Control and Resistance
169
history of prolifi c defacements and is critical of opposition media sites. An IRC user
reporting to be Lynn Htun had xer0 in his connection information, which matched
a user in a channel on “ overkill.myanmarchat.org ” that was used by the attackers.
However, it is unclear if the user we spoke with was really Lynn Htun. In addition,
oGc and Lynn Htun ’ s Myanmar Online appear to be rival IRC networks, a fact that
may explain why the oGc administrator implicated Lynn Htun in the attacks.
Another explanation concerns the use of the oGc ’ s IRC infrastructure as a platform
for the attackers. It is possible that the attackers used the oGc infrastructure through
some arrangement with oGc or that the oGc simply tolerated their presence. This
scenario is consistent with Lynn Htun ’ s charge that the oGc provides hosting for
botnets in return for the ability to occasionally use them for DDoS targets. Another
consistent explanation is that the oGc could have also supplied access to censorshipcircumvention proxies to their general membership. The administrator ’ s accounts of
oGc on the circumvention software network could have been shared across members
of the oGc.
Based on the evidence we collected, we assessed that the suspected attackers in this
case are not particularly favorable to the Burmese opposition but cannot be simplistically characterized as “ progovernment ” either. Their hostility toward the Burmese
opposition appears to stem from feelings of nationalism and a belief that the opposition promotes a negative image of their country. Most appear to be concerned with
gaining employment and improving the state of information and communications
technology in Burma. Although they have both the skills and motivation to attack
opposition Web sites, they may have attacked such Web sites without formal connections to the government. While our investigation provides indications of the possible
identities of the attackers, it presents more questions than answers around state
involvement in the ongoing cyber attacks against Burmese opposition groups.
The characteristics of the attackers and the opportunistic nature of the attacks may
refl ect a “ swarming effect ” in which private individuals, inspired by patriotic sentiments, voluntarily participate in cyber attacks during political events without clear
approval or direction from state entities. This phenomenon has been observed in a
number of recent confl icts and political events, including the 2008 Russia-Georgia war,
the 2009 Gaza confl ict, and the 2009 Iranian elections.
58 Our investigation shows that
even a relatively simplistic attack can have signifi cant effects if it is executed at a sensitive time. The attackers in this case were able to deface Mizzima News because it was
running a version of Joomla! that was known to be vulnerable. In effect, this was a
preventable attack — a known vulnerability that was exploited by opportunistic attackers. However, the timing of the attack coincided with ongoing DDoS attacks, and the
addition of a visible threat (defacement) compounded the effect on the political opposition and their supporters. The involvement of private individuals in cyber attacks
during political events demonstrates the chaotic nature of cyberspace and shows that
169
history of prolifi c defacements and is critical of opposition media sites. An IRC user
reporting to be Lynn Htun had xer0 in his connection information, which matched
a user in a channel on “ overkill.myanmarchat.org ” that was used by the attackers.
However, it is unclear if the user we spoke with was really Lynn Htun. In addition,
oGc and Lynn Htun ’ s Myanmar Online appear to be rival IRC networks, a fact that
may explain why the oGc administrator implicated Lynn Htun in the attacks.
Another explanation concerns the use of the oGc ’ s IRC infrastructure as a platform
for the attackers. It is possible that the attackers used the oGc infrastructure through
some arrangement with oGc or that the oGc simply tolerated their presence. This
scenario is consistent with Lynn Htun ’ s charge that the oGc provides hosting for
botnets in return for the ability to occasionally use them for DDoS targets. Another
consistent explanation is that the oGc could have also supplied access to censorshipcircumvention proxies to their general membership. The administrator ’ s accounts of
oGc on the circumvention software network could have been shared across members
of the oGc.
Based on the evidence we collected, we assessed that the suspected attackers in this
case are not particularly favorable to the Burmese opposition but cannot be simplistically characterized as “ progovernment ” either. Their hostility toward the Burmese
opposition appears to stem from feelings of nationalism and a belief that the opposition promotes a negative image of their country. Most appear to be concerned with
gaining employment and improving the state of information and communications
technology in Burma. Although they have both the skills and motivation to attack
opposition Web sites, they may have attacked such Web sites without formal connections to the government. While our investigation provides indications of the possible
identities of the attackers, it presents more questions than answers around state
involvement in the ongoing cyber attacks against Burmese opposition groups.
The characteristics of the attackers and the opportunistic nature of the attacks may
refl ect a “ swarming effect ” in which private individuals, inspired by patriotic sentiments, voluntarily participate in cyber attacks during political events without clear
approval or direction from state entities. This phenomenon has been observed in a
number of recent confl icts and political events, including the 2008 Russia-Georgia war,
the 2009 Gaza confl ict, and the 2009 Iranian elections.
58 Our investigation shows that
even a relatively simplistic attack can have signifi cant effects if it is executed at a sensitive time. The attackers in this case were able to deface Mizzima News because it was
running a version of Joomla! that was known to be vulnerable. In effect, this was a
preventable attack — a known vulnerability that was exploited by opportunistic attackers. However, the timing of the attack coincided with ongoing DDoS attacks, and the
addition of a visible threat (defacement) compounded the effect on the political opposition and their supporters. The involvement of private individuals in cyber attacks
during political events demonstrates the chaotic nature of cyberspace and shows that
