<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Dark Visitor &#187; UK Attacks</title>
	<atom:link href="http://www.thedarkvisitor.com/category/uk-attacks/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thedarkvisitor.com</link>
	<description></description>
	<lastBuildDate>Wed, 08 Jun 2011 03:15:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>PRC Gov Responses to Hacking Allegations &#8211; Timeline</title>
		<link>http://www.thedarkvisitor.com/2010/01/prc-gov-responses-to-hacking-allegations-timeline/</link>
		<comments>http://www.thedarkvisitor.com/2010/01/prc-gov-responses-to-hacking-allegations-timeline/#comments</comments>
		<pubDate>Thu, 21 Jan 2010 03:58:49 +0000</pubDate>
		<dc:creator>jumper</dc:creator>
				<category><![CDATA[China internet]]></category>
		<category><![CDATA[Other attacks]]></category>
		<category><![CDATA[UK Attacks]]></category>
		<category><![CDATA[US attacks]]></category>
		<category><![CDATA[Government]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=2117</guid>
		<description><![CDATA[All dates represent the date the article was published, not necesarily the date that the quote was made. July 26, 2004 In response to accusations that the Chinese government was involved in computer intrusions against ROK government agencies &#8220;Some media reports that the Chinese government might be behind the hacking incident are groundless&#8221; &#8211; Chinese [...]]]></description>
			<content:encoded><![CDATA[<p>All dates represent the date the article was published, not necesarily the date that the quote was made.</p>
<p><strong>July 26, 2004</strong><br />
In response to accusations that the Chinese government was involved in computer intrusions against ROK government agencies<br />
<em>&#8220;Some media reports that the Chinese government might be behind the hacking incident are groundless&#8221;</em> &#8211; Chinese Embassy in Seoul (no personal attribution)</p>
<p><strong>December 15, 2005</strong><br />
Response to SANS comments about China being involved in world wide hacking<br />
<em>&#8220;Work units and individuals are not permitted to use the Internet to be engaged in illegal activities or commit crimes,&#8230; China has laws that make tampering with or cracking a computer&#8217;s code illegal.&#8221;</em> &#8211; Qin Gang<br />
<strong></p>
<p>August 27, 2007</strong><br />
In response to a Der Spiegel article that reported intrusions into the German governemnt<br />
<em>&#8220;The Chinese government attaches great importance to the hacker attack on the German government networks,&#8221;</em> adding China would take <em>&#8220;determined&#8221;</em> and <em>&#8220;forceful&#8221;</em> measures to combat hacker activities.  &#8211; Wen Jiabao</p>
<p><strong>August 28, 2007</strong><br />
In response to the reports of Chinese attributed intrusions into the government of Germany<br />
<em>&#8220;The Chinese government has always opposed and prohibited any criminal activity that breaks down computer networks, including hacker attacks,&#8230; China has clear rules and regulations on this.&#8221;</em> &#8211; Jiang Yu</p>
<p><strong>September 4, 2007</strong><br />
In a public response to the FT article that suggested PRC government involvement in a Pentagon intrusion<br />
<em>&#8220;The Chinese government has always opposed any Internet-wrecking crime, including hacking, and cracked down on it according to the law&#8221;</em> &#8211; An Lu (editor)</p>
<p><strong>September 10, 2007</strong><br />
Response to reports about intrusions into the French government for which the French plainly stated that they have no evidence to indicate PRC gov involvement.<br />
<em>&#8220;Saying that the Chinese military has made cyber-attacks on the networks of foreign governments is groundless and irresponsible and are a result of ulterior motives&#8221;</em> &#8211; Jiang Yu</p>
<p><strong>April 9, 2008</strong><br />
In response to Business Week&#8217;s e-Spionage article<br />
<em>&#8220;The Chinese Government always opposes and forbids any cyber crimes including &#8220;hacking&#8221; that undermine the security of computer networks. Chinese laws and regulations are explicit in this regard.&#8221;</em> &#8211; Wang Baodong</p>
<p><strong>April 1, 2009</strong><br />
In response to Ghostnet report<br />
<em>&#8220;There is a ghost called the Cold War and a virus called the Theory of China&#8217;s Threat overseas,&#8230; Some people, possessed by this ghost and infected with this virus, &#8216;fall ill&#8217; from time to time. Their attempts at using rumors to disgrace China will never succeed&#8230;  It is the ghost and the virus that should be ferreted out&#8221; </em>- Qin Gang</p>
<p><strong>May 15, 2009</strong><br />
Response to accusations of Chinese espionage in PACOM.<br />
<em>&#8220;We urge the United States to abandon Cold War mentality, stop its groundless accusations against China and do more to help build mutual trust between the United States and China and the friendship between the two peoples,&#8221; &#8211; Ma Zhaoxu<br />
&#8220;The intrusion doesn&#8217;t exist at all&#8221;</em> &#8211; Jiang Yu</p>
<p><strong>Jun 12, 2008</strong><br />
In response to reports of Chinese hacking into computers in the offices of Rep. Frank Wolf and Rep. Chris Smith.<br />
<em>&#8220;Is there any evidence? &#8230; Do we have such advanced technology? Even I don&#8217;t believe it,&#8230; I&#8217;d like to urge some people in the U.S. not to be paranoid,&#8230; They should do more to contribute to mutual understanding, trust and friendship between the U.S. and China.&#8221;</em> &#8211; Qin Gang</p>
<p><strong>January 19, 2010</strong><br />
In response to Indian allegations of Chinese hacking (following the Google intrusion)<br />
&#8220;I can say that these accusations are groundless&#8230; The Chinese government is firmly against hacking activities and will deal with relevant cases in accordance with the law&#8221; &#8211; Ma Zhaoxu</p>
<p><strong>January 22, 2010</strong><br />
In response to US Sec of State Hillary Clinton&#8217;s remarks about Internet Freedom and the Google intrusion<br />
<em>&#8220;We urge the United States to respect the facts and cease using so-called Internet freedom to make groundless accusations against China&#8221;</em> &#8211; Ma Zhaoxu<br />
<em>&#8220;China resolutely opposes Clinton&#8217;s remarks and it is not true that the country restricts online freedom&#8230;&#8221;</em> &#8211; Ma Zhaoxu</p>
<p><strong><a href="http://www.nytimes.com/2010/01/26/world/asia/26google.html?partner=rssnyt&#038;emc=rss">January 25, 2010</a></strong><br />
In response to US Sec of State Clinton&#8217;s request for a transparent investigation into the Google intrusion<br />
<em>“We are resolutely against those who make a issue of things without referring to actual facts by needlessly accusing China, ignoring Chinese laws and interfering in Chinese internal politics&#8221;</em> &#8211; unnamed spokesperson for the State Council Information Office</p>
<p><em>“As the global landscape is undergoing profound irreversible shifts, the calculated free-Internet scheme is just one step of a U.S. tactic to preserve its hegemonic domination”</em> &#8211; Yan Xuetong </p>
<p><strong><a href="http://news.yahoo.com/s/afp/20100125/wl_asia_afp/chinausitinternetgoogle6thleadwrap">January 25, 2010</a></strong><br />
Response to Google intrusion<br />
<em>The &#8220;accusation that the Chinese government participated in (any) cyberattack, either in an explicit or inexplicit way, is groundless and aims to denigrate China&#8230; We are firmly opposed to that&#8221; &#8211; unnamed spokesman for the Ministry of Industry and Information Technology to Xinhua </p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2010/01/prc-gov-responses-to-hacking-allegations-timeline/feed/</wfw:commentRss>
		<slash:comments>26</slash:comments>
		</item>
		<item>
		<title>Chinese hacker blooper&#8230;but success!</title>
		<link>http://www.thedarkvisitor.com/2009/01/chinese-hacker-blooperbut-success/</link>
		<comments>http://www.thedarkvisitor.com/2009/01/chinese-hacker-blooperbut-success/#comments</comments>
		<pubDate>Fri, 30 Jan 2009 04:31:17 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[UK Attacks]]></category>
		<category><![CDATA[US attacks]]></category>
		<category><![CDATA[New York University]]></category>
		<category><![CDATA[SQL]]></category>
		<category><![CDATA[York College]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1192</guid>
		<description><![CDATA[There isn&#8217;t a day that goes by that I don&#8217;t thank karma for Jumper.  He was blessed with the gift of not making people feel stupid for asking really dumb questions. Me: It really hurts when I touch the light socket, what should I do? Jumper: Hey, great question! Stop doing that. He is good [...]]]></description>
			<content:encoded><![CDATA[<p>There isn&#8217;t a day that goes by that I don&#8217;t thank karma for Jumper.  He was blessed with the gift of not making people feel stupid for asking really dumb questions.</p>
<p>Me: It really hurts when I touch the light socket, what should I do?</p>
<p>Jumper: Hey, great question! Stop doing that.</p>
<p>He is good to me that way.</p>
<p>Over at 7747.net, the New Year holiday has been a bit hectic for one of the boys.  He has taken over the job of website moderator and wants to keep the conversation lively.  Not a slacker by any means, he has been using the holiday season to sharpen his skills at manual <a href="http://www.7747.net/Article/200901/31542.html">SQL injection</a>.  Our guru has posted his SQL injection attack on New York University and wants a little feedback/review of his methodology.</p>
<p><strong>Problem:</strong> New York University is in the US.</p>
<p><strong>Blooper:</strong> Our pilot drifts slightly east of target and hits York College in the UK.  Hey, we have all been there.</p>
<p>I could only tell that this was an SQL injection attempt and that he wanted to go after NYU and missed; then other stuff happened.  What, I had no idea.  So, I sent a note to Jumper pleading/begging for guidance&#8230;he was good enough not to laugh.</p>
<p>I will now turn you over to the smart guy on this site:</p>
<p><strong>Jumper:</strong> That appears to be the wrong target indeed. It seems like he was able to obtain a username and password and that he used manual techniques to do this rather than HDSI or NBSI to automate it.  This PHP/MYSQL combination is a popular target for SQL injection and remote file includes (RFI).  Javaphile wrote a paper on blind SQL injection by the way.</p>
<p>Oh yeah &#8211; SQL Injection.  You probably know a little about database queries and boolean logic already.  SQL injection is basically where a hacker is able to escape the query structure and add additional queries such as username/password.</p>
<div>In the most classic example, one can inject &#8216;or 1=1&#8211; into the username field of a web form and authenticate as the first user in the users table.  The &#8216;or 1=1&#8211; bit forces the query to evaluate to true every time instead of actually comparing the input with a username in the table.</div>
<div></div>
<p></p>
<div><strong>UPDATE</strong>: For those of you concerned, an attempt has been made to contact York College an inform them of the possible compromise.</div>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/01/chinese-hacker-blooperbut-success/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chinese hackers targeting French Embassy websites around the world</title>
		<link>http://www.thedarkvisitor.com/2008/12/chinese-hackers-targeting-french-embassy-websites-around-the-world/</link>
		<comments>http://www.thedarkvisitor.com/2008/12/chinese-hackers-targeting-french-embassy-websites-around-the-world/#comments</comments>
		<pubDate>Fri, 12 Dec 2008 00:24:38 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Hacker Organization]]></category>
		<category><![CDATA[Nationalism]]></category>
		<category><![CDATA[Other attacks]]></category>
		<category><![CDATA[UK Attacks]]></category>
		<category><![CDATA[US attacks]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[Dalai Lama]]></category>
		<category><![CDATA[Embassy]]></category>
		<category><![CDATA[France]]></category>
		<category><![CDATA[Sarkozy]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=811</guid>
		<description><![CDATA[Chinese hackers are targeting French Embassy websites all around the world to protest President Nicolas Sarkozy&#8217;s visit with the Dalai Lama. According to hack4.com, featured in CNN documentary on Chinese hackers, the following French Embassy websites were successfully defaced: 法驻美国大使馆:http://www.ambafrance-us.org/ 法驻英国大使馆:http://www.ambafrance-uk.org/ 法驻中国大使馆:http://www.ambafrance-cn.org/（最新消息，已经恢复正常） (Repaired) 法驻加拿大使馆:http://www.ambafrance-ca.org/ Visiting all of the above websites shows that either they were [...]]]></description>
			<content:encoded><![CDATA[<p>Chinese hackers are targeting French Embassy websites all around the world to protest <a href="http://www.abc.net.au/news/stories/2008/12/10/2442066.htm?section=justin">President Nicolas Sarkozy&#8217;s visit with the Dalai Lama</a>.</p>
<p>According to hack4.com, <a href="http://www.thedarkvisitor.com/2008/03/chinese-hacker-xiao-chens-organization-revealed/">featured in CNN documentary on Chinese hackers</a>, the following <a href="http://www.hack4.com/news/17935.html">French Embassy websites were successfully defaced</a>:</p>
<p>法驻美国大使馆:http://www.ambafrance-us.org/<br />
法驻英国大使馆:http://www.ambafrance-uk.org/<br />
法驻<span class="UBBWordLink">中国</span>大使馆:http://www.ambafrance-cn.org/（最新消息，已经恢复正常） (Repaired)<br />
法驻加拿大使馆:http://www.ambafrance-ca.org/</p>
<p>Visiting all of the above websites shows that either they were not defaced or have been repaired since the attack. Hack4.com points out that the following websites have not been hit, suggesting they are future targets:</p>
<p>法驻日本大使馆:http://www.ambafrance-jp.org/<br />
法驻冰岛大使馆:http://www.ambafrance-is.org/</p>
<p><span style="text-decoration: line-through;">Hack4.com&#8217;s gives this screenshot of the reported hacked website(s)</span> (Deleted):</p>
<p><strong>UPDATE</strong>: Better screenshots of the <a href="http://www.7747.net/Article/200812/30852.html">defaced French Embassy websites</a> from 7747.net:</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/12/frenchembassy2.jpg"><img class="size-full wp-image-817 aligncenter" title="frenchembassy2" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/12/frenchembassy2.jpg" alt="frenchembassy2" width="476" height="423" /></a></p>
<p><span style="text-decoration: line-through;"><strong>(Sorry guys, just updated to WordPress 2.7 and having a few problems.   Can&#8217;t seem to get the screenshot to enlarge when you click on it.   The three defaced websites are the US, UK and Canada.)</strong></span></p>
<p><strong>UPDATE</strong>: Once again, <a href="http://www.google.com/url?sa=t&amp;source=web&amp;ct=res&amp;cd=1&amp;url=http%3A%2F%2Fwww.eastwoodzhao.com%2F&amp;ei=Nc5BSaKsDtG3twfmqP3TCA&amp;usg=AFQjCNFagWyaNm9QzKlEea4iL5BhsqaBJA&amp;sig2=H5rVYGVV-CdVMy_saIwRmA">Eastwood has set me straight</a>.  Linked the image through the Chinese hacker website and now you should be able to pull up the graphic.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/12/chinese-hackers-targeting-french-embassy-websites-around-the-world/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Chinese hackers vacuuming up security and economic secrets</title>
		<link>http://www.thedarkvisitor.com/2008/10/chinese-hackers-vacuuming-up-security-and-economic-secrets/</link>
		<comments>http://www.thedarkvisitor.com/2008/10/chinese-hackers-vacuuming-up-security-and-economic-secrets/#comments</comments>
		<pubDate>Thu, 30 Oct 2008 01:48:53 +0000</pubDate>
		<dc:creator>jumper</dc:creator>
				<category><![CDATA[UK Attacks]]></category>
		<category><![CDATA[CPNI]]></category>
		<category><![CDATA[ira winkler]]></category>
		<category><![CDATA[vacuum]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=670</guid>
		<description><![CDATA[An brief article from silicon.com discusses a warning given to UK critical businesses by the Centre for the Protection of National Infrastructure.  From the article: Internet warfare expert Ira Winkler, president of the Internet Security Advisory Group, said Chinese hackers were &#8220;vacuuming up the internet for security and economic secrets&#8221;   ]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-medium wp-image-671" title="wikipedia_vacuum_cleaner" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/10/wikipedia_vacuum_cleaner.jpg" alt="" /></p>
<p>An brief <a href="http://www.silicon.com/publicsector/0,3800010403,39330307,00.htm">article</a> from silicon.com discusses a warning given to UK critical businesses by the Centre for the Protection of National Infrastructure.  From the article:</p>
<blockquote><p>Internet warfare expert Ira Winkler, president of the Internet Security Advisory Group, said Chinese hackers were &#8220;vacuuming up the internet for security and economic secrets&#8221; </p>
<p> </p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/10/chinese-hackers-vacuuming-up-security-and-economic-secrets/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chinese hackers killed Whoopy, you bastards!</title>
		<link>http://www.thedarkvisitor.com/2008/08/chinese-hackers-killed-whoopy-you-bastards/</link>
		<comments>http://www.thedarkvisitor.com/2008/08/chinese-hackers-killed-whoopy-you-bastards/#comments</comments>
		<pubDate>Fri, 22 Aug 2008 10:51:14 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Hacking for money]]></category>
		<category><![CDATA[UK Attacks]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[Whoopy]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=436</guid>
		<description><![CDATA[I am wrong&#8230;very, very wrong. This is not funny (but it is hilarious) and I know better than posting other people&#8217;s pain. From the European WoW forum: (Click to enlarge)]]></description>
			<content:encoded><![CDATA[<p>I am wrong&#8230;very, very wrong.  This is not funny (but it is hilarious) and I know better than posting other people&#8217;s pain.  From the <a href="http://forums.wow-europe.com/thread.html;jsessionid=EDEF86F8962F520E250967B4DFC793B8.app06_01?topicId=5383699574&amp;sid=1">European WoW forum</a>: (Click to enlarge)</p>
<p><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/08/whoopy.jpg"><img class="aligncenter size-thumbnail wp-image-437" title="whoopy" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/08/whoopy.jpg" alt="" width="443" height="509" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/08/chinese-hackers-killed-whoopy-you-bastards/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Summary: Chinese cyberwarfare threat by the Heritage Foundation</title>
		<link>http://www.thedarkvisitor.com/2008/06/summary-chinese-cyberwarfare-threat-by-the-heritage-foundation/</link>
		<comments>http://www.thedarkvisitor.com/2008/06/summary-chinese-cyberwarfare-threat-by-the-heritage-foundation/#comments</comments>
		<pubDate>Thu, 26 Jun 2008 03:44:48 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Tibet]]></category>
		<category><![CDATA[UK Attacks]]></category>
		<category><![CDATA[US attacks]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[cyberwarfare]]></category>
		<category><![CDATA[PLA]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=627</guid>
		<description><![CDATA[This is a very interesting read by John J. Tkacik on Chinese cyber attacks that runs counter to many of my arguments.  The PDF document titled Trojan Dragon: China’s Cyber Threat is 12 pages but well worth checking out. Genesis of China’s Cyberwarfare In the 1990s, China’s Ministry of Public Security (MPS), which manages the country’s [...]]]></description>
			<content:encoded><![CDATA[<p>This is a very interesting read by John J. Tkacik on Chinese cyber attacks that runs counter to many of my arguments.  The PDF document titled <a href="http://www.heritage.org/Research/asiaandthepacific/upload/bg_2106.pdf"><em>Tr</em><em>ojan Dragon: China’s Cyber Threat</em></a> is 12 pages but well worth checking out.</p>
<blockquote><p>Genesis of China’s Cyberwarfare</p>
<p>In the 1990s, China’s Ministry of Public Security (MPS), which manages the country’s police services, pioneered the art of state control of cyberspace by partnering with foreign network systems firms to monitor information flows via the Internet. By 1998, according to an insider’s account of China’s Internet development, the MPS and its subordinate bureaus found that their resources for monitoring the Internet had been overwhelmed by the sheer volume of Internet traffic—which by 1998 had not yet reached 1 million users in China.</p></blockquote>
<p><a href="http://www.heritage.org/Research/asiaandthepacific/upload/bg_2106.pdf">Keep reading&#8230;</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/06/summary-chinese-cyberwarfare-threat-by-the-heritage-foundation/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Chinese hacker Xiao Chen&#8217;s Organization Revealed!</title>
		<link>http://www.thedarkvisitor.com/2008/03/chinese-hacker-xiao-chens-organization-revealed/</link>
		<comments>http://www.thedarkvisitor.com/2008/03/chinese-hacker-xiao-chens-organization-revealed/#comments</comments>
		<pubDate>Sun, 09 Mar 2008 14:49:18 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese hacker video]]></category>
		<category><![CDATA[Hacker Hunting]]></category>
		<category><![CDATA[Hacker Organization]]></category>
		<category><![CDATA[Hackers Talking]]></category>
		<category><![CDATA[UK Attacks]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[Organization]]></category>
		<category><![CDATA[Xiao Chen]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=398</guid>
		<description><![CDATA[First, a very big thank you to reader Copper, who first pointed out that there was a BIG button right over the article on Chinese hacker Xiao Chen that said&#8230;VIDEO! And, if you watch said video&#8230;it gives Xiao Chen&#8217;s webiste. Here is the 1st screenshot from the CNN video, notice the links section at the botttom that I have circled in red.  The first link is to Hacker World (hack4.com) 黑客天下 [...]]]></description>
			<content:encoded><![CDATA[<p>First, a very big thank you to reader Copper, who first pointed out that there was a BIG button right over the article on   <a HREF="http://www.cnn.com/2008/TECH/03/07/china.hackers/index.html?eref=rss_latest">Chinese hacker Xiao Chen</a> that said&#8230;VIDEO! And, if you watch said <a HREF="http://www.cnn.com/2008/TECH/03/07/china.hackers/index.html?eref=rss_latest#cnnSTCVideo">video</a>&#8230;it gives Xiao Chen&#8217;s webiste.</p>
<p>Here is the 1st screenshot from the CNN video, notice the links section at the botttom that I have circled in red.  The first link is to Hacker World (hack4.com) 黑客天下 and the second is to Hackbase.com.  It is typical for Chinese hackers to list their own website first in the links section.</p>
<p><strong>UPDATE:</strong> Sorry, I was unclear in the paragraph above, Xiao Chen only owns <br />
hack4.com.  Hackbase.com was listed just to show similarity in the websites.</p>
<p><img ALT="xiaochen11.JPG" SRC="http://www.thedarkvisitor.com/wp-content/uploads/2008/03/xiaochen11.JPG" /></p>
<p>Now look at this screen shot from <a HREF="http://www.hack4.com/index.html">hack4.com</a>. There are a couple of differences but clearly the same website:</p>
<p><img ALT="hack4.JPG" SRC="http://www.thedarkvisitor.com/wp-content/uploads/2008/03/hack4.JPG" /></p>
<p>Next image from the  CNN video gives the Chinese 黑客天下, Hacker World or hack4.com:</p>
<p><img SRC="http://www.thedarkvisitor.com/wp-content/uploads/2008/03/xiaochen2.JPG" ALT="xiaochen2.JPG" /></p>
<p>Now take a look at this graphic from CNN in the left corner of the page:</p>
<p><img ALT="xiaochen3.JPG" SRC="http://www.thedarkvisitor.com/wp-content/uploads/2008/03/xiaochen3.JPG" /></p>
<p>and this one from <a HREF="http://bbs.hack4.com/index.asp?boardid=15">hack4.com</a>&#8230;</p>
<p><img ALT="hack41.JPG" SRC="http://www.thedarkvisitor.com/wp-content/uploads/2008/03/hack41.JPG" /></p>
<p>Finally, this one from CNN and you really had to be watching for it:</p>
<p><img ALT="xiaochen4.JPG" SRC="http://www.thedarkvisitor.com/wp-content/uploads/2008/03/xiaochen4.JPG" /></p>
<p>In the CNN interview, Xiao Chen claimed to have 10,000 registered members.<br />
From the hack4.com website, they list the number of registered members as <a HREF="http://bbs.hack4.com/">9,746</a>&#8230;pretty darn close:</p>
<p><img SRC="http://www.thedarkvisitor.com/wp-content/uploads/2008/03/hack42.JPG" ALT="hack42.JPG" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/03/chinese-hacker-xiao-chens-organization-revealed/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Heikeba Update&#8230;Never hack inside China&#8230;Ever!</title>
		<link>http://www.thedarkvisitor.com/2008/01/heikeba-updatenever-hack-inside-chinaever/</link>
		<comments>http://www.thedarkvisitor.com/2008/01/heikeba-updatenever-hack-inside-chinaever/#comments</comments>
		<pubDate>Thu, 31 Jan 2008 21:23:06 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese hacker video]]></category>
		<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Hacker Organization]]></category>
		<category><![CDATA[Hackers Talking]]></category>
		<category><![CDATA[Hacking for money]]></category>
		<category><![CDATA[Leaders]]></category>
		<category><![CDATA[UK Attacks]]></category>
		<category><![CDATA[US attacks]]></category>
		<category><![CDATA[Chinese hacker organization]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[Heikeba]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=284</guid>
		<description><![CDATA[This was more than likely a message to the rest of the Red Hacker Alliance that we do not hack inside China or there will be consequences.  According to the video, it wasn&#8217;t just money that Heikeba was after but fame played a large part as well.  The downfall seems to have come when they [...]]]></description>
			<content:encoded><![CDATA[<p>This was more than likely a message to the rest of the Red Hacker Alliance that we do not hack inside China or there will be consequences.  According to the video, it wasn&#8217;t just money that Heikeba was after but fame played a large part as well.  The downfall seems to have come when they decided to break into banks inside of China and steal from Chinese citizens.  That my friends is a no-no!</p>
<p><img SRC="http://www.thedarkvisitor.com/wp-content/uploads/2008/01/updateheikeba.JPG" ALT="updateheikeba.JPG" /></p>
<p>Also, it is not nice to attach Trojans to music and picture downloads.</p>
<p><img SRC="http://www.thedarkvisitor.com/wp-content/uploads/2008/01/updateheikeba2.JPG" ALT="updateheikeba2.JPG" /></p>
<p>This is the part I&#8217;m not completely clear on and if someone who has better ears than I do can provide clarification it would be really appreciated.  The police discovered that the site was spread out across 15 cities inside of China. Here is the difficult part, they found records on the site dealing with New York, London and Paris and something about logging into the sites at the same time which seemed impossible or only slightly possible.  There is some discussion of time-zones and logging into them at the same time.</p>
<p><img ALT="updateheikeba3.JPG" SRC="http://www.thedarkvisitor.com/wp-content/uploads/2008/01/updateheikeba3.JPG" /></p>
<p>Difficult to tell if they are saying Heikeba was responsible for hacking into<br />
websites in these cities.  Hopefully, we can get a little help here.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/01/heikeba-updatenever-hack-inside-chinaever/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>SANS Institute&#8217;s Top Cyber Menaces 08</title>
		<link>http://www.thedarkvisitor.com/2008/01/sans-institutes-top-cyber-menaces-08/</link>
		<comments>http://www.thedarkvisitor.com/2008/01/sans-institutes-top-cyber-menaces-08/#comments</comments>
		<pubDate>Mon, 28 Jan 2008 18:21:14 +0000</pubDate>
		<dc:creator>jumper</dc:creator>
				<category><![CDATA[Hacker Organization]]></category>
		<category><![CDATA[UK Attacks]]></category>
		<category><![CDATA[US attacks]]></category>
		<category><![CDATA[Charlie Chen]]></category>
		<category><![CDATA[espionage]]></category>
		<category><![CDATA[pwn3d]]></category>
		<category><![CDATA[SANS]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=279</guid>
		<description><![CDATA[Of interest to Dark Visitor readers is item number three in the SANS list: Cyber Espionage Efforts By Well Resourced Organizations Looking To Extract Large Amounts Of Data &#8211; Particularly Using Targeted Phishing One of the biggest security stories of 2007 was disclosure in Congressional hearings and by senior DoD officials of massive penetration of [...]]]></description>
			<content:encoded><![CDATA[<p>Of interest to Dark Visitor readers is item number three in the <a target="_blank" href="http://www.sans.org/2008menaces/" title="SANS list">SANS list</a>:</p>
<blockquote><p><em>Cyber Espionage Efforts By Well Resourced Organizations Looking To Extract Large Amounts Of Data &#8211; Particularly Using Targeted Phishing</em></p>
<p><em>One of the biggest security stories of 2007 was disclosure in Congressional hearings and by senior DoD officials of massive penetration of federal agencies and defense contractors and theft of terabytes of data by the Chinese and other nation states. In 2008, despite intense scrutiny, these nation-state attacks will expand; more targets and increased sophistication will mean many successes for attackers. Economic espionage will be increasingly common as nation-states use cyber theft of data to gain economic advantage in multinational deals. The attack of choice involves targeted spear phishing with attachments, using well-researched social engineering methods to make the victim believe that an attachment comes from a trusted source, and using newly discovered Microsoft Office vulnerabilities and hiding techniques to circumvent virus checking. </em></p></blockquote>
<p>The open-source information we have so far about this type of well-resourced [Chinese] cyber espionage is anecdotal and positive attribution hasn&#8217;t been possible.  Our only sources are the <a href="http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details.php?uid=ji4nv9e06bju6jkrq7nndvpdc0@google.com" title="Rolls-Royce">Rolls-Royce </a>information (very detailed) and <a href="http://www.thedarkvisitor.com/?p=252" title="Charlie Chen">Charlie Chen</a>.  The information that we have from DoD sources is very limited on detail and a lot of readers are inclined to dismiss it because attribution by IP address only is pretty unreliable.  I think there is a lot more going on behind the scenes than IP geolocation.  Consider the information that has been exfiltrated.  Consider the methods that were used to harvest email addresses to use for social engineering.  Consider the tools that were used and then you have a much better picture.  Let&#8217;s face it, script kiddies aren&#8217;t interested in Naval Order of Battle in the Taiwan Straight.  Also, script kiddies aren&#8217;t after specific information from the world&#8217;s largest research based pharmaceutical company. <strong>Update:</strong>  I neglected to reference another attack with some good details:  <a href="http://isc.sans.org/diary.html?storyid=3400" title="SANS ISC">SANS ISC</a> covered the spear-phishing attack on 30 members of Fa1un G0ng which is banned in the PRC.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/01/sans-institutes-top-cyber-menaces-08/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mysterious Chinese Hacker Slide Show</title>
		<link>http://www.thedarkvisitor.com/2008/01/mysterious-chinese-hacker-slide-show/</link>
		<comments>http://www.thedarkvisitor.com/2008/01/mysterious-chinese-hacker-slide-show/#comments</comments>
		<pubDate>Mon, 21 Jan 2008 00:38:36 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Hacker Organization]]></category>
		<category><![CDATA[UK Attacks]]></category>
		<category><![CDATA[US attacks]]></category>
		<category><![CDATA[Chinese Hacker Government Affiliation]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[Hacker Slide Show]]></category>
		<category><![CDATA[How hackers invade]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=252</guid>
		<description><![CDATA[UPDATE: Jumper adds the following on this post: I doubt that the mystery poster is Charlie Chung-Ping Chen. Charlie Chung-Ping Chen researches processors. It is certainly possible that he made the transition during his four year absence from the web but I think it is a stretch. At any rate, he hasn’t responded to Gordon. [...]]]></description>
			<content:encoded><![CDATA[<p>UPDATE: Jumper adds the following on this post:</p>
<blockquote><p>I doubt that the mystery poster is Charlie Chung-Ping Chen. Charlie Chung-Ping Chen researches processors. It is certainly possible that he made the transition during his four year absence from the web but I think it is a stretch. At any rate, he hasn’t responded to Gordon. I assume Gordon contacted him by his university email and his status at the university is listed as “leave of absence”.</p>
<p>I tried to find out more about the powerpoint and didn’t have much luck. There isn’t any intro slide and the person who posted the presentation hasn’t posted anything else. It is very amusing that the poster’s handle is Deep Throat.</p></blockquote>
<p ALIGN="center">  <img ALT="taiwanhackerslides.JPG" SRC="http://www.thedarkvisitor.com/wp-content/uploads/2008/01/taiwanhackerslides.JPG" /></p>
<p ALIGN="center"><img SRC="http://www.thedarkvisitor.com/wp-content/uploads/2008/01/taiwanhackerslides2.JPG" ALT="taiwanhackerslides2.JPG" /></p>
<p ALIGN="center"> <img SRC="http://www.thedarkvisitor.com/wp-content/uploads/2008/01/taiwanhackerslides3.JPG" ALT="taiwanhackerslides3.JPG" /></p>
<p>This thread was first  <a HREF="http://www.thedarkvisitor.com/?p=245">brought to my attention by Jumper </a>who has been collecting postings from an individual in Taiwan named Charlie Chen who is fairly elusive.  The same theme runs through all of Chen&#8217;s postings concerning a PRC government run organization of eight Chinese hacker groups dedicated to cyber espionage.</p>
<p>Did a little checking and came across an article by Gordon Housworth who is just as curious about the mystery poster as Jumper.  <a HREF="http://spaces.icgpartners.com/index2.asp?category=&amp;eventdate=1/8/2008">Gordon did a ton of research</a> and from what I can tell has a good handle on the identity of our mystery man.  He was also able to locate a <a HREF="http://www.slideshare.net/DeepThroat/china-cyber-army/">26-frame slide show  associated with Mr. Chen</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/01/mysterious-chinese-hacker-slide-show/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>

