Showing posts with label chinese hackers. Show all posts
Showing posts with label chinese hackers. Show all posts

Sunday, May 20, 2012

Philippines ready for Chinese cyber warfare, Malacañang says

Malacañang on Sunday said it is ready to deal with potential cyber-attacks, amid reports that China is investing in cyber-warfare as part of its steady military buildup.

“Our technical people are very competent, we have been coordinating with the Department of Science and Technology. As to whether (the) Chinese have been involved or investing in that, we are in no position to comment," presidential spokesman Edwin Lacierda said on dzRB radio.

"Suffice it to say that as soon as we detect on our servers (an incident) that would point to a (denial of service attack), our IT people are on top of it and they are competent in dealing with it,” he added.

He was referring to recent cyber-attacks on government websites, including that on the Official Gazette (www.gov.ph), where there were signs the attacks originated from China.

Other recent attacks had targeted the sites of the Department of Budget and Management (www.dbm.gov.ph) and the Philippine Atmospheric Geophysical and Astronomical Services Administration (www.pagasa.dost.gov.ph).

The attacks occurred amid a month-long standoff between the Philippines and China at Panatag (Scarborough) Shoal.

The dispute started when Philippine military forces spotted Chinese fishermen gathering marine species from the area but were blocked by Chinese vessels when they tried to make arrests.

Some of the attacks from China had involved the defacement of the sites with a Chinese flag and the Chinese national anthem playing in the background, along with a message that Huangyan Island – the name China uses to refer to the shoal – is China’s.

Reports during the weekend quoted the Pentagon as saying China is pursuing a steady military buildup and investing in cyber-warfare.

“We have recently been the subject of several cyber-attacks... (but) so far we have been able to defend our website,” Lacierda said.

No info on added Chinese warships

Meanwhile, Lacierda said the Palace has no information on reports that China has sent five warships close to the maritime domains of the Philippines after the arrival of the nuclear-powered US submarine USS North Carolina.

“We have no information na magpapadala ng Chinese warships sa waters natin, I have no information on that. I chekced it with the AFP, wala sila ganoong information," he said.

In the meantime, he said it is in the interest of both the Philippines and China to continue pursuing a peaceful solution to the standoff.

“It’s in the interest of both countries to pursue a peaceful resolution to this,” he said.

He added that on the part of the Philippines, it has been “prudent” in both actions and words in making gestures of goodwill on the matter.

“As emphasized by (President Benigno Aquino III), we have maintained our position of de-escalating the tension in the Bajo de Masinloc standoff,” he said.

-----------------------------------------------------------------------------------------------------
GMA News Online | May 20, 2012 | Article Link

Monday, May 14, 2012

Gov’t websites, private firms endure 30-hour cyber attack — source

MANILA,Phiippines — A number of websites owned by the government and private firms have come under intense Distributed Denial-of-Service (DDOS) attacks for 30 hours on Monday, suggesting possible attempts to cripple online services given out by these institutions.
 
The agencies and companies that endured the attack are all part of the Philippine Research, Education, and Government Network (PREGINET), an association of private- and public-sector entities acting as a research and education network in the country.

“Since yesterday (Sunday), we were under attack (Denial of Service) from a server located abroad,” stated an email sent out to PREGINET members on Monday, a copy of which was obtained by InterAksyon.com. “We have already coordinated with the web hosting company that was sourcing the attack and we are awaiting on details from them.”

DDoS is a form of cyber attack used by hacking groups to take down particular websites involving the act of overwhelming the website’s server by executing external commands from a number of terminals, which tend to cripple the server indefinitely.

The email, however, did not identify where the attacks were coming from, nor did it enumerate which websites were affected by the attacks. 

Members of PREGINET include the Office of the President, the House of Representatives, the Department of Science and Technology, the Metro Manila Development Authority, the Ateneo de Manila University and the University of the Philippines, among others.

According to a reliable source, the perpetrators launched a DDoS attack from a Tier-3 data center located abroad, which they infiltrated, enabling them to initiate attacks of an unprecedented scale against Philippine-based websites.

A Tier-3 data center means the facility has been certified to have redundant components, dual-powered equipment and multiple uplinks, giving them as much as 99.982 percent of guaranteed availability.

The source said no notable damage or downtime were incurred by the PREGINET websites, except that connections to the web properties have been sluggish throughout the duration of the attacks.

From a US server but not from a US national

According to Information and Communications Technology Office (ICTO) Executive Director Louis Casambre, the attack has already been dealt with by the government’s “overseas partners,” and confirmed that the attacks came from a breached server located in the United States.

“However, evidence suggests that it may not have been caused by a US national,” Casambre told InterAksyon.com via email. “No sites subject to these attacks were breached; however, the traffic caused may be considered significant so the matter is not being taken lightly.”

Government websites have come under hacking attacks in the past several weeks, arising from the ongoing standoff between China and the Philippines regarding Scarborough or Panatag Shoal, a disputed territory just West of Luzon.

Among the most notable government websites defaced by suspected hackers from China include the web properties of Malacanang’s Communications Group; the Department of Budget and Management; the country’s weather bureau; the Philippine News Agency; and the University of the Philippines.

The hackers were also able to infiltrate the Web systems of private entities such as the news website Philstar.com and the educational institution Colegio de San Agustin.

In all of the defacements, the hackers emphasized that the disputed territory belongs to China and not the Philippines, as evidenced by its nine-dash line claim.

The ICTO had already ordered government agencies to re-evaluate the security measures implemented in their respective IT systems, in light of the successful breaches incurred by other public-sector agency websites.

------------------------------------------------------------------------------------------------------
Patrick Villavicencio | InterAksyon.com | May 14, 2012 | Article Link

Thursday, May 10, 2012

Philippines asks agencies to check Internet security amid hack attacks

MANILA, Philippines – The Philippine Information and Communications Technology Office (ICTO) has called on other state agencies to review their Internet security measures amid recent hacking incidents of government websites by supporters of China’s claim to the disputed Scarborough Shoal.
 
In a statement, the ICTO said government Internet managers and systems administrators should review the security of their respective websites, “to ensure that homepage defacements like those that happened several weeks… do not happen in the future.”
The most notable victims of hacking have been the Department of Budget and Management, the University of the Philippines and, most recently, the Philippine Atmospheric, Geophysical and Astronomical Services Administration (Pagasa).

The defacement of Pagasa’s website took place on Wednesday. The site’s homepage was vandalized by hackers “of still undetermined origin,” the ICTO said. The www.pagasa.dost.gov.ph site, which citizens and media organizations alike rely on for weather forecasts, was back online three hours after the attack was discovered.

“The recent defacement of the PAGASA website only illustrates the patent vulnerabilities inherent on some web platforms. We would like to request system administrators of government websites to review their source code for these security flaws,” ICTO executive director Louis Casambre said in a statement.

A common flaw in these sites, he said, was the use of third-party applications or “plug-ins,” or ready-made programs that make it easier for IT managers to add features to a certain site without having to write code.

Casambre said the ICTO has taken “definitive” steps to help other agencies improve their IT security measures to ward off future hacking attempts.

“It is unfortunate however that the Pagasa website was hacked so soon. In light of this new development, we are looking at accelerating our on-going effort,” he said.

In the meantime, Casambre said individual agencies should take steps on their own to help the understaffed and underfunded ICTO.

Like that of Pagasa’s, many government websites are still hosted on in-house servers that may not be equipped with the latest security features, making them easier to hack in to, according to Casambre.

He said hosting of government sites can be out-sourced to third-party IT providers.  

Outsourcing this service would also be less costly for agencies. He said the Department of Science and Technology’s (DOST) own servers, more secure than other government facilities, could also be used by other agencies.

“As potential high-profile targets for hackers both local and foreign, government system administrators must take the extra effort to ensure that our servers are safe from cyber vandalism,” Science and Technology Secretary Mario G. Montejo said in a statement.

---------------------------------------------------------------------------------------------------------

Wednesday, April 25, 2012

Chinese hackers target more Philippine websites

MANILA, Philippines (UPDATED) - Chinese hackers plan to attack more Philippine government websites, according to their discussions on the Internet.

An online forum of Chinese hackers belonging to the "Silic Group" tagged the Philippine Institute of Development Studies (PIDS) and Bulacan provincial government websites that are next in their firing line.

One forum user even posted usernames and passwords of Bulacan provincial government website administrators. 

The Bulacan website remained intact as of 8 p.m. Wednesday. Its log-in page for administrators has a time-lock security feature that prevents people logging in outside regular office hours.

On Wednesday night, a purported hacker from China claiming to be a member of the "Honker Union" also published on Facebook the alleged usernames and passwords of administrators of websites belonging to Radio Mindanao Network (http://www.rmn.ph), the University of the Philippines College of Arts and Letters (http://kal.upd.edu.ph), and the People Management Association of the Philippines (http://www.pmap.org.ph).

The website of the Philippine National Police (http://www.pnp.gov.ph) also seemed to be in error  as it showed only a raw index page. However it was not confirmed if the police website has been hacked. 

An administrator of the Chinese hackers' forum at bbs.blackbap.org also boasted about "first-hand" details about the attack that crippled the Department of Budget and Management (DBM) website on Wednesday afternoon.

The message indicated that those who defaced the DBM website are the same ones who attacked the Vietnamese government's website, gov.vn.

The hackers allegedly discussed their attack on the DBM website in a chat hub for several minutes.

Details about the DBM server webshell address, administrator and publisher accounts were posted online.

While the Philippine government has yet to publish full details about the DBM attack, the Chinese hackers apparently turned the DBM website into a chat room.

"How Come a Small Bitch Border Country are (sic) Overconfident? And Challenged (sic) to Our Chinese Super Hacker (sic)?" the hackers posted on the DBM website in mangled English. 

The hackers also post racist comments  in  the forum, referring to Filipinos as "maids who are going up against the Chinese government." 

One thread on the hackers' forum, meanwhile, expressed glee at the recent attack on the University of the Philippines website. 

It is not clear if members of the forum are the perpetrators of the UP website defacement.
Some of the threads on the "Silic Group" hackers' forum directly referred to the dispute between China and the Philippines over Scarborough shoal. They indicated that their attacks are linked to the issue.

One forum member referred to the Scarborough standoff as "Huangyan Island incident."
He said Chinese hackers should "punish the Philippines" and target Philippine websites, "especially its portal." 

Malacañang on Monday said websites of the Official Gazette, the PCDSPO, and the Presidential Museum and Library website were targets of a denial-of-service attack.
"Information gathered through our data analysis indicated that the attack originated from IP addresses assigned to Chinese networks," Presidential Spokesperson Edwin Lacierda said in a statement.

----------------------------------------------------------------------------------------
Jojo Malig | ABS-CBNnews.com | April 25, 2012 | Article Link

Pinoy hackers scale up attacks on China websites

MANILA, Philippines (UPDATED) - Filipino and Chinese hackers are engaged in a raging battle on the Internet amid the 2 countries' dispute over Scarborough Shoal and the Spratlys.

On Tuesday, members of "PrivateX" and "Anonymous #OccupyPhilippines" took down more Chinese websites in response to an attack allegedly made by Chinese Internet users on Philippine websites.

The Palace on Monday said the Presidential Communications Development and Strategic Planning Office (PCDSPO) monitored a distributed denial-of-service attack (DDOS) on www.gov.ph, www.pcdspo.gov.ph, and www.malacanang.gov.ph that caused the government's servers to momentarily lag. 

"Information gathered through our data analysis indicated that the attack originated from IP addresses assigned to Chinese networks," Presidential spokesperson Edwin Lacierda said in statement yesterday. 

Suspected Chinese hackers also defaced the University of the Philippines website over the weekend while another attack early Tuesday allegedly targetted the Philippines' Department of Foreign Affairs website.

In reaction, Filipino hackers launched a series of attacks on Chinese websites starting Monday.

In an operation dubbed "#OpChinaDown," Filipinos attacked the following websites:
"They want Distributed Denial Of Service let's give them DDOS," said the Facebook page administrator of "Anonymous #OccupyPhilippines."

They also warned that they have not yet started a full-blast hacking spree.
"Di pa nagi-init upuan namin sa tapat ng computer. Sabi kasi dahan-dahan daw para ramdam ang sakit," said the Facebook page administrator of the "PrivateX" hacking group.

The same group was behind the attack on Vice-President Jejomar Binay's website on New Year's day.

"The recent defacements occurred on certain Chinese websites were just a simple response to what happened to the UP site.  You may continue bullying our country's waters but we will not tolerate you from intimidating our own cyber shores," said a message left by Filipino hackers on some of the websites they defaced.

"Those defacements are just a mere response to what you have initially started. We are not trying to start anything. We are just trying to tell you that we do not want to be bullied in our own cyberspace too," the message added.

"#OpChinaDown is not a threat. It will be a response. A response to future attacks within our cyberspace. We will leave our country's disputes to our government's hands. Yet this does not mean we will not support them," said the hackers, who are allegedly associated with the Anonymous global hackers group.

"One Truth Prevails, Scarborough Shoal is ours," they said. "We are Anonymous. We are legion. We don't forgive. We don't forget. United as one, Divided by zero. Expect us."
DFA spokesman Raul Hernandez earlier condemned the cyber attacks and called on hackers from both sides to stop the online war.

"We denounce such cyber attacks regardless from which side they are coming from," Hernandez said.

"We think they are counter productive and only add to the tension. We call on both Filipino and Chinese netizens to be more responsible and encourage dialogue rather than discord," he said.

-------------------------------------------------------------------------------

Jojo Malig | ABS-CBNnews.com | April 25, 2012 | Article Link

Monday, April 23, 2012

Palace websites hacked by suspected Chinese hackers

Malacañang on Monday afternoon said three of its official websites were attacked by hackers whose IP addresses are assigned to Chinese networks.

In a press statement, the office of the Press Secretary said the websites of the Official Gazette, Presidential Communications Development and Strategic Planning Office (PCDSPO), and the Presidential Museum and Library were attacked.

“At around 4 o’clock in the afternoon of April 23, 2012, the PCDSPO noticed a significant spike in traffic with malicious URL requests from forged user-agents being channeled to the Official Gazette website, to the PCDSPO website, and to the Presidential Museum and Library website, causing our servers to momentarily lag,” the OPS said.

“We determined that this was a denial-of-service attack. Information gathered through our data analysis indicated that the attack originated from IP addresses assigned to Chinese networks,” it further said.

The OPS said the PCDSPO is endeavoring to maintain its websites.

“Please note that we can expect temporary disruption of service while the attack is ongoing,” it added.

Last Friday, the website of University of the Philippines was attacked by alleged pro-China hackers.

Posted with the message “We come from China! Huangyan Island is Ours!” is a map of China’s so-called "9-dash line," supposedly indicating the superpower’s territorial claim in its southern seas —which extends to the Philippines and even to Malaysia’s coastline

“We strongly denounce the attempt to deprive the UP community of vital information,” said UP Assistant Vice President for Public Affairs Danilo Arao via a text message to GMA News Online.

The attack came amidst the Philippines’ ongoing standoff with China regarding the Panatag (Scarborough) Shoal.
--------------------------------------------------------------------------------------------
Amita O. Legaspi/KBK | GMA News Online | April 23, 2012 | Article Link

Featured Posts

AFP Modernization 2017: Highlights and Review

The modernization of the Armed Forces of the Philippines was on a roll this year, as we've seen a few big ticket items having completely...

Popular Posts