Showing posts with label hacktivism. Show all posts
Showing posts with label hacktivism. Show all posts

Friday, February 12, 2010

Hacktivists Attack Australian Government Systems

A hacktivist group call "Anonymous" is claiming responsibility for Distributed Denial-of-Service attacks against government systems in Australia. The attacks are a protest against proposed filtering of Internet content by the Australian government.
"The group consists of "a few thousand people" based all over the world Coldblood said."
Coldblood is a psydonym for an individual claiming to be a spokesperson for the group. The spokesperson also claimed responsibility for other hacktivist attacks protesting other forms of censorship:
"They staged cyber attacks on Iran following the election protests and have publicly protested against the Scientology movement. "

Cyber attacks against Australia 'will continue'

Tuesday, March 10, 2009

"Political Hacking" Is a Growing Trend

International Relations and Security Network (ISN) published an article on the increasing nature of politically motivated computer crime and hacktivism:
"A growing trend of politicized hacking or "hacktivism" is emerging. The incidents in Estonia and Georgia were most likely carried out by state-encouraged Russian nationalist youth groups and criminal organizations, as well as at-large volunteers. One German youth claimed on a web forum that, with instruction from a Russian website, he was initiating fully functional denial-of-service attacks against targets in Georgia in a manner of hours. In reaction to a Danish newspaper cartoon of the Prophet Mohammad, loose groups of hackers in Turkey and other Muslim countries cyberattacked that publication's website."

The report summarizes some of the related recent activity.

The State of the Data War

Monday, February 02, 2009

Indymedia Server Seized - A Lesson in Network Resilience

Indymedia - one of the largest international clearinghouses of news and information for social activism - was recently raided by police in the UK. The raid was apparently the result of an investigation into the publication of personal information belonging to a trail judge in a comment to an article on an animal rights trial.

Indymedia had already removed the offending article per their own policies, however, police seized a server containing a large quantity of information:
"...by seizing this server they [the police] are not only getting information on Indymedia but also on wholly unrelated groups."
However, the seizure of the server did not interrupt Indymedia operations. Indymedia's network is highly distributed and redundant with extensive mirroring of data:
"As with previous cases, Indymedia UK stayed online this time. This was possible due to a system of "mirrors", which was set up to protect the technical infrastructure of the alternative media project. Despite the resource intensive interruptions caused by server seizures, the DIY-media activists continue to provide a platform for "news straight from the streets"."
Although it appears the police were not attempting to censor the information, this case shows both the flexibility, power and dynamic nature of online communication. However, this resilience cuts both ways: Activists and other politically motivated sites are difficult to censor or disrupt, but likewise, when commercial or government sites are the target of online protests by hacktivists, their online attacks often have limited or no operational impact on their targets for the same reason.

Other case studies of this phenomenon are documented in Hacktivism and Politically Motivated Computer Crime.

Police Seize UK Indymedia Server (Again)

Sunday, January 04, 2009

Increased Use of Social Networks in Protests

MetaSecurity has posted a discussion and analysis of the use of social network sites by protest groups around the world.
"Networked inchoate anarchic protest is in itself a significant potential trend over the medium-term. The global economic crash will create new systems and ideas or at least new ways of using old ideas. As the Economist [magazine] notes the traditional mass staged rally aimed at G8 gatherings seems particularly quaint when put against the practice and potential of networked spontaneous protest. The key element these new technologies provide is the ability to amplify the protest message to a wider networked audience – this trend will only increase."

Globally Networked Anarchism (#Griot)

Wednesday, October 29, 2008

Terrorist Twitters

The Federation of American Scientists has posted a draft report produced by an U.S. Army intelligence unit that looks at several uses of technology by al-Qaida and other terrorist organizations for communications include the use of the quick messaging system, twitter.com.


The short section titled "Potential for Terrorist Use of Twitter: A Red Teaming Perspective" provides background on twitter and discusses its use by activists protesting at the U.S. Republican Convention:
"...extremist and terrorist use of Twitter could evolve over time to reflect tactics that are already evolving in use by hacktivists and activists for surveillance. This could theoretically be combined with targeting. Twitter was recently used as a counter-surveillance, command and control, and movement tool by activists at the Republican National Convention (RNC). The activists would Tweet each other and their Twitter pages to add information on what was happening with Law Enforcement near realtime."

The article concludes with three simple scenarios of terrorist use of Twitter.

The full report can be found at:

Sample Overview: alQaida-Like Mobile Discussions & Potential Creative Uses

Wednesday, May 28, 2008

Russian Radiation Level Website Knocked Offline

RIA Novosti, the Russian News Agency, is reporting a denial-of-service attack against a public website used to inform citizens about radiation levels associated with nuclear power plants. It appears the attacks coincided with the release of false reports of a radiation leak.
"This was a planned action by hackers, which has brought down almost all sites providing access to the Automatic Radiation Environment Control System (ASKRO), including the Leningrad NPP site, the rosatom.ru site, and others. For several hours users were unable to reach the sites and obtain reliable information on the situation at the plant."


Russian nuclear power websites attacked amid accident rumors

Friday, May 16, 2008

Political Cyber Attacks As a Form of Censorship

Forbes magazine published an article discussing the censorship motive behind online political attacks against Estonia and Radio Free Europe.

The 2007 Estonia cyber attacks are some of the most widely reported and studied cyber attacks. Yet to date, no definitive conclusion can be made concerning the motive or exactly who sponsored the attacks. The article quotes various authorities who have widely varying theories of the motives behind the Estonia attacks. This is an excellent example of the difficulty in determining motive - or conversely, the ease in mis-identifying an attacker's motive.
"The difference between government-sponsored attacks and grassroots cyber terrorism is growing increasingly fuzzy, even as researchers try to sift through who did what on Estonia's Web. And the difficulty of tracing responsibility for even massive cyber attacks suggests that such maneuvers may become an effective tool not just for indiscriminate vandalism, but also for stealthy cyber censorship."


When Cyber Terrorism Becomes State Censorship

Saturday, May 03, 2008

Increase in Hacktivism?

Online protest and hacktivist attacks are gaining more publicity but does this reflect a sudden increase in activity or just more press coverage? A recent blog posting concluding a sudden increase in activity has gained some media attention:

"While incidents of Hacktivism are not new, they are beginning to become a lot more frequent — perhaps due to the availability of tools to conduct hacktivist mischief, but also perhaps due to the ubiquitous social networking mechanisms which can now be used as to build consensus when times of cultural or political unrest present the opportunity.

In any event, Hacktivism is becoming a disturbing trend, and one which can have serious ripple effects that interfere with Internet operational continuity — sometimes in ways which we may have not even thought of yet."

While the availability of social networks and 'hacktivist' tools do contribute to both increasing number of attacks and their effectiveness, most professionals that closely follow politically motivated computer crimes and hacktivism believe there has been a steady increase in activity for several years, with ups and downs following political events in the real world (such as Olympic protests, Israeli-Palestinian conflicts, etc.). What has become more frequent is press coverage of attacks which creates a cycle of more activity followed by more press (see Hacktivism & Politically Motivated Computer Crime for a detailed analysis of the relationship between hacktivism and media coverage).


‘Hacktivism’ Incidents Escalate, Become More Frequent

Activists Swarm French Olympic Boycott Voting

The website of French magazine 'Capital', conducting an online poll concerning boycotting the 2008 Chinese Olympics, was flooded with votes, apparently from China.

"On the first day, we had about 300 responses, which was normal for this type of poll, and they were 80 percent in favour of a boycott. The next day there were 20,000 responses, with 80 percent opposing a boycott," he [Jean-Joel Gurviez, publisher of the website for Capital magazine] said.

"Almost all of the responses arrived via Chinese servers, Gurviez said, leading technicians to initially think the influx was driven by Chinese sites directing patriotic fans to vote.

"But a few days later we had hackers operating off servers in China try to change our content, and there were 2.5 million attempts to access protected files. We had to shut down the site temporarily," he said."


Hackers hit French magazine website over China poll

Monday, April 07, 2008

NATO and EU Concern on Cybercrime

In separate meetings last week, both the EU and NATO organizations discussed cyberterror issues and their need to respond.

The Council of Europe will review the new Convention on Cybercrime and discuss how to strengthen online anti-terrorism activities.

Separately, politically motivated computer crime was discussed at the NATO summit held in Romania including how member countries can better coordinate online defense activities.
"World leaders gathered in Bucharest for this week’s NATO summit are debating what role the trans-Atlantic alliance can play in containing “cyberterrorists,” “hacktivists” and other emerging menaces that experts concede are untraditional, but still potentially lethal."

Most of the concern quoted in the press center around the cyber attacks against Estonia.

European Union, NATO to tackle cybercrime

NATO grows increasingly concerned about terrorism on world's computer networks

Tuesday, March 11, 2008

Reporters without Borders to Host Cyber Protest against Internet Censorship March 12

Reporters without Borders will host a day long cyber protest against online censorship on March 12, 2008:

"To denounce government censorship of the Internet and to demand more online freedom, Reporters Without Borders is calling on Internet users to come and protest in online versions of the nine countries that are “Internet enemies” during the 24 hours from 11 a.m. on 12 March to 11 a.m. on 13 March (Paris time). Anyone with Internet access will be able to create an avatar, choose a message for their banner and take part in one of the nine cyber-demos (Burma, China, North Korea, Cyba, Egypt, Erithrea, Tunisia, Turkmenistan and Viêt-nam).

"Reporters Without Borders will release its latest list of “Internet enemies” together with a new version of its Handbook for Cyber-Dissidents."

Wednesday 12 March : launch of Online Free Expression Day plus repeat of last year’s "24-hour online demo"

Thursday, December 13, 2007

"Cyber Terror" Label Too Easily Applied to Lesser Crimes

Zeid Nasser has posted an excellent commentary concerning the overuse of the word "cyber terror".
"In the first couple of years following the events of September 11, 2001, a hysteria regarding Internet-fueled terrorism reached fever pitch.

In the midst of this atmosphere, many Islamic movements and organizations on the web were banned, blocked, censored or monitored. With time, the term “cyber terror” emerged to describe any form of Internet aided attack for political causes, yet many still disagree to this day on the use of the word ‘terror’, opposed to more accurate words like ‘vandalism’ or simply just ‘hacking’."
Sensationalizing words will often grab headlines but diminishes their impact and create ambiguity - a problem that is rampant in the IT security profession. The articles presented here often overuse this and other words such as "cyber war", "infowar" and will often be offset in quotations to identify their inappropriate application. "Cyber war" and similar words should only be used for offensive use of technology to further a political or idealogical agenda, not for simple misuse such as hacking (trespass), web defacements (vandalism) or data theft (see Hacktivism & Politically Motivated Computer Crime for a discussion on political 'use', 'misuse' and 'offensive use' of technology for political purposes).

Nomina si nescis, perit et cognitio rerum

(Who knows not the names, knows not the subject)

- Linnaeus



Zeid Nasser's Tech Blog: Cyber-terror makes a comeback in the news

Monday, December 10, 2007

India Issues Arrest Warrents for Dutch Web Activists

An Indian court in Bangalore has issued arrest warrants and will request extradition of eight Dutch nationals who are members of several labor activist groups including Clean Clothes Campaign (CCC), the India Committee of the Netherlands (ICN) and the director a Dutch ISP "antenna.org". The charges relate to an ongoing activist campaign against Dutch jeans company"G-Star" and their India based manufacturing supplier Fibres and Fabrics International (FFI) and its subsidiary Jeans Knits Pvt. Ltd.

The activist groups are protesting working conditions at the Indian factory (for example, see "Make it clear that labour rights organisations will not be silenced - Support freedom of speech and freedom of association"). This and other web postings resulted in a defamation case brought against the activists by FFI in India.

Most recently, the Dutch jeans maker "G-Star" has announced it will terminate its contract with the Indian manufacturer (see
"G-star ends jeans contract with Indian firm").

This case is a classic example of three important issues with technology and political issues:

  1. Where does free speech end and crime begin? What are the limits involving web postings, online communications and attempts by various interest groups in using technology to organize?
  2. The lack of any consistent international definitions of computer crime or tort and delict civil laws. What is a crime in one country may be a privileged right in another; and
  3. The power of (negative) press is often the most important aspect. In fact, one of the most attractive attribute of the Internet for activist groups is its power as a PR mechanism.

Indian court orders 'arrest without bail' of Dutch activists

Friday, September 28, 2007

Vitural Sit-In Protest in Michigan Gets Late Press

In May of 2007, the Electronic Disturbance Theater (EDT) called for a "virtual sit-in" of Michigan State's main website to protest cuts in health care benefits.

For some reason it made very little press until just recently when InfoWorld picked up the story. Not sure what caused it to appear on the radar screen at such a late date. The attack had very little impact on Michigan's systems.

EDT was one of the first online protest groups to make available simple DoS attack applets called "FloodNet" to support the Zapatista movement in Mexico during the late 1990s. EDT has not been as active the last few years.

New activist tool: Cyber sit-ins