Stories
Slash Boxes
Comments
typodupeerror delete not in

Comments: 161 +-   Chinese "Cyber-Attack" US Department of Commerce on Monday October 09 2006, @08:08AM

Posted by CmdrTaco on Monday October 09 2006, @08:08AM
from the and-you-thought-your-weekend-was-boring dept.
security
Kranfer writes "The register has an article about how the Chinese have recently launched an attack against the US Department of Commerce. From the article: '...attacks originating from computer crackers largely located in China's Guangdong province are aimed at extracting sensitive information from targets such as the Commerce Department's technology export office. Security consultants and US government officials reckon the assaults have at least the tacit support of the Chinese government...' This is not the first time Chinese hackers have attempted to gain access to US Government systems."
story

Related Stories

This discussion has been archived. No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More
Loading... please wait.
  • Not Chinese (Score:5, Insightful)

    by suv4x4 (956391) on Monday October 09 2006, @08:11AM (#16363077)
    As mentioned before, the attack are most likely not from China at all.

    No decent hacker would leave traces from his own machine when he could easily use a zombie network to carry out the attacks and collect information.

    They keep claiming China, China, China.. I'm starting to think it's convenient for them to stick to that version for their own internal affairs.
    • Re: (Score:2, Insightful)

      Al Quaeda is not going to last for ever, you know? they need a solid and real danger to wave in front of the US population in order to take more civil rights away. Apparently, China is second in the list.
      • Re: (Score:3, Insightful)

        Instead of "danger", think "rival". This kind of espionage is more commercial, not military, and frankly stuff like this has happened before even between our closest allies.
      • China is a lot scarier than anything else on this planet right now, especially to the US. China should frighten the world though, there's no women for something like twenty-five percent of their male population and given the attitude of the Chinese culture towards women, they're not likely to find a bunch of willing mail-order brides. I mean people are still leaving their girl babies out to die of exposure in that country, you know what I mean?

        But to the US it's scary for a different reason: the trade i

    • Re:Not Chinese (Score:5, Informative)

      by Shoten (260439) on Monday October 09 2006, @08:38AM (#16363341)
      Well, yes and no. There are a few problems with this hypothesis; one, and the most important of them, is that attacks have been conclusively back-traced to China. And yes, the guy who did it actually broke the law in the process, but c'est la guerre, non? The event is known as "Titan Rain," [schneier.com] and it began with a series of targeted attacks against the Department of Energy. A computer security worker, in his spare time (and a wink/nod from the FBI) counter-hacked hosts that were the source of the attacks, eventually following the trail back to mainland China. There, he saw that the logins which executed commands were being performed locally, and that the devices were not forwarding pilfered data on to other hosts but were instead the repositories of that data.

      Other things involve the fact that when you see attacks from China, you usually get one of two kinds of hosts: you get a wildly unpatched Windows box that's being used as a bot, or you get a decently-secured (usually linux or *BSD) system that is doing some rather specific things to a specific target. And last of all, let's not forget that most of the seminal works on information warfare were written by Chinese military officers, and that it's no secret whatsoever that China actually does have a significant infowar capability. We have no rules of engagement that classify hacking as an act of war, so they can get away with it; what are we going to do, bomb them over it? They have the world's largest standing army, are a (increasingly) crucial economic partner, and we're already overburdened militarily with a two-front war where we've bogged down fighting insurgents. They do it because they know they can get away with it, and they're correct in that thinking.
      • ***We have no rules of engagement that classify hacking as an act of war, so they can get away with it; what are we going to do, bomb them over it? They have the world's largest standing army, are a (increasingly) crucial economic partner, and we're already overburdened militarily with a two-front war where we've bogged down fighting insurgents. They do it because they know they can get away with it, and they're correct in that thinking.***

        Moreover, I'll be suprised and mildly appalled if the NSA and CIA

        • I'd say you're spot on with this. But conversely, I would expect that we'd be doing so anyways; we don't need an excuse to do spook-like things to other countries. So again, there's no disincentive for the Chinese to do the same. After all, the French spy on us, the Israelis spy on us...some of our closest friends with whom we have far less competitive motiviations, in other words, spy on us. So why wouldn't a country like China, with far less to lose and far more to gain not do the same? When you push
      • Re:Not Chinese (Score:4, Interesting)

        by suv4x4 (956391) on Monday October 09 2006, @09:26AM (#16363821)
        I'd like to defend my viewpoint since I've been called, by some, an idiot and uninformed.

        Consider you have to hack into Us givernment servers with confidential data. Even if you're not an incredible hax0r, it's obvious that if they find out about you, you're totally screwed. So the first thing you do, the MOMENT you grab the data, is cut the PC off the network.

        Then encrypt and record the data on a mobile media (CD, DVD, Flash, whatever), and securely format the PC or even just destroy the original HDD.

        Even before this, you'd turn off all possible logging activity, lock up the security, stop unneeded services, so that you can be relatively secure during the attack.

        How is it that so much evidence in logs and what not was found on the "source" machines. This is WAY too much evidence. The contrast between the Windows hacked machines and the linux machines may be just a decoy to get the investigators stop tracing right there.

        If the boxes were so secure, how did they get in there?

        Why were the Windows boxes having "logs" of where the data was sent and so on. What kind of trojan would log their own activity on the compromised machine?

        And the million dollar question is: how the f*ck they tied the Chinese *GOVERNMENT* with a Chinese *HACKER*... In fact, the first thought to occur to a government trying to hack into US's servers would be to hire hackers from another country to do it.

        All the "evidence" presented is incredibly shallow and inconvincing if you try and put yourself in place of the people who did the attack.

        Add to this the constant FUD that US spread that Lenovo puts spying chips in ThinkPads and similar conspiracy theories. It's apparent US find China a convenient target to blame, just the way they did with Iraq after 9/11.
        • Add to this the constant FUD that US spread that Lenovo puts spying chips in ThinkPads and similar conspiracy theories.

          You know, the idea that Lenovo would put spying software/firmware in the system is an entirely logical one. It wouldn't even be the first time such a thing happened, although it would probably be the first time it happened on such a large scale.

          Ever think that maybe people are paranoid because they know just how plausible it is?

          • You know, the idea that Lenovo would put spying software/firmware in the system is an entirely logical one. It wouldn't even be the first time such a thing happened, although it would probably be the first time it happened on such a large scale.

            Ever think that maybe people are paranoid because they know just how plausible it is?

            The ThinkPC's were produced in China even before Lenovo owned the department. So are most other laptop brands, macs and even mp3 players, including iPod.

            If you feel it's plausible, t

      • Re: (Score:3, Interesting)

        "attacks have been conclusively back-traced to China."

        How could one do this?

        ...you usually get one of two kinds of hosts: you get a wildly unpatched Windows box that's being used as a bot, or you get a decently-secured (usually linux or *BSD) system that is doing some rather specific things to a specific target.

        Isn't the first thing that a hacker does when they get their hands on a decent box is apply all security patches so that *another* hacker cannot get into it? What's the point of co-opting a wi
        • Re: (Score:3, Insightful)

          You're reading too much into individual components of my post, and not taking them as a whole. I'll answer your questions in turn. For one, how does someone backtrack to the original host? By gaining control of the next hop, one at a time, essentially. You know that your box got owned by 10.20.30.1, so you counter-hack it. Once in, you look around, and see who connects to it. More importantly, you see who is connected to it while it connects to your box. (This is detailed in a number of the articles
      • 'They do it because they know they can get away with it, and they're correct in that thinking.'

        "I Fart in Your General Direction..."

        Since I live in that province, and work in the telecom sector, I think I'll ask the boys in R & D tomorrow if anyone knows of anyone knock, knock, knocking on USDCs' digital door...
    • "As mentioned before, the attack are most likely not from China at all. No decent hacker would leave traces from his own machine", suv4x4

      It's not as if they had access to the hackers computers. They would use evidence of portscans being run against their own computers.

      "A few minutes ago, we received a complaint from the U.S. Department of Commerce [google.co.uk] about them being portscanned"

      "Attacks on UK government systems using a then unpatched ,Microsoft Windows [theregister.co.uk] Meta File (WMF) exploit last Christmas were tra
    • Re: (Score:2, Insightful)

      by Anonymous Coward
      Does everyone have to take every story about someone attacking the US and claim it is a lie? I'm guessing since it' safer to believe nothing is wrong than face reality then this is the reason. "They keep claiming China...." Yes, god forbid someone should point out the person who is doing something. If the guy accross the street keeps attacking you, stealing from you, and destroying your property it's bad to keep blaming him.

      This is why the United States will fall apart. We have two groups, one that se
    • You know... While its true that Hackers try to obscure where they came from, its also true that some of the best in the field are tracing them back to China.
  • by crazyjeremy (857410) * on Monday October 09 2006, @08:13AM (#16363093) Homepage Journal
    They hacked WindowsUpdate.com [mtrx.net] as well... It must be them. The screen capture of the hacked website says "hacked by chinese".
    • 1) Chinese hacked US Govt computers
      2) Most of US Govt computers run MS Windows
      3) Bill Gates is in charge of MS

      Therefore, Bill Gates is a Chinese Spy!!1!!!!11
      • I know you're making a joke, but what about a capitalist/communist China wouldn't any US corporation like?

        A few select business leaders are allowed to run massive monopolies, labor disputes are settled with an AK-47, and there's no noisy press to berate your crappy products or your business leadership.

        Sounds like Bill Gates might actually like the Chinese afterall.
  • These are Chinese hacker infantry, who steal money from the internet to fund the war against the GLA.
  • What could possibly be of importance on US Department of Commerce computers? Are they trying to download warez? Logs off steamy chat rooms? Minutes of another boring meeting a typical government official attended?
    • by acvh (120205) <geek.mscigars@com> on Monday October 09 2006, @08:49AM (#16363465) Homepage
      Actually, the Department of Commerce has become as important to foreign relations as the Department of State. Maybe even more so. State is concerned with PR, diplomacy and such. Commerce cuts deals worth billions of dollars; the prospect of being able or not to do business with the US is a much bigger stick than threatening to refer someone to the UN.

      If a foreign power could gain access to internal Commerce discussions it would give them some leverage in negotiations; and in the realm of international business a little inside info can go a long way.
  • by organgtool (966989) on Monday October 09 2006, @08:27AM (#16363213)
    I was going to suggest blocking all traffic coming from the IP range of addresses from China, but they could easily circumvent that by using a proxy outside of China. Maybe the U.S. Department of Commerce could create a welcome message that promotes democrary and condemns the inhumane treatment of the Chinese government and have that message appear before prompting for the username. That traffic would probably get blocked by the Great Firewall of China. When your weapons fail to work, turn your enemy's weapons against them.
    • by smilindog2000 (907665) <bill@billrocks.org> on Monday October 09 2006, @09:07AM (#16363635) Homepage
      That would really PO the Chinese. They hate it when we point at their miserable human-rights record in public. A better way IMO to deal with the Chinese is to work behind the scenes to get them to improve while publicly praising their efforts. IMO, Chinese culture cares much about 'face', a concept of honor that requires the appearance of respect, even if we bicker shamelessly behind closed doors. Bush routinely shows his ignorance of the Chinese by publicly lashing them, and then he gets bent out of shape when the Chinese retaliate with substance rather than words.

      When the Chinese accidentally rammed one of our surveillance planes was a great example. Bush immediately publicly blamed the Chinese overly-hostile pilots (who were, of course, at fault), and demanded back our plane and it's crew. The correct course would have been to call the Chinese first, and negotiate terms for getting our plane and crew back secretly. IMO, the Chinese can be far more reasonable if we agree to put on a face showing friendship, cooperation, and respect for each other. We could have agreed to publicly call it a freak accident, with no one to blame. That probably would have gotten our guys and maybe even the plane back far quicker.

      So, I think changing the web site to shame the Chinese government would be a bad idea. Instead, we should work with the Chinese behind close doors to solve the problem. Of course, that wont end Chinese spying on the US, nor will it end our spying on them. In general, I feel that it is good for world stability when we know the truth about each other. Fear of the unknown can cause major problems (like WMD in Iraq).
      • Fear of the unknown can cause major problems (like WMD in Iraq).

        I hate to break it to you, but the iraq invasion was not caused by lack of knowledge. It was actually the fact that Bush new that Iraq didn't have any meaningful WMD that allowed the invasion.

        Countries with real WMD like North Korea dont get invaded. If you disregard the US rethoric, invading Iraq has sent the message that you need WMD in order to keep the americans at bay. That is why Iran and NK pursue them as fast as they can.
  • by BlabberMouth (672282) on Monday October 09 2006, @08:31AM (#16363271)
    for all the cracking attempts our own guys have launched against China. I'd be schocked if we (the United States) haven't been doing this type of thing against China, North Korea, Iran, or just about anybody all long.
  • "BIS discovered a targeted effort to gain access to BIS user accounts," Commerce Department spokesperson Richard Mills said. "They took a series of immediate action steps to ensure that no BIS data is compromised. We have no evidence that any BIS data has been lost or compromised," Mills said.

    Oh yeah, I too must be specifically targeted then, because I've seen these sequences in my log:

    May 31 13:06:27 gator sshd[18127]: Invalid user tony from 210.196.254.66
    May 31 13:06:30 gator sshd[18129]: Invalid user

    • You know, I can understand all those attempted logins -- core, visitor, ftpuser, and so on -- except for the first one. "tony"?! Is this some kind of default login name?

      --Rob

  • by lwap0 (866326) on Monday October 09 2006, @08:54AM (#16363513)
    I frequently work with the U.S. government to prevent export control violations in the defense contracting world. While I can't name specific countries, I can tell you that East Asia accounts for 34% of all attacks both cyber and conventional targeting U.S. Industry and government agencies (as of 2005). My peers and I agree that this is likely directly or indirectly sponsored by the Chinese government. And contrary to popular belief, about 90% of what they want is export controlled information, not classified information.

    Why export controlled information? Think about how much money it takes to protect classified information - guards, safes, alarm systems etc., it's a lot of cash, and it's damn secure. Export controlled information doesn't enjoy those same protections, just export compliance waivers to sell or ship said products overseas. As an example: Say we have a dual use technology, both military and civilian use - like jet engines. We won't sell it to certain countries we compete with both economically, and militarily, but they will do their very damndest to steal it, either by forging state department waivers, lying, stealing, black-mailing, hacking - whatever it takes. Why do they want it? To equip their jets to compete with ours on the battlefield, or to sell, or maybe even find it's weaknesses to compromise if we ever went to war with them.

    I'm willing to bet here that the network used to launch the attack was a University school network, which to most people seems pretty innocent - except that in China, all schools are state run and owned. Is it an academic institution, or an extension of the Chinese government? Likely both. In this instance, the Chinese government gets plausible deniability - they had no control over, or knowledge of any cyber attack. I'll don my tin-foil hat, and disagree with that assertion only because I'm jaded and cynical enough to know better.
    • In your field, you've probably run across the Israel-to-Chinese tech-transfer problem. I hate linking to this obviously BS site, but I'd like to know if this article it carries has any truth to it:

      http://www.americanintifada.com/2005/5/05-06.htm [americanintifada.com]

      I've seen similar stories elsewhere. Have we in fact indirectly sold F-16 technology to the Chinese through Israel? Thanks.
  • by knorthern knight (513660) on Monday October 09 2006, @09:20AM (#16363759)
    According to the Register article...
    > Information housed on the department's systems includes sensitive commercial and
    > economic data on US exporters as well as data involving law enforcement records.

        How many times does this have to be drilled into people? If you put something on an internet-accessable server, it *WILL* be accessed from the internet, and not only by "authorized personnel". For additional giggles, put the following key into a Google search...

    inurl:.gov confidential "do not distribute"

        The f***ing idiots who put sensitive government data on publicly accessable servers should be shot by a firing squad for treason.
  • Is government stupid enough to expose information that is incredibly sensitive to the internet? (Please, don't answer this).

    If they had clear information and data policies, their data would all be on private networks, without access to the outside. Not doing so is just an invitation for crackers who love challenges.
  • Ok, assuming for just a moment that it is government backed ( which i honestly doubt ), wouldn't this be considered a declaration of war and a 'first strike' ?

    And all we are going to do is sit on our hands and let them?
    • Yeah, I mean look how well things are going for us in Iraq! We should get into that situation with at least a few more countries. Especially China - I hear their millitary is really small.
      • I disagree. Its time for wwiii to commence ( in some ways its already started ). Its time to purge the lesser peoples of the world again, and smack into obedience what is left.
  • One has to wonder, with all the uproar about hacking from China into US Gov't computers, why don't they just block all the IP blocks in China? Download the list from APNIC, use something like Perl's Net::CIDR to merge the blocks and add to your firewall. It's rather easy...
    • Because then whatever organisations that are doing this in China will simply move elsewhere and attack from there.

      Hows this for your next headlines? "Mexico and Canada jointly attack the US commerce department."
  • I'm a bit surprised by this. Not that the Chinese Government would approve such action, but that somebody is able to perform it. My indirect experience with the culture suggests that finding individuals capable of the type of on-the-fly problem solving necessary to attack a protected network is very difficult. While the application of such skills is a bit maligned, I'd say it's a good sign for them that such people do in fact exist and can be motivated to utilize their abilities. I know of a few groups
  • Based on the other recent post, many government employees browse pron and gambling sites and get infected with bots.

    That would probably be a better vector.

    Plus they might make a profit while doing it.
  • by heybo (667563) on Tuesday October 10 2006, @12:24PM (#16380337) Homepage

    People seem to forget. The US does this kind of thing all the time. Not only to other countries but to their own Citizens. Remember we have all those three letter agencies that do this sort of thing all the time. So what is good for the goose is it not good for the gander? Or is it like torture these days? We gasp and cry when we see someone get their head lopped off on TV, and say "What savages!" Still it is ok for us to torture people for weeks on end because we are the good guys so this is good torture. Who is the savage really? The person that quickly puts and end to the pain of the enemy by whacking off their head or the person that makes their enemy suffer for weeks without end?

    You see I come from a group of people that was once "Branded" savages by the US goverment. One example that even lives up to today. We were savages for taking scalps of our enemies. The part that is ALWAYS left out is we only took scalps in revenge for taking the scalps of our women and children for $5.00 a scalp. Payable by the US Goverment. Funny how that part of history is left out and still scalping is always related back to Native Americans even today. "Scalp'm Braves"

    So are the Chinese really the bad guys or are they protecting their own assests? We're trying to pick their pockets all the time so why is it so bad when they try to pick ours?

    The simple truth for people and goverments is you can't run around beating up other people all the time. Sooner or later someone bigger and badder than you will finally get tired of your shit and your continued assaults against them and in defense will either gang up with the other guys you are beating up on or if big enough on their own will turn around and beat the shit out of you.

    The solution is simple. Leave them alone and they will leave us alone. It is all "Cause and Effect" Don't be the "cause" and you won't feel the effect. You can't blame someone for taking a defensive position to your offenceive moves.

    The same rule of "cause and effect" applies to networks. You choose to run Windows that can access sensetive areas then YOU are setting yourself up to get hacked. I find it strange that the NSA would build something as secure as SELinux and the rest of the goverment not use it. Maybe not strange just stupid. The point is they have the tools to lock everything down and if they don't well too bad should have bought a better lock for the front door.

    • China is our enemy
      Depends on who you are.

      If you're a democracy and liberty loving citizen, then yes, the Chinese regieme represents oppression and injustice and stands against you and your way of life.

      However, if you're a corporate shareholder, or one of their shills in public office, then the Chinese regieme represents untold potential to shaft billions and make billions in the process. Ergo, you'll want to keep them sweet.
      • And if you are Wal-Mart, China is a suplier for 80% of their clothing. If China is our enemy, then what does that make Wal-Mart?? "A friend of my enemy is also my enemy." Sure there are sweatshops in other impoverished areas of the world, but man, China's sweatshops are the cheapest!!
Does the name Pavlov ring a bell?