Hi there, !
Today Tue 12/20/2005 Mon 12/19/2005 Sun 12/18/2005 Sat 12/17/2005 Fri 12/16/2005 Thu 12/15/2005 Wed 12/14/2005 Archives
Rantburg
532756 articles and 1859144 comments are archived on Rantburg.

Today: 63 articles and 241 comments as of 6:46.
Post a news link    Post your own article   
Area: WoT Operations    WoT Background    Non-WoT           
Iraq Votes
Today's Headlines
Headline Comments [Views]
Page 4: Opinion
11 00:00 PBMcL [2] 
5 00:00 Red Dog [] 
Page 1: WoT Operations
5 00:00 JAB [1]
6 00:00 mhw [1]
1 00:00 Super Hose [1]
16 00:00 2b []
0 []
15 00:00 Alaska Paul []
2 00:00 Super Hose []
0 []
4 00:00 Anonymoose [1]
7 00:00 J.C. and V.P. [1]
4 00:00 Super Hose []
0 [4]
0 [1]
0 []
20 00:00 Old Patriot [1]
1 00:00 Frank G [2]
4 00:00 Ebberesh Ulaviling3841 [1]
6 00:00 .com []
3 00:00 Captain America [2]
Page 2: WoT Background
2 00:00 gromgoru []
1 00:00 Spembelov [1]
4 00:00 Omoluting Chuque6056 [1]
2 00:00 2b [2]
7 00:00 macofromoc []
0 [1]
2 00:00 Frank G [1]
4 00:00 Scooter McGruder []
1 00:00 john []
1 00:00 gromgoru [3]
8 00:00 Phil []
6 00:00 CaziFarkus []
10 00:00 Chuck [2]
1 00:00 Lookin at the Pikture Spemble1217 [1]
6 00:00 lotp []
1 00:00 2b []
5 00:00 Red Dog [2]
0 []
2 00:00 anon1 []
1 00:00 Super Hose []
2 00:00 gromgoru [1]
2 00:00 Barbara Skolaut []
1 00:00 Glenmore []
0 []
15 00:00 Jan []
4 00:00 James []
12 00:00 newc []
0 [1]
4 00:00 Johnny Rivers [1]
Page 3: Non-WoT
0 [1]
0 []
1 00:00 gromgoru [1]
4 00:00 Farmin B SPemble1217 []
0 []
0 []
2 00:00 john []
5 00:00 Susi SPemble1217 []
2 00:00 49 pan []
0 []
2 00:00 CaziFarkus []
2 00:00 gromgoru []
9 00:00 DMFD []
China-Japan-Koreas
Kaidai Hackers Attack StrategyPage Servers
StrategyPage Server Stormed

December 17, 2005: StrategyPage doesn’t just report on Cyber War, sometimes we get caught in the middle of it. We got an electronic nastygram from China recently when, as we were installing a new server, at a hosting site (to improve response time, and lessen the workload on the volunteer staffers who maintain the server). There was a gap of a few days between the time the new server went online, and the hardware firewall (which is a bear to configure) got installed. Into that opening, some Chinese hackers got onto the server and tried to take it over. Actually, it was unclear what they were trying to do, but they did it at 2 AM, when one of our techies was trying to get onto the server to do some database maintenance, the hack attempt was noticed. There ensued a duel between our two guys and the Chinese. The Chinese lost, and we found out they were Chinese when we examined the tools and documents they left behind once they were locked out. Based on that, and the fight they put up, it appears it may have been a training exercise. When China trains its Internet warriors, it sends them out on training missions, to get into a vulnerable server and do the sort of things (like planting a rootkit) that one would do in preparation for a Cyber War. Of course, they could have just been part of a criminal gang, collecting zombie machines to use for extortion and other illegal Internet activities. But they way they were not all business when they were caught, and seemed a little green, indicated someone on some kind of training mission. Their tools and entry methods were more typical of a well equipped hacking enterprise. Actually, it could also have been a very elaborate bot (an automated hacking program). It did leave some code behind, and some modifications to some of our news databases. Whatever it was, it was apparently not completely set up before we cut off the hacker access and deleted stuff that was left on our server. We reformatted and reloaded from backups and were back in business in a few hours.

All this during the last week of November, and, after three unsuccessful attacks, someone got in and modified out main page. They did this by installing an encrypted Javascript Trojan that would try to infect client machines (this sometimes triggered a virus alarm with some anti-virus programs). The Javascript was poorly written, and the Trojan was unable to carry out this infection. The Trojan concept was clever enough, tt was included in an [iframe] tag which basically allows a web page to be included on another webpage – in this case, ours. The other webpage was hosted on a server called freewebs.com, but the hacker hacker webpage was gone, removed by the hosting service, by the time we went looking for it (about 12 hours after our page was hacked).

Those hackers have not been back. We piled up additional defense and tripwires, to hold us until the hardware firewall went online last week. None of these attacks got close to any customer data, which is kept on a separate server (at another location, there are actually three physically very separate servers running StrategyPage.)

As a practical matter, no server on the planet, that is connected to the Internet, is invulnerable to an attack. But if you put up stout enough defenses, you reduce the number of hackers skillful enough to get through, and increase the chances of the attacker getting caught. That’s how financial institutions, which are the most attacked targets, maintain their defenses. The most skilled hackers want to avoid arrest, so they tend to avoid taking on these heavily defended servers. There are plenty of less well defended targets, and that’s who the hackers are now going after. Well, except for one fellow, who we’ve tracked back to Montevallo University in Montevallo, Alabama. So, either we have a student from there doing this or (more likely) they have a school PC that was taken over by a hack, and turned into a zombie. He’s hammering, futilely, at port 1305 on our main server. The hardware firewall just notes this for us, and life goes on.


Posted by: Wholurong Speremp9471 || 12/17/2005 14:44 || Comments || Link || [0 views] Top|| File under:

#1  Leaving a Windows/IIS server exposed for 'a few days' is not exactly what you call playing good defense.
Posted by: SteveS || 12/17/2005 16:33 Comments || Top||

#2  My 'puter keeps crashing too


Posted by: Red Dog || 12/17/2005 17:15 Comments || Top||

#3  We piled up additional defense and tripwires, to hold us until the hardware firewall went online last week. None of these attacks got close to any customer data, which is kept on a separate server (at another location, there are actually three physically very separate servers running StrategyPage.)

Makes a good story. If true why tell, if a lie tell more. To wit don't talk about structure or changes, don't talk about "duels" jeebus. Keep it tight, and keep it very, very quiet.
Posted by: Lake Worth Spemble1217 || 12/17/2005 17:41 Comments || Top||

#4  hey Red Dog, that link is great thanks
Posted by: Jan || 12/17/2005 21:41 Comments || Top||

#5  glad ya liked it Jan. ;-)
Posted by: Red Dog || 12/17/2005 22:51 Comments || Top||


Fifth Column
Proposal: Rantburg Photoshop Contest
"I'm meltingggggggggg!"


MADRID, Spain - Anti-war activist Cindy Sheehan led a small protest Saturday outside the U.S. Embassy to denounce the war in Iraq.

About 100 protesters carried banners criticizing President Bush.

Sheehan, whose soldier son was killed in Iraq, called Bush a war criminal and said, "Iraq is worse than Vietnam."

The protest also was called in memory of Jose Couso, a Spanish television cameraman killed on April 8, 2003, in Baghdad when a U.S. tank fired at a hotel where many foreign correspondents were staying. Reuters cameraman Taras Protsyuk, a Ukrainian, also was killed in that incident.
Posted by: Anonymoose || 12/17/2005 18:30 || Comments || Link || [2 views] Top|| File under:

#1 

Cindy's moonbats molerats.
Posted by: Red Dog || 12/17/2005 19:37 Comments || Top||

#2 


#1  

http://image63.webshots.com/63/2/9/24/524620924qKPzLG_ph.jpg

Sigh. I tried. Apparently good ol' HTML ain't good enough anymore.
Posted by: Parabellum || 12/17/2005 20:33 Comments || Top||

#3  how about a caption contest:

"I'M MELLLLTING"
Posted by: 2b || 12/17/2005 21:28 Comments || Top||

#4  Beatcha to it!
Posted by: Fred || 12/17/2005 21:32 Comments || Top||

#5  By golly, you did. It was darn funny too!
Posted by: 2b || 12/17/2005 21:36 Comments || Top||

#6  "I could've have been a contender" :)
Posted by: djohn66 || 12/17/2005 21:36 Comments || Top||

#7  "Gawd I miss dry-humping Jesse Jackson!"
Posted by: Cindy Sheehan || 12/17/2005 22:13 Comments || Top||

#8  "If you only knew the POWER of the dark side..."
Posted by: jules 2 || 12/17/2005 22:19 Comments || Top||

#9 
Be quiet everyone!

I'm channeling the Great Generalissimo
Posted by: Cindy || 12/17/2005 23:01 Comments || Top||

#10  Quiet on the set please......

Quiet....

....and .....action!!!


annnnnndddd.. Cut!


Posted by: macofromoc || 12/17/2005 23:42 Comments || Top||

#11  "Oh Gawd! It's Rantburg! My eyes! My eyes!"
Posted by: PBMcL || 12/17/2005 23:42 Comments || Top||



Who's in the News
63[untagged]

Bookmark
E-Mail Me

The Classics
The O Club
Rantburg Store
The Bloids
The Never-ending Story
Thugburg
Gulf War I
The Way We Were
Bio

Merry-Go-Blog











On Sale now!


A multi-volume chronology and reference guide set detailing three years of the Mexican Drug War between 2010 and 2012.

Rantburg.com and borderlandbeat.com correspondent and author Chris Covert presents his first non-fiction work detailing the drug and gang related violence in Mexico.

Chris gives us Mexican press dispatches of drug and gang war violence over three years, presented in a multi volume set intended to chronicle the death, violence and mayhem which has dominated Mexico for six years.
Click here for more information

Meet the Mods
In no particular order...
Steve White
Seafarious
tu3031
badanov
sherry
ryuge
GolfBravoUSMC
Bright Pebbles
trailing wife
Gloria
Fred
Besoeker
Glenmore
Frank G
3dc
Skidmark

Two weeks of WOT
Sat 2005-12-17
  Iraq Votes
Fri 2005-12-16
  FSB director confirms death of Abu Omar al-Saif
Thu 2005-12-15
  Jordanian PM vows preemptive war on "Takfiri culture"
Wed 2005-12-14
  Iraq Guards Intercept Forged Ballots From Iran
Tue 2005-12-13
  US, UK, troop pull-out to begin in months
Mon 2005-12-12
  Iraq Poised to Vote
Sun 2005-12-11
  Chechens confirm death of also al-Saif, deputy emir also toes up
Sat 2005-12-10
  EU concealed deal allowing rendition flights
Fri 2005-12-09
  Plans for establishing Al-Qaeda in North African countries
Thu 2005-12-08
  Iraq Orders Closure Of Syrian Border
Wed 2005-12-07
  Passenger who made bomb threat banged at Miami International
Tue 2005-12-06
  Sami al-Arian walks
Mon 2005-12-05
  Allawi sez gunmen tried to assassinate him
Sun 2005-12-04
  Sistani sez "Support your local holy man"
Sat 2005-12-03
  Qaeda #3 helizapped in Waziristan


Rantburg was assembled from recycled algorithms in the United States of America. No trees were destroyed in the production of this weblog. We did hurt some, though. Sorry.
18.224.67.149
Help keep the Burg running! Paypal:
WoT Operations (19)    WoT Background (29)    Non-WoT (13)    (0)    (0)