<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Dark Visitor &#187; CNN</title>
	<atom:link href="http://www.thedarkvisitor.com/tag/cnn/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thedarkvisitor.com</link>
	<description></description>
	<lastBuildDate>Wed, 08 Jun 2011 03:15:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Chinese hackers: Social Engineering and CNN</title>
		<link>http://www.thedarkvisitor.com/2009/01/chinese-hackers-social-engineering-and-cnn/</link>
		<comments>http://www.thedarkvisitor.com/2009/01/chinese-hackers-social-engineering-and-cnn/#comments</comments>
		<pubDate>Sun, 11 Jan 2009 15:46:42 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Hacking for money]]></category>
		<category><![CDATA[Other attacks]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[CNN]]></category>
		<category><![CDATA[Phishing]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=948</guid>
		<description><![CDATA[Top of the news lately has been the ongoing Israel-Hamas conflict and this hasn&#8217;t been lost on Chinese hackers.  RSA is reporting that the fake CNN website is luring people with graphic images of the conflict.  RSA claims that they have shutdown the attack and that the website was hosted in China. Yes, I know [...]]]></description>
			<content:encoded><![CDATA[<p>Top of the news lately has been the ongoing Israel-Hamas conflict and this hasn&#8217;t been lost on Chinese hackers.  <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1416">RSA is reporting that the fake CNN website</a> is luring people with graphic images of the conflict.  RSA claims that they have shutdown the attack and that the website was hosted in China.</p>
<p>Yes, I know hosted in China does not mean Chinese hackers&#8230;fine.</p>
<p style="text-align: center;"><img class="aligncenter" title="China Phishing Site CNN" src="http://www.rsa.com/Blog/bimgs/cnn2.png" alt="" width="368" height="343" /></p>
<p>RSA mentions that the &#8220;gang&#8221; is known but checking the links did not indicate if they were Chinese or from another source.  Left them a comment on the site requesting more info&#8230;so, I leave you with this until informed otherwise.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/01/chinese-hackers-social-engineering-and-cnn/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CNN&#8217;s angry Chinese hacker Xiao Chen returns</title>
		<link>http://www.thedarkvisitor.com/2008/08/cnns-angry-chinese-hacker-xiao-chen-returns/</link>
		<comments>http://www.thedarkvisitor.com/2008/08/cnns-angry-chinese-hacker-xiao-chen-returns/#comments</comments>
		<pubDate>Mon, 18 Aug 2008 23:56:59 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese hacker video]]></category>
		<category><![CDATA[Hacker Organization]]></category>
		<category><![CDATA[Hackers Talking]]></category>
		<category><![CDATA[Hacking for money]]></category>
		<category><![CDATA[US attacks]]></category>
		<category><![CDATA[chinese hacker]]></category>
		<category><![CDATA[CNN]]></category>
		<category><![CDATA[Xiao Chen]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=415</guid>
		<description><![CDATA[In March of this year, CNN ran a story about Xiao Chen and his organization of hackers, reporting that the group had broken into the Pentagon and received payments from the Chinese government. Xiao Chen, in a subsequent interview with the Shanghai Post, refuted all of CNN&#8217;s allegations and tearfully explained how all of this [...]]]></description>
			<content:encoded><![CDATA[<p>In March of this year, CNN ran a story about <a href="http://www.cnn.com/2008/TECH/03/07/china.hackers/index.html?eref=rss_latest">Xiao Chen and his organization of hackers</a>, reporting that the group had broken into the Pentagon and received payments from the Chinese government.</p>
<p>Xiao Chen, in a subsequent interview with the <em>Shanghai Post</em>, <a href="http://www.thedarkvisitor.com/2008/03/chinese-hacker-xiao-chen-mad-as-hell-closes-website/">refuted all of CNN&#8217;s allegations</a> and tearfully explained how all of this controversy had caused him to close his website <a href="http://www.thedarkvisitor.com/2008/03/chinese-hacker-xiao-chens-organization-revealed/"><strong>hack4.com</strong></a>&#8230;he had struggled to create it&#8230;he had poured his heart and soul into it&#8230;and now was left with only had a handful of magic beans to show for his trouble.</p>
<p>I may be mixing my stories but he did elevate whining to an art form.</p>
<p>No need to worry, Xiao Chen pulled himself up, dusted himself off and managed to get back in the hacking game.  Welcome to <a href="http://www.hack4.com/index.html">the new hack4.com </a>, decorated in Olympic themed swirls guaranteed to never go out of style:</p>
<p><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/08/hack4com-new.jpg"><img class="aligncenter size-thumbnail wp-image-416" title="hack4com-new" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/08/hack4com-new.jpg" alt="" width="451" height="456" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/08/cnns-angry-chinese-hacker-xiao-chen-returns/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>More on anticnn.exe</title>
		<link>http://www.thedarkvisitor.com/2008/04/more-on-anticnnexe/</link>
		<comments>http://www.thedarkvisitor.com/2008/04/more-on-anticnnexe/#comments</comments>
		<pubDate>Tue, 22 Apr 2008 13:31:07 +0000</pubDate>
		<dc:creator>jumper</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Nationalism]]></category>
		<category><![CDATA[US attacks]]></category>
		<category><![CDATA[CNN]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=500</guid>
		<description><![CDATA[CNN hating Chinese nationalists can download a tool to send high volumes of requests to www.cnn.com in an attempt to knock it offline.  The tool is bundled in a .rar file that contains a readme and the pre-compiled windows binary.  A quick virus check showed that some scanners identified it as backdoor but that didn&#8217;t [...]]]></description>
			<content:encoded><![CDATA[<p>CNN hating Chinese nationalists can download a tool to send high volumes of requests to www.cnn.com in an attempt to knock it offline.  The tool is bundled in a .rar file that contains a readme and the pre-compiled windows binary.  A quick virus check showed that some scanners identified it as backdoor but that didn&#8217;t seem to be the case.  When I ran the tool, a simple flag icon appeared in the lower right of my test VM.</p>
<p><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/anticnn_flag.png"><img class="alignleft size-full wp-image-505" title="anticnn_flag" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/anticnn_flag.png" alt="" width="182" height="160" /></a></p>
<p> When I click on the flag, the full interface appears with three options:  start/stop, minimize and exit. </p>
<p><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/anticnn_ui.png"><img class="alignnone size-medium wp-image-506" title="anticnn_ui" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/anticnn_ui-300x244.png" alt="" width="300" height="244" /></a></p>
<p>Here is a sample of the request/response I got after running it for a few seconds:</p>
<p><em>GET /aux/con/com1/../../[LAG]../.%%%%%%%%./../../../../fakecnn/redflag-stay-here.php.aspx.asp.cfm.jsp HTTP/1.1</em></p>
<p><em>Accept: */*</em></p>
<p><em>Host: </em><a href="http://www.cnn.com"><em>www.cnn.com</em></a></p>
<p><em>Connection: Keep-Alive</em></p>
<p><em> <br />
HTTP/1.1 400 Bad Request</em></p>
<p><em>Date: Tue, 22 Apr 2008 12:12:34 GMT</em></p>
<p><em>Server: Apache</em></p>
<p><em>Vary: Accept-Encoding</em></p>
<p><em>Content-Length: 287</em></p>
<p><em>Connection: close</em></p>
<p><em>Content-Type: text/html; charset=iso-8859-1</em></p>
<p><em> </em></p>
<p><em>&lt;!DOCTYPE HTML PUBLIC &#8220;-//IETF//DTD HTML 2.0//EN&#8221;&gt;<br />
&lt;html&gt;&lt;head&gt;<br />
&lt;title&gt;400 Bad Request&lt;/title&gt;<br />
&lt;/head&gt;&lt;body&gt;<br />
&lt;h1&gt;Bad Request&lt;/h1&gt;<br />
&lt;p&gt;Your browser sent a request that this server could not understand.&lt;br /&gt;<br />
&lt;/p&gt;<br />
&lt;hr&gt;<br />
&lt;address&gt;Apache Server at </em><a href="http://www.cnn.com"><em>www.cnn.com</em></a><em> Port 80&lt;/address&gt;<br />
&lt;/body&gt;&lt;/html&gt;</em></p>
<p>I read somewhere that it is self-updating but I never saw any requests other than DNS resolution (to my own configured DNS servers, not hard-coded) and requests to www.cnn.com.  I&#8217;ll run it in &#8220;paused&#8221; mode for a while to see what happens.</p>
<p><strong>UPDATE (0100GMT 23 April 08):  </strong>No suspicious traffic came from this binary (apart from what was expected, of course).</p>
<p><strong>UPDATE (1628GMT 24 April 08): </strong>Heike and I have dubbed anticnn.exe the &#8220;Mao-inator&#8221;.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/04/more-on-anticnnexe/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Anatomy of a Chinese hacker attack</title>
		<link>http://www.thedarkvisitor.com/2008/04/495/</link>
		<comments>http://www.thedarkvisitor.com/2008/04/495/#comments</comments>
		<pubDate>Tue, 22 Apr 2008 01:37:21 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Hacker Organization]]></category>
		<category><![CDATA[US attacks]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[CNN]]></category>
		<category><![CDATA[DDoS]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=495</guid>
		<description><![CDATA[Even though a major attack did not occur on CNN, there were some lessons learned that we can take away from this event. So what did we learn? Here are some of things I noted: We can reconstruct a bit of the social side of the attack There is some evidence about their method of [...]]]></description>
			<content:encoded><![CDATA[<p>Even though a major <a href="http://www.thedarkvisitor.com/2008/04/breaking-anti-cnns-call-for-european-protests-spreading-onlinebreaking-cnn-possible-target-of-chinese-hacker-attack-on-19-april-what-beijing-police-supplied-eggs-to-protesters-during-anti-japan/">attack did not occur on CNN</a>, there were some lessons learned that we can take away from this event.  So what did we learn?   Here are some of things I noted:</p>
<ol>
<li>We can reconstruct a bit of the social side of the attack</li>
<li>There is some evidence about their method of organization for operational tactics</li>
<li>Stockpile of ready made software for novice attackers</li>
<li>Possible reasons the attack was canceled</li>
</ol>
<p style="text-align: center;"><strong>Social</strong></p>
<p style="text-align: left;">The first thing we need to do is identify the reason behind the attack.  What were the catalysts that led the Chinese hacker community to go after CNN?  This would be my list:</p>
<ol>
<li>CNN <a href="http://www.cnn.com/2008/TECH/03/07/china.hackers/index.html?eref=rss_latest">report on Chinese hackers</a> is seen as unfair and accusations that parts of the<a href="http://www.thedarkvisitor.com/2008/03/chinese-hacker-xiao-chen-mad-as-hell-closes-website/"> CNN interview were fabricated</a></li>
<li>CNN makes <a href="http://www.iol.co.za/index.php?art_id=nw20080415132027187C604276">remarks about the Tibet situation</a> that angers the nation</li>
<li>Anti-CNN&#8217;s <a href="http://www.thedarkvisitor.com/2008/04/breaking-anti-cnns-call-for-european-protests-spreading-onlinebreaking-cnn-possible-target-of-chinese-hacker-attack-on-19-april-what-beijing-police-supplied-eggs-to-protesters-during-anti-japan/">call for protests</a> provides timing for coordinated effort</li>
<li>Beijing&#8217;s call for an apology from CNN may have been seen as tacit support for the attack.  Or, at least that there would be no retribution if one did take place. This might be the most important factor of all.</li>
<li>Reliving the glory days of the Sino-US cyber conflicts</li>
<li>Making a name for themselves and building their own Chinese hacker cell.  Many of China&#8217;s most famous hackers got their start during the early years of conflict with different nations.</li>
</ol>
<p style="text-align: center;"><strong>Organization</strong></p>
<p>With the decision made to launch an attack, they seem to have decided to use the website that cn_magistrate opened in 2007:</p>
<p>Domain Name: <strong style="color: #333333;">hacksa.cn</strong><br />
ROID: 20070811s10001s50288265-cn<br />
Domain Status: ok<br />
Registrant Organization: 判官<br />
Registrant Name: 判官<br />
Administrative Email: Kenan2677@126.com<br />
Sponsoring Registrar: 北京万网志成科技有限公司<br />
Name Server:ns1.okidc.com Name Server:ns2.okidc.com<br />
Registration Date: 2007-08-11 11:59<br />
Expiration Date: 2008-08-11 11:59</p>
<p>The website would be used for a central gathering point, dissemination of information and organization. During this phase, they probably planned their basic attack formation and strategy.  Using the QQ charts found on www.hacksa.com, I was able to make this very rough organizational chart:</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/rforgchart.jpg"><img class="alignnone size-medium wp-image-496" title="rforgchart" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/rforgchart-300x207.jpg" alt="" width="300" height="207" /></a></p>
<p style="text-align: center;">(Yes, very rough and ugly chart.  God I miss my I2 for making charts)</p>
<p>The QQ numbers listed six headquarters units (probably the more experienced hackers), 42 regular groups (actually 44, since he started with zero and may have accidentally listed group 32 twice), and one propaganda unit.  For easy math, I took the number of headquarter units and evenly divided the regular units among them as best I could.  You will note I put the two group 32&#8242;s together and placed the left over regular units into the final formation. The propaganda unit was made as a separate organization, some of the additional units may have belonged with them.  Of course, cn_magistrate may have used a completely different configuration but this is the one that made the most sense to me.  The chart brings up several questions:</p>
<ol>
<li>The character 满 to the right of the groups means filled.  Why did cn_magistrate skip the additional group 32 and group 33 when bringing the units up to full strength?  Groups 37-42 seem logical if you are filling them in as recruits become available.  Were the extra group 32 and group 33 special somehow?</li>
<li>Only one of the headquarter units shows it to be full.  Were they possibly having trouble getting skilled hackers to join the attack?</li>
<li>How many people did it take to fill up the groups?  We can guess that it was more than one, since a QQ number was assigned each of the groups.</li>
<li>What was the function of the propaganda unit?  A possible answer is that it was to spread news if the attack turned out to be successful.  Useless to have a political attack if no one is aware it happened.</li>
</ol>
<p>The next thing we are able to tell was the means they used to get recruits to participate in the attack.  This was accomplished through posting requests on popular websites and probably through restricted registration areas.   Here is a listing of just some of the websites the group posted to:</p>
<p>http://bbs.neteasy.cn/showthread.php?p=984976</p>
<p>http://www.coogo.net/bbs/showtopic-444648.aspx http://www.ytjt.com.cn/bbs/redirect.php?tid=36644&amp;goto=lastpost http://www.ipark.cn/bbs/Post.asp?PostID=836336</p>
<p>http://blog.xuite.net/lemon_head/simple/16728332</p>
<p>http://tieba.baidu.com/f?kz=357748876</p>
<p>http://bbs.neteasy.cn/showthread.php?p=984976</p>
<p>http://www.coogo.net/bbs/showtopic-444648.aspx http://www.ytjt.com.cn/bbs/redirect.php?tid=36644&amp;goto=lastpost http://www.ipark.cn/bbs/Post.asp?PostID=836336</p>
<p>http://blog.xuite.net/lemon_head/simple/16728332</p>
<p>http://tieba.baidu.com/f?kz=357748876</p>
<p>http://bbs.hackbase.com/viewthread.php?tid=3210548</p>
<p>http://tianya.com</p>
<p>The group used thes sites to request compromised computers and while I can&#8217;t locate the posting now, also funds.  Was the money donated to be used to rent botnets?</p>
<p style="text-align: center;"><strong>Stockpile</strong></p>
<p>The website http://playgood.ys168.com was used to stock scripted software that could be downloaded by recruits who had little technical ability.</p>
<p style="text-align: center;"><strong>End Game</strong></p>
<p>Finally, the assault was <a href="http://www.thedarkvisitor.com/2008/04/chinese-hacker-group-identified-as-revenge-of-the-flame-calls-off-attack-on-cnntoo-many-people-know/">called off</a> and then the organization was <a href="http://www.thedarkvisitor.com/2008/04/revenge-of-the-flame-disbands-denies-all-responsibility-for-attack-on-cnnand-kills-website/">disband</a>.  Big question, why?</p>
<ol>
<li>As stated, that too many people were aware of the operation</li>
<li>Unable to fill the units enough to be effective</li>
<li>Just plain worried about the consequences</li>
<li>Beijing sent out an order to shut it down</li>
</ol>
<p>Please feel free to comment on other things we should have learned from this or where I totally botched this analysis.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/04/495/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Chinese hackers displaying CNN hack trophy?</title>
		<link>http://www.thedarkvisitor.com/2008/04/chinese-hackers-displaying-cnn-hack-trophy/</link>
		<comments>http://www.thedarkvisitor.com/2008/04/chinese-hackers-displaying-cnn-hack-trophy/#comments</comments>
		<pubDate>Mon, 21 Apr 2008 10:17:27 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Nationalism]]></category>
		<category><![CDATA[Tibet]]></category>
		<category><![CDATA[US attacks]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[CNN]]></category>
		<category><![CDATA[Hack]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=493</guid>
		<description><![CDATA[Danwei reporting that Chinese hackers are celebrating a successful hack on a portion of the CNN website with screen shots of their trophy: The top picture is screen grab that shows the current state of the website. The second image shows the hacked web page and the slogans left by the hackers, both in English [...]]]></description>
			<content:encoded><![CDATA[<p>Danwei reporting that Chinese hackers are celebrating a successful hack on a portion of the CNN website with <a href="http://www.danwei.org/internet/anticnn_hackers_misfired.php">screen shots of their trophy:</a></p>
<blockquote><p>The top picture is screen grab that shows the current state of the website. The second image shows the hacked web page and the slogans left by the hackers, both in English and Chinese.:</p></blockquote>
<blockquote></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/04/chinese-hackers-displaying-cnn-hack-trophy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BREAKING: Upcoming Chinese hacker attack on CNN building steam</title>
		<link>http://www.thedarkvisitor.com/2008/04/breaking-upcoming-chinese-hacker-attack-on-cnn-building-steam/</link>
		<comments>http://www.thedarkvisitor.com/2008/04/breaking-upcoming-chinese-hacker-attack-on-cnn-building-steam/#comments</comments>
		<pubDate>Thu, 17 Apr 2008 23:25:05 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Nationalism]]></category>
		<category><![CDATA[Tibet]]></category>
		<category><![CDATA[US attacks]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[CNN]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=484</guid>
		<description><![CDATA[UPDATE: It looks like the organizers might be trying to put a stop to the attack due to the number of people who are aware of it. Translating some of it now. UPDATE to UPDATE While the group may be trying to call off the attack, it might be too late. CNN is now reporting [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #ff0000;">UPDATE</span>: It looks like the organizers might be trying to put a stop to the attack due to the number of people who are aware of it. Translating some of it now.<br />
<span style="color: #ff0000;">UPDATE to UPDATE</span> While the group may be trying to call off the attack, it might be too late. CNN is now reporting that they have been targeted in an attempt to <a href="http://edition.cnn.com/2008/TECH/04/18/cnn.websites/">disrupt their web site</a>.<br />
<span style="color: #ff0000;">FINAL UPDATE FOR THIS POST</span>: See the newest release by the <a href="http://www.thedarkvisitor.com/2008/04/chinese-hacker-group-identified-as-revenge-of-the-flame-calls-off-attack-on-cnntoo-many-people-know/">group planning attack on CNN here</a></p>
<p><iframe src="http://free.timeanddate.com/clock/izgk4e1/n33/fs22/fcf00/bo2/tt0/tw1" frameborder="0" width="411" height="30"></iframe></p>
<p>First, I have added a clock with the Beijing local time because it crossed my mind that some people might be thinking the scheduled attack on CNN is going to take place on US date, time. Nope, Beijing local. So that means it is suppose to take place tomorrow. I will leave the clock up if you want to check back.</p>
<p>Second, many more Chinese sites, not just hacker, starting to call for the DDOS attack on CNN. Also they are starting to <a href="http://bbs.gliet.edu.cn/bbs/index.php?s=40e077245937853cd6075b3d1cf365f2&amp;showtopic=157692&amp;st=0�entry2321659">solidify their plans</a>. Here are the details from one posting on the Guilin University of Electronic Technology bulletin board:</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/guilin.jpg"><img class="alignnone size-full wp-image-485" title="guilin" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/guilin.jpg" alt="" width="309" height="71" /></a></p>
<ol>
<li>Attack will start on 19 April 2008, at 8:00 pm</li>
<li>DDOS attack on www.cnn.com</li>
<li>The DDOS attack is going to last over three hours</li>
<li>They need a large number of compromised computers to carry out the attack and are requesting everyone&#8217;s support in putting to together the number needed</li>
</ol>
<p>The plan has many more details but unfortunately the language is too technical for me to translate.</p>
<p>Here are additional sites calling for the attack on CNN.</p>
<p>http://bbs.neteasy.cn/showthread.php?p=984976</p>
<p>http://www.coogo.net/bbs/showtopic-444648.aspx</p>
<p>http://www.ytjt.com.cn/bbs/redirect.php?tid=36644&#038;goto=lastpost</p>
<p>http://www.ipark.cn/bbs/Post.asp?PostID=836336</p>
<p>http://blog.xuite.net/lemon_head/simple/16728332</p>
<p>http://tieba.baidu.com/f?kz=357748876</p>
<p>Probably many more out there.</p>
<p><strong>UPDATE</strong>: Carl Jongsma, from <em>Computer World</em>, was kind enough to provide us a <a href="http://www.computerworld.com.au/index.php/id;115383651;fp;4194304;fpid;1">little press</a> on this breaking situation.</p>
<p><strong>UPDATE</strong>: Tried once again to contact CNN and warn them of the scheduled attack. If anyone has a better contact than just their news tip e-mail, please inform them.</p>
<p><strong>UPDATE (APRIL 18 1556GMT; Jumper): </strong>Arbor Networks is using their tools to monitor the situation.  Take a look at Jose Nazario&#8217;s post <a href="http://asert.arbornetworks.com/2008/04/impending-cnncom-ddos/">here</a>.</p>
<p><strong>UPDATE: </strong>Since we have some smart people looking at the blog, I wanted to post below part of the Chinese hackers&#8217; attack plan. This seems to be part of the DDoS call for large numbers of attacking computers. Will supply what I can about the Chinese, though it is possibly wrong. If someone knows what this is referring to please post in the comments and we will move it to the blog:</p>
<p>总群：29332975 (This refers to the total number)<br />
复仇的火焰分群1：10093595 (Revenge of the flame group 1)<br />
复仇的火焰分群2：60087657 (Revenge of the flame group 2)<br />
复仇的火焰分群3：17697381 (Revenge of the flame group 3)<br />
复仇的火焰分群4：52911651 (Revenge of the flame group 4)<br />
复仇的火焰分群5：13283694 (Revenge of the flame group 5)<br />
复仇的火焰分群6：52274747 (Revenge of the flame group 6)<br />
复仇的火焰分群7：13735729 (Revenge of the flame group 7)<br />
复仇的火焰分群8：28556275 (Revenge of the flame group 8 )<br />
复仇的火焰分群9：8333214 (Revenge of the flame group 9)<br />
复仇的火焰分群10：24207831 (Revenge of the flame group 10)<br />
复仇的火焰分群11：18574877 (Revenge of the flame group 11)</p>
<p><strong>UPDATE to UPDATE</strong> Jumper figured out that these were probably the QQ numbers for the group leaders of the attack. When I went back and looked at some of the sites calling for the DDoS attack, one did list it as QQ群 or QQ groups.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/04/breaking-upcoming-chinese-hacker-attack-on-cnn-building-steam/feed/</wfw:commentRss>
		<slash:comments>27</slash:comments>
		</item>
		<item>
		<title>BREAKING: Anti-CNN&#8217;s call for European protests spreading onlineBREAKING: CNN possible target of Chinese hacker attack on 19 April  What?: Beijing police supplied eggs to protesters during anti-Japanese demonstrations</title>
		<link>http://www.thedarkvisitor.com/2008/04/breaking-anti-cnns-call-for-european-protests-spreading-onlinebreaking-cnn-possible-target-of-chinese-hacker-attack-on-19-april-what-beijing-police-supplied-eggs-to-protesters-during-anti-japan/</link>
		<comments>http://www.thedarkvisitor.com/2008/04/breaking-anti-cnns-call-for-european-protests-spreading-onlinebreaking-cnn-possible-target-of-chinese-hacker-attack-on-19-april-what-beijing-police-supplied-eggs-to-protesters-during-anti-japan/#comments</comments>
		<pubDate>Wed, 16 Apr 2008 23:35:24 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Hackers Talking]]></category>
		<category><![CDATA[Nationalism]]></category>
		<category><![CDATA[Tibet]]></category>
		<category><![CDATA[US attacks]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[CNN]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=479</guid>
		<description><![CDATA[Anti-CNN has issued a call for the Chinese flag to wave over Europe on 19 April 2008. The call was issued to show opposition to Europe&#8217;s stance on the Tibet issue. Anti-CNN has called for all overseas Chinese in Germany, France, England and Holland to appear in a simultaneous protest. Overseas Chinese were asked to [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.kina.cc/cm/script/forum/view.asp?Article_id=4748118">Anti-CNN has issued a call for the Chinese flag to wave over Europe</a> on 19 April 2008.  The call was issued to show opposition to Europe&#8217;s stance on the Tibet issue.  <a href="http://www.anti-cnn.com/">Anti-CNN</a> has called for all overseas Chinese in Germany, France, England and Holland to appear in a simultaneous protest. Overseas Chinese were asked to have their voices penetrate the European sky.  It appears the protests may have been scheduled for April 26th, as the announcement asked for people who had already made plans, to switch them to 19 April.  The protests on the 19th are scheduled as follows:</p>
<ol>
<li> 1500-1800hrs, 19 April 2008, at the Bundestag, Platz der Republik, Berlin</li>
<li> 1300-1500hrs, 19 April 2008, two routes (from Talie – Hotel de Ville –  Bastille) or (Republique – Bastille – Hotel de Ville –Bastille, Paris</li>
<li>1100-1500hrs, 19 April 2008, Downing Street outside of Whitehall, England</li>
<li>(No time given) 19 April 2008, Amsterdam, Holland</li>
</ol>
<p>The protests appear to be well organized, with the coordination of donations, banners, flags, T-shirts&#8230;etc.  While it is of course impossible to tell how widespread the demonstrations will be, an online keyword search, using Chinese, did produce <a href="http://www.google.com/search?hl=en&amp;q=4%E6%9C%8819%E6%97%A5+%E5%8F%8DCNN++%E6%AC%A7%E6%B4%B2+%E6%B8%B8%E8%A1%8C+&amp;btnG=Search">several hundred hits</a>.</p>
<p>To coincide with the European protests, several Chinese hacker groups are calling for a DDOS attack on the CNN website to begin at 8:00pm on 19 April 2008.  While only three websites have openly posted about this attack, my guess is that many more calls are going on behind closed doors.</p>
<p>The first screen shot below <a href="http://ricohack.blogspot.com/">calls for an attack similar to the Sino-US hacker war</a>.</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/attackcnn1.jpg"><img class="alignnone size-thumbnail wp-image-480" title="attackcnn1" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/attackcnn1-150x150.jpg" alt="" width="150" height="150" /></a></p>
<p>Could not get the web page for Tianya to open but it clearly calls for a DDOS attack on the CNN website to begin at 8:00 pm (Beijing time) on 19 April 2008.</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/attackcnn2.jpg"><img class="alignnone size-medium wp-image-481" title="attackcnn2" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/attackcnn2-300x60.jpg" alt="" width="300" height="60" /></a></p>
<p>Over at Hackbase, Dreamsmaker is also putting out the word for an <a href="http://bbs.hackbase.com/viewthread.php?tid=3210548">attack on the CNN website</a>.</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/attackcnn3.jpg"><img class="alignnone size-medium wp-image-482" title="attackcnn3" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/attackcnn3-300x153.jpg" alt="" width="300" height="153" /></a></p>
<p>The final tidbit of this story comes from a thread discussing the possibility of having demonstrations inside the country to support China&#8217;s position on Tibet.  It was mentioned that during the <a href="http://en.wikipedia.org/wiki/2005_anti-Japanese_demonstrations">anti-Japanese protests</a> of 2005, all the people who passed out leaflets supporting the protests were punished.  While some thought it was impossible to hold the demonstrations inside&#8230;a commenter calling himself&#8230;<a href="http://www.irelandbbs.com/showthread.php?t=101461&amp;pp=0#pid955008"><strong>little stupid</strong> told this story</a>:</p>
<p>I was in Beijing during that time, leaflets were everywhere.  Although the next day they were all torn down, the schools still had them all over the place.  Even <strong>the Beijing police supplied free eggs to throw at the Japanese Consulate</strong>.</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/littlestupid.jpg"><img class="alignnone size-medium wp-image-483" title="littlestupid" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/littlestupid-300x131.jpg" alt="" width="300" height="131" /></a></p>
<p><strong>UPDATE: From CNN</strong></p>
<p>&#8220;Thank you for contacting CNN. This email is to notify you that your news tip has been received and will be reviewed in a timely manner.  You will be contacted if the news tip is valid and we need further information and verification.</p>
<p>We appreciate your news tip and thank you for choosing CNN as your breaking news source.</p>
<p>Sincerely,</p>
<p>CNN Viewer Communications Management<br />
&#8216;CNN, The Most Trusted Name In News&#8217;</p>
<p>Wonder if they will check before it all goes black? <img src='http://www.thedarkvisitor.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/04/breaking-anti-cnns-call-for-european-protests-spreading-onlinebreaking-cnn-possible-target-of-chinese-hacker-attack-on-19-april-what-beijing-police-supplied-eggs-to-protesters-during-anti-japan/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
	</channel>
</rss>

