<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Dark Visitor &#187; lost33</title>
	<atom:link href="http://www.thedarkvisitor.com/tag/lost33/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thedarkvisitor.com</link>
	<description></description>
	<lastBuildDate>Wed, 08 Jun 2011 03:15:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>IWM and Shadow Server Project Report:  Shadows in the Clouds</title>
		<link>http://www.thedarkvisitor.com/2010/04/iwm-and-shadow-server-project-report-shadows-in-the-clouds/</link>
		<comments>http://www.thedarkvisitor.com/2010/04/iwm-and-shadow-server-project-report-shadows-in-the-clouds/#comments</comments>
		<pubDate>Wed, 07 Apr 2010 01:28:29 +0000</pubDate>
		<dc:creator>jumper</dc:creator>
				<category><![CDATA[Hacker Hunting]]></category>
		<category><![CDATA[India Attacks]]></category>
		<category><![CDATA[Nationalism]]></category>
		<category><![CDATA[Other attacks]]></category>
		<category><![CDATA[US attacks]]></category>
		<category><![CDATA[gh0stnet]]></category>
		<category><![CDATA[Ghostnet]]></category>
		<category><![CDATA[lost33]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=2148</guid>
		<description><![CDATA[The researchers at InfoWar Monitor and Shadow Server have released a great research paper that adds to the Ghostnet report from last year. TDV gets a plug in the report for our chat with lost33.]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.scribd.com/doc/29435784/SHADOWS-IN-THE-CLOUD-Investigating-Cyber-Espionage-2-0"><img class="alignleft size-medium wp-image-2149" title="TItle Page" src="http://www.thedarkvisitor.com/wp-content/uploads/2010/04/Picture-2-300x136.png" alt="" width="300" height="136" /></a></p>
<p>The researchers at <a href="http://www.infowar-monitor.net/">InfoWar Monitor</a> and <a href="http://www.shadowserver.org/wiki/">Shadow Server</a> have released a great <a href="http://www.scribd.com/doc/29435784/SHADOWS-IN-THE-CLOUD-Investigating-Cyber-Espionage-2-0">research paper</a> that adds to the Ghostnet report from last year.  TDV gets a <a href="http://www.thedarkvisitor.com/tag/lost33/">plug</a> in the report for our chat with lost33.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2010/04/iwm-and-shadow-server-project-report-shadows-in-the-clouds/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>CasperNet gets punked</title>
		<link>http://www.thedarkvisitor.com/2009/04/caspernet-gets-punked/</link>
		<comments>http://www.thedarkvisitor.com/2009/04/caspernet-gets-punked/#comments</comments>
		<pubDate>Sat, 04 Apr 2009 13:37:33 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Hacker Hunting]]></category>
		<category><![CDATA[Hackers Talking]]></category>
		<category><![CDATA[India Attacks]]></category>
		<category><![CDATA[CasperNet]]></category>
		<category><![CDATA[lost33]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1497</guid>
		<description><![CDATA[Remember the fable about the Scorpion and the Frog?  Well, we got stung&#8230; Lost33 did not make contact with Jumper last night.  In fact, it seems he spent the night changing his QQ number and deleting all info from his blog. The website is now completely empty, except for a change to his personal data.  [...]]]></description>
			<content:encoded><![CDATA[<p>Remember the fable about the <a href="http://en.wikipedia.org/wiki/The_Scorpion_and_the_Frog">Scorpion and the Frog</a>?  Well, we got stung&#8230;</p>
<p>Lost33 did not make contact with Jumper last night.  In fact, it seems he spent the night changing his QQ number and deleting all info from <a href="http://hi.baidu.com/damnfootman">his blog</a>. The website is now completely empty, except for a change to his personal data.  Lost33 changed his current residence from Sichuan to Beijing:</p>
<p style="text-align: center;"><a rel="attachment wp-att-1638" href="http://www.thedarkvisitor.com/2009/04/caspernet-gets-punked/capsernetpunk1-2/"><img class="aligncenter size-medium wp-image-1638" title="CapserNetPunk1" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/04/CapserNetPunk1-300x205.jpg" alt="CapserNetPunk1" width="300" height="205" /></a></p>
<p>We retained a full copy of the previous night&#8217;s conversation with Lost33 but have decided to only release two sections.  The first section is being reprinted to prove the connection between Lost33 and the losttemp33 hotmail account:</p>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; color: #008242; text-align: center;">jumper_tdv 2009-04-02 23:57:28</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; text-align: center;">Do you have the email address <a href="mailto:losttemp33@hotmail.com">losttemp33@hotmail.com</a>?</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; color: #0000ff; text-align: center;"><span style="font-family: STHeiti Light; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal;">周小屁</span> 2009-04-02 23:57:30</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: 'Lucida Grande'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; text-align: center;">Sorry for my english too</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; color: #0000ff; text-align: center;"><span style="font-family: STHeiti Light; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal;">周小屁</span> 2009-04-02 23:58:11</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: 'Lucida Grande'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; text-align: center;">yes ,but i never use it.</div>
<p>The second section is being released&#8230;well, to be honest, just because I think it is funny. I can practically see Jumper&#8217;s expression as he types, &#8220;Yes, really.&#8221;</p>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; color: #008242; text-align: center;">jumper_tdv 2009-04-03 00:05:29</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; text-align: center;">The problem is that your lost33 email is used to register DNS names for hackers</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; color: #0000ff; text-align: center;"><span style="font-family: STHeiti Light; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal;">周小屁</span> 2009-04-03 00:05:43</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: 'Lucida Grande'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; text-align: center;"><span style="font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 12px; line-height: normal; font-size-adjust: none; font-stretch: normal;"> </span> really?</div>
<p style="text-align: center;">
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; color: #008242; text-align: center;">jumper_tdv 2009-04-03 00:05:51</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; text-align: center;">Yes, really</div>
<p>Are we surprised, shocked, or angry over Lost33 punking us&#8230;</p>
<p>-Hey, it&#8217;s just his nature.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/04/caspernet-gets-punked/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Hunting the GhostNet Hacker</title>
		<link>http://www.thedarkvisitor.com/2009/04/hunting-the-ghostnet-hacker/</link>
		<comments>http://www.thedarkvisitor.com/2009/04/hunting-the-ghostnet-hacker/#comments</comments>
		<pubDate>Thu, 02 Apr 2009 17:16:55 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Hacker Hunting]]></category>
		<category><![CDATA[Hacker Organization]]></category>
		<category><![CDATA[Ghostnet]]></category>
		<category><![CDATA[IWM]]></category>
		<category><![CDATA[lost33]]></category>
		<category><![CDATA[opanpan]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1441</guid>
		<description><![CDATA[UPDATE: James Tay from Citizen Lab left us a comment.  That&#8217;s right, part of the support team for the Ghostnet Report.  God, we really should have cleaned up the place.  Thanks for taking the time to stop by James! (originally I stated he was a contributing author, James has clarified). UPDATE2: Lost33 is now in [...]]]></description>
			<content:encoded><![CDATA[<p><strong>UPDATE:</strong> James Tay from <a href="http://www.citizenlab.org/"><em>Citizen Lab</em></a> left us a comment.  That&#8217;s right, part of the support team for the <em>Ghostnet Report</em>.  God, we really should have cleaned up the place.  Thanks for taking the time to stop by James! (originally I stated he was a contributing author, James has clarified).</p>
<p><span style="color: #ff0000;">UPDATE2: </span><span style="color: #ff0000;">Lost33 is now in contact with us and we are trying to get his side of the story.  He has requested we mask his QQ number now that he is in contact and we have complied.  (Never do late night updates.  A commenter pointed out that the original wording for this update sounded like we were holding his QQ hostage unless he spoke with us.  That certainly wasn&#8217;t my meaning but that is definitely what it sounded like.  Just wanted to explain the reason for the sudden masking of his contact number.)<br />
</span></p>
<p>First, hats off to the researchers at <a href="http://www.infowar-monitor.net/">IWM</a>.  They did great work on the GhostNet project and we owe them a debt of gratitude for sharing it with us.</p>
<p style="text-align: center;"><strong>The Hunt</strong></p>
<p>One aspect skipped over in the GhostNet report were the e-mails associated with the websites, losttemp33@hotmail.com and opanpan@gmail.com.  For the last two days, Jumper and I have been tracking them down to see where they would take us.</p>
<p>Comparing the Whois returns for two of the websites involved, macfeeresponse.com and scratchindian.com, yields startlingly similar results:</p>
<p style="text-align: center;"><a rel="attachment wp-att-1643" href="http://www.thedarkvisitor.com/2009/04/hunting-the-ghostnet-hacker/ghostnetwhoiscompare-2/"><img class="aligncenter size-thumbnail wp-image-1643" title="ghostnetwhoiscompare" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/04/ghostnetwhoiscompare-150x150.jpg" alt="ghostnetwhoiscompare" width="150" height="150" /></a></p>
<p style="text-align: center;">Double-click to fully englarge</p>
<p style="text-align: left;">We conclude that this is the same person using different e-mail addresses or associates working together.  The domains are registered on the same server and are too close in content to be considered a random coincidence.</p>
<p style="text-align: left;">The Opanpan e-mail went nowhere, so we concentrated on losttemp33.  A simple Google search for the e-mail address, led us to the website for <em><a href="http://search.pudn.com/friend_i.asp?e=litonghui*263.net" target="_blank">Programmers United Development Net:</a></em></p>
<p style="text-align: center;"><a rel="attachment wp-att-1644" href="http://www.thedarkvisitor.com/2009/04/hunting-the-ghostnet-hacker/ghostnetpudn-2/"><img class="aligncenter size-full wp-image-1644" title="ghostnetPUDN" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/04/ghostnetPUDN.JPG" alt="ghostnetPUDN" width="489" height="262" /></a></p>
<p style="text-align: left;">Clicking on the link leads to <a href="http://www.pudn.com/upload_log.asp?e=losttemp33*hotmail.com">three programs losttemp33</a> provided for download.</p>
<p>Next we were able to locate a post from <a href="http://www.whitecell.org/forums/viewthread.php?tid=101&amp;page=1&amp;sid=gtGR1QRz#pid497">2005 on Windows hacking</a>:</p>
<p style="text-align: center;"><a rel="attachment wp-att-1645" href="http://www.thedarkvisitor.com/2009/04/hunting-the-ghostnet-hacker/ghostnetfirstemail-2/"><img class="aligncenter size-full wp-image-1645" title="ghostnetfirstemail" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/04/ghostnetfirstemail.JPG" alt="ghostnetfirstemail" width="489" height="274" /></a></p>
<p style="text-align: left;">Notice that the author of this post uses the signature <strong>Lost33</strong> in the upper left-hand corner.  Using the signature <a href="http://www.google.com/search?q=lost33+%E9%BB%91%E5%AE%A2&amp;hl=en&amp;client=firefox-a&amp;rls=org.mozilla:en-US:official&amp;start=0&amp;sa=N">Lost33 and the Chinese characters for hacker</a> (黑客), we were able to find an individual who was associated with Xfocus, Isbase and even seems to have <a href="http://209.85.173.132/search?q=cache:6O3meawl2sgJ:https://www.xfocus.org/bbs/index.php?act%3DST%26f%3D12%26t%3D27219%26page%3D6+%22lost33%22+%E9%BB%91%E5%AE%A2&amp;cd=2&amp;hl=en&amp;ct=clnk&amp;gl=us">studied under Glacier</a>.  More importantly, we found a <a href="http://i.mop.com/lost33">blog</a> under the same name.</p>
<p style="text-align: center;"><a rel="attachment wp-att-1646" href="http://www.thedarkvisitor.com/2009/04/hunting-the-ghostnet-hacker/ghostnetmopprofile-2/"><img class="aligncenter size-full wp-image-1646" title="ghostnetmopprofile" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/04/ghostnetmopprofile.JPG" alt="ghostnetmopprofile" width="485" height="399" /></a></p>
<p style="text-align: left;">This blog stopped getting updates in 2006 but provided us with a couple of more clues to keep searching.  The first red box shows the date of birth as 24 July 1982 and place of current residence as Chengdu City, Sichuan.  It is important to recall that all of the Whois results for GhostNet associated websites showed Chengdu, Sichuan as the city and province for the organization. The second red box at the bottom is Lost33&#8242;s personal motto, &#8220;The bored soldier swaying on an empty battlefield.&#8221;</p>
<p style="text-align: left;">We kept searching but it seemed like we had hit a brick wall, Lost33 vanished from the internet in 2006.  That was when we decided that a person might change their user id but never their motto.  Can&#8217;t abandon your motto.</p>
<p style="text-align: left;">Plugged in the &#8220;The bored soldier,&#8221; and bingo&#8230;<a href="http://hi.baidu.com/damnfootman">The Bored Soldier&#8217;s blog space</a>:</p>
<p style="text-align: center;"><a rel="attachment wp-att-1647" href="http://www.thedarkvisitor.com/2009/04/hunting-the-ghostnet-hacker/ghostnetbannerheader-2/"><img class="aligncenter size-medium wp-image-1647" title="ghostnetbannerheader" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/04/ghostnetbannerheader-300x131.jpg" alt="ghostnetbannerheader" width="300" height="131" /></a></p>
<p style="text-align: left;">Lost33 now blogs under the name Damnfootman:</p>
<p style="text-align: left;"><a rel="attachment wp-att-1451" href="http://www.thedarkvisitor.com/2009/04/hunting-the-ghostnet-hacker/ghostnetdamnfootman/"></a></p>
<p style="text-align: center;"><a rel="attachment wp-att-1702" href="http://www.thedarkvisitor.com/2009/04/hunting-the-ghostnet-hacker/ghostnetdamnfootman-2/"><img class="aligncenter size-full wp-image-1702" title="ghostnetdamnfootman" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/04/ghostnetdamnfootman.JPG" alt="ghostnetdamnfootman" width="430" height="578" /></a></p>
<p style="text-align: left;">
<p style="text-align: left;">Why are we sure this is the same person as Lost33?  Well, they not only share the same motto but <a href="http://hi.baidu.com/damnfootman/profile">birth date and place of residence as well</a>:</p>
<p style="text-align: left;"><a rel="attachment wp-att-1452" href="http://www.thedarkvisitor.com/2009/04/hunting-the-ghostnet-hacker/ghostnetprofile/"></a></p>
<p style="text-align: center;"><strong><a rel="attachment wp-att-1703" href="http://www.thedarkvisitor.com/2009/04/hunting-the-ghostnet-hacker/ghostnetprofile-2/"><img class="aligncenter size-full wp-image-1703" title="ghostnetprofile" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/04/ghostnetprofile.JPG" alt="ghostnetprofile" width="481" height="192" /></a></strong></p>
<p style="text-align: left;">
<p style="text-align: center;"><strong>Blog bits of interest</strong></p>
<ul>
<li>Lost33 attended the <a href="http://www.uestc.edu.cn/web3/">University of Electronic Science and Technology</a> in China.</li>
</ul>
<ul>
<li>He has a <a href="http://forum.eviloctal.com/thread-29717-1-1.html">link</a> on the website to the Chinese hacker<em> </em>forum for<em> Eviloctal</em> and our dear friend <a href="http://www.thedarkvisitor.com/2007/11/peoples-armed-police-officer-hacking/">Sunwear</a>.</li>
</ul>
<ul>
<li>Lost33 is also keeping up with friends at <a href="http://hi.baidu.com/damnfootman/blog/item/b6f0d71959d5350034fa41b8.html">Xfocus and NSfocus</a><a href="http://cache.baidu.com/c?m=9d78d513d9d430ae4f9d90697d61c010124381132ba7a6020bde843892732a30506692e761615753938e3d2c40e91e03b1ac622f775c73f1c095d45dddcad06872d97075311d8615499358e9df01659f2fca1cafed0ee6c9ed2fd9ff8f8fc854248007582bc7b19c5a77489d29ed7e40befa994a17590de9ad613fa41d2068824911eb1bf9e230681086829b055bc35d923745&amp;p=9e718d1486cc41dd0be295644f&amp;user=baidu"> </a>on garden variety hacker tools.</li>
</ul>
<p>We have left a couple of posts on Lost33&#8242;s blog and are waiting to see if he will respond:</p>
<p style="text-align: center;"><a rel="attachment wp-att-1648" href="http://www.thedarkvisitor.com/2009/04/hunting-the-ghostnet-hacker/ghostnetpost-2/"><img class="aligncenter size-medium wp-image-1648" title="ghostnetpost" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/04/ghostnetpost-285x300.jpg" alt="ghostnetpost" width="285" height="300" /></a></p>
<p>The note asks Lost33 if he would be willing to discuss the GhostNet matter with us.</p>
<p>There were two QQ numbers associated with the opanpan and lost33 email addresses.  We attempted to contact both of them but were rejected.</p>
<p style="text-align: center;"><strong>Summary</strong></p>
<p>While we are aware that there are other lost33 websites out there, such as myspace/lost33, these do not meet the profile of our hacker. It would be a very unusual set of circumstances that would lead to such a bizarre set of coincidences coming together as we have here:</p>
<ul>
<li>The Ghostnet websites list Chengdu, Sichuan under organization and the pseudonym losttemp33 as the contact e-mail address.</li>
</ul>
<ul>
<li>The e-mail address losttemp33@hotmail.com has been posted on at least two websites dealing with computer programming. The post on hacking Windows shows that the person also uses the alias lost33 as an alternative to the full e-mail address.</li>
</ul>
<ul>
<li>An individual using the lost33 signature has posted on several Chinese hacker forums including Xfocus and Isbase (the Green Army). He may even have been a student under Glacier.</li>
</ul>
<ul>
<li>The first lost33 website shows a birth date of 24 July 1982 and current address as Chengdu, Sichuan. The website motto is, “The bored solider sways on the empty battlefield.”</li>
</ul>
<ul>
<li>The second “bored soldier” website is clearly owned by the same person as the first lost33 website. The owners were born on the same date; both live in Chengdu, Sichuan and use the same motto. The new website has links with known hacker websites (Xfocus, NSfocus and Eviloctal), links to hacker programs and demonstrates and education in technology (University of Electronic Science and Technology of China).</li>
</ul>
<p>Obviously the weakest link in the analysis is the jump between losttemp33 and lost33 but we feel the weight of the evidence shows a connection. We do not conclusively claim this person is involved but we think further inquiry is needed.</p>
<p>&lt;edit&gt; &#8211; A few readers have asked for the QQ number that was redacted.  Since lost33 doesn&#8217;t seem to be using that QQ number anymore &#8211; here is the original screenshot:</p>
<p><img class="alignleft size-full wp-image-1516" title="picture-11" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/04/picture-11.png" alt="lost33's QQ" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/04/hunting-the-ghostnet-hacker/feed/</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
	</channel>
</rss>

