<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Dark Visitor &#187; Network Boy</title>
	<atom:link href="http://www.thedarkvisitor.com/tag/network-boy/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thedarkvisitor.com</link>
	<description></description>
	<lastBuildDate>Wed, 08 Jun 2011 03:15:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Chinese hackers eating Chinese hackers&#8230;with a side of government</title>
		<link>http://www.thedarkvisitor.com/2008/08/chinese-hackers-eating-chinese-hackerswith-a-side-of-government/</link>
		<comments>http://www.thedarkvisitor.com/2008/08/chinese-hackers-eating-chinese-hackerswith-a-side-of-government/#comments</comments>
		<pubDate>Sun, 10 Aug 2008 23:48:14 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Hacker Hunting]]></category>
		<category><![CDATA[Hackers Talking]]></category>
		<category><![CDATA[chinese hacker]]></category>
		<category><![CDATA[Network Boy]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=388</guid>
		<description><![CDATA[This is the official Chinese government website for Longgang Emergency Management: This is also the official Longgang Emergency Management website, when you add xiaozi.html: You would think, with the recent earthquake in Sichuan and the ongoing Olympics, that government websites dealing with emergency management would be inspected rather thoroughly. Not so much. Google spiders crawling [...]]]></description>
			<content:encoded><![CDATA[<p>This is the official Chinese government website for <a href="http://www.ics.lg.gov.cn/">Longgang Emergency Management</a>:</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/08/longgang.jpg"><img class="size-thumbnail wp-image-389 aligncenter" title="longgang" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/08/longgang.jpg" alt="" width="427" height="383" /></a></p>
<p>This is also the official Longgang Emergency Management website, when you add <a href="http://www.ics.lg.gov.cn/xiaozi.html">xiaozi.html</a>:</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/08/longgang2.jpg"><img class="size-thumbnail wp-image-391 aligncenter" title="longgang2" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/08/longgang2.jpg" alt="" width="430" height="294" /></a></p>
<p>You would think, with the recent earthquake in Sichuan and the ongoing Olympics, that government websites dealing with emergency management would be inspected rather thoroughly.  Not so much.  Google spiders crawling the internet, show that the website has been hacked since at least <a href="http://64.233.167.104/search?q=cache:-1WlI-1wdFMJ:www.ics.lg.gov.cn/xiaozi.html+%22%E7%BD%91%E7%BB%9C%E5%B0%8F%E5%AD%90%22+%E9%BB%91%E5%AE%A2&amp;hl=en&amp;ct=clnk&amp;cd=14&amp;gl=us">31 July 08</a>.</p>
<p>Is it unusual for a Chinese hacker to attack their own government&#8217;s website?  The first-generation of Chinese hackers had very strict rules about not hacking inside China but the current crop doesn&#8217;t seem to adhere to the same code.   Doing a pull on Zone-h.com.cn, gives <a href="http://www.zone-h.com.cn/index.php?mode=domain&amp;type=&amp;key=.gov&amp;page=1">1,952 known Chinese government websites</a> that have been hacked.  A fairly large number of those attacks appear to be carried out by Chinese hackers.</p>
<p>So, from the URL extension on the hacked page of the Longgang Emergency Management website, who or what is a xiaozi?  It is a who, or to be more precise, a him.</p>
<p>Meet Network Boy (Wanglu Xiaozi):</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/08/networkboy.jpg"><img class="size-full wp-image-393 aligncenter" title="networkboy" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/08/networkboy.jpg" alt="" /></a></p>
<p>Blog name: Network boy&#8217;s BLog Hacker<br />
Site admin nickname: Network boy<br />
Age: 18<br />
Birthday: 13 December 1989<br />
Sex: Male<br />
Blood type: B<br />
Zodiac sign: Virgo<br />
Address: Wulumuqi, Xinjiang<br />
Personal quote:<br />
Hobbies:</p>
<p>Not to get in a battle over Zodiac signs but isn&#8217;t someone born on 13 December a Sagittarius?  Maybe something to do with the Chinese <a href="http://www.chinesefortunecalendar.com/ClunarCal1.htm">Lunar Calendar</a> but trying to figure it out hurts my head about as much as International Date Line conversion.  I have Chinese friends I give birthday gifts to five times a year just to be on the safe side.  Moving on.</p>
<p>Going through Netboy&#8217;s website reveals that government websites are not his only target, he also has an affinity for fellow hacker websites as well.</p>
<p>1)  First  target, zgmuma.com (China&#8217;s Trojan Base):</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/08/zgmuma.jpg"><img class="size-thumbnail wp-image-394 aligncenter" title="zgmuma" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/08/zgmuma.jpg" alt="" width="472" height="387" /></a></p>
<p>According to Netboy, he was bored and went to his favorite hacker site (hackol.com) to study but the website was down.  He did notice a link toward the bottom of the page that connected to zgmuma.com and for reasons unmentioned decided to see if he could break into the site.   Zgmuma.com is another Chinese hacker website that boasts the largest collection of online game trojans around.  It also provides hacker training.</p>
<p>I have to give Netboy credit, <a href="http://www.ykhack.com/article.asp?id=62">he provides a step-by-step account of his exploits</a>, to include screen shots and the tools used to perform reconnaissance on the intended victim.  With this one he was able to find a fatal flaw in the server to crack.  While Netboy was breaking into zgmuma, his buddy, who goes by the name of Ice Sugar, contacted him to say that he had gained access to cnhacker.com and posted a hacked page:</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/08/cnhackerhacked.jpg"><img class="size-medium wp-image-395 aligncenter" title="cnhackerhacked" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/08/cnhackerhacked.jpg" alt="" width="448" height="312" /></a></p>
<p>Ice Sugar passed over the info on cnhacker.com to Netboy, who said he also posted a hacked page on the site.</p>
<p>2) Second target, an81.cn (The Dark Hacker Group):</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/08/darkhackergroup.jpg"><img class="size-medium wp-image-396 aligncenter" title="darkhackergroup" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/08/darkhackergroup.jpg" alt="" width="461" height="363" /></a></p>
<p><a href="http://www.ykhack.com/article.asp?id=60">Netboy was able to gain access to this website</a> because they were using Dvbbs8.1.  He was thankful that it was not 8.2, because then he would not have been able to gain access to the backstage shell.  Using Thunder (unclear) he was able to discover the site admin&#8217;s password, 6423987, after making several manual guesses.  He also used an ASP trojan during the process but I couldn&#8217;t begin to tell you what he was talking about; didn&#8217;t understand much of the technical jargon.</p>
<p>3) Third target, www.163???.com (Hacker)</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/08/redyellow.jpg"><img class="size-medium wp-image-397 aligncenter" title="redyellow" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/08/redyellow.jpg" alt="" width="459" height="309" /></a></p>
<p>Netboy really liked the design of this website and consider it difficult to break but still managed.  Once again, he takes you through his very <a href="http://www.ykhack.com/article.asp?id=59">methodical system of cracking the website</a> and I wish I was able to translate it but can&#8217;t.  Some of you people who are more on the tech side might be able to gather what he did even better than me by the screen shots.</p>
<p>For whatever reason, he decided to hide the target&#8217;s URL but it only took about a minute to find the site, www.163xjs.com.   Wasn&#8217;t able to access the site due to a &#8220;directory listing denied&#8221; message.  However, <a href="http://64.233.167.104/search?q=cache:dbwOgG8nT40J:www.163xsj.com/+www.163+%E9%BB%91%E5%AE%A2%E5%90%A7&amp;hl=en&amp;ct=clnk&amp;cd=1&amp;gl=us">Google&#8217;s cache</a> was not so particular about who peeked:</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/08/redandyellow1.jpg"><img class="size-thumbnail wp-image-398 aligncenter" title="redandyellow1" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/08/redandyellow1.jpg" alt="" width="472" height="460" /></a></p>
<p>Even though the imagery is absent, it is clearly the same website.</p>
<p>4) Fourth target, hacker98.cn</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/08/hacker98.jpg"><img class="size-medium wp-image-399 aligncenter" title="hacker98" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/08/hacker98.jpg" alt="" width="485" height="345" /></a></p>
<p>Lot of <a href="http://www.ykhack.com/article.asp?id=58">stuff on this hack</a> too but I&#8217;m getting bored and you get the point.  He hacks other Chinese hacker websites.</p>
<p><strong>Conclusion:</strong> At the end of each of these attacks, Netboy posts an invitation for other skilled people to join his group.  So, this all may be just to gain recruits by proving he is better than the other groups out there.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/08/chinese-hackers-eating-chinese-hackerswith-a-side-of-government/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

