Skip to comments.
Slammer Source Code Provides Clues - [Chinese hackers]
EWeek.com ^
| January 27, 2003
| Dennis Fisher
Posted on 01/27/2003 5:12:57 PM PST by HAL9000
Edited on 04/13/2004 2:58:58 AM PDT by Jim Robinson.
[history]
As corporate IT departments go about the business of cleaning up their networks, there are strong indications that the SQL Slammer worm that brought down portions of the Internet over the weekend is based on the work of an obscure Chinese cracking group.
(Excerpt) Read more at eweek.com ...
TOPICS: Crime/Corruption; News/Current Events
KEYWORDS: china; honkerunion; internet; microsoft; mssql; slammer; virus; worm
1
posted on
01/27/2003 5:12:57 PM PST
by
HAL9000
To: HAL9000
When this all sorts out I think they will note that the attack actually began in Asia on Friday (local time). I live in Taiwan and noticed a decided slow down in the Internet beginning about noon on Friday.
2
posted on
01/27/2003 5:16:19 PM PST
by
twntaipan
(Political Correctness: Liberal's "Cultural Revolution" --with equally devastating results!)
To: twntaipan
Is it my tinfoil hat showing, or would it be impossible for this Honkers group to be doing what it's doing from inside China without the full support of the Chinese government?
To: GovernmentShrinker
No...try as they might, no government, not even the Chinese government, can restrain determined people in accessing their Internet.
It could have been as simple as establishing a session to a willing or unwilling host outside of China and firing off the worm.
4
posted on
01/27/2003 5:50:32 PM PST
by
xrp
To: HAL9000
Disconnect China from the web?
5
posted on
01/27/2003 5:55:52 PM PST
by
boris
To: GovernmentShrinker
No, I don't think they could be doing it without at least some protection from someone at some level of government. There are more than 40,000 people employeed by the PRC government to monitor and clamp down on Internet activities (most specifically anything related to dissent, but that includes access to most Western news cites; CNN is allowed for reasons you can probably figure).
6
posted on
01/27/2003 5:55:52 PM PST
by
twntaipan
(Political Correctness: Liberal's "Cultural Revolution" --with equally devastating results!)
To: xrp
You are probably right about finding a willing site outside of China. But the majority of hacking/viri writing is associated mostly with a university in the south of China, about an hour from Hong Kong. I believe the university is FuoShan University.
7
posted on
01/27/2003 5:58:55 PM PST
by
twntaipan
(Political Correctness: Liberal's "Cultural Revolution" --with equally devastating results!)
To: twntaipan
All it took to get the ball rolling was a single UDP packet. Not that hard to get out, even if the government is stringently monitoring the net. Remember, UDP is connectionless, so spoofing the originator makes it hard to determine the origin past a couple of hops.
8
posted on
01/27/2003 6:04:42 PM PST
by
cryptical
To: cryptical
But clues in the code have, apparently, been used to trace it back to the probable source. Triads (Chinese gangs) are reported to have invested heavily in hacking for their own purposes. Those gangs exist only because they are allowed to in China.
9
posted on
01/27/2003 6:13:40 PM PST
by
twntaipan
(Political Correctness: Liberal's "Cultural Revolution" --with equally devastating results!)
To: GovernmentShrinker
To: edwin hubble
Yes. I figured this one was from Chinese military as well as earlier ones. Not surprised to see it confirmed.
It is part of their program on asymetrical warfare. They are sponsored by the Chinese government.
Disclaimer:
Opinions posted on Free Republic are those of the individual
posters and do not necessarily represent the opinion of Free Republic or its
management. All materials posted herein are protected by copyright law and the
exemption for fair use of copyrighted works.
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson