Tuesday, August 26, 2008

Chinese "Hacker" Discusses Chinese Underground and Attacks on Western Systems

An interview with a Chinese "hacker" who claims to have participated in pro-Chinese attacks against CNN and other western organizations has been posted on YouTube.
"If there is a cyber war between two countries and if our country needs us, as cyber citizens or as IT fans, we can work together and we can certainly protect ourselves."



Dutch Websites Defaced in Protest of Film Release

An attacker using the pseudonym of "nEt^DeViL" has attacked and defaced several hundred websites in the Netherlands in protest of the release of the Dutch film "Fitna" critical of Islamic extremists.

Part of the message left in the defacements states:
"If you think that ” Insulting GOD Religion is a Freedom of Speech as your country did , then allow me to show you my Freedom knowledge of Hacking ;)" [sic].

Hundreds of Dutch web sites hacked by Islamic hackers

Tuesday, June 24, 2008

Islamic Jihad Creates Cyber War Unit

Islamic Jihad, a Palestinian Islamist group, has created a cyber-war unit to aid its armed Al-Quds Brigades in attacks on Israel:
"It was a response to years of attacks by Israeli hackers, and according to the Brigades spokesman, Abu Hamza, it equals the playing field in cyber-space.

"The Israeli's have worked very hard the past few years on monitoring all the Palestinian websites, especially those of Islamic Jihad and Al-Quds Brigades," Hamza told MENASSAT.

"They (Israeli hackers) hacked these websites and erased them from the electronic boards or even added indecent pictures to them," he said.
"Hamza told MENASSAT that the Brigades had to establish an e-media military unit "because we had to fight the enemy in the electronic media to resist being assaulted on two fronts – physically and virtually."

The article discusses several specific attacks against Israeli interests; mostly web defacements but also discusses attempts at system based attacks against Israeli infrastructure targets:
"Abu Hamza said that the e-media military unit doesn't just work on breaking the security of the Israeli websites – both governmental and civilian –, but it is also "expanding its cyber-reach to include attempts at hacking and bugging the Israeli telecommunications network."

"So far, these attempts have not succeeded," he [said]."

Islamic Jihad’s cyber-war brigades

India's Military Concerned over Chinese Cyber Attacks

India's military is taking steps to counter alleged Chinese intrusions into Indian systems:
"In April 2008, Indian intelligence agencies detected Chinese hackers breaking into the computer network of the Ministry of External Affairs forcing the government to think about devising a new strategy to fortify the system. Though the intelligence agencies failed to get the identity of the hackers, the IP addresses left behind suggested Chinese hands."

The article rambles somewhat between discussion of web defacements in India (with no apparent link to China) and discussion of India's vulnerability to cyber attacks:

"Unless India takes adequate steps to protect itself from external cyber threats, the world famous IT giant could be facing a grim situation. Cyber attacks are dangerous for India because of the growing reliance on networks and technology to control critical systems that run power plants and transportation systems. Cyber attacks on banks, stock markets and other financial institutions could likewise have a devastating effect on a nation's economy.

"As a countermeasure, the Indian armed forces are trying to enhance their C4ISR capabilities, so that the country can launch its own cyber offensive if the need arises. Given Chinese cyber attacks, there is need for the army to fight digital battles as well."

China's cyber warfare against India

Kurdish Immigrant in Germany Convicted for Promoting Terrorism Online

An unnamed Kurdish immigrant to Germany has been convicted and sentenced to three years in prison for posting files and making statements that supported al-Qaeda leaders.

"The court in the northern German city of Celle convicted him on 22 counts of recruiting on behalf of a non-German terrorist organization, which is a crime under German law.

"Defence lawyers had called for the acquittal of the man, who has Iraqi nationality. Presiding judge Wolfgang Siolek said the verdict sets a legal precedent in Germany, as the first where a person has been jailed for remarks on the internet in support of a foreign terrorist cause.

"The court said the internet postings had the purpose of urging others to join in the jihad, and went well beyond a mere statement of sympathy with al-Qaeda, which would have been protected by free-speech laws and would not have been punishable."

Kurd used internet to urge terrorists on: three years jail

Friday, June 13, 2008

China Denies Attacks on U.S. Congressional Computer Systems Becuase It Lacks the Capability

China's Foreign Ministry has denied reports that China was the source of attacks on U.S. Congressional systems because it lacks the technology to do so:
"China denied accusations by two U.S. lawmakers that it hacked into congressional computers, saying Thursday that as a developing country it wasn't capable of sophisticated cybercrime.

"Is there any evidence? ... Do we have such advanced technology? Even I don't believe it," Foreign Ministry spokesman Qin Gang told a regularly scheduled news conference."

The article discusses the inconsistency in this statement - China is a leader in high technology; not only manufacturing but in design and development:

"China has a thriving information technology industry and claims to have 221 million Internet users — equal to the U.S. as the most in the world.

"I'd like to urge some people in the U.S. not to be paranoid," Qin said. "They should do more to contribute to mutual understanding, trust and friendship between the U.S. and China."


China denies hacking into US computers

U.S. Congressional Systems Targeted for Chinese Dissident Info - Maybe

Two U.S. congressmen have gone public accusing China as the source of intrusions into their computer systems searching for information on Chinese dissidents.

"Two congressmen, both longtime critics of Beijing's record on human rights, said the compromised computers contained information about political dissidents from around the world. One of the lawmakers said he'd been discouraged from disclosing the computer attacks by other U.S. officials.

"Rep. Frank Wolf, R-Va., said four of his computers were compromised beginning in 2006. New Jersey Rep. Chris Smith, a senior Republican on the House Foreign Affairs Committee, said two of the computers at his global human rights subcommittee were attacked in December 2006 and March 2007.

"Wolf said that following one of the attacks, a car with license plates belonging to Chinese officials went to the home of a dissident in Fairfax County, Va., outside Washington and photographed it."

The article discusses other potential intrusions in the US government systems from China and attempts by investigators to keep the attacks secret:

"Wolf said the FBI had told him that computers of other House members and at least one House committee had been accessed by sources working from inside China. The Virginia Republican suggested that Senate computers could have been attacked as well.

"He said the hacking of computers in his Capitol Hill office began in August 2006, that he had known about it for a long time and that he had been discouraged from disclosing it by people in the U.S. government he refused to identify.

"The problem has been that no one wants to talk about this issue," he said. "Every time I've started to do something I've been told 'You can't do this.' A lot of people have made it very, very difficult."

"The FBI and the White House declined to comment.

"The Bush administration has been increasingly reluctant publicly to discuss or acknowledge cyber attacks, especially ones traced to China."


Other articles have been published discussing the lack of specific evidence that the source of these attacks is actually China and discusses the difficulty in determining both source and motive.

Lawmakers say Capitol computers hacked by Chinese

Weak Evidence Links Congressmen's Cyber-attacks to China

Thursday, June 12, 2008

Mandate Extended for the European Network and Information Security Agency

The European Network and Information Security Agency (ENISA) will release a media statement tomorrow announcing the extension of its mandate through 2012.

Mr. Andrea Pirotti, Executive Director of ENISA, stated:
“Network and information security is crucial for the European economy. The need for secure networks, systems and services will certainly not suddenly disappear in 2012. Following the EU parliamentary elections in 2009 and the establishment of a new European Commission, this extension allows for the necessary time to reflect thoroughly upon the activities of ENISA 'post-2012'. Network and information security touches business and the daily lives of citizens in Europe. It consequently needs constant reinforcement to keep up with the evolving threats landscape.”
www.enisa.europa.eu

Thursday, May 29, 2008

Belgian Woman Convicted for Islamist Website

A Belgian woman has been convicted in Switzerland for maintaining a website supporting Islamist groups including al-Qa'eda. Malika El Aroud (who's husband Abdessatar Dahmane killed the anti-Taliban resistance leader Ahmed Shah Massoud in Afghanistan two days before September 11th) is quoted in the article:

"I have a weapon. It's to write. It's to speak out. That's my jihad. You can do many things with words. Writing is also a bomb."

"I write in a legal way. I know what I'm doing. I'm Belgian. I know the system."

"...ask your mothers, your wives to order your coffins Vietnam is nothing compared to what awaits you on our lands [sic]".


Female al-Qa'eda supporter uses internet as 'bomb' to recruit others to wage jihad on West

Spanish Police Arrest Online Protest Group

This was originally posted several weeks ago in Gary Warner's CyberCrime & Doing Time blog.

Spanish police announced on May 17, 2008 the arrest of at least four members of a Spanish speaking group called D.O.M. This group is alleged to be one of the more prolific web defacement groups in the world. Spanish police estimate they were responsible for as many as 21,000 attacks on websites - most as political protests:
"Some of the more high-profile attacks credited to the group, at least from an American perspective, would include having hit the US government's National Cancer Institute with an SQL injection attack back in July of 2007, ( archived from Zone-H). In February, an0de defaced an MIT server with an anti-American, anti-Bush message, archive from Zone-H ."

Spanish Arrest D.O.M. Team

Wednesday, May 28, 2008

Russian Radiation Level Website Knocked Offline

RIA Novosti, the Russian News Agency, is reporting a denial-of-service attack against a public website used to inform citizens about radiation levels associated with nuclear power plants. It appears the attacks coincided with the release of false reports of a radiation leak.
"This was a planned action by hackers, which has brought down almost all sites providing access to the Automatic Radiation Environment Control System (ASKRO), including the Leningrad NPP site, the rosatom.ru site, and others. For several hours users were unable to reach the sites and obtain reliable information on the situation at the plant."


Russian nuclear power websites attacked amid accident rumors

Monday, May 19, 2008

Hate Speech on the Internet

The Anti-Defamation League (ADL) has published a speech by Christopher Wolf, Chair, ADL Internet Task Force and Chair, International Network Against Cyber-Hate (INACH) to the Commission on Security and Cooperation in Europe. The speech discusses the use of the Internet to facilitate hate speech:
"The Internet allows haters to communicate, collaborate and plot in ways simply not possible in the off-line world. The Internet inspires and facilitates real-world violence.And the misuse of the Internet to propagate hate victimizes those vulnerable to hurtful words and images, especially minorities, and it serves to mislead and even recruit young people to become the next generation of hate-mongers."


Hate in the Information Age

North America Hosts Terrorist Web Sites

Israel 21c posted an article discussing the use of North American ISPs to host terrorist supporting websites:
"Prof. Niv Ahituv, academic director of the Netvision Institute for Internet Studies (NIIS) at Tel Aviv University (TAU), said that some of the world's most dangerous organizations, including Hezbollah and al-Qaeda, host their web sites on servers owned by popular American and Canadian ISPs used by most North Americans."
This issue has been documented since 2000 when the first serious cyber conflicts occurred between Israeli and Palestinian supporters during the second Intifada. Since both sides targeted systems hosted by North American ISPs, the attacks affected many U.S. companies not directly involved with the conflict - a form of electronic collateral damage (See: Hacktivism and Politically Motivated Computer Crime).

The article discusses a presentation on this topic that Professor Ahituv made at a NATO conference earlier this year. The article also addresses the debate on shutting down this type of activity and the U.S. First Amendment issues involved:
"Unfortunately, in the wired world, the base location is a technical matter. Geography is not a limiting factor. "A half an hour after a website is shut down in the US, it is registered in Malaysia, Saudi Arabia, or Iran. The FBI has shut down a few websites, but it is like chasing the wind," warns Ahituv."


Israeli study shows US a digital haven for terrorists

Cyber Attacks Against Palestinian Bloggers

Picked up a short blog posting concerning the high volume of attacks against bloggers who post articles concerning issues in Palestine. The article doesn't specify any technical details nor speculate on the source or motive...
"It's funny how every time I write about Palestine, I get a slew of hack attempts ranging from the most primitive to the most complicated scary ones. I won't get into much details, but I've been noticing a huge amount of unnatural activity."


H-a-c-k-e-r Friendly

Friday, May 16, 2008

Recommended Reading: Carpet Bombing in Cyberspace

The title is a misnomer - this article is a well written and thought provoking discussion on how the U.S. might build an offensive military cyber capability and what the ramifications would be of its use.

Col. Charles W. Williamson III wrote the feature article in Armed Forces Journal and begins with a discussion of the changing aspect of cyberspace in national defense. It gives several very good comparisons of the currently situation with previous challenges in military history - from Troy to WWII:
"Today, every Army outpost in America traces its roots to the walls, guards and gates of Troy. But none of today’s forts relies for boundary defense on anything more substantial than a chain-link fence, even though the base may contain billions of dollars in military equipment and the things most important to the soldiers — their families. The U.S. intends for defense of its “forts” to occur thousands of miles away. We intend to take the fight to the enemy before the enemy has a chance to come here. So, if the fortress ultimately failed, does history provide a different model?"
Col. Williamson reports on suggestions for creating a military botnet using existing Air Force systems to provide an U.S. offensive cyber capability and discusses defensive requirements.

However, probably the most interesting part of the article is the discussion of the pros and cons of developing and using this type of offensive capability:

"Lawyers have been known to trot out a “parade of horribles” to demonstrate weaknesses in an idea. These issues are difficult but not insurmountable. But before addressing them, it is important to note what the botnet is not.

"The af.mil botnet is not a replacement for law enforcement action or diplomacy. If the harm coming to U.S. systems is low enough that a military response is not required, the U.S. must default to traditional responses that respect the sovereignty of other nations, just as we expect them to respect our sovereignty and the primacy of our responsibility to stop harm coming to them from the U.S. With that understanding, what challenges remain?"


The article goes on to discuss several of the key concerns with offensive cyber warfare and attempts to address them. The most critical of these is The Difficulty in Identifying Source and Motive of Politically Motivated Computer Crimes. Col. Williamson writes:

"The truly difficult problems come in defending against attack from devices adversaries have captured from U.S. or allies’ civilians. Generally, the U.S. military is not going to attack a U.S. private computer. Harm coming from one of those machines will first be treated as a crime, and military forces should stay out of the situation in accordance with the Posse Comitatus Act. However, Title 10 of the United States Code, Section 333, allows the president to order use of the military in the U.S. under tightly controlled conditions when civil authorities are overborne.

"More challenging is the problem of an attack coming from an ally’s civilian computers. Obviously, the U.S. would seek allies’ cooperation if at all possible, but we could be in a position of launching an attack on a nation whom we have sworn to protect in a mutual defense pact. Together, the U.S. and its allies can reduce this risk by cooperating to maximize computer security. If we attack them as a matter of proportionate response, it would only be because computers in their territory are attacking us.

"The biggest challenge will be political. How does the U.S. explain to its best friends that we had to shut down their computers? The best remedy for this is prevention. The U.S. and its allies need to engage in a robust joint endeavor to improve net defense and intelligence to minimize this risk."


Regardless of whether you agree or disagree with the author, it is refreshing to see a well thought-out and nicely argued discussion on the topic of cyber warfare.

Thanks to Gareth Gange for the the pointer to this article.

Carpet bombing in cyberspace

Political Cyber Attacks As a Form of Censorship

Forbes magazine published an article discussing the censorship motive behind online political attacks against Estonia and Radio Free Europe.

The 2007 Estonia cyber attacks are some of the most widely reported and studied cyber attacks. Yet to date, no definitive conclusion can be made concerning the motive or exactly who sponsored the attacks. The article quotes various authorities who have widely varying theories of the motives behind the Estonia attacks. This is an excellent example of the difficulty in determining motive - or conversely, the ease in mis-identifying an attacker's motive.
"The difference between government-sponsored attacks and grassroots cyber terrorism is growing increasingly fuzzy, even as researchers try to sift through who did what on Estonia's Web. And the difficulty of tracing responsibility for even massive cyber attacks suggests that such maneuvers may become an effective tool not just for indiscriminate vandalism, but also for stealthy cyber censorship."


When Cyber Terrorism Becomes State Censorship

Attacks Target Specific Chinese Dialects

The Dark Visitor, a blog that tracks Chinese hacker activity, provides some technical details on attacks that selectively target systems based on the Chinese dialect used by web browsers. Although these types of attacks have been seen before, this is a good example of the trend toward selective targeting.

The post also provides a sample protest message sent in SQL-injection attacks:
"This is a mass invasion. Safeguard the motherland’s dignity!
F*** FRANCE! F*** CNN! I WILL ATTACK you ALWAYS !
I love my motherland!"


More Patriotic Hacking

Wednesday, May 14, 2008

NATO Announces Cyber Defence Centre in Estonia

NATO has announced it will open a Cooperative Cyber Defence (CCD) Centre of Excellence (COE) in Tallin, Estonia. This is in response to last year's cyber attacks against Estonia.
"The centre will conduct research and training on cyber warfare and include a staff of 30 persons, half of them specialists from the sponsoring countries, Estonia, Germany, Italy, Latvia, Lithuania, Slovakia and Spain."


NATO opens new centre of excellence on cyber defence

US Senate Report on Use of the Internet by Islamist Groups

The U.S. Senate Committee on Homeland Security and Governmental Affairs has released a report titled: "Violent Islamist Extremism, The Internet, and the Homegrown Terrorist Threat".

The following quotes [reformatted for readability] give an overview of the report's contents:

"This staff report concerns ... – how violent Islamist terrorist groups like al-Qaeda are using the Internet to enlist followers into the global violent Islamist terrorist movement and to increase support for the movement, ranging from ideological support, to fundraising, and ultimately to planning and executing terrorist attacks.

"In the second section of this report, we examine the increasing number of homegrown incidents and the judgments of the intelligence and law enforcement communities that there will likely be additional homegrown threats in the future.

"The third section explores the four-step radicalization process through which an individual can be enticed to adopt a violent Islamist extremist mindset and act on the ideology’s call to violence.

"Section four identifies the disturbingly broad array of materials available on the Internet that promote the violent Islamist extremist ideology. The availability of these resources is not haphazard, but is part of a comprehensive, tightly controlled messaging campaign by al-Qaeda and like-minded extremists designed to spread their violent message.

"The fifth section of the report examines how these materials facilitate and encourage the radicalization process.

"Finally, the report assesses the federal government’s response to the spread of the violent Islamist message on the Internet and concludes that there is no cohesive and comprehensive outreach and communications strategy in place to confront this threat."


Violent Islamist Extremism, The Internet, and the Homegrown Terrorist Threat

Zimbabwe State Newspaper Attacked in Protest of 1980s Killings

The BBC is reporting on an attack against the website of Zimbabwe's state-owned Herald newspaper. The report provides no technical details but links the attack to allegations that the government carried out mass killings in the 1980s:

"Headlines on the site were replaced by the word Gukurahundi.

"The word refers to a campaign of mass slaughter that the government has been accused of carrying out after independence."


Hackers shut Zimbabwe website