Bruce Schneier | |||||||||||||||
Schneier on SecurityA blog covering security and security technology. « Friday Squid Blogging: Squid Fishing in Ulleungdo, Korea | Main | Details of the RSA Hack » August 29, 2011Screenshots of Chinese Hacking ToolIt's hard to know how serious this really is: The screenshots appear as B-roll footage in the documentary for six secondsbetween 11:04 and 11:10 minutes -- showing custom built Chinese software apparently launching a cyber-attack against the main website of the Falun Gong spiritual practice, by using a compromised IP address belonging to a United States university. As of Aug. 22 at 1:30pm EDT, in addition to Youtube, the whole documentary is available on the CCTV website. Posted on August 29, 2011 at 6:20 AM • 22 Comments To receive these entries once a month by e-mail, sign up for the Crypto-Gram Newsletter. It must be quite challenging to wage a cyber espionage campaign as vast as China's without leaks. I imagine that the various groups within China are constantly competing with each other for funds, attention, et cetera. This is most likely a symptom of an organ with weak opsec beaming with a little too much pride over it's efforts to train new cyber operators and create new tools. They probably didn't think it was a big deal because it's not directly related to any of the touchy CNE activities. Posted by: Nick Levay at August 29, 2011 7:03 AM What can it be beside a LOIC like software? What I mean is: What can such a distributed software do except giving DDoS and potentially providing background noise to hide some other more sophisticated attack? Posted by: ChristianO at August 29, 2011 7:09 AM seems like this software was developed by someone else and is being used by someone else it seems this software is in large circulation Posted by: CoreComments at August 29, 2011 7:12 AM Couldn't someone simply contact admins at UAB and ask for logs to get a pretty good idea what it's like? It's probably just Chinese version of LOIC. Posted by: Tomasz Wegrzanowski at August 29, 2011 7:28 AM Keep in mind that you're citing the Epoch Times, a Falun Gong-controlled outlet that has a much stronger commitment to being anti-CCP than it does to responsible journalism. Posted by: Evan H at August 29, 2011 7:47 AM There are quite a few analysis of this. The first thing to note is the Chinese put it out on Chinese State television on a channel (CCTV7) which is combined military show case and agracultural programs... The second thing to note is that it is a fairly crude attack that is more than ten years old. It appears that acording to UAB there was a student/technician working there and they did run a website against UAB rules and it was taken down. Also they say that the IP address has not been used in a considerable period of time. Of more interest is that some think the tool appears to have been written by crackers/gamesplayers possibly students at the Chhinese Military institution. Have a look at one view, http://www.chinasignpost.com/2011/08/... However as normal with such sites treat with caution. Posted by: Clive Robinson at August 29, 2011 8:27 AM The Reuters article claimed that the UAB IP address was a compromised machine that would be used to launch the attack. That's kind of a wild conclusion, without supporting evidence in the video. If anything, it is the IP address that the hacking software associates with minghui.org (even though minghui.org does not resolve to that address). I had a Chinese friend translate the text, and she said that the IP text box is something like "target web server IP". Worth noting that my Chinese friend was unsurprised and unapologetic about the idea that China might attack overseas Falun Gong web sites. Posted by: L at August 29, 2011 9:13 AM And if you go into every research lab in the US, there will be applications with Chinese IP addresses typed in. This is a non-news event. Posted by: Andrew at August 29, 2011 11:27 AM Andrew. That depends on what you mean by "news". If what you mean is that this is something new and different to the security community, you're correct; it's not news. It's in the news, however, because it provides some small support to the larger public narrative that China is not just a rival to the USA/western world but an actual enemy. Posted by: Daniel at August 29, 2011 12:16 PM For all those now crying "proof!", it is nothing of the sort. This could well be a mock-up with no attack software connected to it. The choice of IP address is unfortunate, but again does not "proof" anything. In fact with the IP not being assigned to anything at the moment (according to some other report), the mock-up seems likely. The one thing that can be observed here (again and again) is the incompetence of the press with regard to Internet technology and their unwillingness to ask people that understand. Posted by: Gweihir at August 29, 2011 12:23 PM What's on the screens in the vid I find immaterial. It could even be a total mock-up. What's material is they are telling millions of young Chinese kids that cyberwar is a valid military technology and they plan on exploiting it to the hilt. So... 1) Self-educated Chinese hackers feel like it's a go-ahead to screw with western severs. 2) Young patriotic Chinese will show up at the military recruitment posts and want to get in on the "cyberwar" thing. Even with the leak I think the video was a brilliant move. Little things like this when you have a massive population with ever-increasing industrialization pay big benefits down the road. Welcome to the 21st century! Posted by: Poster of Brucedom Currently Being Tracked by the SEC at August 29, 2011 12:44 PM >he shots then show a big "Attack" button Something like http://www.turnofftheinternet.com/ Posted by: NZ at August 29, 2011 2:39 PM @Andrew You're changing the subject from "military-led denial of service attack" to "research" and then saying that because researchers (like myself) study Chinese and all other hosts, to prevent/limit abuse, that military-led denial of service attacks are okay, a "non-news event." You are equating those who wage abuse with those who try to stop it. Why? Posted by: Webster at August 29, 2011 2:45 PM Looks to me the article is about hackers / DDOS / attack of Falon Gong sites... The commentators change the subject and make it a military thing. My guess is all the above commentators are Americans? Who has changed the Internet in a tool for warfare? The 1st hacker who shuts down the whole military network has my blessings. I rather have 10,000 hackers attacking my site than 1 military (USA) operator aiming with his joystick and put the cross on me and then push the fire button... Posted by: Ronny at August 29, 2011 5:12 PM My only concern is that we are spend more on trying to build systems to attack others than we spend on building protocols to defend with. And that problem, it seems to me, is rooted on the fact that the best defenses are built with open collaboration between interested parties which is anathema to the defense department. Seriously, Bruce taught me that if you don't put your code out in the public to be abused you'll never find the holes. (Thanks, man!) I honestly believe that the Powers that Be in the Pentagon think if we are attacked and things get bad they can just "turn off the internet." So as I pay all my bills online, schedule classes online, make phone calls online, and surf pr0n - I think if all this was turned off for more than a week we'd have a serious economic crash. We're hip deep in the wires and there is no backing out gracefully. Better to start designing life rafts in case worse comes to worst. Wurst? Posted by: Poster of Brucedom Currently Being Tracked by the CIA at August 29, 2011 6:53 PM i hope the chinese dont watch 24. They might think we have amazing cyber hacking warfare tools that can be run from an Iphone to remotely hack a AES encrypted data stream. Posted by: JT at August 29, 2011 8:17 PM It was featured on F-secure a couple of days ago, part of video is still there: http://www.f-secure.com/weblog/archives/... And the follow up when the video was gone: Posted by: Jos at August 30, 2011 6:05 AM What's the deal? A utility like that is nothing special - even I could code it on a slow weekend (but there's no need to, since there are already dozens of those out there). It might be harder if it uses a botnet, but even that is not very impressive. Posted by: Autolykos at August 31, 2011 7:15 AM the IP belongs to: Address Lookup IP Location Birmingham, United States[US] the GUI of the attack tool is not so cute... Posted by: fatfish at September 2, 2011 1:48 AM UPDATE: The University of Alabama at Birmingham made a statement after the news broke, noting that the IP address belonged to a website that was decommissioned in 2001 because it had been created against UAB rules. They said that they believe the purpose of the action demonstrated in the video was not to launch an attack from that website, but to block access to it, and that they're not aware of any such attack, past or present. Posted by: Xingdao at September 3, 2011 6:37 PM Subscribe to comments on this entry Post a comment
Powered by Movable Type. Photo at top by Geoffrey Stone.
Schneier.com is a personal website. Opinions expressed are not necessarily those of BT. |
|
Comments