Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 36 guests and 2 members online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow News from the Outside Worldarrow Congress Hacked
Ethical Hacker Community Forums
December 01, 2008, 12:53:40 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Congress Hacked  (Read 3320 times)
0 Members and 1 Guest are viewing this topic.
oneeyedcarmen
Full Member
***
Offline Offline

Posts: 205

Klaatu, Borada,Necktie?


View Profile
« on: June 12, 2008, 08:04:55 AM »

Though I think this is related to the discussion on the ethics of government sposored hacking, I believe it deserved its own thread.

It's being reported in the LA Times that Chinese hackers have managed to breach more than one Congressman's machines, as well as those of a Congressional committee on human rights.  According to Rep. Frank Wolf (R-VA), "They got everything."

It's believed that the Chinese hackers were looking for information on dissidents living in the US, and again according to Congressman Wolf, "following one of the attacks, a car with license plates belonging to Chinese officials went to the home of a Chinese dissident in the Washington suburbs and took photographs of it."

Thus far, the Chinese government has had nothing to say on the matter, and the FBI has declined to comment. 

Read the full story here


Logged

MCP, Security+, Associate (ISC)2
RoleReversal
Sr. Member
****
Offline Offline

Posts: 469


View Profile WWW
« Reply #1 on: June 12, 2008, 09:54:23 AM »

I've read a few differing stories about this incident.

One of the figures I've heard quoted is that US systems get scanned or attempted compromises 300million times a day, that's a lot of background noise to pick through to find the right answer.

Whilst it is entirely possible that all of these (this and recent) attacks are coming from China, if I (UK citizen) wanted to hit the US systems I might just find myself an unpatched XP machine on a Chinese IP for a jumping point. 'yup, it's the Chinese again, incident closed?

My question from reading this story that I haven't found an answer to so far is, is there evidence to suspect the Chinese in this incident of is it merely Wold's believe due to his aiding of Chinese dissidents?

"following one of the attacks, a car with license plates belonging to Chinese officials went to the home of a Chinese dissident in the Washington suburbs and took photographs of it."
 the full story here[/b][/url]

Of course there is no other way the Chinese officials coud have found out who was living there....

China is becoming a very handy scapegoat at the moment, until there is any evidence one way or another I'd suggest that the attacks are a side-effect of being connected to the internet...
Logged

A little bit of sanity:
http://www.infosanity.co.uk
BillV
Hero Member
*****
Offline Offline

Posts: 868


View Profile
« Reply #2 on: June 12, 2008, 11:37:49 AM »

Quote from: RoleReversal
I'd suggest that the attacks are a side-effect of being connected to the internet...

Haha, I like that statement. Smiley
Logged
geekyone
Full Member
***
Offline Offline

Posts: 123



View Profile
« Reply #3 on: June 12, 2008, 03:43:30 PM »

I wonder if they were a victim of a targeted attack by a Chinese hacker or if they weren't careful about what email attachments they opened so they ended up with a Trojan that just happened to be reporting back to a Chinese server/IP address.
Logged
RoleReversal
Sr. Member
****
Offline Offline

Posts: 469


View Profile WWW
« Reply #4 on: June 13, 2008, 02:34:32 AM »

Looks like the media are starting to report real-life rather than FUD for a change

Quote
However, computer security experts said that the evidence that the two congressmen provided to back up their claims simply does not prove that the Chinese government, or even Chinese nationals, were involved.

"It's so very hard to conclude that something came from someplace if all you're going from is an IP address," said Marcus Sachs, director of the SANS Internet Storm Center, a volunteer-run effort that tracks emerging computer threats. "Those of us who have done this for a living, we know that you can't prove that it was a Chinese person on the keyboard if you have a Chinese IP address," he said. "Without making some of the evidence public … you leave everybody else guessing."

Full article here
Logged

A little bit of sanity:
http://www.infosanity.co.uk
g00d_4sh
Sr. Member
****
Offline Offline

Posts: 295



View Profile
« Reply #5 on: June 13, 2008, 03:33:26 PM »

True it is impossible to 'proove' beyond a doubt... just about anything on the net.  Tongue It's that amazing cloud of anonymity that has confounded and frustrated many attempts at prossecution.  Of course, that is chainging slowly.  None the less, regardless of whether this specific case is China sanctioned or known; there seems to be a rather epidemic problem with ones that are more obviously known to be.   A site I check out once in a while, is: http://www.thedarkvisitor.com/

It has some interesting articles. 
Logged

"Bad.. Good?  I'm the guy with the gun"
p_dub
Newbie
*
Offline Offline

Posts: 6


View Profile
« Reply #6 on: June 16, 2008, 12:22:05 PM »

Regardless of the origin of the attack, the relative ease with which this information was obtained is what is scary.

Encryption anyone?
Logged

Security+, CISSP, GCIH
g00d_4sh
Sr. Member
****
Offline Offline

Posts: 295



View Profile
« Reply #7 on: June 16, 2008, 01:32:19 PM »

Quite true.  My bosses are FINALLY getting into encryption after the couple VA (Vetrans Ass) issues.  We're still deciding on hardware (seagate) vs software encryption. 
Logged

"Bad.. Good?  I'm the guy with the gun"
jason
Sr. Member
****
Offline Offline

Posts: 264


Aut Viam Inveniam Aut Faciam


View Profile
« Reply #8 on: June 25, 2008, 09:34:32 PM »

Linked from the chinese hacker site, I found this

http://failblog.org

My sides hurt from laughing  Grin
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.061 seconds with 23 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.