left homeless. It is all because of that woman,&#8221; said the message, referring to Kadeer.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/09/and-now-the-taiwanese-film-festival/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Chinese hacker defaces Taiwan DPP website</title>
		<link>http://www.thedarkvisitor.com/2008/12/chinese-hacker-defaces-taiwan-dpp-website/</link>
		<comments>http://www.thedarkvisitor.com/2008/12/chinese-hacker-defaces-taiwan-dpp-website/#comments</comments>
		<pubDate>Tue, 23 Dec 2008 12:05:51 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Nationalism]]></category>
		<category><![CDATA[Taiwan]]></category>
		<category><![CDATA[chinese hacker]]></category>
		<category><![CDATA[DPP]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=862</guid>
		<description><![CDATA[A Chinese hacker (elder brother Ma) has defaced the website of the Taiwanese Democratic Progressive Party with the 5-star flag of mainland China to protest the release of Chen Shuibian by a Taiwanese court.  Chen is on trial for embezzlement.]]></description>
			<content:encoded><![CDATA[<div class="wp-caption aligncenter" style="width: 394px"><img title="Defaced DPP website" src="http://webpic.chinareviewnews.com/upload/200812/23/100837366.JPG" alt="Defaced DPP website" width="384" height="342" /><p class="wp-caption-text">Defaced DPP website</p></div>
<p>A Chinese hacker (elder brother Ma) has <a href="http://n.yam.com/rti/politics/200812/20081223935332.html">defaced the website of the Taiwanese Democratic Progressive Party</a> with the <a href="http://n.yam.com/rti/politics/200812/20081223935332.html">5-star flag of mainland China</a> to protest the release of <a href="http://www.etaiwannews.com/etn/news_content.php?id=816931&amp;lang=eng_news">Chen Shuibian by a Taiwanese court</a>.  Chen is on trial for <span id="fullstory" class="fullstory">embezzlement. </span></p>
<p><span class="fullstory"><br />
</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/12/chinese-hacker-defaces-taiwan-dpp-website/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Taiwan breaks up hacking ring</title>
		<link>http://www.thedarkvisitor.com/2008/08/taiwan-breaks-up-hacking-ring/</link>
		<comments>http://www.thedarkvisitor.com/2008/08/taiwan-breaks-up-hacking-ring/#comments</comments>
		<pubDate>Wed, 27 Aug 2008 13:28:35 +0000</pubDate>
		<dc:creator>jumper</dc:creator>
				<category><![CDATA[Taiwan]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=453</guid>
		<description><![CDATA[This AFP/Google News article is very short on detail. Perhaps some of our readers in Taiwan can comment on the local media reporting. From the article: Police in Taiwan have arrested six people suspected of stealing personal data from state firms, including information about the island&#8217;s current and former presidents, officials said Wednesday.]]></description>
			<content:encoded><![CDATA[<p>This <a href="http://afp.google.com/article/ALeqM5jK6252i6eF2Q4jVZG8puXp8g3mKA">AFP/Google News article</a> is very short on detail.  Perhaps some of our readers in Taiwan can comment on the local media reporting.  From the article:</p>
<blockquote><p>Police in Taiwan have arrested six people suspected of stealing personal data from state firms, including information about the island&#8217;s current and former presidents, officials said Wednesday.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/08/taiwan-breaks-up-hacking-ring/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Bruce Schneier:  The Truth About Chinese Hackers</title>
		<link>http://www.thedarkvisitor.com/2008/07/bruce-schneier-the-truth-about-chinese-hackers/</link>
		<comments>http://www.thedarkvisitor.com/2008/07/bruce-schneier-the-truth-about-chinese-hackers/#comments</comments>
		<pubDate>Mon, 14 Jul 2008 23:36:32 +0000</pubDate>
		<dc:creator>jumper</dc:creator>
				<category><![CDATA[Hacker History]]></category>
		<category><![CDATA[Hacker Organization]]></category>
		<category><![CDATA[Nationalism]]></category>
		<category><![CDATA[Taiwan]]></category>
		<category><![CDATA[Tibet]]></category>
		<category><![CDATA[US attacks]]></category>
		<category><![CDATA[bruce schneier]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[not necessarily the truth]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=653</guid>
		<description><![CDATA[Bruce Schneier is a well-known security and cryptography researcher.  He has a popular blog where he posted his recent article detailing &#8220;The Truth About Chinese Hackers&#8221;, which was written for Discovery Channel. This article is not particularly insightful and sort of lumps all of the Chinese hackers into a single group of young, male patriotic [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/07/bruce_schneier_blog_photo.jpg"><img class="alignnone size-medium wp-image-654" title="bruce_schneier_blog_photo" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/07/bruce_schneier_blog_photo.jpg" alt="Bruce Schneier" width="150" height="225" /></a></p>
<p>Bruce Schneier is a well-known security and cryptography researcher.  He has a popular <a href="http://www.schneier.com">blog</a> where he <a href="http://www.schneier.com/blog/archives/2008/07/chinese_cyber_a.html">posted</a> his recent article detailing <a href="http://dsc.discovery.com/technology/my-take/computer-hackers-china.html">&#8220;The Truth About Chinese Hackers&#8221;</a>, which was written for Discovery Channel.</p>
<p>This article is not particularly insightful and sort of lumps all of the Chinese hackers into a single group of young, male patriotic kids doing it for the babes and limos.</p>
<blockquote><p>These hacker groups seem not to be working for the Chinese government. They don&#8217;t seem to be coordinated by the Chinese military.</p></blockquote>
<blockquote><p>The hackers are in this for two reasons: fame and glory, and an attempt to make a living.</p></blockquote>
<p>This is very short sighted.  We should be honest here, neither Bruce Schneier nor Heike and I know with absolute certainty what Chinese hackers are doing, who is coordinating them and who might be paying them.  Maybe the article shouldn&#8217;t be titled &#8220;The Truth About Chinese Hacker&#8221; because Bruce doesn&#8217;t know what the truth is (Heike would have said that he couldn&#8217;t handle the truth either, but that&#8217;s not my style).</p>
<p>I think a lot of people assume that activity attributed to the PRC is simply based on the IP address.  After studying spear phishing attacks, custom malware attacks and the types of data that have been exfiltrated from various NGO targets it seems likely that some entity is coordinating the collection and exploitation of this information.  In my humble opinion, there may be more to this than WoW passwords.</p>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/07/bruce-schneier-the-truth-about-chinese-hackers/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>Vampires, Chinese hackers, Treachery and Smoking Hacker Babe&#8230;Let&#8217;s face it, this post has it all!</title>
		<link>http://www.thedarkvisitor.com/2008/06/vampires-chinese-hackers-treachery-and-smoking-hacker-babelets-face-it-this-post-has-it-all/</link>
		<comments>http://www.thedarkvisitor.com/2008/06/vampires-chinese-hackers-treachery-and-smoking-hacker-babelets-face-it-this-post-has-it-all/#comments</comments>
		<pubDate>Sat, 21 Jun 2008 16:32:40 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Hacker Hunting]]></category>
		<category><![CDATA[Hacker Organization]]></category>
		<category><![CDATA[Leaders]]></category>
		<category><![CDATA[Taiwan]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[Jiajia]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Vampire]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=617</guid>
		<description><![CDATA[New Chinese hacker program making the rounds called Chinese Vampire v2.2.1 (starving anti-virus) billed as a trojan downloader tool, ARP attack, QQ tail&#8230;etc. The screenshot below shows the downloader interface: From what I have read about the tool, it is very effective. So effective in fact, that another Chinese hacker calling himself Sadness, from the [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/06/vampire.jpg"><img class="alignnone size-full wp-image-616 aligncenter" title="vampire" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/06/vampire.jpg" alt="" width="382" height="295" /></a></p>
<p>New Chinese hacker program making the rounds called <em>Chinese Vampire v2.2.1</em> (starving anti-virus) billed as a trojan downloader tool, ARP attack, QQ tail&#8230;etc.  The screenshot below shows the downloader interface:</p>
<p style="text-align: center;"><img class="alignnone size-medium wp-image-618 aligncenter" title="vampire2" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/06/vampire2-300x298.jpg" alt="" width="300" height="298" /></p>
<p>From what I have read about the tool, it is very effective.  So effective in fact, that another Chinese hacker calling himself Sadness, from the Black Wolf hacker group, stole it.  Yes, he did. Look at the trackback URLs associated with this <a href="http://64.233.167.104/search?q=cache:W0otg_l2CQcJ:bbs.hksxs.com/read.php%3Ftid%3D8025+%E9%BB%91%E7%8B%BC%E5%9F%BA%E5%9C%B0+%E4%B8%AD%E5%8D%8E%E5%90%B8%E8%A1%80%E9%AC%BC&amp;hl=en&amp;ct=clnk&amp;cd=1&amp;gl=us">screenshot </a>compared to the one above (circled in red).  Notice that our thief has changed it to the Black Wolf website instead of the www.9u9u9.cn address.</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/06/vampire3.jpg"><img class="alignnone size-medium wp-image-619 aligncenter" title="vampire3" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/06/vampire3-300x300.jpg" alt="" width="300" height="300" /></a></p>
<p>The true author of Vampire v2.2.1 runs the <a href="http://hi.baidu.com/sksgod">website</a> pictured below and calls himself SKSgod&#8230;sigh.  He was really unhappy with the theft of his property and posted a pretty nasty response to Sadness.  Yeah, hacker on hacker violence doesn&#8217;t concern me in the least.</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/06/vampire4.jpg"><img class="alignnone size-medium wp-image-620 aligncenter" title="vampire4" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/06/vampire4-300x221.jpg" alt="" width="300" height="221" /></a></p>
<p>Now the truly exciting part of this post, there is also a female hacker involved in the marketing of this fine product named Jiajia (佳佳).   Hmmm, you say&#8230;that name sounds familiar?  Well it should!  It is the same name as one of the members of the <a href="http://www.thedarkvisitor.com/2008/02/the-six-golden-flowerschinas-female-hackers/">Six Golden Flowers</a>.</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/06/jiajia1.jpg"><img class="alignnone size-full wp-image-622 aligncenter" title="jiajia1" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/06/jiajia1.jpg" alt="" width="215" height="296" /></a></p>
<p style="text-align: center;">Jiajia of the Six Golden Flowers</p>
<p style="text-align: left;">Is the same Jiajia?  I don&#8217;t think it is but not sure.  On <a href="http://hi.baidu.com/hackjiajia">her blog</a>, this Jiajia claims that due to the controversy over the stolen program, there are only two legitimate sites to download Vampire v2.2.1.  One is her site and the other at SKSgod&#8217;s.  Yes, there was a picture associated with Jiajia&#8217;s website:</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/06/jiajia2.jpg"><img class="alignnone size-full wp-image-623 aligncenter" title="jiajia2" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/06/jiajia2.jpg" alt="" width="273" height="303" /></a></p>
<p>Now this girl certainly doesn&#8217;t look like Jiajia number one and she appears to be a bit younger.  Also, the characters next to the picture said &#8220;Sleepless Night.&#8221;  Hell, this could be the picture off an album cover (and yes I did try to see if I could find a record called Sleepless Night) for all I know.  She may just be the Brittany Spears of China.  Thought I would include it anyway&#8230;sue me.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/06/vampires-chinese-hackers-treachery-and-smoking-hacker-babelets-face-it-this-post-has-it-all/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Taiwan&#8217;s Nautica Retailer Pwn3d</title>
		<link>http://www.thedarkvisitor.com/2008/02/taiwans-nautica-retailer-pwn3d/</link>
		<comments>http://www.thedarkvisitor.com/2008/02/taiwans-nautica-retailer-pwn3d/#comments</comments>
		<pubDate>Thu, 21 Feb 2008 02:16:34 +0000</pubDate>
		<dc:creator>jumper</dc:creator>
				<category><![CDATA[Hacking for money]]></category>
		<category><![CDATA[Taiwan]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=349</guid>
		<description><![CDATA[The Nautica clothing site in the Republic of China has been compromised by a malicious iframe that redirects to very well-known rogue anti-spyware pushers often associated with the Russian Business Network.  If the site is searched on Google, the index listing indicates that &#8220;This site may harm your computer&#8221;.         So naturally, the first thing I [...]]]></description>
			<content:encoded><![CDATA[<p><!--noadsense-->The Nautica clothing site in the Republic of China has been compromised by a malicious iframe that redirects to very well-known rogue anti-spyware pushers often associated with the <a href="http://rbnexploit.blogspot.com" title="Russian Business Network">Russian Business Network</a><a href="http://rbnexploit.blogspot.com" title="Russian Business Network"></a>.  If the site is searched on Google, the index listing indicates that &#8220;This site may harm your computer&#8221;.<br />
<blockquote class="webkit-indent-blockquote" style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-width: initial; border-color: initial; border-style: none; padding: 0px"> <img src="http://www.thedarkvisitor.com/wp-content/uploads/2008/02/naut_tw.png" alt="Google index of Nautica TW" />      </p></blockquote>
<p>So naturally, the first thing I do is check it out.  <br />
<blockquote class="webkit-indent-blockquote" style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-width: initial; border-color: initial; border-style: none; padding: 0px"> <img src="http://www.thedarkvisitor.com/wp-content/uploads/2008/02/picture-5.thumbnail.png" alt="nautica_taiwan" />      </p></blockquote>
<p>I was a little bit disappointed that all I found was an iframe redirect to meoryprof.info which 302&#8242;s to spywaresafe.net, which refused my connection.   Initially I thought it was because I was using wget so I passed a valid looking IE user-agent string to it and was still refused.  Google&#8217;s cache only shows the text &#8220;sl0n&#8221; on the site.  Not very effective malware, I guess. Most of these fake anti-spyware programs don&#8217;t use packers, debugger detection or any anti-RE techniques.  I have about 40 or so different versions of this type of malware.  </p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/02/taiwans-nautica-retailer-pwn3d/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

