Advertisement
Promo

Security threats Toolkit

Security experts lift lid on Chinese hack attacks

Tom Espiner ZDNet.co.uk

Published: 23 Nov 2005 17:05 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security experts have revealed tantalising details about a group of Chinese hackers who are suspected of launching intelligence gathering attacks against the US government.

The hackers, who are believed to be based in the Chinese province of Guangdong, are thought to have stolen US military secrets, including aviation specifications and flight-planning software.

The US government has coined the term 'Titan Rain' to describe the hackers.

"From the Redstone Arsenal, home to the Army Aviation and Missile Command, the attackers grabbed specs for the aviation mission-planning system for Army helicopters, as well as Falconview 3.2, the flight-planning software used by the Army and Air Force," said Alan Paller, director of the SANS Institute, on Tuesday.

The team is thought to consist of 20 hackers. Paller claimed that the Chinese government was the most likely recipient of the information they intercepted.

"Of course it's the government. Governments will pay anything for control of other governments' computers. All governments will pay anything. It's so much better than tapping a phone," Paller told an event at the Department of Trade and Industry on Tuesday.

Titan Rain first came to public attention this summer, when the Washington Post  reported that Web sites in China were being used to target computer networks in the Defense Department and other US agencies.

Time  later reported that Titan Rain had been counter-hacked by a US security expert called Shawn Carpenter.

The attacks, which are ongoing, were particularly effective on the night of 1 November, 2004, said Paller, who outlined how the hackers first scanned then broke into US government computers.

At 2223 Pacific Standard Time, the Titan Rain hackers exploited vulnerabilities at the US Army Information Systems Engineering Command at Fort Huachuca, Arizona.

At 0119 they exploited the same hole in computers at the Defense Information Systems Agency in Arlington, Virginia.

At 0325 they hit the Naval Ocean Systems Center, a Defense Department installation in San Diego, California.

At 0446, they struck the United States Army Space and Strategic Defense installation in Huntsville, Alabama.

The UK is also under intelligence-gathering cyber-attack from the Far East, according to National Infrastructure Security Co-ordination Centre (NISCC). The government body cannot name the countries concerned as this may "ruin diplomatic efforts to halt the attacks", NISCC director Roger Cummings said on Tuesday.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
123 out of 258 people found this useful


Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

2 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters