Control and Resistance
161
users in Burma. Therefore, the attackers had to bypass this ISP-level fi ltering in order
to attack the Web site. They also probably believed that using the service would shield
their identities.
To summarize, the evidence suggests there were two primary attackers working in
collaboration with one another other to exploit and “ Trojan ” the Mizzima News Web
server. These attackers appear to have shared links to the Trojans that they had
installed with additional attackers. In total, there appear to have been fi ve attackers
working together to maintain control over the Mizzima News Web server. The attackers
deleted portions of Mizzima ’ s database and defaced the Web site repeatedly. Over the
course of seven days, they continued to attack Mizzima ’ s server while the Mizzima
administrators worked to delete the different backdoors that the attackers frequently
installed. By the fi fth day they were shut out of the system, although they continued
to check for access on the sixth and seventh days but were denied. We further confi rmed that the attacks originated from Burma and used the proxy service to bypass
national-level fi ltering of Mizzima News .
Investigating the Attackers
We investigated the identities of the attackers by analyzing the versions of the backdoor program c99shell and the IRC bot pBot they used, the specifi c attackers who
downloaded these fi les, and the location they retrieved the programs from. What
follows is an analysis of the data trail we followed by analyzing and linking the information contained in these fi les.
The c99shell backdoor program is a widely available Trojan backdoor written in the
PHP programming language.
42 The versions of c99shell that the attackers tried to
download to the Mizzima News Web server were slightly modifi ed to include text in
the interface reading, “ Hacked by doscoder — oGc Security Team — #cyberw0rm @ oGc ”
( fi gure 8.2 ).
Based on this information, we could infer that the tool had been modifi ed by
“ doscoder ” — who is a member of the “ oGc Security Team ” and IRC channel “ #cyberw0rm ” on an IRC network called “ oGc. ” However, these data points do not necessarily
Figure 8.2
Screen shot of the modifi ed interface for the c99shell backdoor program.
161
users in Burma. Therefore, the attackers had to bypass this ISP-level fi ltering in order
to attack the Web site. They also probably believed that using the service would shield
their identities.
To summarize, the evidence suggests there were two primary attackers working in
collaboration with one another other to exploit and “ Trojan ” the Mizzima News Web
server. These attackers appear to have shared links to the Trojans that they had
installed with additional attackers. In total, there appear to have been fi ve attackers
working together to maintain control over the Mizzima News Web server. The attackers
deleted portions of Mizzima ’ s database and defaced the Web site repeatedly. Over the
course of seven days, they continued to attack Mizzima ’ s server while the Mizzima
administrators worked to delete the different backdoors that the attackers frequently
installed. By the fi fth day they were shut out of the system, although they continued
to check for access on the sixth and seventh days but were denied. We further confi rmed that the attacks originated from Burma and used the proxy service to bypass
national-level fi ltering of Mizzima News .
Investigating the Attackers
We investigated the identities of the attackers by analyzing the versions of the backdoor program c99shell and the IRC bot pBot they used, the specifi c attackers who
downloaded these fi les, and the location they retrieved the programs from. What
follows is an analysis of the data trail we followed by analyzing and linking the information contained in these fi les.
The c99shell backdoor program is a widely available Trojan backdoor written in the
PHP programming language.
42 The versions of c99shell that the attackers tried to
download to the Mizzima News Web server were slightly modifi ed to include text in
the interface reading, “ Hacked by doscoder — oGc Security Team — #cyberw0rm @ oGc ”
( fi gure 8.2 ).
Based on this information, we could infer that the tool had been modifi ed by
“ doscoder ” — who is a member of the “ oGc Security Team ” and IRC channel “ #cyberw0rm ” on an IRC network called “ oGc. ” However, these data points do not necessarily
Figure 8.2
Screen shot of the modifi ed interface for the c99shell backdoor program.
