<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>The Dark Visitor</title>
	<atom:link href="http://www.thedarkvisitor.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thedarkvisitor.com</link>
	<description>Tracking the history, organization, exploits and government affiliation of Chinese hackers</description>
	<pubDate>Thu, 24 Jul 2008 03:54:57 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
	<language>en</language>
			<item>
		<title>Five favorite targets of Chinese hackers</title>
		<link>http://www.thedarkvisitor.com/2008/07/five-favorite-targets-of-chinese-hackers/</link>
		<comments>http://www.thedarkvisitor.com/2008/07/five-favorite-targets-of-chinese-hackers/#comments</comments>
		<pubDate>Thu, 24 Jul 2008 02:21:42 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
		
		<category><![CDATA[Chinese Malware]]></category>

		<category><![CDATA[Hacking for money]]></category>

		<category><![CDATA[Chinese hackers]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[targets]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=663</guid>
		<description><![CDATA[
One thing that has always interested me is the types of targets Chinese hackers seek out for attack.  Since it is impossible for us to protect everything, or be everywhere, understanding the most likely targets should be a high priority. Of course this is only part of a comprehensive cyber security program but knowing [...]]]></description>
			<content:encoded><![CDATA[<p><a href='http://www.thedarkvisitor.com/wordpress/wp-content/uploads/2008/07/target.jpg'><img src="http://www.thedarkvisitor.com/wordpress/wp-content/uploads/2008/07/target.jpg" alt="" title="target" width="297" height="369" class="aligncenter size-full wp-image-664" /></a></p>
<p>One thing that has always interested me is the types of targets Chinese hackers seek out for attack.  Since it is impossible for us to protect everything, or be everywhere, understanding the most likely targets should be a high priority. Of course this is only part of a comprehensive cyber security program but knowing how your adversary thinks is one area we need to explore.</p>
<p>An article in pchome.net gave the <a href="http://article.pchome.net/content-672455.html" onclick="javascript:pageTracker._trackPageview('outbound//http://article.pchome.net/content-672455.html');">five most desired websites Chinese hackers</a> sought out in order to hang trojans.  Trojans have been the tool of choice for Chinese hackers since their first indigenously produced program Glacier was introduced into the cyber conflict with Taiwan in 1999.</p>
<p>According to pchome.net, these were the preferred websites:</p>
<p> 1)  <strong></strong></p>
<ul>Government websites</ul>
<p>: Government sites are chosen due to low-level security and the lack of specially trained security personnel.  They do not bring financial gain but have the potential to influence public opinion. This type of attack &#8220;challenges authority&#8221; and brings about personal satisfaction for the hacker.  A successful attack on a government website provides the attacker with recognition and fame.</p>
<p> 2) <strong></strong></p>
<ul>Medium and Small-Scale company websites</ul>
<p>: Similar to government websites due to the lack of security.  While these types of attacks to not bring about fame for the hacker, they are very good practice for the novice.  </p>
<p> 3) <strong></strong></p>
<ul>Community websites</ul>
<p>: Huge number of visitors, even if the trojan is only around for a short period of time, it can result in a large number of infected visitors.  Although the value of the individual users is not as great as a financial website, the collective of infected users can be used to create a botnet.  Furthermore, this allows the hacker to steal virtual game assets and QQ (ICQ) money.</p>
<p>4) <strong></strong></p>
<ul>Financial websites</ul>
<p>: This type of website does not have a larger number of users but the average individual has a high net worth. If a hacker is able to install a trojan here, they can gain user account passwords, access bank accounts and control stock securities.  Although this type of website has very high security, it is the most desirable.</p>
<p>5) <strong></strong></p>
<ul>E-commerce sites</ul>
<p>: These website share the benefits of both community and financial websites and are the most lucrative.  Hackers are able to manipulate price, supply/demand and control the online transactions.  Furthermore, they can use trusted user accounts to construct phishing &#8220;activities.&#8221;  E-commerce website are the most favored for hackers to carry out phishing exploits.</p>
<p>Army lessons learned: First rule in the Army is never present a problem without a solution.  Solution, hire people like Jumper who are experts in preventing these types of attacks.</p>
<p>People often ask me if I am worried about this website getting hacked or shutdown by Chinese hackers&#8230;I tell them no, I have an excellent firewall&#8230;called Jumper.</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Ffive-favorite-targets-of-chinese-hackers%2F&amp;title=Five+favorite+targets+of+Chinese+hackers" onclick="javascript:pageTracker._trackPageview('outbound//http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Ffive-favorite-targets-of-chinese-hackers%2F&amp;title=Five+favorite+targets+of+Chinese+hackers');" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Ffive-favorite-targets-of-chinese-hackers%2F&amp;title=Five+favorite+targets+of+Chinese+hackers" onclick="javascript:pageTracker._trackPageview('outbound//http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Ffive-favorite-targets-of-chinese-hackers%2F&amp;title=Five+favorite+targets+of+Chinese+hackers');" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Ffive-favorite-targets-of-chinese-hackers%2F&amp;title=Five+favorite+targets+of+Chinese+hackers" onclick="javascript:pageTracker._trackPageview('outbound//http://reddit.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Ffive-favorite-targets-of-chinese-hackers%2F&amp;title=Five+favorite+targets+of+Chinese+hackers');" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Ffive-favorite-targets-of-chinese-hackers%2F&amp;title=Five+favorite+targets+of+Chinese+hackers" onclick="javascript:pageTracker._trackPageview('outbound//http://del.icio.us/post?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Ffive-favorite-targets-of-chinese-hackers%2F&amp;title=Five+favorite+targets+of+Chinese+hackers');" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Ffive-favorite-targets-of-chinese-hackers%2F&amp;title=Five+favorite+targets+of+Chinese+hackers', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Ffive-favorite-targets-of-chinese-hackers%2F" onclick="javascript:pageTracker._trackPageview('outbound//http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Ffive-favorite-targets-of-chinese-hackers%2F');" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Ffive-favorite-targets-of-chinese-hackers%2F" onclick="javascript:pageTracker._trackPageview('outbound//http://technorati.com/faves?add=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Ffive-favorite-targets-of-chinese-hackers%2F');" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Ffive-favorite-targets-of-chinese-hackers%2F&amp;title=Five+favorite+targets+of+Chinese+hackers" onclick="javascript:pageTracker._trackPageview('outbound//http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Ffive-favorite-targets-of-chinese-hackers%2F&amp;title=Five+favorite+targets+of+Chinese+hackers');" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Ffive-favorite-targets-of-chinese-hackers%2F&amp;title=Five+favorite+targets+of+Chinese+hackers" onclick="javascript:pageTracker._trackPageview('outbound//http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Ffive-favorite-targets-of-chinese-hackers%2F&amp;title=Five+favorite+targets+of+Chinese+hackers');" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/07/five-favorite-targets-of-chinese-hackers/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Chinese and Iranian hacker connection?</title>
		<link>http://www.thedarkvisitor.com/2008/07/chinese-and-iranian-hacker-connection/</link>
		<comments>http://www.thedarkvisitor.com/2008/07/chinese-and-iranian-hacker-connection/#comments</comments>
		<pubDate>Tue, 22 Jul 2008 10:58:38 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
		
		<category><![CDATA[US attacks]]></category>

		<category><![CDATA[Chinese hackers]]></category>

		<category><![CDATA[jerusalemonline]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=662</guid>
		<description><![CDATA[Skimming through the news today and came across an article in pr-inside.com, on Iranian hacker attempts to disrupt Jewish American leader&#8217;s message to Iran.  A small blurb in the piece suggested that there was some evidence of Chinese fingerprints or assistance:
In the month since Hoenlein&#8217;s message was posted, Rosen said there have been «dozens» [...]]]></description>
			<content:encoded><![CDATA[<p>Skimming through the news today and came across an article in pr-inside.com, on <a href="http://www.pr-inside.com/israeli-web-site-iranian-hackers-trying-r715484.htm" onclick="javascript:pageTracker._trackPageview('outbound//http://www.pr-inside.com/israeli-web-site-iranian-hackers-trying-r715484.htm');">Iranian hacker attempts to disrupt Jewish American leader&#8217;s message to Iran</a>.  A small blurb in the piece suggested that there was some evidence of Chinese fingerprints or assistance:</p>
<blockquote><p>In the month since Hoenlein&#8217;s message was posted, Rosen said there have been «dozens» of attempts to hack into the site, called Jerusalemonline.com. He said they succeeded in labeling the Web site as «dangerous» on the Google search engine.</p>
<p>In an e-mail message to The Associated Press, Rosen said his <strong>technicians identified the hackers as «probably Iranian based with Chinese assistance or fingerprints</strong>.</p></blockquote>
<p>I have written to Jerusalemonline for further clarification on this section of the article and hopefully will have an update.  It would be very interesting to see if there is more to this, even if the Iranians are just using Chinese hacker malware.  </p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-and-iranian-hacker-connection%2F&amp;title=Chinese+and+Iranian+hacker+connection%3F" onclick="javascript:pageTracker._trackPageview('outbound//http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-and-iranian-hacker-connection%2F&amp;title=Chinese+and+Iranian+hacker+connection%3F');" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-and-iranian-hacker-connection%2F&amp;title=Chinese+and+Iranian+hacker+connection%3F" onclick="javascript:pageTracker._trackPageview('outbound//http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-and-iranian-hacker-connection%2F&amp;title=Chinese+and+Iranian+hacker+connection%3F');" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-and-iranian-hacker-connection%2F&amp;title=Chinese+and+Iranian+hacker+connection%3F" onclick="javascript:pageTracker._trackPageview('outbound//http://reddit.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-and-iranian-hacker-connection%2F&amp;title=Chinese+and+Iranian+hacker+connection%3F');" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-and-iranian-hacker-connection%2F&amp;title=Chinese+and+Iranian+hacker+connection%3F" onclick="javascript:pageTracker._trackPageview('outbound//http://del.icio.us/post?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-and-iranian-hacker-connection%2F&amp;title=Chinese+and+Iranian+hacker+connection%3F');" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-and-iranian-hacker-connection%2F&amp;title=Chinese+and+Iranian+hacker+connection%3F', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-and-iranian-hacker-connection%2F" onclick="javascript:pageTracker._trackPageview('outbound//http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-and-iranian-hacker-connection%2F');" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-and-iranian-hacker-connection%2F" onclick="javascript:pageTracker._trackPageview('outbound//http://technorati.com/faves?add=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-and-iranian-hacker-connection%2F');" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-and-iranian-hacker-connection%2F&amp;title=Chinese+and+Iranian+hacker+connection%3F" onclick="javascript:pageTracker._trackPageview('outbound//http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-and-iranian-hacker-connection%2F&amp;title=Chinese+and+Iranian+hacker+connection%3F');" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-and-iranian-hacker-connection%2F&amp;title=Chinese+and+Iranian+hacker+connection%3F" onclick="javascript:pageTracker._trackPageview('outbound//http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-and-iranian-hacker-connection%2F&amp;title=Chinese+and+Iranian+hacker+connection%3F');" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/07/chinese-and-iranian-hacker-connection/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Leader of Chinese female hacker &#8220;security&#8221; team not happy</title>
		<link>http://www.thedarkvisitor.com/2008/07/leader-of-chinese-female-hacker-security-team-not-happy/</link>
		<comments>http://www.thedarkvisitor.com/2008/07/leader-of-chinese-female-hacker-security-team-not-happy/#comments</comments>
		<pubDate>Mon, 21 Jul 2008 23:04:05 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
		
		<category><![CDATA[Hacker Organization]]></category>

		<category><![CDATA[Hackers Talking]]></category>

		<category><![CDATA[Leaders]]></category>

		<category><![CDATA[Chinese hackers]]></category>

		<category><![CDATA[Cn Girl Security Team]]></category>

		<category><![CDATA[Xiao Tian]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=660</guid>
		<description><![CDATA[
On May 29th, we posted a profile of Cn Girl Security Team, an organization of female hackers.  A reporter from the Daily News and Analysis, Venkatesan Vembu, picked up the story and called for an interview.  
Not sure how widely the story was circulated in the western press but it sure was popular [...]]]></description>
			<content:encoded><![CDATA[<p><a href='http://www.thedarkvisitor.com/wordpress/wp-content/uploads/2008/07/xiaotian2.jpg'><img src="http://www.thedarkvisitor.com/wordpress/wp-content/uploads/2008/07/xiaotian2.jpg" alt="" title="xiaotian2" width="397" height="611" class="aligncenter size-full wp-image-661" /></a><br />
On May 29th, we posted a profile of <a href="http://www.thedarkvisitor.com/2008/05/chinese-female-hacker-group/" >Cn Girl Security Team</a>, an organization of female hackers.  A reporter from the <em>Daily News and Analysis</em>, Venkatesan Vembu, picked up the story and <a href="http://www.dnaindia.com/report.asp?newsid=1177482" onclick="javascript:pageTracker._trackPageview('outbound//http://www.dnaindia.com/report.asp?newsid=1177482');">called for an interview</a>.  </p>
<p>Not sure how widely the story was circulated in the western press but it sure was <a href="http://www.google.com/search?hl=en&#038;q=%E6%8F%AD%E7%A7%98%E4%B8%AD%E5%9B%BD%E2%80%9C%E9%BB%91%E5%AE%A2%E8%BE%A3%E5%A6%B9%E2%80%9D+%E5%B0%8F%E5%B0%8F%E5%B9%B4%E7%BA%AA%E4%B8%8D%E7%AE%80%E5%8D%95&#038;btnG=Google+Search" onclick="javascript:pageTracker._trackPageview('outbound//http://www.google.com/search?hl=en&#038;q=%E6%8F%AD%E7%A7%98%E4%B8%AD%E5%9B%BD%E2%80%9C%E9%BB%91%E5%AE%A2%E8%BE%A3%E5%A6%B9%E2%80%9D+%E5%B0%8F%E5%B0%8F%E5%B9%B4%E7%BA%AA%E4%B8%8D%E7%AE%80%E5%8D%95&#038;btnG=Google+Search');">popular in China</a>.</p>
<p>On her blog, Xiao Tian admits that all the sudden publicity came as a shock when people started calling asking about the article.  She claims to have stepped away from the &#8220;security&#8221; site for quite some time and that much of what was written was hype.  Just a girl who enjoys blogging and computers. For someone who takes so many pictures of herself, it is hard to believe that this has become such a burden on her. </p>
<p>The Cn Girl Security Team website has been showing a 403 error for the past week and some have suggested it was done by hackers.  They say this further demonstrates the low-level technical skills possessed by the group.  Xiao Tian denies the rumor and contends there was a problem with the hosting service.</p>
<p>Either way, one more hacker website bites the dust.  Hundreds remain but we got you covered.</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fleader-of-chinese-female-hacker-security-team-not-happy%2F&amp;title=Leader+of+Chinese+female+hacker+%26%238220%3Bsecurity%26%238221%3B+team+not+happy" onclick="javascript:pageTracker._trackPageview('outbound//http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fleader-of-chinese-female-hacker-security-team-not-happy%2F&amp;title=Leader+of+Chinese+female+hacker+%26%238220%3Bsecurity%26%238221%3B+team+not+happy');" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fleader-of-chinese-female-hacker-security-team-not-happy%2F&amp;title=Leader+of+Chinese+female+hacker+%26%238220%3Bsecurity%26%238221%3B+team+not+happy" onclick="javascript:pageTracker._trackPageview('outbound//http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fleader-of-chinese-female-hacker-security-team-not-happy%2F&amp;title=Leader+of+Chinese+female+hacker+%26%238220%3Bsecurity%26%238221%3B+team+not+happy');" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fleader-of-chinese-female-hacker-security-team-not-happy%2F&amp;title=Leader+of+Chinese+female+hacker+%26%238220%3Bsecurity%26%238221%3B+team+not+happy" onclick="javascript:pageTracker._trackPageview('outbound//http://reddit.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fleader-of-chinese-female-hacker-security-team-not-happy%2F&amp;title=Leader+of+Chinese+female+hacker+%26%238220%3Bsecurity%26%238221%3B+team+not+happy');" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fleader-of-chinese-female-hacker-security-team-not-happy%2F&amp;title=Leader+of+Chinese+female+hacker+%26%238220%3Bsecurity%26%238221%3B+team+not+happy" onclick="javascript:pageTracker._trackPageview('outbound//http://del.icio.us/post?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fleader-of-chinese-female-hacker-security-team-not-happy%2F&amp;title=Leader+of+Chinese+female+hacker+%26%238220%3Bsecurity%26%238221%3B+team+not+happy');" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fleader-of-chinese-female-hacker-security-team-not-happy%2F&amp;title=Leader+of+Chinese+female+hacker+%26%238220%3Bsecurity%26%238221%3B+team+not+happy', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fleader-of-chinese-female-hacker-security-team-not-happy%2F" onclick="javascript:pageTracker._trackPageview('outbound//http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fleader-of-chinese-female-hacker-security-team-not-happy%2F');" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fleader-of-chinese-female-hacker-security-team-not-happy%2F" onclick="javascript:pageTracker._trackPageview('outbound//http://technorati.com/faves?add=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fleader-of-chinese-female-hacker-security-team-not-happy%2F');" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fleader-of-chinese-female-hacker-security-team-not-happy%2F&amp;title=Leader+of+Chinese+female+hacker+%26%238220%3Bsecurity%26%238221%3B+team+not+happy" onclick="javascript:pageTracker._trackPageview('outbound//http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fleader-of-chinese-female-hacker-security-team-not-happy%2F&amp;title=Leader+of+Chinese+female+hacker+%26%238220%3Bsecurity%26%238221%3B+team+not+happy');" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fleader-of-chinese-female-hacker-security-team-not-happy%2F&amp;title=Leader+of+Chinese+female+hacker+%26%238220%3Bsecurity%26%238221%3B+team+not+happy" onclick="javascript:pageTracker._trackPageview('outbound//http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fleader-of-chinese-female-hacker-security-team-not-happy%2F&amp;title=Leader+of+Chinese+female+hacker+%26%238220%3Bsecurity%26%238221%3B+team+not+happy');" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/07/leader-of-chinese-female-hacker-security-team-not-happy/feed/</wfw:commentRss>
		</item>
		<item>
		<title>This blog is at least a solid 8.1&#8230;maybe an 8.2!!</title>
		<link>http://www.thedarkvisitor.com/2008/07/this-blog-is-at-least-a-solid-81maybe-an-82/</link>
		<comments>http://www.thedarkvisitor.com/2008/07/this-blog-is-at-least-a-solid-81maybe-an-82/#comments</comments>
		<pubDate>Mon, 21 Jul 2008 21:55:14 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[blogged.com]]></category>

		<category><![CDATA[The Dark Visitor]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=658</guid>
		<description><![CDATA[Received an e-mail today from www.blogged.com that has rated us as follows:
We evaluated your blog based on the following criteria: Frequency of Updates, Relevance of Content, Site Design, and Writing Style.
After carefully reviewing each of these criteria, your site was given its 8.0 score.

An 8.0&#8230;I mean WTF?  I strongly suspect that Jumper has pulled [...]]]></description>
			<content:encoded><![CDATA[<p>Received an e-mail today from <a href="http://www.blogged.com/search/the%20dark%20visitor" onclick="javascript:pageTracker._trackPageview('outbound//http://www.blogged.com/search/the%20dark%20visitor');">www.blogged.com that has rated us as follows</a>:</p>
<blockquote><p>We evaluated your blog based on the following criteria: Frequency of Updates, Relevance of Content, Site Design, and Writing Style.</p>
<p>After carefully reviewing each of these criteria, your site was given its <strong>8.0 score</strong>.</p>
</blockquote>
<p>An 8.0&#8230;I mean WTF?  I strongly suspect that Jumper has pulled the blog down from my own unbiased rating of around 8.15 prior to his arrival.  </p>
<p><a href='http://www.thedarkvisitor.com/wordpress/wp-content/uploads/2008/07/blogged.jpg'><img src="http://www.thedarkvisitor.com/wordpress/wp-content/uploads/2008/07/blogged-300x123.jpg" alt="" title="blogged" width="300" height="123" class="alignnone size-medium wp-image-659" /></a></p>
<p>An 8.0 is great? Not in my book buddy, that is like low hanging &#8220;B&#8221; work.  We at TDV vow to increase the quality of our postings, we will spare nothing to move up the ladder at blogged.com&#8230;unless of course it involves too much effort.</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fthis-blog-is-at-least-a-solid-81maybe-an-82%2F&amp;title=This+blog+is+at+least+a+solid+8.1%26%238230%3Bmaybe+an+8.2%21%21" onclick="javascript:pageTracker._trackPageview('outbound//http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fthis-blog-is-at-least-a-solid-81maybe-an-82%2F&amp;title=This+blog+is+at+least+a+solid+8.1%26%238230%3Bmaybe+an+8.2%21%21');" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fthis-blog-is-at-least-a-solid-81maybe-an-82%2F&amp;title=This+blog+is+at+least+a+solid+8.1%26%238230%3Bmaybe+an+8.2%21%21" onclick="javascript:pageTracker._trackPageview('outbound//http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fthis-blog-is-at-least-a-solid-81maybe-an-82%2F&amp;title=This+blog+is+at+least+a+solid+8.1%26%238230%3Bmaybe+an+8.2%21%21');" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fthis-blog-is-at-least-a-solid-81maybe-an-82%2F&amp;title=This+blog+is+at+least+a+solid+8.1%26%238230%3Bmaybe+an+8.2%21%21" onclick="javascript:pageTracker._trackPageview('outbound//http://reddit.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fthis-blog-is-at-least-a-solid-81maybe-an-82%2F&amp;title=This+blog+is+at+least+a+solid+8.1%26%238230%3Bmaybe+an+8.2%21%21');" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fthis-blog-is-at-least-a-solid-81maybe-an-82%2F&amp;title=This+blog+is+at+least+a+solid+8.1%26%238230%3Bmaybe+an+8.2%21%21" onclick="javascript:pageTracker._trackPageview('outbound//http://del.icio.us/post?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fthis-blog-is-at-least-a-solid-81maybe-an-82%2F&amp;title=This+blog+is+at+least+a+solid+8.1%26%238230%3Bmaybe+an+8.2%21%21');" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fthis-blog-is-at-least-a-solid-81maybe-an-82%2F&amp;title=This+blog+is+at+least+a+solid+8.1%26%238230%3Bmaybe+an+8.2%21%21', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fthis-blog-is-at-least-a-solid-81maybe-an-82%2F" onclick="javascript:pageTracker._trackPageview('outbound//http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fthis-blog-is-at-least-a-solid-81maybe-an-82%2F');" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fthis-blog-is-at-least-a-solid-81maybe-an-82%2F" onclick="javascript:pageTracker._trackPageview('outbound//http://technorati.com/faves?add=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fthis-blog-is-at-least-a-solid-81maybe-an-82%2F');" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fthis-blog-is-at-least-a-solid-81maybe-an-82%2F&amp;title=This+blog+is+at+least+a+solid+8.1%26%238230%3Bmaybe+an+8.2%21%21" onclick="javascript:pageTracker._trackPageview('outbound//http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fthis-blog-is-at-least-a-solid-81maybe-an-82%2F&amp;title=This+blog+is+at+least+a+solid+8.1%26%238230%3Bmaybe+an+8.2%21%21');" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fthis-blog-is-at-least-a-solid-81maybe-an-82%2F&amp;title=This+blog+is+at+least+a+solid+8.1%26%238230%3Bmaybe+an+8.2%21%21" onclick="javascript:pageTracker._trackPageview('outbound//http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fthis-blog-is-at-least-a-solid-81maybe-an-82%2F&amp;title=This+blog+is+at+least+a+solid+8.1%26%238230%3Bmaybe+an+8.2%21%21');" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/07/this-blog-is-at-least-a-solid-81maybe-an-82/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Getting &#8220;electronically&#8221; naked at the Beijing Olympics</title>
		<link>http://www.thedarkvisitor.com/2008/07/getting-electronically-naked-at-the-beijing-olympics/</link>
		<comments>http://www.thedarkvisitor.com/2008/07/getting-electronically-naked-at-the-beijing-olympics/#comments</comments>
		<pubDate>Thu, 17 Jul 2008 09:38:37 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
		
		<category><![CDATA[Chinese Malware]]></category>

		<category><![CDATA[US attacks]]></category>

		<category><![CDATA[Beijing Olympics]]></category>

		<category><![CDATA[Chinese hackers]]></category>

		<category><![CDATA[Laptops]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=657</guid>
		<description><![CDATA[I swear people have to sit around and think of phrases like this&#8230;from the WSJ:
In addition to cybersecurity threats in other countries, &#8220;so many people are going to the Olympics and are going to get electronically undressed,&#8221; said Joel Brenner, the government&#8217;s top counterintelligence officer. He tells of one computer-security expert who powered up a [...]]]></description>
			<content:encoded><![CDATA[<p>I swear people have to sit around and think of phrases like this&#8230;from the WSJ:</p>
<blockquote><p>In addition to cybersecurity threats in other countries, &#8220;so many people are going to the Olympics and are going to get electronically undressed,&#8221; said Joel Brenner, the government&#8217;s top counterintelligence officer. He tells of one computer-security expert who powered up a new Treo hand-held computer when his plane landed in China. By the time he got to his hotel, a handful of software programs had been wirelessly inserted.</p></blockquote>
<p><a href="http://online.wsj.com/article/SB121625646058760485.html?mod=googlenews_wsj" onclick="javascript:pageTracker._trackPageview('outbound//http://online.wsj.com/article/SB121625646058760485.html?mod=googlenews_wsj');">More nudity here&#8230;</a></p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fgetting-electronically-naked-at-the-beijing-olympics%2F&amp;title=Getting+%26%238220%3Belectronically%26%238221%3B+naked+at+the+Beijing+Olympics" onclick="javascript:pageTracker._trackPageview('outbound//http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fgetting-electronically-naked-at-the-beijing-olympics%2F&amp;title=Getting+%26%238220%3Belectronically%26%238221%3B+naked+at+the+Beijing+Olympics');" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fgetting-electronically-naked-at-the-beijing-olympics%2F&amp;title=Getting+%26%238220%3Belectronically%26%238221%3B+naked+at+the+Beijing+Olympics" onclick="javascript:pageTracker._trackPageview('outbound//http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fgetting-electronically-naked-at-the-beijing-olympics%2F&amp;title=Getting+%26%238220%3Belectronically%26%238221%3B+naked+at+the+Beijing+Olympics');" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fgetting-electronically-naked-at-the-beijing-olympics%2F&amp;title=Getting+%26%238220%3Belectronically%26%238221%3B+naked+at+the+Beijing+Olympics" onclick="javascript:pageTracker._trackPageview('outbound//http://reddit.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fgetting-electronically-naked-at-the-beijing-olympics%2F&amp;title=Getting+%26%238220%3Belectronically%26%238221%3B+naked+at+the+Beijing+Olympics');" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fgetting-electronically-naked-at-the-beijing-olympics%2F&amp;title=Getting+%26%238220%3Belectronically%26%238221%3B+naked+at+the+Beijing+Olympics" onclick="javascript:pageTracker._trackPageview('outbound//http://del.icio.us/post?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fgetting-electronically-naked-at-the-beijing-olympics%2F&amp;title=Getting+%26%238220%3Belectronically%26%238221%3B+naked+at+the+Beijing+Olympics');" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fgetting-electronically-naked-at-the-beijing-olympics%2F&amp;title=Getting+%26%238220%3Belectronically%26%238221%3B+naked+at+the+Beijing+Olympics', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fgetting-electronically-naked-at-the-beijing-olympics%2F" onclick="javascript:pageTracker._trackPageview('outbound//http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fgetting-electronically-naked-at-the-beijing-olympics%2F');" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fgetting-electronically-naked-at-the-beijing-olympics%2F" onclick="javascript:pageTracker._trackPageview('outbound//http://technorati.com/faves?add=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fgetting-electronically-naked-at-the-beijing-olympics%2F');" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fgetting-electronically-naked-at-the-beijing-olympics%2F&amp;title=Getting+%26%238220%3Belectronically%26%238221%3B+naked+at+the+Beijing+Olympics" onclick="javascript:pageTracker._trackPageview('outbound//http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fgetting-electronically-naked-at-the-beijing-olympics%2F&amp;title=Getting+%26%238220%3Belectronically%26%238221%3B+naked+at+the+Beijing+Olympics');" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fgetting-electronically-naked-at-the-beijing-olympics%2F&amp;title=Getting+%26%238220%3Belectronically%26%238221%3B+naked+at+the+Beijing+Olympics" onclick="javascript:pageTracker._trackPageview('outbound//http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fgetting-electronically-naked-at-the-beijing-olympics%2F&amp;title=Getting+%26%238220%3Belectronically%26%238221%3B+naked+at+the+Beijing+Olympics');" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/07/getting-electronically-naked-at-the-beijing-olympics/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Bruce Schneier:  The Truth About Chinese Hackers</title>
		<link>http://www.thedarkvisitor.com/2008/07/bruce-schneier-the-truth-about-chinese-hackers/</link>
		<comments>http://www.thedarkvisitor.com/2008/07/bruce-schneier-the-truth-about-chinese-hackers/#comments</comments>
		<pubDate>Mon, 14 Jul 2008 23:36:32 +0000</pubDate>
		<dc:creator>jumper</dc:creator>
		
		<category><![CDATA[Hacker History]]></category>

		<category><![CDATA[Hacker Organization]]></category>

		<category><![CDATA[Nationalism]]></category>

		<category><![CDATA[Taiwan]]></category>

		<category><![CDATA[Tibet]]></category>

		<category><![CDATA[US attacks]]></category>

		<category><![CDATA[bruce schneier]]></category>

		<category><![CDATA[Chinese hackers]]></category>

		<category><![CDATA[not necessarily the truth]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=653</guid>
		<description><![CDATA[
Bruce Schneier is a well-known security and cryptography researcher.  He has a popular blog where he posted his recent article detailing &#8220;The Truth About Chinese Hackers&#8221;, which was written for Discovery Channel.
This article is not particularly insightful and sort of lumps all of the Chinese hackers into a single group of young, male patriotic kids [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.thedarkvisitor.com/wordpress/wp-content/uploads/2008/07/bruce_schneier_blog_photo.jpg" ><img class="alignnone size-medium wp-image-654" title="bruce_schneier_blog_photo" src="http://www.thedarkvisitor.com/wordpress/wp-content/uploads/2008/07/bruce_schneier_blog_photo.jpg" alt="Bruce Schneier" width="150" height="225" /></a></p>
<p>Bruce Schneier is a well-known security and cryptography researcher.  He has a popular <a href="http://www.schneier.com" onclick="javascript:pageTracker._trackPageview('outbound//http://www.schneier.com');">blog</a> where he <a href="http://www.schneier.com/blog/archives/2008/07/chinese_cyber_a.html" onclick="javascript:pageTracker._trackPageview('outbound//http://www.schneier.com/blog/archives/2008/07/chinese_cyber_a.html');">posted</a> his recent article detailing <a href="http://dsc.discovery.com/technology/my-take/computer-hackers-china.html" onclick="javascript:pageTracker._trackPageview('outbound//http://dsc.discovery.com/technology/my-take/computer-hackers-china.html');">&#8220;The Truth About Chinese Hackers&#8221;</a>, which was written for Discovery Channel.</p>
<p>This article is not particularly insightful and sort of lumps all of the Chinese hackers into a single group of young, male patriotic kids doing it for the babes and limos.</p>
<blockquote><p>These hacker groups seem not to be working for the Chinese government. They don&#8217;t seem to be coordinated by the Chinese military.</p></blockquote>
<blockquote><p>The hackers are in this for two reasons: fame and glory, and an attempt to make a living.</p></blockquote>
<p>This is very short sighted.  We should be honest here, neither Bruce Schneier nor Heike and I know with absolute certainty what Chinese hackers are doing, who is coordinating them and who might be paying them.  Maybe the article shouldn&#8217;t be titled &#8220;The Truth About Chinese Hacker&#8221; because Bruce doesn&#8217;t know what the truth is (Heike would have said that he couldn&#8217;t handle the truth either, but that&#8217;s not my style).</p>
<p>I think a lot of people assume that activity attributed to the PRC is simply based on the IP address.  After studying spear phishing attacks, custom malware attacks and the types of data that have been exfiltrated from various NGO targets it seems likely that some entity is coordinating the collection and exploitation of this information.  In my humble opinion, there may be more to this than WoW passwords.</p>
<p> </p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fbruce-schneier-the-truth-about-chinese-hackers%2F&amp;title=Bruce+Schneier%3A++The+Truth+About+Chinese+Hackers" onclick="javascript:pageTracker._trackPageview('outbound//http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fbruce-schneier-the-truth-about-chinese-hackers%2F&amp;title=Bruce+Schneier%3A++The+Truth+About+Chinese+Hackers');" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fbruce-schneier-the-truth-about-chinese-hackers%2F&amp;title=Bruce+Schneier%3A++The+Truth+About+Chinese+Hackers" onclick="javascript:pageTracker._trackPageview('outbound//http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fbruce-schneier-the-truth-about-chinese-hackers%2F&amp;title=Bruce+Schneier%3A++The+Truth+About+Chinese+Hackers');" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fbruce-schneier-the-truth-about-chinese-hackers%2F&amp;title=Bruce+Schneier%3A++The+Truth+About+Chinese+Hackers" onclick="javascript:pageTracker._trackPageview('outbound//http://reddit.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fbruce-schneier-the-truth-about-chinese-hackers%2F&amp;title=Bruce+Schneier%3A++The+Truth+About+Chinese+Hackers');" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fbruce-schneier-the-truth-about-chinese-hackers%2F&amp;title=Bruce+Schneier%3A++The+Truth+About+Chinese+Hackers" onclick="javascript:pageTracker._trackPageview('outbound//http://del.icio.us/post?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fbruce-schneier-the-truth-about-chinese-hackers%2F&amp;title=Bruce+Schneier%3A++The+Truth+About+Chinese+Hackers');" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fbruce-schneier-the-truth-about-chinese-hackers%2F&amp;title=Bruce+Schneier%3A++The+Truth+About+Chinese+Hackers', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fbruce-schneier-the-truth-about-chinese-hackers%2F" onclick="javascript:pageTracker._trackPageview('outbound//http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fbruce-schneier-the-truth-about-chinese-hackers%2F');" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fbruce-schneier-the-truth-about-chinese-hackers%2F" onclick="javascript:pageTracker._trackPageview('outbound//http://technorati.com/faves?add=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fbruce-schneier-the-truth-about-chinese-hackers%2F');" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fbruce-schneier-the-truth-about-chinese-hackers%2F&amp;title=Bruce+Schneier%3A++The+Truth+About+Chinese+Hackers" onclick="javascript:pageTracker._trackPageview('outbound//http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fbruce-schneier-the-truth-about-chinese-hackers%2F&amp;title=Bruce+Schneier%3A++The+Truth+About+Chinese+Hackers');" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fbruce-schneier-the-truth-about-chinese-hackers%2F&amp;title=Bruce+Schneier%3A++The+Truth+About+Chinese+Hackers" onclick="javascript:pageTracker._trackPageview('outbound//http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fbruce-schneier-the-truth-about-chinese-hackers%2F&amp;title=Bruce+Schneier%3A++The+Truth+About+Chinese+Hackers');" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/07/bruce-schneier-the-truth-about-chinese-hackers/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Liquor is quicker but&#8230;</title>
		<link>http://www.thedarkvisitor.com/2008/07/liquor-is-quicker-but/</link>
		<comments>http://www.thedarkvisitor.com/2008/07/liquor-is-quicker-but/#comments</comments>
		<pubDate>Mon, 14 Jul 2008 01:01:16 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[candy]]></category>

		<category><![CDATA[chinese hacker]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=651</guid>
		<description><![CDATA[Chinese hacker candy is dandy&#8230;

Hat tip: To you know who










]]></description>
			<content:encoded><![CDATA[<p>Chinese hacker candy is dandy&#8230;</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wordpress/wp-content/uploads/2008/07/hackercandy.jpg" ><img class="alignnone size-full wp-image-652 aligncenter" title="hackercandy" src="http://www.thedarkvisitor.com/wordpress/wp-content/uploads/2008/07/hackercandy.jpg" alt="" width="470" height="254" /></a></p>
<p>Hat tip: To you know who</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fliquor-is-quicker-but%2F&amp;title=Liquor+is+quicker+but%26%238230%3B" onclick="javascript:pageTracker._trackPageview('outbound//http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fliquor-is-quicker-but%2F&amp;title=Liquor+is+quicker+but%26%238230%3B');" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fliquor-is-quicker-but%2F&amp;title=Liquor+is+quicker+but%26%238230%3B" onclick="javascript:pageTracker._trackPageview('outbound//http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fliquor-is-quicker-but%2F&amp;title=Liquor+is+quicker+but%26%238230%3B');" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fliquor-is-quicker-but%2F&amp;title=Liquor+is+quicker+but%26%238230%3B" onclick="javascript:pageTracker._trackPageview('outbound//http://reddit.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fliquor-is-quicker-but%2F&amp;title=Liquor+is+quicker+but%26%238230%3B');" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fliquor-is-quicker-but%2F&amp;title=Liquor+is+quicker+but%26%238230%3B" onclick="javascript:pageTracker._trackPageview('outbound//http://del.icio.us/post?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fliquor-is-quicker-but%2F&amp;title=Liquor+is+quicker+but%26%238230%3B');" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fliquor-is-quicker-but%2F&amp;title=Liquor+is+quicker+but%26%238230%3B', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fliquor-is-quicker-but%2F" onclick="javascript:pageTracker._trackPageview('outbound//http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fliquor-is-quicker-but%2F');" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fliquor-is-quicker-but%2F" onclick="javascript:pageTracker._trackPageview('outbound//http://technorati.com/faves?add=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fliquor-is-quicker-but%2F');" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fliquor-is-quicker-but%2F&amp;title=Liquor+is+quicker+but%26%238230%3B" onclick="javascript:pageTracker._trackPageview('outbound//http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fliquor-is-quicker-but%2F&amp;title=Liquor+is+quicker+but%26%238230%3B');" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fliquor-is-quicker-but%2F&amp;title=Liquor+is+quicker+but%26%238230%3B" onclick="javascript:pageTracker._trackPageview('outbound//http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fliquor-is-quicker-but%2F&amp;title=Liquor+is+quicker+but%26%238230%3B');" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/07/liquor-is-quicker-but/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Chinese hacker Withered Rose returns</title>
		<link>http://www.thedarkvisitor.com/2008/07/chinese-hacker-withered-rose-returns/</link>
		<comments>http://www.thedarkvisitor.com/2008/07/chinese-hacker-withered-rose-returns/#comments</comments>
		<pubDate>Mon, 14 Jul 2008 00:41:35 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
		
		<category><![CDATA[Hacker History]]></category>

		<category><![CDATA[Hacker Hunting]]></category>

		<category><![CDATA[Hacker Organization]]></category>

		<category><![CDATA[Hackers Talking]]></category>

		<category><![CDATA[Chinese hackers]]></category>

		<category><![CDATA[mghacker]]></category>

		<category><![CDATA[NCPH]]></category>

		<category><![CDATA[Withered Rose]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=649</guid>
		<description><![CDATA[

UPDATE: Dominic reminds me that some people might not be as Chinese hacker obsessed as myself and suggests I give some links as to why Withered Rose is important.  Whoops on my part! For some background on rose, read here and here.
As mentioned yesterday and updated today, Withered Rose (Tan Dailin) is back to his [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;">
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wordpress/wp-content/uploads/2008/07/rose22.jpg" ><img class="alignnone size-full wp-image-650 aligncenter" title="rose22" src="http://www.thedarkvisitor.com/wordpress/wp-content/uploads/2008/07/rose22.jpg" alt="" width="471" height="348" /></a></p>
<p>UPDATE: Dominic reminds me that some people might not be as Chinese hacker obsessed as myself and suggests I give some links as to why Withered Rose is important.  Whoops on my part! For some background on rose, read <a href="http://www.time.com/time/magazine/article/0,9171,1692063,00.html" onclick="javascript:pageTracker._trackPageview('outbound//http://www.time.com/time/magazine/article/0,9171,1692063,00.html');">here</a> and <a href="http://www.thedarkvisitor.com/2007/12/your-clever-cake-disguise-is-no-match-for-our-defrosting-technology/" >here</a>.</p>
<p>As mentioned yesterday and updated today, Withered Rose (Tan Dailin) is back to his old haunts; both mghacker.com and ncph.net websites are up and running again. Just a couple of observations:</p>
<p>1) Rose has done some scrubbing of his personal blog mghacker.com. Had to go to the wayback machine to make sure but you can tell a number of posts have been deleted for some reason by comparing the <a href="http://web.archive.org/web/*/http://www.mghacker.com" onclick="javascript:pageTracker._trackPageview('outbound//http://web.archive.org/web/*/http://www.mghacker.com');">wayback machine</a> to what is listed on the <a href="http://www.mghacker.com/default.asp" onclick="javascript:pageTracker._trackPageview('outbound//http://www.mghacker.com/default.asp');">current blog&#8217;s archive</a>. Rose has wiped out everything prior to March of 2007 and selectively edited the months still showing.</p>
<p>2) Not sure why but at least four of the new post on ncph.net are old posts from the mghacker.com blog:</p>
<p><strong>a.</strong></p>
<p>Mghacker <a href="http://www.mghacker.com/article.asp?id=25" onclick="javascript:pageTracker._trackPageview('outbound//http://www.mghacker.com/article.asp?id=25');">再现社会工程学</a> (29 Mar 2007)<br />
Ncph <a href="http://www.ncph.net/ct/ZaiXianSheHuiGongChengXue/" onclick="javascript:pageTracker._trackPageview('outbound//http://www.ncph.net/ct/ZaiXianSheHuiGongChengXue/');">再现社会工程学</a> (31 May 2008)</p>
<p><strong>b.</strong></p>
<p>Mghacker <a href="http://www.mghacker.com/article.asp?id=30" onclick="javascript:pageTracker._trackPageview('outbound//http://www.mghacker.com/article.asp?id=30');">3389密码的嗅探 </a>(29 Mar 2007)</p>
<p>Ncph <a href="http://www.ncph.net/ct/3389MiMaDeXiuTan/" onclick="javascript:pageTracker._trackPageview('outbound//http://www.ncph.net/ct/3389MiMaDeXiuTan/');">3389密码的嗅探</a> (11 May 2008)</p>
<p><strong>c.</strong></p>
<p>Mghacker <a href="http://www.mghacker.com/article.asp?id=36" onclick="javascript:pageTracker._trackPageview('outbound//http://www.mghacker.com/article.asp?id=36');">Rainbow Table 分析</a> (10 Apr 2007)</p>
<p>Ncph <a href="http://www.ncph.net/ld/Rainbow_Table_FenXi/" onclick="javascript:pageTracker._trackPageview('outbound//http://www.ncph.net/ld/Rainbow_Table_FenXi/');">Rainbow Table 分析</a> (11 May 2008)</p>
<p><strong>d.</strong></p>
<p>Mghacker <a href="http://www.mghacker.com/article.asp?id=40" onclick="javascript:pageTracker._trackPageview('outbound//http://www.mghacker.com/article.asp?id=40');">获取cuteftp中的ssh密码</a> (16 May 2007)</p>
<p>Ncph <a href="http://www.ncph.net/ld/HuoQucuteftpZhongDesshMiMa/" onclick="javascript:pageTracker._trackPageview('outbound//http://www.ncph.net/ld/HuoQucuteftpZhongDesshMiMa/');">获取cuteftp中的ssh密码</a> (11 May 2008)</p>
<p>3) Whois data shows that NCPH.net administrative contact as:</p>
<p>Administrative Contact:<br />
ncph studio<br />
ncph studio ()<br />
si chuan li gong xue yuan<br />
zigong, Sichuan, cn 643000<br />
P: +86.13154663992 F: +86.13154663992</p>
<p>Sichuan Ligong Xueyuan is the <a href="http://www.suse.edu.cn/" onclick="javascript:pageTracker._trackPageview('outbound//http://www.suse.edu.cn/');">Sichuan University of Science and Engineering.</a> Rose founded NCPH while a student at the university. A Chinese hacker going by the name of Rodag, who was also a member of NCPH lists the university as a contact on <a href="http://rodag.blogbus.com/">his blog.<br />
</a></p>
<p>The contact number 86.13154663992, was <a href="http://www.thedarkvisitor.com/2007/12/your-clever-cake-disguise-is-no-match-for-our-defrosting-technology/#comment-38" >noted by Jumper in an IRC log</a>:</p>
<blockquote><p># jumperon 08 Dec 2007 at 11:04 pm edit this</p>
<p>In the second picture of Rose, he is using a tool called Metasploit on his computer. http://www.metasploit.com.</p>
<p>IDefense has a lot of stuff on NCPH and Rose. There are a couple of archived webcast videos about them on idefense’ website. I did a bunch of searching and found this funny tidbit:</p>
<p>21:41 gila poyo<br />
21:41 you computer is hack by chinese’s hack infall, shit!<br />
21:41 from http://www.chinahonker.com my name is tan dailin<br />
21:41 contact us with QQ 5372453 or<br />
21:41 tel:<strong>86+0+13154663992</strong><br />
21:41 my blog :www.mghacker.com or http://www.ncph.net<br />
21:41 ~~~~~~~~~~~~~~~~~~~~~~~~~shit! you are a pig !<br />
21:41 i found this in some machine<br />
21:41 haha<br />
21:41 YOUR COMPUTER IS HACK</p>
<p>It is from an archived IRC log. There isn’t any more context to go off of so I’m not sure who is who in this. Gila poyo is malay but I don’t know what it means.</p></blockquote>
<p>My guess is the at the two of them are old college buddies.</p>
<p>4) What does this random sampling of information mean? Not much. Just wanted people to be aware that Mr. Rose is back in business and on the internet.</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-hacker-withered-rose-returns%2F&amp;title=Chinese+hacker+Withered+Rose+returns" onclick="javascript:pageTracker._trackPageview('outbound//http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-hacker-withered-rose-returns%2F&amp;title=Chinese+hacker+Withered+Rose+returns');" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-hacker-withered-rose-returns%2F&amp;title=Chinese+hacker+Withered+Rose+returns" onclick="javascript:pageTracker._trackPageview('outbound//http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-hacker-withered-rose-returns%2F&amp;title=Chinese+hacker+Withered+Rose+returns');" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-hacker-withered-rose-returns%2F&amp;title=Chinese+hacker+Withered+Rose+returns" onclick="javascript:pageTracker._trackPageview('outbound//http://reddit.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-hacker-withered-rose-returns%2F&amp;title=Chinese+hacker+Withered+Rose+returns');" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-hacker-withered-rose-returns%2F&amp;title=Chinese+hacker+Withered+Rose+returns" onclick="javascript:pageTracker._trackPageview('outbound//http://del.icio.us/post?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-hacker-withered-rose-returns%2F&amp;title=Chinese+hacker+Withered+Rose+returns');" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-hacker-withered-rose-returns%2F&amp;title=Chinese+hacker+Withered+Rose+returns', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-hacker-withered-rose-returns%2F" onclick="javascript:pageTracker._trackPageview('outbound//http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-hacker-withered-rose-returns%2F');" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-hacker-withered-rose-returns%2F" onclick="javascript:pageTracker._trackPageview('outbound//http://technorati.com/faves?add=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-hacker-withered-rose-returns%2F');" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-hacker-withered-rose-returns%2F&amp;title=Chinese+hacker+Withered+Rose+returns" onclick="javascript:pageTracker._trackPageview('outbound//http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-hacker-withered-rose-returns%2F&amp;title=Chinese+hacker+Withered+Rose+returns');" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-hacker-withered-rose-returns%2F&amp;title=Chinese+hacker+Withered+Rose+returns" onclick="javascript:pageTracker._trackPageview('outbound//http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fchinese-hacker-withered-rose-returns%2F&amp;title=Chinese+hacker+Withered+Rose+returns');" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/07/chinese-hacker-withered-rose-returns/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Withered Rose, NCPH.net active again?</title>
		<link>http://www.thedarkvisitor.com/2008/07/withered-rose-ncphnet-active-again/</link>
		<comments>http://www.thedarkvisitor.com/2008/07/withered-rose-ncphnet-active-again/#comments</comments>
		<pubDate>Sun, 13 Jul 2008 03:58:53 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
		
		<category><![CDATA[Hacker Organization]]></category>

		<category><![CDATA[Hackers Talking]]></category>

		<category><![CDATA[Leaders]]></category>

		<category><![CDATA[Chinese hackers]]></category>

		<category><![CDATA[NCPH]]></category>

		<category><![CDATA[Withered Rose]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=647</guid>
		<description><![CDATA[
UPDATE 13 JULY 08: Still doing some research but at this point it  is kind of a moot question&#8230; CHINESE HACKER WITHERED ROSE HAS RETURNED! Why I don&#8217;t do things the simple way is one of those questions that may never be answered. Did you checked his blog site?  Yep, Withered Rose reopened it on [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wordpress/wp-content/uploads/2008/07/ncphpic.jpg" ><img class="alignnone size-full wp-image-648" title="ncphpic" src="http://www.thedarkvisitor.com/wordpress/wp-content/uploads/2008/07/ncphpic.jpg" alt="" width="239" height="162" /></a></p>
<p><strong>UPDATE 13 JULY 08: </strong>Still doing some research but at this point it  is kind of a moot question&#8230;<strong> CHINESE HACKER WITHERED ROSE HAS RETURNED!</strong> Why I don&#8217;t do things the simple way is one of those questions that may never be answered. Did you checked his blog site?  Yep, <a href="http://www.mghacker.com/" onclick="javascript:pageTracker._trackPageview('outbound//http://www.mghacker.com/');">Withered Rose reopened it on 2 July 08</a>.  The only explanation given for the long absence was that he was busy but his new job allows him time to blog.  More later.</p>
<p>Jumper and I are in the process of looking through the posts at <a href="http://www.ncph.net/" onclick="javascript:pageTracker._trackPageview('outbound//http://www.ncph.net/');">NCPH.net</a> (it became active again on 14 April 08), a site previously run by <a href="http://www.thedarkvisitor.com/2007/12/your-clever-cake-disguise-is-no-match-for-our-defrosting-technology/" >Withered Rose</a>, to determine if it is indeed the same organization.  The site went down after it received a bit of notoriety from a Time&#8217;s article titled <em><a href="http://www.time.com/time/magazine/article/0,9171,1692063,00.html" onclick="javascript:pageTracker._trackPageview('outbound//http://www.time.com/time/magazine/article/0,9171,1692063,00.html');">Enemies at The Firewall.</a> </em></p>
<p>There are at least two articles that detail hacks of Taiwanese websites but it is uncertain if it is still run by Rose.</p>
<p>Hopefully, more to follow.</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fwithered-rose-ncphnet-active-again%2F&amp;title=Withered+Rose%2C+NCPH.net+active+again%3F" onclick="javascript:pageTracker._trackPageview('outbound//http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fwithered-rose-ncphnet-active-again%2F&amp;title=Withered+Rose%2C+NCPH.net+active+again%3F');" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fwithered-rose-ncphnet-active-again%2F&amp;title=Withered+Rose%2C+NCPH.net+active+again%3F" onclick="javascript:pageTracker._trackPageview('outbound//http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fwithered-rose-ncphnet-active-again%2F&amp;title=Withered+Rose%2C+NCPH.net+active+again%3F');" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fwithered-rose-ncphnet-active-again%2F&amp;title=Withered+Rose%2C+NCPH.net+active+again%3F" onclick="javascript:pageTracker._trackPageview('outbound//http://reddit.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fwithered-rose-ncphnet-active-again%2F&amp;title=Withered+Rose%2C+NCPH.net+active+again%3F');" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fwithered-rose-ncphnet-active-again%2F&amp;title=Withered+Rose%2C+NCPH.net+active+again%3F" onclick="javascript:pageTracker._trackPageview('outbound//http://del.icio.us/post?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fwithered-rose-ncphnet-active-again%2F&amp;title=Withered+Rose%2C+NCPH.net+active+again%3F');" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fwithered-rose-ncphnet-active-again%2F&amp;title=Withered+Rose%2C+NCPH.net+active+again%3F', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fwithered-rose-ncphnet-active-again%2F" onclick="javascript:pageTracker._trackPageview('outbound//http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fwithered-rose-ncphnet-active-again%2F');" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fwithered-rose-ncphnet-active-again%2F" onclick="javascript:pageTracker._trackPageview('outbound//http://technorati.com/faves?add=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fwithered-rose-ncphnet-active-again%2F');" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fwithered-rose-ncphnet-active-again%2F&amp;title=Withered+Rose%2C+NCPH.net+active+again%3F" onclick="javascript:pageTracker._trackPageview('outbound//http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fwithered-rose-ncphnet-active-again%2F&amp;title=Withered+Rose%2C+NCPH.net+active+again%3F');" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fwithered-rose-ncphnet-active-again%2F&amp;title=Withered+Rose%2C+NCPH.net+active+again%3F" onclick="javascript:pageTracker._trackPageview('outbound//http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fwithered-rose-ncphnet-active-again%2F&amp;title=Withered+Rose%2C+NCPH.net+active+again%3F');" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/07/withered-rose-ncphnet-active-again/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Maarten Van Horenbeeck speaking at SANS Fire DC</title>
		<link>http://www.thedarkvisitor.com/2008/07/maarten-van-horenbeeck-speaking-at-sans-fire-dc/</link>
		<comments>http://www.thedarkvisitor.com/2008/07/maarten-van-horenbeeck-speaking-at-sans-fire-dc/#comments</comments>
		<pubDate>Thu, 10 Jul 2008 23:08:59 +0000</pubDate>
		<dc:creator>jumper</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=646</guid>
		<description><![CDATA[Remember Crouching Powerpoint, Hidden Trojan?  Maarten VAn Horenbeeck will be giving a presentation at the SANS Fire conference in DC later this month.
Is Troy Burning? An analysis of targeted cyber attacks.
- Maarten Van Horenbeeck, SANS ISC
- Thursday, July 24, 2008 * 7:00pm
The use of trojans in targeted attacks has been known dating back to at [...]]]></description>
			<content:encoded><![CDATA[<p>Remember <a href="http://www.thedarkvisitor.com/2008/02/crouching-powerpoint-hidden-trojan-by-maarten-van-horenbeeck/" >Crouching Powerpoint, Hidden Trojan</a>?  Maarten VAn Horenbeeck will be giving a presentation at the SANS Fire conference in DC later this month.</p>
<p><strong>Is Troy Burning? An analysis of targeted cyber attacks.</strong><br />
- Maarten Van Horenbeeck, SANS ISC<br />
- Thursday, July 24, 2008 * 7:00pm</p>
<p>The use of trojans in targeted attacks has been known dating back to at least 2002. However, only since 2005 has their use and methodology become relatively widespread and better understood. Recently some of the more notorious attacks, especially those on governments, have been widely discussed in the media, but little technical information is available.</p>
<p>This presentation is based on private investigations of targeted attacks against various organizations, and provides a detailed view on the methodologies, both from a technical as a social engineering perspective, most popular in these attacks. In addition, it briefly touches on how effective today&#8217;s protection mechanisms are and to what degree these attacks can be mitigated and detected.</p>
<p> </p>
<p>More details on the conference <a href="http://www.sans.org/sansfire08/special.php" onclick="javascript:pageTracker._trackPageview('outbound//http://www.sans.org/sansfire08/special.php');">here</a>.  If anyone is going, please let me or Heike know.</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fmaarten-van-horenbeeck-speaking-at-sans-fire-dc%2F&amp;title=Maarten+Van+Horenbeeck+speaking+at+SANS+Fire+DC" onclick="javascript:pageTracker._trackPageview('outbound//http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fmaarten-van-horenbeeck-speaking-at-sans-fire-dc%2F&amp;title=Maarten+Van+Horenbeeck+speaking+at+SANS+Fire+DC');" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fmaarten-van-horenbeeck-speaking-at-sans-fire-dc%2F&amp;title=Maarten+Van+Horenbeeck+speaking+at+SANS+Fire+DC" onclick="javascript:pageTracker._trackPageview('outbound//http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fmaarten-van-horenbeeck-speaking-at-sans-fire-dc%2F&amp;title=Maarten+Van+Horenbeeck+speaking+at+SANS+Fire+DC');" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fmaarten-van-horenbeeck-speaking-at-sans-fire-dc%2F&amp;title=Maarten+Van+Horenbeeck+speaking+at+SANS+Fire+DC" onclick="javascript:pageTracker._trackPageview('outbound//http://reddit.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fmaarten-van-horenbeeck-speaking-at-sans-fire-dc%2F&amp;title=Maarten+Van+Horenbeeck+speaking+at+SANS+Fire+DC');" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fmaarten-van-horenbeeck-speaking-at-sans-fire-dc%2F&amp;title=Maarten+Van+Horenbeeck+speaking+at+SANS+Fire+DC" onclick="javascript:pageTracker._trackPageview('outbound//http://del.icio.us/post?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fmaarten-van-horenbeeck-speaking-at-sans-fire-dc%2F&amp;title=Maarten+Van+Horenbeeck+speaking+at+SANS+Fire+DC');" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fmaarten-van-horenbeeck-speaking-at-sans-fire-dc%2F&amp;title=Maarten+Van+Horenbeeck+speaking+at+SANS+Fire+DC', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fmaarten-van-horenbeeck-speaking-at-sans-fire-dc%2F" onclick="javascript:pageTracker._trackPageview('outbound//http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fmaarten-van-horenbeeck-speaking-at-sans-fire-dc%2F');" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fmaarten-van-horenbeeck-speaking-at-sans-fire-dc%2F" onclick="javascript:pageTracker._trackPageview('outbound//http://technorati.com/faves?add=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fmaarten-van-horenbeeck-speaking-at-sans-fire-dc%2F');" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fmaarten-van-horenbeeck-speaking-at-sans-fire-dc%2F&amp;title=Maarten+Van+Horenbeeck+speaking+at+SANS+Fire+DC" onclick="javascript:pageTracker._trackPageview('outbound//http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fmaarten-van-horenbeeck-speaking-at-sans-fire-dc%2F&amp;title=Maarten+Van+Horenbeeck+speaking+at+SANS+Fire+DC');" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fmaarten-van-horenbeeck-speaking-at-sans-fire-dc%2F&amp;title=Maarten+Van+Horenbeeck+speaking+at+SANS+Fire+DC" onclick="javascript:pageTracker._trackPageview('outbound//http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F07%2Fmaarten-van-horenbeeck-speaking-at-sans-fire-dc%2F&amp;title=Maarten+Van+Horenbeeck+speaking+at+SANS+Fire+DC');" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/07/maarten-van-horenbeeck-speaking-at-sans-fire-dc/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
