<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Dark Visitor &#187; DDoS</title>
	<atom:link href="http://www.thedarkvisitor.com/tag/ddos/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thedarkvisitor.com</link>
	<description></description>
	<lastBuildDate>Tue, 27 Jul 2010 00:14:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>PRC Hacker Street Tax</title>
		<link>http://www.thedarkvisitor.com/2009/04/prc-hacker-street-tax/</link>
		<comments>http://www.thedarkvisitor.com/2009/04/prc-hacker-street-tax/#comments</comments>
		<pubDate>Mon, 27 Apr 2009 03:26:00 +0000</pubDate>
		<dc:creator>jumper</dc:creator>
				<category><![CDATA[China internet]]></category>
		<category><![CDATA[Hacking for money]]></category>
		<category><![CDATA[Arrest]]></category>
		<category><![CDATA[Changsha]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[Extortion]]></category>
		<category><![CDATA[Hunan]]></category>
		<category><![CDATA[Police]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1552</guid>
		<description><![CDATA[Some Chinese hackers have been arrested for performing DDoS extortion attacks.  The hackers launched a successful denial of service attack on a well-known website and then send an SMS text message asking for 30,000RMB (about 4,400 USD).  At least one of the hackers was arrested on April 7th in Changsha City, Hunan Province. See the [...]]]></description>
			<content:encoded><![CDATA[<p>Some Chinese hackers have been arrested for performing DDoS extortion attacks.  The hackers launched a successful denial of service attack on a well-known website and then send an SMS text message asking for 30,000RMB (about 4,400 USD).  At least one of the hackers was arrested on April 7th in <span onmouseover="_tipon(this)" onmouseout="_tipoff()">Changsha City, Hunan Province.</span></p>
<p>See the rest <a title="Hackbase Report (Chinese)" href="http://www.hackbase.com/news/2009-04-26/25522.html">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/04/prc-hacker-street-tax/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Dear Chinese hacker master, I have a question&#8230;</title>
		<link>http://www.thedarkvisitor.com/2008/06/dear-chinese-hacker-master-i-have-a-question/</link>
		<comments>http://www.thedarkvisitor.com/2008/06/dear-chinese-hacker-master-i-have-a-question/#comments</comments>
		<pubDate>Thu, 19 Jun 2008 02:30:08 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Hackers Talking]]></category>
		<category><![CDATA[Hacking for money]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[finance]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=614</guid>
		<description><![CDATA[Dear Chinese hacker master, Sadly, I have all these compromised computers just laying around the place and don&#8217;t know what do with them, could you please help?!? - Confucius&#8230;sed amateur Dear Confused, No need to be embarrassed, we have all experienced this dilemma at one time or another. Let me offer a few simple solutions [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Dear Chinese hacker master</strong>,</p>
<p>Sadly, I have all these compromised computers just laying around the place and don&#8217;t know what do with them, could you please help?!?</p>
<p>- Confu<span style="text-decoration: line-through;">cius</span>&#8230;sed amateur</p>
<p><strong>Dear Confused</strong>,</p>
<p>No need to be embarrassed, we have all experienced this dilemma at one time or another. Let me offer a few simple solutions to this common problem:</p>
<ol>
<li>Steal virtual property from the compromised computer. Take their game account ID, QQ number and Q money.</li>
<li>Steal real property from the compromised computer. Real property can consist of bank accounts or online stock speculator account numbers. There are many types of trojans designed specifically for getting the account numbers of online stock speculators.</li>
<li>Steal people&#8217;s private data. Remember, just like the Edison Chen photo scandal, regular people can be extorted too if you threaten to release their explicit photos on the internet. Use their private information that could be harmful to blackmail them. If you steal commercial data such as financial reports and personnel records it can be used for your illegal benefit. Also, you can attempt to control their webcam in order to fill the desires of peeping toms.</li>
<li>Use the victim&#8217;s connections to get illegal benefits. Perhaps you think your QQ number is insignificant, you don&#8217;t have QQ 秀 (unclear) or QQ money. Not so, your friends QQ numbers, your e-mail contacts and cellphone contacts are all targets for the attacker. The attacker can fake your identity to carry out all manner of illegal activity. Everyone&#8217;s personal connections have commercial worth. The most common example of this is the 12950 service that used groups of QQ numbers to send out trash/spam? information to steal money or the MSN virus that automatically sent out information to your friends to defraud them. <strong>NOTE: the <a href="http://www.chinamobile.com/en/mainland/products/mzone.html">12590 service</a> could refer to this: Optional service Game treasure box makes the mobile into a game machine. A mobile QQ can go anywhere, 12586 online entertainment (that has many strange old friends), 12590 interactive message service (that has various voice monsters), CRBT and MMS (that are full of fun, personalized ring tones and pictures that can be downloaded anytime)……your enjoyment with these features is endless!</strong></li>
<li>Plant rogue software on the compromised computer. This will make it automatically click online advertising for profit. This can really effect your online experience as I suspect everyone hates online pop-up ads. After the attacker controls a lot of compromised computers, they can force out ads and obtain profits from the ad owners. The number one reason for rogue software flooding is that many companies purchase rogue software developers&#8217; advertisements. Other attackers use the rear platform? to covertly click on advertisements in order to gain profits. This causes the ad owner to waste money through invalid clicks.</li>
<li>Use the compromised computer as a springboard (proxy server) to attack other computers. Any type of hacker attack can leave behind traces and in order to better conceal yourself, it is necessary to use many proxy jumps. The compromised computers can act as an agent and a scapegoat. The attacker can disseminate even more trojans and think of your computer as a downloading station. It is a possibility that network speed and performance will be improved with proxy servers.</li>
<li>The compromised computer is the foot soldier to launch DDOS attacks. DDOS attacks can earn money for internet gangs or cyberwarfare (those who engage in it) as some people will hire these internet goons who initiate conflicts. Internet gang members can carry out an attack directly against their target and then blackmail the victim. Compromised computers are a chess piece for internet gangs and DDOS attacks have become a poisonous cancer for the internet.</li>
</ol>
<p>Yep, a little fun in the beginning with this post (I made it up)  but the rest is <a href="http://www.3800hk.com/news/w32/138724.html">a real list of uses for compromised computers put out by Chinese hackers</a>.</p>
<p>I swear I heard the sound of people flipping their webcams towards the ceiling after reading number 3.</p>
<p><strong>UPDATE</strong>: Hat-Tip to Therese who sets me straight on the definition of QQ 秀:</p>
<p>QQ 秀 == QQ “Show”</p>
<p>It’s one of the things that you can spend QQB on. You purchase outfits and accessories to dress up your little avatar. It’s like putting on a show. Therese also provides a Flickr link to &#8220;patriotism QQ-Show.&#8221;</p>
<p><a onclick="pageTracker._trackPageview('/outbound/comment/http://www.flickr.com/photos/keso/2421813915/');" rel="nofollow" href="http://www.flickr.com/photos/keso/2421813915/"><span style="color: #585d8b;">http://www.flickr.com/photos/keso/2421813915/</span></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/06/dear-chinese-hacker-master-i-have-a-question/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Chinese hackers&#8230;DDoS attack services</title>
		<link>http://www.thedarkvisitor.com/2008/05/chinese-hackersddos-attack-services/</link>
		<comments>http://www.thedarkvisitor.com/2008/05/chinese-hackersddos-attack-services/#comments</comments>
		<pubDate>Wed, 21 May 2008 17:23:03 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Hacker Hunting]]></category>
		<category><![CDATA[Hacker Organization]]></category>
		<category><![CDATA[Hackers Talking]]></category>
		<category><![CDATA[Hacking for money]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[money]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=565</guid>
		<description><![CDATA[Meet Demon Group, an organization that specializes in providing much needed hacking services&#8230;their fellow citizens would like to see them dead or jailed&#8230;in no particular order or combination. The screen capture above had to be taken from a Google cache because Demon Group&#8217;s website (www.ddosx.cn) seems to have vanished from the interwebs. I have some [...]]]></description>
			<content:encoded><![CDATA[<p>Meet Demon Group, an organization that specializes in providing much needed hacking services&#8230;their fellow citizens would like to see them dead or jailed&#8230;in no particular order or combination.</p>
<p><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon1.jpg"><img class="alignnone size-medium wp-image-566 aligncenter" title="demon1" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon1-300x277.jpg" alt="" width="300" height="277" /></a><br />
The <a href="http://72.14.205.104/search?q=cache:genNCjLmbx4J:www.ddosx.cn/+ddosx+qq:81991&amp;hl=en&amp;ct=clnk&amp;cd=3&amp;gl=us">screen capture</a> above had to be taken from a Google cache because Demon Group&#8217;s website (www.ddosx.cn) seems to have vanished from the interwebs.  I have some theories on why it disappeared, which I will share later.</p>
<p>First noticed the group when I found one of <a href="http://tieba.baidu.com/f?kw=%D6%D0%B9%FA%BA%DA%BF%CD">their advertisements</a> on Baidu Postings (Large Chinese BBS):</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon2.jpg"><img class="alignnone size-medium wp-image-567 aligncenter" title="demon2" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon2-300x118.jpg" alt="" width="300" height="118" /></a></p>
<p>The group claims to provide various types of <a href="http://tieba.baidu.com/f?kz=383575417">DDoS attack services</a> on internet cafes, websites, private servers, servers&#8230;etc.  They sell attack software packages and rent out specialized tools to gather up infected computers (Guaranteed to gather up no fewer than 600-900 in a single day).  The contact number provided is QQ:81991.</p>
<p style="text-align: center;"><strong>Demon Group Spams</strong></p>
<p>Demon group, you spam your services&#8230;you spam them a lot!  <a href="http://www.google.com/search?hl=en&amp;q=%E6%8F%90%E4%BE%9B%E5%90%84%E7%A7%8DDDOS%E6%94%BB%E5%87%BB%E4%B8%9A%E5%8A%A1QQ81991&amp;btnG=Search">You spam them too much</a>!  Now you have ticked off a guy named Good Good, he would like to see you go to jail, he has reported you to the <strong>INTERNET POLICE</strong>!</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon3.jpg"><img class="alignnone size-medium wp-image-568 aligncenter" title="demon3" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon3-300x208.jpg" alt="" width="300" height="208" /></a></p>
<p><span id="more-285"></span><br />
Internet Police Officer Cha Cha has responded to the <a href="http://jmjl.tjwj.gov.cn/redirect.php?tid=165&amp;goto=lastpost">complaint</a> and says she will be paying close attention -cough- :</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon4.jpg"><img class="alignnone size-full wp-image-569 aligncenter" title="demon4" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon4.jpg" alt="" width="401" height="231" /></a></p>
<p style="text-align: center;">
<p style="text-align: center;"><strong>Demon Group Spams and Lacks Common Sense</strong></p>
<p style="text-align: left;">In another ill-fated attempt to <a href="http://72.14.205.104/search?q=cache:jLHri62_eM0J:tieba.baidu.com/f%3Fkz%3D376521415+ddosx.cn/anrls/article.asp%3Fid%3D136&amp;hl=en&amp;ct=clnk&amp;cd=2&amp;gl=us">promote their website</a>, they appear to have decided to get a viral story started that someone had predicted the Sichuan earthquake two months earlier.  Of course, they linked the story back to a webpage on their own site and continued to repeat the story for over 300 posts.</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon5.jpg"><img class="alignnone size-full wp-image-570 aligncenter" title="demon5" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon5.jpg" alt="" width="369" height="760" /></a></p>
<p style="text-align: left;">These postings were of course interspersed with predictable <strong>DEATH THREATS </strong>and <strong>WARNINGS</strong> if they didn&#8217;t stop!</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon6.jpg"><img class="alignnone size-full wp-image-571 aligncenter" title="demon6" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon6.jpg" alt="" width="357" height="95" /></a></p>
<blockquote>
<p style="text-align: left;">Die, once again you are deceiving people, how is it you weren&#8217;t buried under a collapsed building in Wenchuan!!!!</p>
</blockquote>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon7.jpg"><img class="alignnone size-full wp-image-572 aligncenter" title="demon7" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon7.jpg" alt="" width="357" height="97" /></a></p>
<blockquote><p>Careful in this time of crisis, it is against the law to fabricate a rumor.</p></blockquote>
<p>Yeah, by this point in the story, my theory on why their website has now disappeared from the face of the Earth is pretty much unnecessary.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/05/chinese-hackersddos-attack-services/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New &#8220;Kinda-Lazy&#8221; Chinese hacker attack on CNN scheduled for tomorrow. UPDATE x2</title>
		<link>http://www.thedarkvisitor.com/2008/04/new-kinda-lazy-chinese-hacker-attack-on-cnn-scheduled-for-tomorrow/</link>
		<comments>http://www.thedarkvisitor.com/2008/04/new-kinda-lazy-chinese-hacker-attack-on-cnn-scheduled-for-tomorrow/#comments</comments>
		<pubDate>Thu, 24 Apr 2008 22:13:48 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Chinese hacker video]]></category>
		<category><![CDATA[Hacker Hunting]]></category>
		<category><![CDATA[Hacker Organization]]></category>
		<category><![CDATA[Hackers Talking]]></category>
		<category><![CDATA[Leaders]]></category>
		<category><![CDATA[Nationalism]]></category>
		<category><![CDATA[Tibet]]></category>
		<category><![CDATA[US attacks]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[CNN attack]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=513</guid>
		<description><![CDATA[UPDATE FIZZLE: Just got word from Jose that nothing happened with the CNN website today. Chinese hackers are starting to make me look bad and I will not stand for that!! If this keeps up, it may be easier to list the days that Chinese hackers are not calling for an attack on CNN. Had [...]]]></description>
			<content:encoded><![CDATA[<p><strong>UPDATE FIZZLE</strong>: Just got word from Jose that nothing happened with the CNN website today.  Chinese hackers are starting to make me look bad and I will not stand for that!! <img src='http://www.thedarkvisitor.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>If this keeps up, it may be easier to list the days that Chinese hackers are not calling for an attack on CNN.</p>
<p>Had some serious reservations about posting this article for a couple of reasons but decided it is probably worthwhile.  The cons are that there is ZERO confirmation from other sites about the impending attack and the alert posting did not list a sponsoring organization.  On the pro side, it included a website that was setup on the 20th (after initial attack) that is linked in the post and looks like it is there to support the action.</p>
<p>So, large CAVEAT: <strong>UNCONFIRMED</strong></p>
<p>Added bonus, stupid clock again:</p>
<p style="text-align: center;"><strong>The Announcement</strong></p>
<p>At 8:00 pm (Beijing local) on 25 April, <a href="http://bbs.dzwww.com/forum/detail.jsp?id=18497149">Chinese hackers will attack CNN</a></p>
<p>[Announcement]  2008-04-21  On 25 April, 8:00 pm (Beijing local), Chinese hackers will attack CNN.</p>
<p>Everyone, please pay attention to the issuses regarding the effort to invade the CNN website. We are requesting the support of all Chinese.  If you are an expert hacker, we request you ardently strive to invade www.cnn.com. If you are a novice, we request you use DDOS flood attack or put up a couple of pieces of hacker software. If you are not a hacker, we request that you land on the www.cnn.com website at 8:00 pm on 25 April.</p>
<p>Try with all your might to establish a link with the website in order to waste its resources. If their website is continually at capacity for three hours, the server may just crash. Don’t forget, there are over 1.4 billion Chinese! There are over 100 million Chinese online, they won’t be able to withstand us.</p>
<p>Please, assist us with the invasion of www.cnn.com, this represents the honor of China over the issue of Tibetan independence. The www.cnn.com website has put out a large amount of unsubstantiated reports that are a serious challenge and US hackers have already invaded many of our websites. It is time for revenge; let us begin a new round of Sino-US hacker wars. Let them know the strength of the Chinese people.</p>
<p>If it is convenient, please circulate this message to all of your groups.  We need support….  Currently, many of us are going to this webpage to carry out the attack, http://www.goupsoft.com.cn/Bs_Cnn.html. The first time you open it, it might not display. Just refresh the page and it should be okay.</p>
<p style="text-align: center;"><strong>Kinda Lazy (but genius!)</strong></p>
<p>Over at the attack website of goupsoft.com, you land on an automated webpage that uses your computer and IP address to continuously “attack” the CNN website unless you close the browser. My guess is that it is constantly making fresh requests from CNN to tie up bandwidth. The graphic below even shows the number of attacks you have made on the site.</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/newattack1.jpg"><img class="alignnone size-medium wp-image-516" title="newattack1" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/newattack1-300x271.jpg" alt="" width="300" height="271" /></a></p>
<p>Yeah, I kinda attacked CNN 24 times…Whoops! Well, CNN never returned my e-mail either! Damn, I’m sort of a Chinese hacker now? Anyway, the only really interesting thing in that blurb of Chinese above is that they call CNN a “whore.” Really, twice.</p>
<p style="text-align: center;"><strong>This Attack Method Spreading</strong></p>
<p>While this might be the oldest trick in the book, it is new to me so I’m putting it out there. The website http://www.chenmin.org/doscnn.html is using pretty much the exact same attack method as mentioned previously.</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/newattack2.jpg"><img class="alignnone size-medium wp-image-517" title="newattack2" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/newattack2-300x187.jpg" alt="" width="300" height="187" /></a></p>
<p>Once again, you land on the webpage above and it begins refreshing the CNN website in an iFrame every five seconds using up their bandwidth (Jumper explained this to me).  So, I sort of attacked CNN another five,six, seven…forty times looking at the program. Here is Jumper’s full explanation from the question I e-mailed to him last night about the site:</p>
<blockquote><p>Yes. It loads an iframe: And then it reloads itself every five seconds:</p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: &quot;Times New Roman&quot;;">&lt;script&gt;</span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: &quot;Times New Roman&quot;;">var e=document.getElementById(&#8216;cnn&#8217;);</span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Times New Roman&quot;; font-size: small;">setInterval(&#8220;e.src=&#8217;</span><a href="http://www.cnn.com/" target="_blank"><span style="font-family: &quot;Times New Roman&quot;; font-size: small;">http://www.cnn.com</span></a><span style="font-size: small;"><span style="font-family: &quot;Times New Roman&quot;;">&#8216;&#8221;,5000);</span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: &quot;Times New Roman&quot;;">//1000 </span><span style="font-family: ">表示</span><span style="font-family: &quot;Times New Roman&quot;;">1000</span><span style="font-family: ">毫秒</span><span style="font-family: &quot;Times New Roman&quot;;">,</span><span style="font-family: ">你可以修改并转发</span></span></p>
<p><span style="font-size: 12pt; font-family: ">&lt;/script&gt;</span> <strong>Probably not as effective as the Mao-inator program.</strong></p></blockquote>
<p>I direct your attention to the last line (emphasis mine) in Jumper’s e-mail. Number one, he dubs the program he analyzed yesterday as the <a href="http://www.thedarkvisitor.com/2008/04/return-of-poizon-box/">Mao-inator</a>™, which I personally find hilarious. Number two, there seems to be a slight amount of professional jealousy involved since he is dismissing my program as “less effective” than the one he worked with. Yeah, but did yours call CNN a “whore” didn’t think so! Less effective, I think not sir!</p>
<p>All kidding aside, this is an excellent method for incorporating large numbers of unskilled people into your DDoS attack. It comes with the added advantage of using their computers, IP addresses and bandwidth and you don&#8217;t have to train them.  The only skill that is required is the ability to open a webpage in a browser and let it run.  Plus, recruits who might not be so willing to stick around to the end of the fight, if tied to a computer all day, are free to do whatever they want while at the same time defending the motherland.  My vote GENIUS!</p>
<p>Make up your own odds if this will actually take place.  I have informed <a href="http://asert.arbornetworks.com/author/jnazario/">Jose Nazario</a> at Arbor Networks who has been monitoring this situation closely and has had great insights.</p>
<p><strong>UPDATE 1:</strong> Located the blog for <a href="http://www.goupsoft.com.cn/Blog/article.asp?id=8">Li Haiwei</a>, the owner of the attack website goupsoft.com.cn, and my boy has some serious issues with CNN and Tibet.  Lots of disturbing imagery for the whole family:</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/lihaiwei.jpg"><img class="alignnone size-full wp-image-518" title="lihaiwei" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/lihaiwei.jpg" alt="" width="363" height="508" /></a></p>
<p>The graphic reads, &#8220;CNN- I like it. I am CNN.&#8221; Then some stuff way too small to read. The Nobel Peace Prize award you can read yourself and at the bottom Tibet.</p>
<p><strong>UPDATE 2:</strong> Netcraft has a <a href="http://uptime.netcraft.com/up/performance?product=blog&amp;site=www.cnn.com">live performance monitor for the CNN webiste here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/04/new-kinda-lazy-chinese-hacker-attack-on-cnn-scheduled-for-tomorrow/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>More on anticnn.exe</title>
		<link>http://www.thedarkvisitor.com/2008/04/more-on-anticnnexe/</link>
		<comments>http://www.thedarkvisitor.com/2008/04/more-on-anticnnexe/#comments</comments>
		<pubDate>Tue, 22 Apr 2008 13:31:07 +0000</pubDate>
		<dc:creator>jumper</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Nationalism]]></category>
		<category><![CDATA[US attacks]]></category>
		<category><![CDATA[CNN]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=500</guid>
		<description><![CDATA[CNN hating Chinese nationalists can download a tool to send high volumes of requests to www.cnn.com in an attempt to knock it offline.  The tool is bundled in a .rar file that contains a readme and the pre-compiled windows binary.  A quick virus check showed that some scanners identified it as backdoor but that didn&#8217;t [...]]]></description>
			<content:encoded><![CDATA[<p>CNN hating Chinese nationalists can download a tool to send high volumes of requests to www.cnn.com in an attempt to knock it offline.  The tool is bundled in a .rar file that contains a readme and the pre-compiled windows binary.  A quick virus check showed that some scanners identified it as backdoor but that didn&#8217;t seem to be the case.  When I ran the tool, a simple flag icon appeared in the lower right of my test VM.</p>
<p><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/anticnn_flag.png"><img class="alignleft size-full wp-image-505" title="anticnn_flag" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/anticnn_flag.png" alt="" width="182" height="160" /></a></p>
<p> When I click on the flag, the full interface appears with three options:  start/stop, minimize and exit. </p>
<p><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/anticnn_ui.png"><img class="alignnone size-medium wp-image-506" title="anticnn_ui" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/anticnn_ui-300x244.png" alt="" width="300" height="244" /></a></p>
<p>Here is a sample of the request/response I got after running it for a few seconds:</p>
<p><em>GET /aux/con/com1/../../[LAG]../.%%%%%%%%./../../../../fakecnn/redflag-stay-here.php.aspx.asp.cfm.jsp HTTP/1.1</em></p>
<p><em>Accept: */*</em></p>
<p><em>Host: </em><a href="http://www.cnn.com"><em>www.cnn.com</em></a></p>
<p><em>Connection: Keep-Alive</em></p>
<p><em> <br />
HTTP/1.1 400 Bad Request</em></p>
<p><em>Date: Tue, 22 Apr 2008 12:12:34 GMT</em></p>
<p><em>Server: Apache</em></p>
<p><em>Vary: Accept-Encoding</em></p>
<p><em>Content-Length: 287</em></p>
<p><em>Connection: close</em></p>
<p><em>Content-Type: text/html; charset=iso-8859-1</em></p>
<p><em> </em></p>
<p><em>&lt;!DOCTYPE HTML PUBLIC &#8220;-//IETF//DTD HTML 2.0//EN&#8221;&gt;<br />
&lt;html&gt;&lt;head&gt;<br />
&lt;title&gt;400 Bad Request&lt;/title&gt;<br />
&lt;/head&gt;&lt;body&gt;<br />
&lt;h1&gt;Bad Request&lt;/h1&gt;<br />
&lt;p&gt;Your browser sent a request that this server could not understand.&lt;br /&gt;<br />
&lt;/p&gt;<br />
&lt;hr&gt;<br />
&lt;address&gt;Apache Server at </em><a href="http://www.cnn.com"><em>www.cnn.com</em></a><em> Port 80&lt;/address&gt;<br />
&lt;/body&gt;&lt;/html&gt;</em></p>
<p>I read somewhere that it is self-updating but I never saw any requests other than DNS resolution (to my own configured DNS servers, not hard-coded) and requests to www.cnn.com.  I&#8217;ll run it in &#8220;paused&#8221; mode for a while to see what happens.</p>
<p><strong>UPDATE (0100GMT 23 April 08):  </strong>No suspicious traffic came from this binary (apart from what was expected, of course).</p>
<p><strong>UPDATE (1628GMT 24 April 08): </strong>Heike and I have dubbed anticnn.exe the &#8220;Mao-inator&#8221;.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/04/more-on-anticnnexe/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Anatomy of a Chinese hacker attack</title>
		<link>http://www.thedarkvisitor.com/2008/04/495/</link>
		<comments>http://www.thedarkvisitor.com/2008/04/495/#comments</comments>
		<pubDate>Tue, 22 Apr 2008 01:37:21 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Hacker Organization]]></category>
		<category><![CDATA[US attacks]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[CNN]]></category>
		<category><![CDATA[DDoS]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=495</guid>
		<description><![CDATA[Even though a major attack did not occur on CNN, there were some lessons learned that we can take away from this event. So what did we learn? Here are some of things I noted: We can reconstruct a bit of the social side of the attack There is some evidence about their method of [...]]]></description>
			<content:encoded><![CDATA[<p>Even though a major <a href="http://www.thedarkvisitor.com/2008/04/breaking-anti-cnns-call-for-european-protests-spreading-onlinebreaking-cnn-possible-target-of-chinese-hacker-attack-on-19-april-what-beijing-police-supplied-eggs-to-protesters-during-anti-japan/">attack did not occur on CNN</a>, there were some lessons learned that we can take away from this event.  So what did we learn?   Here are some of things I noted:</p>
<ol>
<li>We can reconstruct a bit of the social side of the attack</li>
<li>There is some evidence about their method of organization for operational tactics</li>
<li>Stockpile of ready made software for novice attackers</li>
<li>Possible reasons the attack was canceled</li>
</ol>
<p style="text-align: center;"><strong>Social</strong></p>
<p style="text-align: left;">The first thing we need to do is identify the reason behind the attack.  What were the catalysts that led the Chinese hacker community to go after CNN?  This would be my list:</p>
<ol>
<li>CNN <a href="http://www.cnn.com/2008/TECH/03/07/china.hackers/index.html?eref=rss_latest">report on Chinese hackers</a> is seen as unfair and accusations that parts of the<a href="http://www.thedarkvisitor.com/2008/03/chinese-hacker-xiao-chen-mad-as-hell-closes-website/"> CNN interview were fabricated</a></li>
<li>CNN makes <a href="http://www.iol.co.za/index.php?art_id=nw20080415132027187C604276">remarks about the Tibet situation</a> that angers the nation</li>
<li>Anti-CNN&#8217;s <a href="http://www.thedarkvisitor.com/2008/04/breaking-anti-cnns-call-for-european-protests-spreading-onlinebreaking-cnn-possible-target-of-chinese-hacker-attack-on-19-april-what-beijing-police-supplied-eggs-to-protesters-during-anti-japan/">call for protests</a> provides timing for coordinated effort</li>
<li>Beijing&#8217;s call for an apology from CNN may have been seen as tacit support for the attack.  Or, at least that there would be no retribution if one did take place. This might be the most important factor of all.</li>
<li>Reliving the glory days of the Sino-US cyber conflicts</li>
<li>Making a name for themselves and building their own Chinese hacker cell.  Many of China&#8217;s most famous hackers got their start during the early years of conflict with different nations.</li>
</ol>
<p style="text-align: center;"><strong>Organization</strong></p>
<p>With the decision made to launch an attack, they seem to have decided to use the website that cn_magistrate opened in 2007:</p>
<p>Domain Name: <strong style="color: #333333;">hacksa.cn</strong><br />
ROID: 20070811s10001s50288265-cn<br />
Domain Status: ok<br />
Registrant Organization: 判官<br />
Registrant Name: 判官<br />
Administrative Email: Kenan2677@126.com<br />
Sponsoring Registrar: 北京万网志成科技有限公司<br />
Name Server:ns1.okidc.com Name Server:ns2.okidc.com<br />
Registration Date: 2007-08-11 11:59<br />
Expiration Date: 2008-08-11 11:59</p>
<p>The website would be used for a central gathering point, dissemination of information and organization. During this phase, they probably planned their basic attack formation and strategy.  Using the QQ charts found on www.hacksa.com, I was able to make this very rough organizational chart:</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/rforgchart.jpg"><img class="alignnone size-medium wp-image-496" title="rforgchart" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/04/rforgchart-300x207.jpg" alt="" width="300" height="207" /></a></p>
<p style="text-align: center;">(Yes, very rough and ugly chart.  God I miss my I2 for making charts)</p>
<p>The QQ numbers listed six headquarters units (probably the more experienced hackers), 42 regular groups (actually 44, since he started with zero and may have accidentally listed group 32 twice), and one propaganda unit.  For easy math, I took the number of headquarter units and evenly divided the regular units among them as best I could.  You will note I put the two group 32&#8242;s together and placed the left over regular units into the final formation. The propaganda unit was made as a separate organization, some of the additional units may have belonged with them.  Of course, cn_magistrate may have used a completely different configuration but this is the one that made the most sense to me.  The chart brings up several questions:</p>
<ol>
<li>The character 满 to the right of the groups means filled.  Why did cn_magistrate skip the additional group 32 and group 33 when bringing the units up to full strength?  Groups 37-42 seem logical if you are filling them in as recruits become available.  Were the extra group 32 and group 33 special somehow?</li>
<li>Only one of the headquarter units shows it to be full.  Were they possibly having trouble getting skilled hackers to join the attack?</li>
<li>How many people did it take to fill up the groups?  We can guess that it was more than one, since a QQ number was assigned each of the groups.</li>
<li>What was the function of the propaganda unit?  A possible answer is that it was to spread news if the attack turned out to be successful.  Useless to have a political attack if no one is aware it happened.</li>
</ol>
<p>The next thing we are able to tell was the means they used to get recruits to participate in the attack.  This was accomplished through posting requests on popular websites and probably through restricted registration areas.   Here is a listing of just some of the websites the group posted to:</p>
<p>http://bbs.neteasy.cn/showthread.php?p=984976</p>
<p>http://www.coogo.net/bbs/showtopic-444648.aspx http://www.ytjt.com.cn/bbs/redirect.php?tid=36644&amp;goto=lastpost http://www.ipark.cn/bbs/Post.asp?PostID=836336</p>
<p>http://blog.xuite.net/lemon_head/simple/16728332</p>
<p>http://tieba.baidu.com/f?kz=357748876</p>
<p>http://bbs.neteasy.cn/showthread.php?p=984976</p>
<p>http://www.coogo.net/bbs/showtopic-444648.aspx http://www.ytjt.com.cn/bbs/redirect.php?tid=36644&amp;goto=lastpost http://www.ipark.cn/bbs/Post.asp?PostID=836336</p>
<p>http://blog.xuite.net/lemon_head/simple/16728332</p>
<p>http://tieba.baidu.com/f?kz=357748876</p>
<p>http://bbs.hackbase.com/viewthread.php?tid=3210548</p>
<p>http://tianya.com</p>
<p>The group used thes sites to request compromised computers and while I can&#8217;t locate the posting now, also funds.  Was the money donated to be used to rent botnets?</p>
<p style="text-align: center;"><strong>Stockpile</strong></p>
<p>The website http://playgood.ys168.com was used to stock scripted software that could be downloaded by recruits who had little technical ability.</p>
<p style="text-align: center;"><strong>End Game</strong></p>
<p>Finally, the assault was <a href="http://www.thedarkvisitor.com/2008/04/chinese-hacker-group-identified-as-revenge-of-the-flame-calls-off-attack-on-cnntoo-many-people-know/">called off</a> and then the organization was <a href="http://www.thedarkvisitor.com/2008/04/revenge-of-the-flame-disbands-denies-all-responsibility-for-attack-on-cnnand-kills-website/">disband</a>.  Big question, why?</p>
<ol>
<li>As stated, that too many people were aware of the operation</li>
<li>Unable to fill the units enough to be effective</li>
<li>Just plain worried about the consequences</li>
<li>Beijing sent out an order to shut it down</li>
</ol>
<p>Please feel free to comment on other things we should have learned from this or where I totally botched this analysis.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/04/495/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
