<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; cyberterrorism</title>
	<atom:link href="http://www.darknet.org.uk/tag/cyberterrorism/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>More Cyberterrorism &#8211; Taiwan Political Party Accuses China of Hacking</title>
		<link>http://www.darknet.org.uk/2011/08/more-cyberterrorism-taiwan-political-party-accuses-china-of-hacking/</link>
		<comments>http://www.darknet.org.uk/2011/08/more-cyberterrorism-taiwan-political-party-accuses-china-of-hacking/#comments</comments>
		<pubDate>Tue, 09 Aug 2011 16:34:30 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General News]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[chinese government hackers]]></category>
		<category><![CDATA[chinese-hackers]]></category>
		<category><![CDATA[cyber attacks]]></category>
		<category><![CDATA[cyber-terrorism]]></category>
		<category><![CDATA[cyberterrorism]]></category>
		<category><![CDATA[tawain]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3166</guid>
		<description><![CDATA[Well there hasn&#8217;t been a whole lot of news the last couple of days apart from the London riots &#8211; which don&#8217;t have much of a technical spin. The only technical part is that the looters/rioters etc seem to be organizing themselves using BBM (BlackBerry Messenger) and Twitter. The former being rather smart as it&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>Well there hasn&#8217;t been a whole lot of news the last couple of days apart from the London riots &#8211; which don&#8217;t have much of a technical spin. The only technical part is that the looters/rioters etc seem to be organizing themselves using BBM (BlackBerry Messenger) and Twitter.</p>
<p>The former being rather smart as it&#8217;s encrypted and sent via a 3rd party network &#8211; so it&#8217;s not open to wiretapping. It&#8217;s unlikely the tracksuit wearing chavs &#038; hoodies know that, but still &#8211; it&#8217;s keeping them safe. Posting videos/pictures of themselves on public Twitter and Facebook accounts is not so smart though and will surely lead to some arrests.</p>
<p>Anyway that&#8217;s not the topic here, the topic here is another politically motivated hacking attack &#8211; what we would commonly call <a href="http://www.darknet.org.uk/tag/cyberterrorism/" title="Cyberterrorism">cyberterrorism</a>.</p>
<blockquote><p>A Taiwanese political party suspects the Chinese government is behind a hacking attack that stole information about the party&#8217;s election activities.</p>
<p>Taiwan&#8217;s Democratic Progressive Party (DPP) said on Tuesday that some of the attacks had been traced to China&#8217;s Xinhua News Agency, a state-run press group. The attack operated as a phishing campaign, in which DPP staffers were sent e-mails by hackers who attempted to impersonate other party employees. The staffers were then told to open the e-mail attachments, which secretly contained viruses to monitor the computers, a DPP spokeswoman said.</p>
<p>The DPP alleges the attacks were routed from the Xinhua News Agency through Malaysia and Australia. The attacks were also traced to IP addresses from the Chinese mainland. The Xinhua News Agency was contacted for response, but has yet to an issue a comment.</p>
<p>IT security experts have said the attacks were part of a state-sponsored hacking attempt, according to the DPP. &#8220;Already many countries and security groups have said the attacks from China&#8217;s cyber army are well organized and that a state actor guides and supports them,&#8221; the DPP said in statement issued on the party&#8217;s website. </p></blockquote>
<p>As we all know, Taiwan and <a href="http://www.darknet.org.uk/tag/china/">China</a> are not really the best of friends with China claiming Taiwan to be part of it and Taiwan not quite agreeing. In China they fully act like Taiwan is just another state/province in China.</p>
<p>This time it seems to be a state run Chinese news agency (Xinhua) attacking Taiwan&#8217;s Democratic Progressive Party (commonly know as DPP).</p>
<p>These are of course at this time just claims, and it&#8217;ll probably stay that way as there&#8217;s no conclusive proof in these kind of situations.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>China is already in the spotlight for cyber attacks after security vendor McAfee reported a massive cyber attack that stole sensitive information from 72 companies and organizations. Although McAfee did not name the group behind the hacking attempts, security experts have pointed fingers at China because of the organizations targeted. China, however, has repeatedly denied it sponsors any kind of hacking.</p>
<p>A DPP spokeswoman said the phishing attacks have been an ongoing problem, but that it appears more of the recent hacking attempts have been coming from China.</p>
<p>Taiwan and China separated in 1949 after a civil war. While China&#8217;s ruling communist party seeks for reunification with the island, the DPP supports Taiwan becoming its own nation, putting the two at odds with one another.</p>
<p>The DPP said on Tuesday it also traced hacking attempts to Taiwan&#8217;s own Research, Development and Evaluation Commission and called for the commission to investigate. The commission could not be reached for immediate comment. </p></blockquote>
<p>China have been in the spotlight fairly recently with some very widespread phishing attacks including &#8211; <a href="http://www.darknet.org.uk/2011/06/targeted-phishing-attacks-carried-out-on-gmail-likely-from-china/">Targeted Phishing Attacks Carried Out On Gmail – Likely From China</a>.</p>
<p>It seems like these kinds of games will be going on forever including hacktivism, cyberterrorism, defacement in the name of certain causes and all kinds of other naughty business.</p>
<p>With so much information on computers now it&#8217;s no surprise, I&#8217;d like to see these kind of organisations having better infosec policies though including awareness training for all staff with access to e-mail accounts and computers.</p>
<p>Source: <a href="http://www.networkworld.com/news/2011/080911-taiwan-political-party-accusses-china.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=More+Cyberterrorism+%E2%80%93+Taiwan+Political+Party+Accuses+China+of+Hacking+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3166+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/08/more-cyberterrorism-taiwan-political-party-accuses-china-of-hacking/&amp;t=More+Cyberterrorism+%E2%80%93+Taiwan+Political+Party+Accuses+China+of+Hacking" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/08/more-cyberterrorism-taiwan-political-party-accuses-china-of-hacking/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/08/more-cyberterrorism-taiwan-political-party-accuses-china-of-hacking/&amp;title=More+Cyberterrorism+%E2%80%93+Taiwan+Political+Party+Accuses+China+of+Hacking" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/08/more-cyberterrorism-taiwan-political-party-accuses-china-of-hacking/&amp;title=More+Cyberterrorism+%E2%80%93+Taiwan+Political+Party+Accuses+China+of+Hacking" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/08/more-cyberterrorism-taiwan-political-party-accuses-china-of-hacking/&amp;title=More+Cyberterrorism+%E2%80%93+Taiwan+Political+Party+Accuses+China+of+Hacking" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/08/more-cyberterrorism-taiwan-political-party-accuses-china-of-hacking/&amp;title=More+Cyberterrorism+%E2%80%93+Taiwan+Political+Party+Accuses+China+of+Hacking" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F08%2Fmore-cyberterrorism-taiwan-political-party-accuses-china-of-hacking%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/08/more-cyberterrorism-taiwan-political-party-accuses-china-of-hacking/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Targeted Phishing Attacks Carried Out On Gmail &#8211; Likely From China</title>
		<link>http://www.darknet.org.uk/2011/06/targeted-phishing-attacks-carried-out-on-gmail-likely-from-china/</link>
		<comments>http://www.darknet.org.uk/2011/06/targeted-phishing-attacks-carried-out-on-gmail-likely-from-china/#comments</comments>
		<pubDate>Thu, 02 Jun 2011 11:02:17 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[chinese political activists]]></category>
		<category><![CDATA[chinese-hackers]]></category>
		<category><![CDATA[cyber-terrorism]]></category>
		<category><![CDATA[cyberterrorism]]></category>
		<category><![CDATA[gmail phishing]]></category>
		<category><![CDATA[hacking-US-government]]></category>
		<category><![CDATA[phising gmail]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[secrecy]]></category>
		<category><![CDATA[spear phishing]]></category>
		<category><![CDATA[targeted phishing]]></category>
		<category><![CDATA[us government officials]]></category>
		<category><![CDATA[us military security]]></category>
		<category><![CDATA[us-military]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3124</guid>
		<description><![CDATA[It was just about a week ago when we wrote about the technical flaw in Hotmail and the fact that the Hotmail Exploit Has Been Silently Stealing E-mail for some time. The latest news is some hackers have been targeting users of the Gmail service, specifically US government officials. This comes shortly after the news [...]]]></description>
			<content:encoded><![CDATA[<p>It was just about a week ago when we wrote about the technical flaw in <a href="http://www.darknet.org.uk/tag/hotmail/">Hotmail</a> and the fact that the <a href="http://www.darknet.org.uk/2011/05/hotmail-exploit-has-been-silently-stealing-e-mail/">Hotmail Exploit Has Been Silently Stealing E-mail</a> for some time.</p>
<p>The latest news is some hackers have been targeting users of the <a href="http://www.darknet.org.uk/tag/gmail/">Gmail</a> service, specifically US government officials. This comes shortly after the news of <a href="http://www.darknet.org.uk/2011/05/lockheed-martin-hacked-rumoured-to-be-linked-to-rsa-securid-breach/">Lockheed Martin being compromised</a> and a second military contractor being <a href="http://www.theregister.co.uk/2011/06/01/military_contractor_2nd_rsa_securid_hack/">attacked using RSA SecurID tokens today</a>.</p>
<p>It is what&#8217;s known as a &#8216;spear phishing&#8217; attack &#8211; which means it&#8217;s aimed at a specific organization or in this case specific individuals. It&#8217;s not a shotgun approach &#8211; where they spray e-mails everywhere, more like a sniper rifle.</p>
<blockquote><p>Google has detected a targeted campaign to collect hundreds of personal Gmail passwords, many of them belonging to senior US government officials, Chinese political activists, military personnel, and journalists.</p>
<p>The accounts may have been compromised using spear phishing techniques in which victims received highly personalized messages that contained links to counterfeit Gmail pages, according to a blog post published in February that Google cited when disclosing the attacks on Wednesday. Google said the campaign “appears to originate from Jinan, China” but didn&#8217;t share any evidence supporting that claim.</p>
<p>“The goal of this effort seems to have been to monitor the contents of these users&#8217; emails, with the perpetrators apparently using stolen passwords to change people&#8217;s forwarding and delegation settings,” Google&#8217;s blog post, titled “Ensuring your information is safe online,” stated. “Google detected and has disrupted this campaign to take users&#8217; passwords and monitor their emails. Company officials have alerted the victims and “relevant government authorities.”</p>
<p>According to the February blog post, some of the phishing pages were hosted using the free dyndns.org service and contained images and text that were almost indistinguishable from those hosted on the real Google service. The links were “customized and individualized for each target,” independent security researcher Mila Parkour wrote</p></blockquote>
<p>They are using the same old trick of getting the passwords then changing the forwarding settings so they can receive all the e-mails sent to that account somewhere else.</p>
<p>The attacks are said to originate from <a href="http://www.darknet.org.uk/tag/china/">China</a>, but as I&#8217;m sure you all know &#8211; just because the IP is in China it doesn&#8217;t mean the attacker is physically there too.</p>
<p>It&#8217;s a pretty systematic attack and extremely hard to defend against, because once they&#8217;ve compromised a few accounts of people that know each other &#8211; they can then make the personalized phishing mails even more relevant and convincing.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>Once accounts were compromised attackers created rules to automatically forward all received email to accounts under their control, Parkour said. The attackers then used the purloined email to “gather information about the closets associates and family/friends” and exploited “the harvested information for making future mailings more plausible.”</p>
<p>Parkour&#8217;s post showed a half-dozen emails exchanged in the campaign, several of which contained Pentagon and US State Department addresses.</p>
<p>“This is the latest version of the State&#8217;s joint statement,” one fraudulent email read. “My understanding is that State put in placeholder econ language and am happy to have us fill in but in their rush to get a cleared version from the WH, they sent the attached to Mike.”</p>
<p>The email contained what appeared to be a Microsoft Word document as an attachment.</p>
<p>The incident harkens back to a separate attack Google disclosed in January 2010, that targeted the company&#8217;s source code and the Gmail accounts of human rights activists in China. Unlike the most recent phishing campaign, the “highly sophisticated and targeted attack” from 2010 exploited vulnerabilities on Google&#8217;s network to gain unauthorized access. Dozens of other companies were also targeted in the earlier attack.</p>
<p>Google&#8217;s blog post provides a variety of tips for keeping accounts secure. They include use of a two-step verification procedure when logging in to accounts to add an extra layer of security to the login process. Gmail also warns users of suspicious logins to their accounts.</p></blockquote>
<p>Google does have a variety of security measure, they allow you see account activity details, IP addresses logged into your account and they do warn you of any suspicious activity. Recently they also started supporting two-factor authentication using tokens, this would totally defeat these kind of phishing attacks.</p>
<p>They support both SMS based authentication and application based (for iPhone, Android and BlackBerry).</p>
<p>So if you&#8217;re using a <a href="http://www.darknet.org.uk/tag/google/">Google</a> account, make sure it&#8217;s secure!</p>
<p>Source: <a href="http://www.theregister.co.uk/2011/06/02/gmail_spear_phishing_exposed/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Targeted+Phishing+Attacks+Carried+Out+On+Gmail+%E2%80%93+Likely+From+China+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3124+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/06/targeted-phishing-attacks-carried-out-on-gmail-likely-from-china/&amp;t=Targeted+Phishing+Attacks+Carried+Out+On+Gmail+%E2%80%93+Likely+From+China" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/06/targeted-phishing-attacks-carried-out-on-gmail-likely-from-china/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/06/targeted-phishing-attacks-carried-out-on-gmail-likely-from-china/&amp;title=Targeted+Phishing+Attacks+Carried+Out+On+Gmail+%E2%80%93+Likely+From+China" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/06/targeted-phishing-attacks-carried-out-on-gmail-likely-from-china/&amp;title=Targeted+Phishing+Attacks+Carried+Out+On+Gmail+%E2%80%93+Likely+From+China" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/06/targeted-phishing-attacks-carried-out-on-gmail-likely-from-china/&amp;title=Targeted+Phishing+Attacks+Carried+Out+On+Gmail+%E2%80%93+Likely+From+China" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/06/targeted-phishing-attacks-carried-out-on-gmail-likely-from-china/&amp;title=Targeted+Phishing+Attacks+Carried+Out+On+Gmail+%E2%80%93+Likely+From+China" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F06%2Ftargeted-phishing-attacks-carried-out-on-gmail-likely-from-china%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/06/targeted-phishing-attacks-carried-out-on-gmail-likely-from-china/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>India Central Bureau of Investigation (CBI) Site Still Down</title>
		<link>http://www.darknet.org.uk/2010/12/india-central-bureau-of-investigation-cbi-site-still-down/</link>
		<comments>http://www.darknet.org.uk/2010/12/india-central-bureau-of-investigation-cbi-site-still-down/#comments</comments>
		<pubDate>Tue, 07 Dec 2010 17:47:54 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General News]]></category>
		<category><![CDATA[cbi]]></category>
		<category><![CDATA[cbi hacked]]></category>
		<category><![CDATA[central bureau of investigation]]></category>
		<category><![CDATA[cyber-terrorism]]></category>
		<category><![CDATA[cyberterrorism]]></category>
		<category><![CDATA[feds]]></category>
		<category><![CDATA[hacking-web-sites]]></category>
		<category><![CDATA[india cbi]]></category>
		<category><![CDATA[india cbi hacked]]></category>
		<category><![CDATA[indian cyber army]]></category>
		<category><![CDATA[indian government]]></category>
		<category><![CDATA[indian site hacked]]></category>
		<category><![CDATA[pakistani cyber army]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[web-defacement]]></category>
		<category><![CDATA[web-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3008</guid>
		<description><![CDATA[There has been quite a lot of chatter online about this case, politically there are long standing disputes between India and Pakistan and naturally these also extend to online wars &#8211; which inevitably end in defacement. The latest target from the group calling themselves the Pakistani Cyber Army was the site for the Central Bureau [...]]]></description>
			<content:encoded><![CDATA[<p>There has been quite a lot of chatter online about this case, politically there are long standing disputes between <a href="http://www.darknet.org.uk/tag/india/">India</a> and Pakistan and naturally these also extend to online wars &#8211; which inevitably end in defacement.</p>
<p>The latest target from the group calling themselves the Pakistani Cyber Army was the site for the Central Bureau of Investigation in India &#8211; <a href="http://cbi.nic.in/">http://cbi.nic.in/</a>.</p>
<p>Almost 4 days after the defacement, the site still appears to be down.</p>
<blockquote><p>Close to four days after the site of India&#8217;s key investigation agency, the Central Bureau of Investigation (CBI), was hacked and defaced, the web site is still inaccessible to users.</p>
<p>The CBI is doing a thorough security audit, and plugging all holes to prevent another hack, Vinita Thakur, a spokeswoman said on Tuesday. She didn&#8217;t say when that would be complete, and the site restored.</p>
<p>The web site of the CBI was hacked and defaced on Friday night. The hackers calling themselves the &#8220;Pakistani Cyber Army&#8221; left a message saying that the attack was in revenge for similar Indian attacks on Pakistani sites.</p>
<p>The CBI&#8217;s IT systems were not compromised by the hack, as the web site and the CBI’s computer systems are separate, Thakur said. </p></blockquote>
<p>They say they are doing a thorough audit and they are going to plug all the holes, but in reality &#8211; we know that&#8217;s not true because it&#8217;s not possible. They both seem to be stuck in a catch 22 situation as both the Indian and Pakistani sides continue with revenge attacks for the previous defacement.</p>
<p>Almost immediately after this attack the Indian Cyber Army executed another hack and deface job to retaliate. And well, whatever happens after this &#8211; it&#8217;s not going to be pretty for either side.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>The information that the hackers had access to was public information, she added.</p>
<p>The border dispute between India and Pakistan over Kashmir has often spilled online, with both sides attempting to hack each other&#8217;s web sites.</p>
<p>The web site of Pakistan&#8217;s Oil &#038; Gas Regulatory Authority was hacked on Saturday by a group called &#8220;Indian Cyber Army&#8221; in retaliation for the CBI web site hack, according to media reports from Pakistan.</p>
<p>The web site which displayed the message &#8220;This Account has been suspended&#8221; late Saturday, has since been restored. </p></blockquote>
<p>The Pakistani site that was attacked is back up and accessible to the public again, but as of now I&#8217;m still seeing some database access error messages in the sidebar and at the top of the page &#8211; <a href="http://www.ogra.org.pk/">http://www.ogra.org.pk/</a>.</p>
<p>My guess would be that this is not going to stop any time soon.</p>
<p>Source: <a href="http://www.networkworld.com/news/2010/120710-hacked-indian-investigation-agency-web.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=India+Central+Bureau+of+Investigation+%28CBI%29+Site+Still+Down+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3008+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/12/india-central-bureau-of-investigation-cbi-site-still-down/&amp;t=India+Central+Bureau+of+Investigation+%28CBI%29+Site+Still+Down" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/12/india-central-bureau-of-investigation-cbi-site-still-down/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/12/india-central-bureau-of-investigation-cbi-site-still-down/&amp;title=India+Central+Bureau+of+Investigation+%28CBI%29+Site+Still+Down" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/12/india-central-bureau-of-investigation-cbi-site-still-down/&amp;title=India+Central+Bureau+of+Investigation+%28CBI%29+Site+Still+Down" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/12/india-central-bureau-of-investigation-cbi-site-still-down/&amp;title=India+Central+Bureau+of+Investigation+%28CBI%29+Site+Still+Down" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/12/india-central-bureau-of-investigation-cbi-site-still-down/&amp;title=India+Central+Bureau+of+Investigation+%28CBI%29+Site+Still+Down" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F12%2Findia-central-bureau-of-investigation-cbi-site-still-down%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/12/india-central-bureau-of-investigation-cbi-site-still-down/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Twitter &amp; Facebook Taken Offline By DDoS Attacks</title>
		<link>http://www.darknet.org.uk/2009/08/twitter-facebook-taken-offline-by-ddos-attacks/</link>
		<comments>http://www.darknet.org.uk/2009/08/twitter-facebook-taken-offline-by-ddos-attacks/#comments</comments>
		<pubDate>Fri, 07 Aug 2009 08:18:08 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General News]]></category>
		<category><![CDATA[cyberterrorism]]></category>
		<category><![CDATA[cyxymu]]></category>
		<category><![CDATA[ddos]]></category>
		<category><![CDATA[dos]]></category>
		<category><![CDATA[facebook ddos]]></category>
		<category><![CDATA[georgia]]></category>
		<category><![CDATA[joe job]]></category>
		<category><![CDATA[joejob]]></category>
		<category><![CDATA[political ddos]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[social networking]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[twitter and facebook ddos]]></category>
		<category><![CDATA[twitter ddos]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1999</guid>
		<description><![CDATA[Both Facebook and Twitter were hit with pretty severe DDoS attacks rendering them useless and unavailable to the majority of users. The thing is it seems like it wasn&#8217;t a traditional network based botnet style DDoS attack, but a &#8216;joejob&#8216; attack where spam is sent out containing a link and the users clicking on the [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Both <a href="http://www.darknet.org.uk/tag/facebook/">Facebook</a> and <a href="http://www.darknet.org.uk/tag/twitter/">Twitter</a> were hit with pretty severe DDoS attacks rendering them useless and unavailable to the majority of users.</p>
<p>The thing is it seems like it wasn&#8217;t a traditional network based botnet style DDoS attack, but a &#8216;<a href="http://en.wikipedia.org/wiki/Joe_job">joejob</a>&#8216; attack where spam is sent out containing a link and the users clicking on the link contribute to the site becoming overwhelmed with requests.</p>
<p>The DoS attack has been confirmed on the Twitter Status page here &#8211; <a href="http://status.twitter.com/post/157191978/ongoing-denial-of-service-attack">Ongoing denial-of-service attack</a>.</p>
<p>The <a href="http://www.theregister.co.uk/2009/08/07/twitter_attack_theory/">attack theory comes from Bill Woodcock</a>, as reported by The Register.</p>
<blockquote><p>Users looking to update their Twitter feeds or Facebook pages were likely disappointed Thursday morning, as a denial-of-service attack made both services hard to reach.</p>
<p>Around 9 a.m. Eastern Time, the number of responses from micro-blogging service Twitter fell precipitously, reaching a bandwidth of 60 Mbps by 10:40 a.m. ET, according to Arbor Networks, a networking services firm. Twitter had reached nearly 200 Mbps prior to the drop.</p>
<p>The service continued to be impacted Thursday afternoon, reaching a peak of 150 Mbps, about half of its normal peak for that time of day, according to Arbor.</p></blockquote>
<p>It seems to be a politically motivated attack aimed at a certain anti-Russian blogger known as Cyxymu.</p>
<p>It targeted all web properties where had profiles, the main ones of course being Facebook and Twitter but also included Livejournal (where he hosts his blog) and his Youtube account.</p>
<p>It&#8217;s a simple but seemingly very successful method of attack, shown by the fact that it took out a couple of major sites which already manage large amounts of traffic.</p>
<blockquote><p>Users also complained of issues accessing Facebook. The service confirmed midday on Thursday that, it too, had suffered a denial-of-service attack.</p>
<p>&#8220;You may have had trouble accessing Facebook earlier today because of network issues related to an apparent distributed denial-of-service attack,&#8221; the social network stated on its own Facebook page. &#8220;We have restored full access for most people. We’ll keep monitoring the situation to make sure you have the reliable experience you expect from us.&#8221;</p></blockquote>
<p>You might have noticed a lot of failed requests if you use Facebook (JavaScript timeout errors and network pipe errors).</p>
<p>Facebook fell because of the same targetted attack on Cyxymu, they <a href="http://www.facebook.com/facebook">acknowledged such on their Facebook page</a>.</p>
<p></p>
<p>Source: <a href="http://www.securityfocus.com/brief/992?ref=rss">Security Focus</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Twitter+%26+Facebook+Taken+Offline+By+DDoS+Attacks+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1999+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/08/twitter-facebook-taken-offline-by-ddos-attacks/&amp;t=Twitter+%26+Facebook+Taken+Offline+By+DDoS+Attacks" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/08/twitter-facebook-taken-offline-by-ddos-attacks/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/08/twitter-facebook-taken-offline-by-ddos-attacks/&amp;title=Twitter+%26+Facebook+Taken+Offline+By+DDoS+Attacks" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/08/twitter-facebook-taken-offline-by-ddos-attacks/&amp;title=Twitter+%26+Facebook+Taken+Offline+By+DDoS+Attacks" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/08/twitter-facebook-taken-offline-by-ddos-attacks/&amp;title=Twitter+%26+Facebook+Taken+Offline+By+DDoS+Attacks" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/08/twitter-facebook-taken-offline-by-ddos-attacks/&amp;title=Twitter+%26+Facebook+Taken+Offline+By+DDoS+Attacks" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F08%2Ftwitter-facebook-taken-offline-by-ddos-attacks%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/08/twitter-facebook-taken-offline-by-ddos-attacks/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

