Control and Resistance
165
country and nationalistic, and they did not approve of the foreign media ’ s portrayal
of Burma. Although the oGc administrator denied being responsible for the defacement of Mizzima , he was often vague and implied that it may have been him. He was
also aware of “ doscoder ” and “ 0verkill ” but refused to discuss them.
Based on our correlative evidence, we directly accused the oGc administrator of
defacing Mizzima in our IRC chat by linking his various aliases to the circumvention
software used in the Mizzima attacks. The oGc administrator never directly accepted
responsibility, but he used tongue-in-cheek responses that alluded to his involvement.
For instance, although he said his involvement was “ impossible, ” he added emoticon
smiley faces to his replies. He also suggested that he was being framed and that a
well-known hacker, Lynn Htun, was the person responsible for the attacks.
Lynn Htun, better known by his handle “ Fluffi Bunni, ” defaced high-profi le information-security-industry Web sites such as the SANS Institute with humorous, taunting text and images between 2000 and 2003. Lynn Htun was arrested in London on
April 29, 2003, while attending the InfoSecurity computer security conference, for his
failure to appear in court on (unrelated) forgery charges. He formerly worked in the
U.K. offi ces of Siemens Communications.
51
In response to a post on Myanmar IT Pros ( http://myanmaritpros.com ) — a popular
forum for Burmese information technology professionals — Lynn Htun posted the following analysis of the oGc:
Their server is called irc.olivegreen.org . . . they set up irc servers and rent them out to botnet
owners, in return, they are allowed to use the botnet to ddos once a month or so. They didn ’ t
hacked the drones for the botnet, they are simply providing the server(s) for harvesting the
botnet. So in other words, there ’ s no real skills there. . . . You should contact their service provider
and tell them to shutdown the botnet hub that is running on the following VPS. . . . All the
above IPs are bound to a FreeBSD box running on a VPS. You wont fi nd the bots on their server
when you join because they are all in a secret channel with umode fl ags set to hide them from
normal users.
52
Lynn Htun ’ s accusation that the oGc occasionally uses a botnet constructed by
others for DDoS attacks as a form of payment infuriated the oGc administrator, who
denied the claims vigorously when we mentioned them during our IRC chats with
him. During one chat a strange coincidence occurred when an IRC user with the
nickname “ lynn ” appeared in the oGc IRC channel, purporting to be Lynn Htun. The
two times that “ lynn ” connected to the server, the following information was
displayed:
lynn (~xero@bagan-3634EE84.childminder.co.uk)
Lynn (humm@bagan-888BA9F1.uk2net.com) has joined #Bagan
[Lynn] (humm@bagan-888BA9F1.uk2net.com): xero
165
country and nationalistic, and they did not approve of the foreign media ’ s portrayal
of Burma. Although the oGc administrator denied being responsible for the defacement of Mizzima , he was often vague and implied that it may have been him. He was
also aware of “ doscoder ” and “ 0verkill ” but refused to discuss them.
Based on our correlative evidence, we directly accused the oGc administrator of
defacing Mizzima in our IRC chat by linking his various aliases to the circumvention
software used in the Mizzima attacks. The oGc administrator never directly accepted
responsibility, but he used tongue-in-cheek responses that alluded to his involvement.
For instance, although he said his involvement was “ impossible, ” he added emoticon
smiley faces to his replies. He also suggested that he was being framed and that a
well-known hacker, Lynn Htun, was the person responsible for the attacks.
Lynn Htun, better known by his handle “ Fluffi Bunni, ” defaced high-profi le information-security-industry Web sites such as the SANS Institute with humorous, taunting text and images between 2000 and 2003. Lynn Htun was arrested in London on
April 29, 2003, while attending the InfoSecurity computer security conference, for his
failure to appear in court on (unrelated) forgery charges. He formerly worked in the
U.K. offi ces of Siemens Communications.
51
In response to a post on Myanmar IT Pros ( http://myanmaritpros.com ) — a popular
forum for Burmese information technology professionals — Lynn Htun posted the following analysis of the oGc:
Their server is called irc.olivegreen.org . . . they set up irc servers and rent them out to botnet
owners, in return, they are allowed to use the botnet to ddos once a month or so. They didn ’ t
hacked the drones for the botnet, they are simply providing the server(s) for harvesting the
botnet. So in other words, there ’ s no real skills there. . . . You should contact their service provider
and tell them to shutdown the botnet hub that is running on the following VPS. . . . All the
above IPs are bound to a FreeBSD box running on a VPS. You wont fi nd the bots on their server
when you join because they are all in a secret channel with umode fl ags set to hide them from
normal users.
52
Lynn Htun ’ s accusation that the oGc occasionally uses a botnet constructed by
others for DDoS attacks as a form of payment infuriated the oGc administrator, who
denied the claims vigorously when we mentioned them during our IRC chats with
him. During one chat a strange coincidence occurred when an IRC user with the
nickname “ lynn ” appeared in the oGc IRC channel, purporting to be Lynn Htun. The
two times that “ lynn ” connected to the server, the following information was
displayed:
lynn (~xero@bagan-3634EE84.childminder.co.uk)
Lynn (humm@bagan-888BA9F1.uk2net.com) has joined #Bagan
[Lynn] (humm@bagan-888BA9F1.uk2net.com): xero
