160
Nart Villeneuve and Masashi Crete-Nishihata
distinct individuals, there is the possibility that they are the two primary attackers
using different browsers (and/or operating systems).
The log fi les indicate that in the days before and after the defacement, the attackers
browsed the Mizzima News Web site from sites with Burma-related content such as
http://komoethee.blogspot.com (September 10, 2008) and http://baganland.blogspot.
com (September 30, 2008). They connected to Mizzima News from articles that referred
to the ongoing DDoS attacks against The Irrawaddy and the Democratic Voice of
Burma and were thus well aware of the scope of the attacks targeting opposition news
media.
38 Just six hours before the defacement, the attackers visited Mizzima News from
an article that detailed Burma ’ s cyberwarfare capabilities and that claimed the attacks
“ may have been conducted by Myanmar military offi cers trained or undergoing training in Russia and China. ”
39 The attackers then accessed a variety of articles on the
Mizzima News Web site. It is likely that at this stage they determined that the Mizzima
News Web site was based on the Joomla! Customer Management System (CMS).
40
Beginning on September 19, 2008, the attackers attempted to exploit a number of
known vulnerabilities in the Joomla! CMS that the Mizzima News Web site was
running on. After a series of unsuccessful attempts, Attacker 2 fi nally managed to
exploit a password reset vulnerability in Joomla! and immediately logged in as the
administrator. This “ remote admin password change ” exploit is very simple and can
be conducted through any Web browser. The exploit was publicly available by August
12, 2008, about two months before it was used to compromise Mizzima News.
41
After acquiring administrator privileges by exploiting the password reset vulnerability, Attacker 2 shared administrator access with Attacker 1. Both attackers attempted
to download c99shell onto the compromised server, and within 20 minutes both
attackers had set up the Trojan tool and began exploring the directories of the Mizzima
News Web servers. Eventually, the attackers shared access with a third attacker and
gained access to several My SQL databases. They deleted parts of the databases, and
by 4:56 PM on September 30, 2008, they had defaced the Mizzima News Web site.
The attackers returned several times and installed more instances of c99shell as well
as pBot, an Internet Relay Chat (IRC) bot with both Trojan and DDoS capabilities,
while Mizzima ’ s administrators attempted to delete the malicious fi les. The attackers
also defaced the Mizzima News Web site repeatedly after Mizzima administrators tried
to restore the original content. The attackers were fi nally locked out on October 4,
2008. They attempted — unsuccessfully — to return on October 5 and 6.
We approached the censorship-circumvention software provider that the attackers
used with convincing evidence of the attacks and the use of their tool and asked if
they could confi rm that the attackers used the IPs we traced back to their services.
The software provider confi rmed that Attacker 1 and Attacker 2 logged in to the circumvention service from IP addresses assigned to Burma, which is interesting because
the Mizzima News Web site is fi ltered by Burmese ISPs and inaccessible to Internet
Précédent

- 177/431

Suivant