Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Who else wants national broadband?
8 things you didn't know about Windows Phone 7
Microsoft touts speed, HTML 5 support in IE9
It's Official: Facebook Rules the Web
New Internet browser threat sneaks by traditional defenses
Novell's Mono project bringing .Net development to Android
HP, IBM, Dell launch servers with new Intel chips
Happy 25th Birthday 'Dot Com': A Look Back
Why is cloud computing hard? Top tech execs speak their minds
Free Microsoft Windows Phone 7 developer tools released
Microsoft: No native code for Windows Phone 7
60% of virtual servers less secure than physical machines, Gartner says
Digg, like Twitter, rips out MySQL
FCC's national broadband plan: What's in it?
FCC broadband test greeted by skepticism
/

U.S.-China hacker brawl draws few Web combatants

Today's breaking news
Send to a friendFeedback


Although not exactly a cyberwar, a hacking brawl of sorts erupted last week between Chinese and U.S. combatants.

The National Information Protection Center (NIPC) at the FBI had earlier warned that Chinese hackers would attack U.S.-based Web sites in a campaign to avenge the U.S. spy plane incident and arms sales to Taiwan.

Web sites run by the Department of Labor, Health and Human Services and the White House Historical Society were among many defaced with Chinese flags and slogans such as "Beat down imperialism of America!" from groups claiming names such as the "Honker Union of China" and "China Eagle."

At the same time, U.S. hackers defaced hundreds of Chinese sites operated by local and national government departments with the .cn domain name, frequently leaving vulgar and racist taunts along with anti-Communist invective and images of nuclear bomb explosions.

Security consulting firm TruSecure, which was tracking the hacker activity, says there were about 260 successful attacks each day perpetrated by perhaps 12 individuals from both sides.

"But we're just beating the snot out of the Chinese," says Peter Tippett, TruSecure's CTO. It appears there were roughly three times more hacks from American locations against Chinese sites than vice versa, although Tippett acknowledges that hackers can use spoofed IP addresses.

He says the main reason the Americans seemed to be having more success than the Chinese was because the Chinese haven't updated their Web servers with software patches to prevent known attacks, which are frequently carried out by hackers with an array of easily obtained scripting hack tools. Software patches for Chinese-language servers using double-byte code don't usually become available as quickly as those for English-language servers.

The American hackers, who sometimes called their fight "Project China," were the usual suspects. The Chinese participants included the Li0n Group, known to have released the dangerous Li0n Trojan horse.

Tippett says there's no evidence the hackers have gone beyond defacing Web sites. "It's like spray-painting a bridge," he says. The attackers frequently even left a link to the home page.

"It's the kind of thing we've seen before, two kids on both sides going after each other," says Steve Trilling, Symantec's director of research. "It's like graffiti."

The NIPC advisory about the attacks and publicity from news sites served to fuel the fire, Tippett adds.

An organization called Attrition.org, which runs a site that documents hacked sites, usually steers clear of commentary, but last week, the group issued a statement denouncing the China-U.S. hacker feud.

"It's just the collective [posturing] of a bunch of script-kiddies fueled by so-called journalists generating media hype, the former trying to feed their egos and the latter to feed their hit counts," the statement says.

RELATED LINKS

Contact Senior Editor Ellen Messmer

Other recent articles by Messmer

Cyberwar with China: Self-fulfilling Prophecy
Attrition.org, which catalogs defaced Web sites, thinks the coverage of it all is overblown.

Network World on Security
Sign up for our free e-mail newsletter.

Breaking hacker news


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.