Tuesday, August 16, 2011
Thoughts on the Operation Shady Rat
Let it be known that the year 2011 is best described as the Year of the Hackers. And I know, one way or another you will agree or disagree with me. But hey! The media publicized these sophisticated security attacks targeting CIA, US Senate, Sony, PBS, Philippine Congress and the list continues. All of these attacks are attributed to hacker groups such as AntiSec, Anonymous and LulzSec.
I have been quiet for a couple of days because of constant research of this unprecedented cyber-espionage campaign which was discovered in the year 2006 because of the logs which was discovered by McAfee. In fact, some people blame China and Russia behind this espionage but it should be noted that McAfee disclaimed that China or Russia is responsible for this and that they also declined to reveal the source where the “Shady RAT” came from.
I’m not really sure who suggested that China should be blamed for this but I think they blamed some of the Chinese hackers because of the recent information gathering they made. It is said that in the past years, they have stolen highly confidential information that is kept secret in supercomputers in the US. But the Chinese government denied its involvement of the said campaign.
Some people may also say that it’s the Russian government because of the unforgotten Cold War between the US but then again it is really unfair to point our fingers to Russia and China because of insufficient evidence against them. All countries are innocent until proven guilty.
I guess McAfee has unleashed a new media storm because of their discovery since 2006. Their rival company, Symantec also posted its own analysis of the campaign and was skeptical of its impact. "Is the attack described in Operation Shady RAT a truly advanced persistent threat? I would contend that it isn’t, especially when you consider the errors made in configuring the servers and the relatively non-sophisticated malware and techniques used in this case," Symantec's Hon Lau wrote in a blog post.
"Sure the people behind it are persistent but no more than the myriad of other malware groups out there such as Zeus, Tidserv, and others like them," said Lau.
Although, it is highly controversial and questionable why McAfee discovered this campaign before any antivirus company or government agency; but could it be possibly an excuse to put blame on China? That I’m not sure of and I lay my hands off regarding this case.
To our valuable readers, I’ll give you a room for your opinions and views regarding this campaign. If you ask me, I have 60% trusts on this revelation. Whether this is true or not, there are questions that will cloud up our minds. So are we ready for this cyber espionage and cyber terrorism?
ROOTCON is managed by like minded InfoSec professionals across the Philippines. All rights reserved.Designated trademarks, brands and articles are the property of their respective owners.
Monday, July 25, 2011
Philippine Congress Hacked by BashCrew for #AntiSec
The Philippine Goverment has become the latest target in the #antisec operation by a foreign hacker team known as BashCrew. The Philippine Congress Website (http://www.congress.gov.ph/) was hacked and some of its data were leaked. The leak has personal information, emails, contact numbers etc via pastebin.

Shipcode is an InfoSec enthusiast from Cebu. During his high school days he was just an ordinary script kiddie. He loves to search for web exploits and other issues concerning network / wireless security.
ROOTCON is managed by like minded InfoSec professionals across the Philippines. All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.
Thursday, June 02, 2011
Pinoy Hacker's Confession 2004
This video clip is from Loren Legarda's Real Life Stories TV Program which I am not so familiar with. I was still on my sixth grade then at that time. I am not sure if you are familiar with this documentary video but if you are an infosec enthusiast, this is worth watching for.
Tamby
Carding is a term for theft and fraud using a credit card (CC) in order to purchase goods, gadgets, shirts, etc. Tamby explained that he got the full credit card details from another IRC user who posted the CC details of an American credit card owner. Tamby also showed how he ordered and received his shipment without being caught.
Michael
He didn't have much to show but explained that he does scamming, phishing and also carding. Michael not only pawns people's accounts, he also sells the goods he purchased online.
He’s a linux user and was frequently on IRC channel #philcarder. This same channel is also featured on this video clip.
Henry
The third video is another cracker named Henry. He was branded here as a computer wizard because he monitors other people's computer and mobile phones. Yeah, you read me right! He also RATs cellphones.
This video was documented in 2004 and it has been three years since the Love Bug (I Love You Virus) incident of Onel de Guzman.
The first two people showed the capabilities of some IRC users in Dalnet which is common on IRC chat rooms. What struck me most is the third person who RATs another computer and mobile phones.
What Now?
To date, the NBI has been tracking carders but there has been no luck lately. This kind of people still exists today and in fact younger people are starting to get hooked up with this dilemma. I bet you have just read the story of a 14 year old boy who was hired by Microsoft.
Still, I don't like to brand them as l337 hackers but IRC enthusiasts and people who cracks out of curiosity. Ordinary users would call them hackers but if you pack them all together, they are just ordinary people like me and you.
What you see in this clip could not be branded as real hacking because hacking is more than just what is shown here.
Hacking is more than what you can acquire physically. Hacking is when you advance yourself to learn more about the intricacies of technology and you help people secure themselves from these prying eyes on cyberspace.
Talk Back
Please comment on this blog at our ROOTCON Forum. We all learn from each other when your views and opinions are shared.
Participate ROOTCON 2011 Security Conference
Our objective here in ROOTCON is to promote "Security Awareness".
Please join us on September 9 - 10, 2011. Venue will be at Parklane International Hotel, Cebu City, Philippines.
Early bird registration is until June 30, 2011. For more info about the registration click here. Check also the list of our seminar tracks and bio of our speakers.
ROOTCON is an independent conference, not owned or controlled by any vendors, the speakers don’t have to “stay on message” – and it’s not a marketing event.
ROOTCON goes beyond the sessions with independent experts that focuses on what works in the real world. That means the experts give the straight scoop on how to workaround any limitations and manage network security wisely.
About the Contributor:
Shipcode is an InfoSec enthusiast from Cebu. During his high school days he was just an ordinary script kiddie. He loves to search for web exploits and other issues concerning network / wireless security.
ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.

