Control and Resistance
159
Secure Your Website. New We Warn to All Media Webadmins That is “ Prepare to more Secure
your Work. ”
This case demonstrates how attackers mask their identity, thus making it diffi cult
to determine those responsible for the attacks. The attackers who defaced Mizzima
News — which is blocked by ISPs in Burma — used censorship-circumvention software
to perpetrate the attack hosted on servers that had IP addresses allocated to the United
States, France, and Germany in order to make it appear as if the attacks originated in
those countries.
34 Mizzima News reported on October 1, 2008, that the attacker ’ s IP
address originated in the United States. On October 10, 2008, Mizzima News reported:
“ While it is still diffi cult to technically trace who is behind the hacking attempts,
Mizzima ’ s technical staff said the main attempt is found to have originated from Russia
with cooperation from other hackers in Germany, France and India. ”
35 The incident
highlights the diffi culty in tracing the geographic location of the attacks, let alone
determining the identity and intent of the attackers. In the absence of suffi cient evidence to attribute attacks, analysts often turn to the political context to fi ll in the
gaps. In view of the persistent efforts by the government and military to crack down
on political dissent, it is clear that they have an interest in silencing critics such as
Mizzima News. However, a careful examination of the technical evidence, as well as
an exploration of alternative explanations, is critical to understand the characteristics
of the attackers.
Investigating the Attack
Following the October 1, 2008, defacement of the Mizzima News Web site, the IWM
offered to assist Mizzima News with an investigation of the attack, and the organization provided us with access to their Web server logs and sample copies of c99shell (a
backdoor program that provides attackers with remote access to a victim ’ s machine)
that were found on the compromised Mizzima News Web server.
36 We processed these
log fi les and isolated the IP addresses that connected to and issued commands on the
c99shell backdoor program. We removed the IP addresses of the legitimate administrators who had later connected to test c99shell. We were left with a set of IP addresses
that we identifi ed as belonging to a censorship-circumvention proxy service. While
some variation existed in the IP addresses, there were consistent browser user-agents
37
that (1) connected from the circumvention proxy service IP addresses and (2) connected to and executed commands on the c99shell backdoor. We collected and analyzed all log entries in which the identifi ed IP addresses connected to and issued
commands on instances of the c99shell backdoor.
We identifi ed fi ve attackers. The two primary attackers appeared to be working in
tandem with one another. Although we believe that the remaining three attackers are
159
Secure Your Website. New We Warn to All Media Webadmins That is “ Prepare to more Secure
your Work. ”
This case demonstrates how attackers mask their identity, thus making it diffi cult
to determine those responsible for the attacks. The attackers who defaced Mizzima
News — which is blocked by ISPs in Burma — used censorship-circumvention software
to perpetrate the attack hosted on servers that had IP addresses allocated to the United
States, France, and Germany in order to make it appear as if the attacks originated in
those countries.
34 Mizzima News reported on October 1, 2008, that the attacker ’ s IP
address originated in the United States. On October 10, 2008, Mizzima News reported:
“ While it is still diffi cult to technically trace who is behind the hacking attempts,
Mizzima ’ s technical staff said the main attempt is found to have originated from Russia
with cooperation from other hackers in Germany, France and India. ”
35 The incident
highlights the diffi culty in tracing the geographic location of the attacks, let alone
determining the identity and intent of the attackers. In the absence of suffi cient evidence to attribute attacks, analysts often turn to the political context to fi ll in the
gaps. In view of the persistent efforts by the government and military to crack down
on political dissent, it is clear that they have an interest in silencing critics such as
Mizzima News. However, a careful examination of the technical evidence, as well as
an exploration of alternative explanations, is critical to understand the characteristics
of the attackers.
Investigating the Attack
Following the October 1, 2008, defacement of the Mizzima News Web site, the IWM
offered to assist Mizzima News with an investigation of the attack, and the organization provided us with access to their Web server logs and sample copies of c99shell (a
backdoor program that provides attackers with remote access to a victim ’ s machine)
that were found on the compromised Mizzima News Web server.
36 We processed these
log fi les and isolated the IP addresses that connected to and issued commands on the
c99shell backdoor program. We removed the IP addresses of the legitimate administrators who had later connected to test c99shell. We were left with a set of IP addresses
that we identifi ed as belonging to a censorship-circumvention proxy service. While
some variation existed in the IP addresses, there were consistent browser user-agents
37
that (1) connected from the circumvention proxy service IP addresses and (2) connected to and executed commands on the c99shell backdoor. We collected and analyzed all log entries in which the identifi ed IP addresses connected to and issued
commands on instances of the c99shell backdoor.
We identifi ed fi ve attackers. The two primary attackers appeared to be working in
tandem with one another. Although we believe that the remaining three attackers are
