Showing posts with label Iran. Show all posts
Showing posts with label Iran. Show all posts

Sunday, 25 April 2010

Iranian "Sun-Army" attacks NASA and JDA

What does NASA, the US space agency, have in common with the Jerusalem Development Authority of the Israeli government? They've both been attacked this week by the new Iranian hacking group, "Sun-Army".

The Defacement authority, Zone-H.org reports that this group did their first reported hacks on February 17th, one more on February 27th, and then on February 23rd defaced:

maorm.larc.nasa.gov
pic.larc.nasa.gov
fabrication.larc.nasa.gov
ohcm.larc.nasa.gov
sw-eng.larc.nasa.gov
cmar.larc.nasa.gov
careertalk.larc.nasa.gov
oea.larc.nasa.gov
technologygateway.nasa.gov

www.zhemgang.gov.bt
www.jda.gov.il



Their earlier defacements accuse "traitors to the Islamic Republic of Iran" and quotes from the Quran - "Sura Araf verse 179"

That verse says, "And in the law of retaliation there is saving of life for you, O' people of understanding, so that you may guard yourselves against evil."

(These verse were teachings to prevent "tribal feuds" - prior to the Quran, when someone was killed, his family would seek vengeance by killing all of the murderers tribe that they could. This passage of the Quran teaches that retaliation should be one for one. The accused can seek limited vengeance, but once retaliation has been achieved, there should be no on-going feud. Lives are saved by limiting the retaliation.)

Here is their defacement of the Jerusalem Development Authority:



The current NASA defacement contained this English language text:

In The Name Of God

The Nasa organization which is funded by Usa and plays an important role not only in the most of scientific fields but also in many other projects like "Star Wars" which was aimed to weeken the former soviet union , now has come down to its knees toward
the scientific level of young iranians and iran , the birth place of Cyrus the great, who formed the biggest empire the world has ever seen.

the scientific apartaide which is imposed by Usa and it alies can never prevent us from progressing in international scene , special peaceful nuclear energy.

We Congratulate You On The Occasion Of Worlds Astronomical Day


The same message is repeated in Persian, with the following line added at the end:

که ایران و ایران زمین زنده باد /// سر افراز و جاوید و پاینده باد

I can't seem to translate that well with Google Translate it is rendered as:

Iran and the Iranian Live Earth / / / partition and the eternal and lasting head wind

(If you can provide a better translation, please let me know! gar at uab dot edu)



The more recent defacement points to the Sun-Army.com website, shown here:



The Sun-Army says on their website that they were created by inviting the leaders of many influential hacking groups to join forces under the new name to support Iran's security and the Quran. They claim the group was created on February 26, 2010.

Mehdy007 is a fairly regular visitor to the Iranian hacking site, Ashiyane Digital Security. One of his posts, from August 2009, shows him uploading links to a set of 55 hacking videos on a wide-range of hacking topics. On February 24th of this year he was sharing SQL Injection attack techniques with the group, one of which he demonstrated by hacking "sciencescotland.org"

Nitrojen26 also is a member at Ashiyane, and has in the past used the Yahoo email address "Nitrojen26@yahoo.com"

The.Mo3tafA, Nitrojen26, and BodyGuard all regularly show up on pages defaced under the name "Ashiyane Digital Security Team" along with Behrooz_Ice and Q7x, with this trademark logo:



MagicCoder is the relative newcomer to the group, though he has done some solo-hacking according to his Zone-H stats, and has his own logo as well:



He's a gmail user = magicc0d3r@gmail.com

PLUS is an unknown for me. Great hacker name, since its basically impossible to Google-search. He's been involved as a named party on a number of "team defacements" for Ashiyane, including ones that left this fairly recent tag:



On defacements that use that image, the message in Persian and English is:

Our belligerence is religious and does not own any borders, thus we are here as long as atheism and blasphemy exist. We do know that effrontery of blasphemy to Imam Khomeini is what that only you can do. This is just a warning to your governmental sites!


The list of members on those hacks is:
Behrooz_Ice -Q7x -Sha2ow -Virangar -Nitrojen26 -BodyGuard -tHe.Mo3tafA MagicCoder -0261 -Ali_Eagle -PLUS -Jok3r -System.Fehler
We Love Iran
Ashiyane Digital Security Team




The WHOIS registration information for Sun-Army.com lists the same email address as their defacements -- sun.army@asia.com -- as well as this address:

Sun Army
Sun Army (sun.army@asia.com)
Iranian Apartment. Azadi Sq. Tehran
Tehran
Zanjan,12365
IR
Tel. +009.2122532689

Domain servers in listed order:
ns4.mihanblog.com
ns3.mihanblog.com


The domain was registered by PublicDomainRegistry.com (DirectI Internet Solutions)

Those nameservers serve more than 700 other domains . . . mostly Iranian TLDs, ".ir"

Many of those domains are listed as attack pages, sucvh as "karrar.ir," which is described by Google SafeBrowsing as:

What happened when Google visited this site?

Of the 871 pages we tested on the site over the past 90 days, 37 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2010-04-25, and the last time suspicious content was found on this site was on 2010-04-22.

Malicious software includes 987 scripting exploit(s).

Malicious software is hosted on 4 domain(s), including link313m.persiangig.com/, link313m.blogfa.com/, bidel.ir.googlepages.com/.

2 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including link313m.blogfa.com/, boxeshia-sonni.mihanblog.com/.

This site was hosted on 1 network(s) including AS30176 (PRIORITYCOLO).


Following the links from that SafeBrowsing page find warning of malware, including malware being distributed via "sarzaminnews.mihanblog.com", "karrar.mihanblog.com", and "karrar.ir".

Friday, 18 December 2009

Who is the "Iranian Cyber Army"? Twitter DNS Redirect

(Update: 12JAN10 - Iranian Cyber Army Returns -- Target: Baidu.com )

#1 Search on Google in the past hour: "Iranian Cyber Army"
#2 Search on Google in the past hour: "Twitter hacked"

What do these things have to do with each other?

A formerly unknown group, the Iranian Cyber Army, was able to redirect the DNS for Twitter, causing all visitors to be temporarily redirected to another IP address, not belonging to Twitter, and sharing the message from the Iranian Cyber Army that they are cooler hackers than you.

Since we do actually track website defacers at UAB, and since we've never heard of the Iranian Cyber Army, we thought we would take a quick peek in our favorite Iranian hacker rooms to see who was boasting of their conquest.

First we found "vhdmsm" sharing details of the attack in the Iranian Hacker Forum, Ashiyane Digital Security.

They quote the defacement:

========================

Iranian Cyber Army

THIS SITE HAS BEEN HACKED BY IRANIAN CYBER ARMY

iRANiAN.CYBER.ARMY@GMAIL.COM

U.S.A. Think They Controlling And Managing Internet By Their Access, But THey Don't, We Control And Manage Internet By Our Power, So Do Not Try To Stimulation Iranian Peoples To....

NOW WHICH COUNTRY IN EMBARGO LIST? IRAN? USA?

WE PUSH THEM IN EMBARGO LIST

Take Care

=====================
and post links to the Twitter Blog entry about the attack, and a CNET news story.

But there is no indication they were themselves involved.

We're going to need some more evidence. Perhaps someone should be talking to the folks at BlueHost this morning.

See for yourself?


A little twiddling with various DNS Caching systems, and we were able to find the IP address to which traffic had been redirected:

66.147.244.182

There are some interesting domains there, including:

http://mowjcamp.net/

That site is interesting, because its on Bluehost, in the United States.

which currently shows content made from these graphic files (I've moved them to a more permanent location...just in case):










In my opinion, it looks like that server was compromised via WordPress vulnerabilities, but that is just an educated guess based on content at this time. So, it looks like the hacker first hacked one of the sites on the Bluehost box, other mowjcamp.org, wpcrowd.com, or coventryri.com, then redirected all the twitter traffic to that IP by changing the Nameserver entries for Twitter to point away from their normal Google-provided IP addresses to 66.147.242.88 instead.

Tuesday, 16 June 2009

Armchair CyberWarriors: Twitter and #IranElection

Our friends over at ThreatChaos let us know about the newest "CyberWar" in their blog this morning, so we went over to Twitter (yeah, follow /garwarner) and decided to check things out for ourselves.

Apparently the Moral Compass of the Internet is currently indicating that CyberWar is a harmless feel good activity that Americans should be involved in. Let me quickly go on the record to say: ALL DDOS ACTIVITY IS A CRIME AND SHOULD NOT BE ENCOURAGED OR CONDONED IN ANY CIRCUMSTANCE

First, let's get the legal part out of the way. In the United States, the relevant code is Title 18 Part I Chapter 47 § 1030(a)(5)(A)(i), which says that anyone who:

(i) knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer;

is in violation of the law and can be fined and imprisoned for up to one year (unless their intrusion causes medical or physical harm, or unless they are already a convicted felon, or unless they seek monetary gain, in which cause the penalties go up).

So, is the president of Iran's website a protected computer? No, probably not. But any computer engaged in Interstate commerce is a protected computer. For example, all of the computers belonging to your ISP, which you are placing load on by your criminal activity. If it turns out you were collaborating with others in order to cause this activity to occur, say for instance, all of your buddies on Twitter, then you could also be said to be part of a Conspiracy, but we won't get into that here.

Before we spend any more time on the wisdom of deciding as a private citizen to declare war on a foreign power, let's see what's actually going on in Twitter-space with regards to this DDOS:

Esko Reinikainen of Wales is offering this #iranelection cyberwar guide for beginners, which includes some Ghandi type actions, such as identifying yourself as an Iranian blogger with a time zone of GMT +3.30, on the theory, I suppose, that Iranian security forces will get confused as they seek out the real Iranian bloggers, and book a flight to Wales or the United States to stop the blogger. His point #6 is:


6. Denial of Service attacks. If you don't know what you are doing, stay out of this game. Oly target those sites the legitimate Iranian bloggers are designating. Be aware that these attacks can have detrimental effects to the network the protesters are relying on. Keep monitoring their traffic to note when you should turn the taps on or off.


Of course you can tell the "legitimate" Iranian bloggers, because they use the tags "#iranelection" or "#gr88" in their posts.

Many of those calling for DDOS attacks are harmless voices that suggest things like:

/nzmrmn - #DDOS this http://isna.ir/ISNA/Default.aspx?Lang=E 1. Load page in browser 2. Hit refresh a million times. 3. ??? 4. Profit!

Others call for DDOS but offer no guidance whatsoever:

/vwkess - ...keep DDOS attacks.

While others promise that the DDOS is having a great affect, such as:

/FREETHEFUTURE: RT UNCONF: News from Inside Tehran #DDOS affecting police communications, not able to track protestors PLZ RT!!

which is being heavily retweeted:
/djd1414, /FreePersians, /ian_lcv, /momsprissy, /Chromedaffodils, /z3bbster, TheBarRag, etc., etc.

Given the high tech crowd on Twitter though, it was certain that someone would come along and build a better mousetrap. Many Twitter folks discussed using "PageReboot.com" early in the DDOS. Giving this site a URL is an easy way for the site to be constantly reloaded. While historically the site has received little traffic, and almost all of it from China (88%), the MediaTemple hosted site is now showing that 25% of its traffic originates from Tehran.

/ElizabethFinn God/Allah bless everyone fighting in Iran. Set your browsers to http://www.pagereboot.com/?url=http://www.khamenei.ir/&Refresh=1 Goodnight.

/Tigrael http://www.pagereboot.com/?url=http://www.farhang.gov.ir/&refresh=1

/protactinium84 Hurt websites. http://www.pagereboot.com Set to 1. http://www.khamenei.ir/ http://www.presstv.ir/ www.President.ir http://www.irna.ir

/kamaleddin RT Lets take this down everybody CopyPasteKeepOpen http://www.pagereboot.com/...www.bornanews.ir&refresh=1 Let EVERYONE know.

The site was taken down, however, as the Twitter's reported:

/iran88 - pagereboot.com used for DDOS attacks in Iran is purposely DOWN.

One popular tweet offering a replacement for the original "PageReboot" is suggesting that people visit the site "whereismyvote.info". At the moment 9 of the 16 targeted pages are unreachable.

The site actually loads a webframe from "www.my-persia.com/ie", which in turn loads 16 frames named "Frame1.html" through "Frame16.html".

Each of these frames is using a service called "PageReboot" which causes the frame to reload itself once per second, so that visiting the single webpage will cause each of 16 "targeted" sites to be visited every second by each person viewing the page. The pages currently targeted by My-Persia are:

1. www.irna.ir = a search string is used to maximize the load on the server.
2. farsnews.com
3. www.rajanews.com = a search string is also used here to maximize the load on the server.
4. www.ahmadinejad.ir
5. www.leader.ir = a search for "khamenei" is used
6. www.president.ir = this site is actually still online despite being the most targeted of the campaign. Located on 80.191.69.40
7. www.irib.ir
8. www.iribnews.ir
9. www.kayhannews.ir = this site is the second one responding as live in my current visit.
10. farsi.khamenei.ir = actually sends a message back, saying that "Your IP, location, and other information has been recorded! Security Defence Team!"
11. www.entekhab10.net
12. www.isna.ir = also live, hosted at 64.130.220.65, which means DDOSing this box is an attack against a computer in Ontario Canada.
13. presstv.com = also live, hosted at 217.218.67.228
14. www.moi.ir = also live, hosted at 80.191.0.78
15. english.iribnews.ir = also live, hosted at 62.220.121.23
16. www.leader.ir = using a search

Other sites also are being put out to do "refreshes" automatically, such as:

/uberguru - who points us to "refreshthing.com" currently being used to DDOS isna.ir

/iran88 - Use refreshthing.com instead of pagereboot if it is down

/ironcamel - provides a pointer to a list of Iranian embassies around the world and suggests those as better DDOS targets: http://www.embassyworld.com/Iran/

/Spooky_Fox - providing a list of proxies to use to perform your DDOS on the site "iran.whyweprotest.net" -- people logging in there are posting offers for proxies to allow "anonymized" twitter posting. Of course following the general theme of paranoia that this whole site is based upon, one has to ask how we know those aren't Iranian security forces offering the proxies??


Others are asking people to STOP the DDOS, such as:

/iron_riots - "RT: Pls stop DDOS on iran's website they slow down the entire countries internet"

/B2020 - (same thing)

/OrangeCorner - offers a link on Daily Kos on why NOT to DDOS Iran. I agree with the general argument ( http://www.dailykos.com/story/2009/6/15/742591/-Do-NOT-DDOS-Iranian-websites ), but please don't tell my Fox News mother-in-law I agreed with something on Daily Kos, or she won't cook me dinner tonight!

/danteimprimis - Iranians reporting that the DDOS attacks on gov't sites are hurting overall bandwidth. May be satisfying, but we should stop.

/danielsandberg - To #IranElection protestors: DO NOT DDOS Iranian gov websites: