Slashdot Mirror


Chinese Hackers Targeting NYPD Computers

Mike writes "A network of hackers, most based in China, have been making up to 70,000 attempts a day to break into the NYPD's computer system, the city's Commissioner, Raymond Kelly, revealed Wednesday. Kelly suggested that 'perhaps it is because of the NYPD's reach into the international arena' that they are being targeted for computer hacking 'in much the way the Pentagon has been.' The hackers are apparently using a botnet to make up to 5,000 attempts a day at various unsecured portals into the NYPD's files. China's foreign ministry spokesman Qin Gang denied involvement in computer espionage. 'Some people outside of China are bent on fabricating lies of so-called Chinese computer spies,' he said last month. The obvious question is, why are the Chinese so interested in the NYPD computer network?"

212 comments

  1. Track an IP? by x_IamSpartacus_x · · Score: 5, Funny

    Someone should create a GUI interface using Visual-Basic to track an IP!

    1. Re:Track an IP? by TheRealMindChild · · Score: 5, Funny

      Don't hate! Visual Basic has always been great for creating GUIs. Just there are people who decided to write their code in it too

      --

      "When life gives you lemons, don't make lemonade. Make life take the lemons back!" -- Cave Johnson
    2. Re:Track an IP? by fisticuffs · · Score: 2, Funny

      Someone should create a GUI interface using Visual-Basic

      Get with the times, man. Haven't you seen CSI? They make 'em with Flash now.

    3. Re:Track an IP? by Anonymous Coward · · Score: 1, Informative

      I thought that was a direct quote from CSI....

    4. Re:Track an IP? by x_IamSpartacus_x · · Score: 3, Informative

      No... I'm pretty sure they still use visual basic

    5. Re:Track an IP? by plover · · Score: 1, Interesting

      Qin Gang denied involvement in computer espionage. 'Some people outside of China are bent on fabricating lies of so-called Chinese computer spies,'

      "So-called Chinese computer spies"? Let's just shut off the routers involved and see exactly which country complains.

      It probably won't be China doing the complaining, because China will be cut off from the net about that time.

      --
      John
    6. Re:Track an IP? by Anonymous Coward · · Score: 0

      Someone should create a GUI interface using Visual-Basic to track an IP!

      I beg your pardon, but I believe that's a "gooey" interface.

    7. Re:Track an IP? by Plekto · · Score: 1

      This probably will eventually happen.

      "Sorry, until you clean up and police your own users' bad behavior, we cannot allow them access to (country/region)"

      Make the "Great Firewall" a reality and see how fast they comply.

    8. Re:Track an IP? by Anonymous Coward · · Score: 0

      Someone should create a GUI interface using Visual-Basic to track an IP!

      In case people are wondering, it's a reference to this: http://www.youtube.com/watch?v=ygB0ZviqXac

    9. Re:Track an IP? by Anonymous Coward · · Score: 0

      Don't hate! Visual Basic has always been great for creating GUIs. Just there are people who decided to write their code in it too

      Visual Basic is perfectly fine for writing some types of code. If you need to do code that'd be better done in another language that what DLLs are for.

      Data -> VB GUI -> VB CODE -> database -> flat file -> C/C++/FORTRAN DLL -> flat file -> database -> VB GUI

    10. Re:Track an IP? by timeOday · · Score: 4, Insightful

      Wait a minute, you want to ban the world's most populus nation from the Internet until they get rid of botnets? No country on earth has done that. So I don't see how you can attribute the attacks to China. For that matter, we already know there are compromised computers everywhere, so why would somebody originate attacks from their own land? Or am I not giving network forensics enough credit here - can they actually tell where an attack ultimately originates? I doubt it.

    11. Re:Track an IP? by Anonymous Coward · · Score: 1, Insightful

      No they can't. There have been many stories in the news lately about "Chinese hackers", the F-35 espionage, blah blah - all over the place. I don't get it. Isn't public perception of china bad enough? They are basically crawling out of an industrial era, and in the next ten years their economy is going to double. My advice to anyone reading this: drop that functional language you're learning and learn mandarin instead, over a billion people speak it, and there are a ton of online resources to help.

    12. Re:Track an IP? by Anonymous Coward · · Score: 0

      I had to watch that several times -- sort of like sucking air over a chipped tooth. It hurt my head enough that I had to try it again.

    13. Re:Track an IP? by JWSmythe · · Score: 2, Insightful

          No shit.... I cringe every time I see one of these stories. Not only are they stupid, but whoever is giving the statements shouldn't be doing computer forensics. My humble opinion, since I don't work for any of the places reporting this crap, is that they overheard an IT guy saying "Someone in China is trying to get in. That IP belongs to a provider [insert city in China]". I've actually made that mistake. Saying it, not believe it, that is. I see a brute force attempt, and someone asks, "who does that IP belong to?" "oh, it resolves to some place in China." Suddenly it's the Chinese attacking. A 5 second conversation usually takes 30+ minutes to explain, even though it took less than 10 seconds to set a firewall rule against their block by hand.

          I see these "oh my gosh, the Chinese are attacking" attacks every day. Well, not just China. They come from all over the freakin' world. But hey, China is the evil Communist nation bent on destroying the American economy by providing substandard underpriced merchandise. Oh ya, and they have nukes to kill us off when they're done.

          It's "the reds are coming" cold war US vs Soviets game all over again, except this time we have IP's, and we can even see where the block is.

          You know, from my own logs, the Americans are coming too. As are ... well ... just about every country that has a freakin' netblock. But with the population of China, they come in just above the United States, mostly because Americans will eventually take their POS computer to the store and ask why it's going so slow. Or more like they'll buy a second one and a hub, so they can have both online and transfer things from one to the other over the next year or two, and never consider that the "old" one is doing malicious things.

          The biggest ones I notice are brute force attempts against SSH (one of the few services I leave public). Next would be SQL injection attempts via HTTP. whoowhoo, it's obviously a foreign government conspiracy. If they can just crack my little web server, they'll have the secrets to .... well .... not too damned much. Anything interesting is already up on my sites. :)

      --
      Serious? Seriousness is well above my pay grade.
    14. Re:Track an IP? by JWSmythe · · Score: 1

        You know, I've only ever seen a couple episodes of that stupid show, with good reason.

        This just makes me want to cry.

        user@mybox~$ nslookup

      So here's my real world example from just now.  They were actually caught and automagically blocked for spamming, so I don't mind posting their info. :)

      user@mybox~$ nslookup 212.80.95.26
      Server:         x.x.x.x
      Address:        x.x.x.x#53

      ** server can't find 26.95.80.212.in-addr.arpa.: NXDOMAIN

      user@mybox~$ whois 212.80.95.26
      % This is the RIPE Whois query server #2.
      % The objects are in RPSL format.
      %
      % Rights restricted by copyright.
      % See http://www.ripe.net/db/copyright.html

      % Note: This output has been filtered.
      %       To receive output for a database update, use the "-B" flag

      % Information related to '212.80.95.0 - 212.80.95.63'

      inetnum:      212.80.95.0 - 212.80.95.63
      netname:      EL-CHA
      descr:        EL-CHA, s.r.o.
      descr:        Spojovaci 19
      descr:        250 65 Boranovice
      country:      CZ
      admin-c:      TC562-RIPE
      tech-c:       TC562-RIPE
      status:       ASSIGNED PA
      mnt-by:       TRANSGASNET-MNT
      source:       RIPE # Filtered

      person:       Tomas Charvat
      address:      Ivan Charvat, EL-CHA
      address:      Spojovaci 19
      address:      250 65 Boranovice
      address:      Czech Republic
      e-mail:       tc@el-cha.cz
      phone:        +420283981167
      fax-no:       +420241404772
      nic-hdl:      TC562-RIPE
      source:       RIPE # Filtered

      % Information related to '212.80.64.0/19AS29208'

      route:          212.80.64.0/19
      descr:          Dial Telecom, a.s.
      origin:         AS29208
      mnt-by:         TRANSGASNET-MNT
      mnt-by:         DIAL-MNT
      source:         RIPE # Filtered

      Ok, call Tomas at +420283981167, and find out who was on that IP.  Maybe it doesn't look so realistic when I can get you close to the problem child in one line in a shell.  If only I could write in VB, then I could make the GUI, and maybe have it control the trigger on a gun pointed at my own head, so I never have to see any more crap like this ever again.

      --
      Serious? Seriousness is well above my pay grade.
    15. Re:Track an IP? by OrangeTide · · Score: 1

      most of the bots in a botnet are compromised computers in the US. So we should isolate the US from the rest of the world until they can manage to secure their own systems. And until US companies and reduce the number of insecure OS releases they produce.

      --
      “Common sense is not so common.” — Voltaire
    16. Re:Track an IP? by 24-bit+Voxel · · Score: 1

      Yes, but do they do it ... in REAL TIME?!?

    17. Re:Track an IP? by Anonymous Coward · · Score: 0

      Good comeback, JACKASS!

    18. Re:Track an IP? by ThomasCharvat · · Score: 1

      No need to call, I'm right here. What do you want?

      TC

    19. Re:Track an IP? by Ex-MislTech · · Score: 2, Interesting

      Well it is more than Botnets.

      http://www.redorbit.com/news/technology/1661861/cyberspies_hack_computers_in_103_countries/

      Some respected ppl in Canada have seen things
      that make it appears its not as minor as one
      might think.

      To make matters worse counterfeit chips were
      made to put into Cisco gear and used to
      penetrate the pentagon among other places.

      http://it.slashdot.org/article.pl?sid=06/10/24/1819200

      So any one piece looks mildly nefarious, but
      when you dig deeper than what I have here
      you start to see a pattern for concern.

      Just my 2 cents.

      --
      google "32 trillion offshore needs IRS attention"
    20. Re:Track an IP? by theelectron · · Score: 1

      Good points. It is also easy to see what information the hackers are gathering and see who that information is most relevant to, especially when these attacks are as systemic as they are. The US intelligence committee are pretty experienced in the field of intelligence. If they really these actions are coming from Chine, chances are really really good that they are.

    21. Re:Track an IP? by JWSmythe · · Score: 1

          Actually, I'll argue both cases.

          People tend to feel they were personally violated by a widespread matter. I've heard people ask "why would someone want to steal my banking information? I only have $10 in there. I'm poor. Shouldn't they be going after people with money?"

          It's not about the person. It's about what they can get into. More like, it's about how many things can they get into. So a government/political agency/group got malware. It most likely wasn't a specific target, but rather the fact that their security wasn't as good as it should have been, and someone (could have been anyone) got in.

          Say I was Mr. Bad Guy Malware Author (tm). I'd write it. I'd get it out in the wild. If it collected information which was worth something, then it could be sold to interested parties. Are they really going after very specific state secrets that may exist on a handful of machines, or are they going after anything they can, and the worth while bits are being taken advantage of? Probably the later.

          Now, for the Pentagon being infiltrated by counterfeit networking gear, that's another completely conspiracy view. There was no way for the manufacturer in China to know that their counterfeit equipment would go through the supply chains and end up at the Pentagon. Hell, if I sell 100 routers, I don't know where they'll be once FedEx drops them at the destination. The counterfeit equipment is exactly that. It's someone who's figured out how to reproduce an expensive item for much less, and still sell it at the real item's cost (or probably slightly cheaper). They're making a buck. The items were slipped into the regular supply chains. That's not an impossible task to do, and it's really what you'd want to do, to move your counterfeit equipment. Any one of those pieces could have landed in a CCIE test rack, a crappy ISP, a small office selling cut rate widgets, or in this case, the Pentagon. The bigger question would be, why aren't they buying from Cisco directly, rather than through 3rd parties.

          But, was any privileged data released? The secure network should be (ummm) secure. I would assume not only just firewalled off from the real world, but actually physically disconnected. If that was so, how would the evil counterfeiter who snuck their counterfeit wares into the Pentagon, ever get any data back out? Oh ya, they wouldn't.

          The only downside to counterfeit parts is that they may not work as well. But sometimes they do. I've wondered about some of the parts I've bought before. Why does a new $1000 part cost $100, and is brand new? I don't ask. Maybe it was bundled and the bundle was seperated, so I'm just buying the surplus. Maybe it's counterfeit. Maybe it was a stolen shipment. Either way, I'm buying a part, and it works. It's not my job to research their supply lines, and I don't have the authority to do that, nor any power to do anything if I were to find irregularities. It would be like calling CDW up, and demanding they prove that the cut rate laptop that you are about to buy was actually purchased from the manufacturer. Their word isn't enough, you have to see receipts. Really, they'd just hang up on you, or laugh you out the door.

       

      --
      Serious? Seriousness is well above my pay grade.
  2. Why so interested? by Jonah+Bomber · · Score: 3, Funny

    Practice makes perfect.

    1. Re:Why so interested? by snowraver1 · · Score: 1

      I was thinking that knowledge is power. You never know when some piece of information can be useful.

      --
      Copyright 2010. All rights reserved. This comment may not be copied in any way including, but not limited to caching.
    2. Re:Why so interested? by castoridae · · Score: 1

      I don't know if there's anything specific to China, but NYPD has been doing some international "outreach". For example, as per the article below, I think Mumbai is outside of their jurisdiction...

      http://www.newsweek.com/id/182526

    3. Re:Why so interested? by c_forq · · Score: 1

      I wouldn't call this "outreach". It is research, with any aid they give just so they can get access to information they want. New York is a prime target for terrorists, as such it is in their interest to know as much as they can of events in other cities and how to prevent them.

      --
      Computers allow humans to make mistakes at the fastest speeds known, with the possible exception of tequila and handguns
  3. Why? by Locke2005 · · Score: 3, Interesting

    why are the Chinese so interested in the NYPD computer network? Perhaps hey've been watching too much US "Law And Order" style television programming?

    --
    I've abandoned my search for truth; now I'm just looking for some useful delusions.
    1. Re:Why? by clarkkent09 · · Score: 4, Insightful

      Looking at my logs there are 1000s of "attempts to break in" as well, almost all from IPs located in China where apparently most botnet computers are - the botnet masters themselves may or may not be in China. The thing is, the sites are completely free and there is no reason to break in at all. It's just scripts trying out known vulnerabilities on a large numbers of sites. Maybe the same thing is happening with NYPD sites and someone panicked when they saw that it is coming from China.

      --
      Negative moral value of force outweighs the positive value of good intentions.
    2. Re:Why? by offrdbandit · · Score: 1

      Sounds like the making of another Die Hard to me.

    3. Re:Why? by stretch0611 · · Score: 3, Funny

      They are trying to "fix" their parking tickets that their ambassadors have received at the UN.

      --
      Looking for a job?
      Want your resume written professionally?
      DON'T USE TUNAREZ!!!
    4. Re:Why? by Jabbrwokk · · Score: 1

      y1p33 k1 y@y m0t||34fu(k3r

    5. Re:Why? by Anonymous Coward · · Score: 0

      Chances are the bot net masters are the 2600 group memebers in NYC? Just a guess.

    6. Re:Why? by Anonymous Coward · · Score: 2, Interesting

      Pentagon needs an enemy. Now it's chinamen coming through cyberspace. And we get thousands upon thousands of news items like this. All blaming random port scans on chinese with no proof or basis in reality to lay it on them than anybody else.

      More likely it's Pentagon or CIA goons themselves trying to get a defence budget raise through chinese zombie machines they've captured with the help of Microsoft Windows and Cisco.

    7. Re:Why? by Anonymous Coward · · Score: 0

      Don't you watch TV? Ambassadors can traffic drugs and kill people in broad daylight thanks to their immunity :)

    8. Re:Why? by rtb61 · · Score: 1

      Police computer networks can provide lots of useful information. Individuals susceptible to blackmail, individuals susceptible to bribery, access details for known criminals and of course ongoing investigation activities. All autocratic governments are well know for their criminal activities and major organised crime activities in those countries can only exist with the support of corrupt government officials and this extends into overseas operations.

      It would be expected that most countries are now involved in computer network espionage activities and, for the Government of China to so childishly deny that activity just makes them look guiltier and more to the point makes those Chinese Officials who are directly involved in those activities look like they are attempting to further their own private interests at the expense of the Government Of China and the childish 'not me, somebody else did it" are self defeating attempts to hide their own guilt.

      Where it maybe difficult to obtain a criminal conviction there is nothing stopping various police departments and investigation agencies from pursuing civil suits and inflicting major fiscal penalties via another route and of course facilitate a legal opening up of a range possible investigation targets.

      --
      Chaos - everything, everywhere, everywhen
    9. Re:Why? by Anonymous Coward · · Score: 0

      I worked computer backups. Believe me, parking ticket data is super physically protected, so this makes sense. Computer protected - well cops are not the brightest lights out there.
      But why not try the online seized drug trading system, or illegal immigrant work placement systems and bail bond commission systems some police run on the side.

    10. Re:Why? by Anonymous Coward · · Score: 0

      Exactly!
      I have hosts that see thousands, sometimes tens of thousands, of door-rattling events every day. Script-kiddies and bots. Big deal, they're easy to repel. This is not news, except maybe for Fox and Friends trying to fan the "Yellow Menace" flames. Nothing to see here. Move along.

  4. Foreign Ministry Spokesman by Toonol · · Score: 4, Insightful

    I like how the summary quotes the minister Qin Gang as denying any involvement, and then immediately goes on to ask "The obvious question is, why are the Chinese so interested in the NYPD computer network?".

    Hey, I'm sure he's lying too...

    1. Re:Foreign Ministry Spokesman by Sean · · Score: 1

      Maybe they should have asked a chinese guy who actually knows something about computer security instead of asking a PR guy if he's stopped beating his wife yet.

  5. Chinese organized crime? by MacColossus · · Score: 1

    Human trafficking? Drugs? Two obvious ones off the top of my head.

    1. Re:Chinese organized crime? by t33jster · · Score: 2, Interesting

      Human trafficking? Drugs? Two obvious ones off the top of my head.

      Exactly. This isn't necessarily the Chinese government, but perhaps some criminal enterprise that has an ajenda with the NYPD. We know the Great Firewall of China is relatively effective of keeping unwholsome content out of China, but what about the reverse? It is not so inconcevable that there are a bunch of pirated Win2k machines in internet cafes around the country that are members of some huge botnet.

      --
      Take off every 'sig' for great justice.
    2. Re:Chinese organized crime? by pmarini · · Score: 1

      I agree with bugi here, they learned those from the British slave trade and the American drug cartels...
      nothing to see here, moving on...

      --
      Can I put a spell on those who can't spell?
      Your wheels are loose and they're losing their grip, good you're there.
    3. Re:Chinese organized crime? by daveime · · Score: 1

      Or even an agenda ?

      It's not that I'm a grammar nazi as such, but come on ... you usually learn to stop spelling things as they are pronounced when you are six-and-a-half.

  6. They're not... by Thelasko · · Score: 5, Insightful

    The obvious question is, why are the Chinese so interested in the NYPD computer network?

    They're not. The bot herder is probably in New York, and controlling the bots by tunneling so it looks like he/she is in China.

    Haven't you seen the movie Hackers?

    --
    One of our competitors trademarked the term "hypothesis". From now on, we will call them "boneheaded ideas".
    1. Re:They're not... by Red+Flayer · · Score: 4, Funny

      Oh, come one, that's just what they want you to believe.

      It's actually the Chinese pretending to be a New Yorker pretending to be the Chinese business mafia.

      It all comes down to logic. Are they the kind of criminals that would initiate the attacks from someone else's IP address block, or have they deduced that we would see through the ruse and would therefore host the attacks from their own IP address block?

      It appears we have made one of the classic blunders, which is never get involved in a technical war in asia.

      My guess is it's probably someone looking for inside information on investigations of financial companies in New York. That's where there are hundreds of millions to be made.

      --
      "Trolls they were, but filled with the evil will of their master: a fell race..." -- J.R.R. Tolkien on Olog-hai
    2. Re:They're not... by Anonymous Coward · · Score: 0

      Zero Cool? Crashed fifteen hundred and seven computers in one day? Biggest crash in history, front page New York Times August 10th, 1988. I thought you was black man. YO THIS IS ZERO COOL!

      Woah, sorry. Had a flashback to that painfully awful movie.

    3. Re:They're not... by Anonymous Coward · · Score: 0

      My guess is it's probably someone looking for inside information on investigations of financial companies in New York. That's where there are hundreds of millions to be made.

      Or maybe since they're the largest holders of US debt, they're trying to find out where the money went.

    4. Re:They're not... by pmarini · · Score: 1

      the ping roundtrip decay should have given that away...

      --
      Can I put a spell on those who can't spell?
      Your wheels are loose and they're losing their grip, good you're there.
    5. Re:They're not... by Anonymous Coward · · Score: 0

      My guess is it's probably someone looking for inside information on investigations of financial companies in New York. That's where there are hundreds of millions to be made.

      They can skip the NYPD then... all the good stuff is at the Federal Reserve, the NY State Attorney General, and Treasury.

    6. Re:They're not... by Anonymous Coward · · Score: 0

      I've spent the last 10 years building an immunity to Iocane.

  7. the real reason why there were so many by TheGratefulNet · · Score: 4, Funny

    is that once they hacked the computer systems, an hour later they needed to hack it again!

    /sorry

    --

    --
    "It is now safe to switch off your computer."
    1. Re:the real reason why there were so many by Anonymous Coward · · Score: 0

      is that once they hacked the computer systems, an hour later they needed to hack it again!

      Did you hear about the restaurant that served Chinese-German cuisine? An hour after eating there you were hungry for power.

    2. Re:the real reason why there were so many by Anonymous Coward · · Score: 0

      poor execution

    3. Re:the real reason why there were so many by daveime · · Score: 1

      The trick is to bulk up on prawn crackers and fried rice, so there's no way you can finish the beef in oyster sauce in one sitting.

      Actually, you know the irony ? ... I moved from UK to Asia about 12 years ago, and the Chinese food STILL tastes better when served in silver foil containers at 3am in Manchester.

      God I miss pineapple rings in batter with golden syrup ... you simply can't get it here :-(

    4. Re:the real reason why there were so many by ponzio · · Score: 1

      Henny? Is that you?

  8. I just block most countries by rackserverdeals · · Score: 4, Informative

    They should do what I, and others do. Just block all traffic from certain countries.

    With most of my sites, I'm not interested in international traffic and all I get is spammers and content scrapers. I cam across this tip on blocking spammers and scrapers using IPFilter on Solaris and just update my ipf.conf file from time to time if I notice anything strange coming in, which I check from time to time. I also grab lists of ip ranges to add as well.

    While it bothers me a bit to limit access to sites in principle, I really don't get any benefit from international traffic that outweighs the nuisance of the few that ruin it for everyone else.

    --
    Dual Opteron < $600
    1. Re:I just block most countries by Tablizer · · Score: 3, Insightful

      They should do what I, and others do. Just block all traffic from certain countries.

      I imagine they do or could use mostly use zombie PC's within *this* country.
         

    2. Re:I just block most countries by rackserverdeals · · Score: 1

      From the article

      Sources said Internet Protocol addresses of computers attempting to breach the NYPD's files have been tracked to China, the Netherlands and the Ukraine.

      --
      Dual Opteron < $600
    3. Re:I just block most countries by Tablizer · · Score: 1

      Yes, but it's difficult to know if what is at the "end of the chain" is a human or a bot, or if you've really traced it back to the end of the chain. The only way to really know for sure is to peek in the window and see if the commands you see on the sniffer are the same ones the user sittin' at the desk is actually typing/mousing in.

      As an analogy, the Matrix managers may also be in another Matrix which has control over their world and not even know it. One of my fav Trek episodes is when the crew was stuck in the Holodeck and thought they got out, but were really in a different simulation that looked like reality without knowing it. Only strings of subtle clues eventually gave it away, right before they were about to give away some secret to the holo-hacker.

    4. Re:I just block most countries by dave1791 · · Score: 1

      >I'm not interested in international traffic and all I get is spammers and content scrapers.

      Why do I get an urge to do a facepalm? As an American expat who has lived in both Europe and Asia, I have nothing good to say about my experiences with geolocation.

    5. Re:I just block most countries by Anonymous Coward · · Score: 0

      i use a script. it watches my login failures, looks up the offending IP address, then proceeds to block the entire IP address range of the ISP. McColo was blocked in this manner, as well as a number of others. to date i have only had one ISP respond to abuse email, thus i consider it a waste of time to bother informing the ISP. either they don't care or are too incompetent to do anything about it.

    6. Re:I just block most countries by __aajoqa250 · · Score: 1

      Dealing with what appears to be to the best of my knowledge, tcp sockstress attacks on one of my machines initially connecting to the net and the three way handshake receiving 4 syn packs from ip addresses from within china, I can tell you that it would be much more comforting if the large majority of slashdotters where trying to be a little less funny (I would like to see the "funny" moderation eliminated from slashdot because it seems everybody wants to quit their day job) so that some people within this community would realize the significance of these security breaches and the possible implications they have with security around the world and change their priorities to help solve them. Tcp is up against a real threat from people who have known of its vulnerabilities from before the turn of the century. It is the exploit that will at some point in time bring down many critical systems around the world.

      Am I the only one who wonders about the untimely death of Jack C. Louis who was working on the definitive vulnerabilities of the TCP/IP Sockstress?

    7. Re:I just block most countries by Anonymous Coward · · Score: 0

      And I thought Internet is free from fascism.

      *sigh*

      Being Russian I sometimes feel like I'm a natural born criminal. At least that's how I'm treated. I also hate those botnets, but there's nothing I can do about them.

      There are already too many borders on this planet, do you really need to bring them all to Internet?

    8. Re:I just block most countries by Anonymous Coward · · Score: 0

      It's not your fault. Like the man said, it's a few ruining it for everyone else.

      I run a low-traffic forum. For several months after the release of phpBB3 things were fine, but eventually the spammers updated their software. At which point I was getting over a dozen spambots registering a day. To put this in context, I get less than a dozen legitimate registrations a year.

      The vast majority of the spam registrations come from Russian IP addresses, with some Chinese, Ukrainian and, for some reason, German addresses making up most of the rest.

      Dealing with a dozen fake registrations a day, all of which have to be vetted for legitimacy, for a small-scale enthusiast forum... just isn't worth it. Instead I wield a heavy ban-hammer and block entire swaths of Russian (etc) IP ranges.

      It's just a cost-benefit analysis. As long as this crud is coming from there in these volumes, it just isn't worth the time to try and filter the good from the bad. Until your ISPs and colos take this seriously, it's going to be a problem for you. Nothing I can do about it from the US.

  9. Obvious questoin by Spazmania · · Score: 5, Insightful

    The obvious question is, why are the Chinese so interested in the NYPD computer network?

    No, the obvious question is why are the NYPD's computer people so dumb that they're reporting the generic, worm-generated port, web and ssh scans that everybody sees from China and everywhere else as an out-of-the-ordinary hacking attempt?

    --
    Moderating "-1, Disagree" is simple censorship. Have the guts to post your opinion.
    1. Re:Obvious questoin by loftwyr · · Score: 1

      What? Do you mean that the NYPD aren't the most special more sought after police in the world that makes the Chinese so envious that only the NYPD are being attacked?!? how dare you be realistic in the face of terror!

    2. Re:Obvious questoin by Albanach · · Score: 3, Insightful

      This was my first thought too.

      Seriously, if I look at the logs for a couple of servers I can see hundreds of brute force ssh attempts a day. Add to that a scan of the apache logs to see all the attempts there and I could get close to a thousand attempts on a bad day on a single server.

      Now you can possibly ignore the SSH attempts by only having public key logins, and ignore anything in the apache log that relates to IIS, or other web apps you're not actually running.

      If, however, you're looking for a budget increase, it sure sounds good to say you thwart thousands of hacking attempts per day.

      It's a bit like the old days when web page popularity was measured in 'hits' and therefore the site with the most 1 pixel transparent gifs was the de facto winner.

    3. Re:Obvious questoin by wsanders · · Score: 3, Insightful

      Because they can get Homeland Security funding to protect them from the Red Terrorist Menace?

      Really, if you have a server on them big tubes and you're not getting 70,000 login failures a day, you need to improve your page rankings.

      --
      Give a man a fish and you have fed him for today. Teach a man to fish, and he'll say "WHERE'S MY FISH, YOU IDIOT?"
    4. Re:Obvious questoin by fishbowl · · Score: 1

      There is no reason that a NYPD network should even open a socket for a connection originating in Asia. "Hacking attempts" should not even reach the first gateway.

      It's a little more complicated for my network, because we do a lot of business in China and Thailand, but we still are no more vulnerable to port/web/ssh scans than a well-configured Cisco 7300, which is to say "not at all vulnerable, I'll bet your life or stake my reputation on it as long as nobody but me has the enable password."

      --
      -fb Everything not expressly forbidden is now mandatory.
    5. Re:Obvious questoin by Spazmania · · Score: 2, Insightful

      There is no reason that a NYPD network should even open a socket for a connection originating in Asia.

      A Japanese traveler about to visit New York on business decides to check the crime stats at http://www.nyc.gov/html/nypd/html/crime_prevention/crime_statistics.shtml to get a perspective on what to watch out for with respect to crime in New York.

      A US soldier stationed in Korea is about to end his tour of duty and wants to check out the job openings at http://www.nyc.gov/html/nypd/html/careers/careers.shtml

      --
      Moderating "-1, Disagree" is simple censorship. Have the guts to post your opinion.
    6. Re:Obvious questoin by M.+Baranczak · · Score: 1

      A gangster who fled to the Philippines wants to check if he made the NYPD's Most Wanted List: http://a056-crimestoppers.nyc.gov/crimestoppers/public/publicMWGallery.cfm

    7. Re:Obvious questoin by JWSmythe · · Score: 1

          Oh, we have our ways. In the end, most of you will be happy telling us your passwords. the rest of you will be your little parts we cut, burnt, and ripped off to "encourage" you to talk.

          But don't worry, we've started using waterboarding to clean your wounds. Don't mind the fact that it's salt water. Or was that sulfuric acid? Oh, I can never remember, I disavow any knowledge of what the screams are in the next room.

         

      --
      Serious? Seriousness is well above my pay grade.
    8. Re:Obvious questoin by citizenr · · Score: 1

      No, the obvious question is why are the NYPD's computer people so dumb that they're reporting the generic, worm-generated port, web and ssh scans that everybody sees from China and everywhere else as an out-of-the-ordinary hacking attempt?

      thats easy, Clippy^^^^^ZoneAlarm pop-up says they are being hacked, it cant be wrong, can it?

      --
      Who logs in to gdm? Not I, said the duck.
    9. Re:Obvious questoin by Marchday · · Score: 1

      It's absurd to get a conclusion only from the sources of ip address.

    10. Re:Obvious questoin by cuban321 · · Score: 1

      Really, if you have a server on them big tubes and you're not getting 70,000 login failures a day, you need to improve your page rankings.

      Really, if you have a server on them "big tubes" and leave ssh open to the world, you need to keep your day job.

    11. Re:Obvious questoin by fishbowl · · Score: 1

      If either of those web properties is on the same network as critical/confidential police business, it should not be.

      The city of New York can't afford me, so this is all the free IT consulting they're gonna get from me.

      --
      -fb Everything not expressly forbidden is now mandatory.
  10. Yeah that seems REAL LIKELY by phantomcircuit · · Score: 4, Insightful

    Right people in China are attacking the NYPD computer systems.

    That seems way more likely than people in NY using proxies in china.

    1. Re:Yeah that seems REAL LIKELY by khallow · · Score: 1

      Well, China does have their country-wide firewall. Seems a bit chancy to me to hack through that when most of the rest of the world is far less secure.

    2. Re:Yeah that seems REAL LIKELY by DNS-and-BIND · · Score: 1
      How so, exactly? Have there been incidents in the past that anyone can point to? As someone who's lived in the PRC for the last few years, I can tell you it is THE WORST place on the planet for internet connectivity. Seriously, proxying yourself through China is just stupid on its face. I just now loaded the Slashdot front page, and it took 10 seconds to load. That's actually quite good! A long time ago, I got in the habit of loading pages in the background (Opera middle click) and coming back to them later.

      I think the slowness is due to the GFW - I can't believe that a country could have such crappy internet access in this day and age - it must be intentionally slowed or degraded. From here to my box in Texas is around 300ms ping with 3% packet loss, consistently, day after day. Contrast this to sites inside China, which load lightning-fast and have no trouble whatsoever. On the other hand, hacking groups and military have access to special lines which bypass the GFW and aren't slowed down at all.

      So, in conclusion, I'm going to have to see some evidence of people in NYC using proxies in China. Because I think it's about the stupidest idea you could have. You'd do it for about 3 days, then get frustrated with the round-trip speeds and get a new proxy in Romania or something.

      --
      Shutting down free speech with violence isn't fighting fascism. It IS fascism!
    3. Re:Yeah that seems REAL LIKELY by aaaantoine · · Score: 1

      Considering the rate of software piracy in China, and the resulting lack of Windows security updates, why would it be improbable that a large number of Chinese computers have been hijacked by an outside nation? Granted, they could just as easily have been taken over by the Chinese government, but still.

    4. Re:Yeah that seems REAL LIKELY by phantomcircuit · · Score: 1

      The internet connections for government servers are often very fast and ridiculously un-secure.

      Often you'll find Chinese education institutions in public proxy lists.

      And once better nobody in the west is ever going to see the logs from any of those servers, not come hell nor high water.

  11. Shows how vulnerable computer systems are by forgoil · · Score: 2, Insightful

    Time to actually use the US "hackers" to teach important US computer users something about security, and demand more of it from the manufacturers.

    Or start using OpenVMS for all important stuff. That OS is nice:)

    1. Re:Shows how vulnerable computer systems are by paazin · · Score: 1

      Or start using OpenVMS for all important stuff. That OS is nice:)

      Great idea! Cheap hardware, too - just go to your local junkyard and grab a VAX sold 10 years ago for scrap :P

    2. Re:Shows how vulnerable computer systems are by pentalive · · Score: 1

      Or buy a normal machine and run SIMH

      http://simh.trailing-edge.com/

      on it.

    3. Re:Shows how vulnerable computer systems are by Nefarious+Wheel · · Score: 1

      Great idea! Cheap hardware, too - just go to your local junkyard and grab a VAX sold 10 years ago for scrap :P

      You can't have it! Mine, or I will help you not.

      I love DCL, but you know what I miss the most? That KESU architecture. Kernel, Exec, Super, User. The fact that Dave Cutler (architect of VMS and WNT) didn't have the hardware to back that when he developed NT for the Intel processor is, I believe, the ultimate source of the endless Windows server security grief.

      WNT:='F$ROT1("VMS") (yes, I know it's a bogus lexical on your system...=)

      --
      Do not mock my vision of impractical footwear
    4. Re:Shows how vulnerable computer systems are by Anonymous Coward · · Score: 0

      > Time to actually use the US "hackers" to teach important

      Wait. You forgot that they were all outsourced to China. Oh, wait!.

  12. Perhaps it is because of the NYPD's reach by Anonymous Coward · · Score: 0

    I suspect it has more to do with NYPD's lack of reach.

    Like most unaccountable organizations, there is rampant incompetence.

    The Chinese are hacking the NYPD because they can.

  13. The Secret Stash! by tnk1 · · Score: 4, Funny

    The Chinese are trying to find out where the best and tastiest donuts in the NYC area are located.

    Unfortunately for them, I happen to know the information they seek is loaded on an air gapped mainframe in the heart of Police HQ which is guarded by automatic defense systems and can only be accessed by the Chief of Police and Rudy Guiliani.

    Yeah, they forgot to update who the mayor is... this is the police here, not the NSA, okay?

    1. Re:The Secret Stash! by rackserverdeals · · Score: 1

      You really have an outdated, stereotypical view of the NYPD.

      They are very helpful and compassionate and willing to share with the community.

      Go up to any officer and just ask. "I'm jonesing for some fresh donuts, I hear you guys know all the best spots all over the city."

      He (or she) will probably be kind enough to invite you to the station house to share some of their private stash.

      --
      Dual Opteron < $600
    2. Re:The Secret Stash! by Whorhay · · Score: 1

      I've only ever been to NYC once and I was lucky enough to have Amy's Bread recommended to me. I had a couple confections from their, but the best by far was the Cherry Fritter. It's been a few years since I was there and I still haven't eaten anything quite as aswesome. http://www.amysbread.com/

    3. Re:The Secret Stash! by HTH+NE1 · · Score: 1

      You really have an outdated, stereotypical view of the NYPD.

      I can't speak for the GP, but I have been waiting forever for the next Duke Nukem game... oh, wait, they were the LAPD. Nevermind.

      --
      Oh, say does that Star-Spangled Banner entwine / The myrtle of Venus with Bacchus's vine?
  14. Assumed Chinese Government Involvement? by twidarkling · · Score: 1

    It seems rather irresponsible to simply assume "The Chinese" are interested in the NYPD at all. It could just be a few random people, some of which are Chinese. Why assume the government has any knowledge at all? Do people automatically assume a US-based hacker ring has the blessings of the US government? It's probably easier to operate in China currently. With massive population densities in some areas, you can fade in to the background, and with the areas where there's no one, a generator and satcom connection make it a real PITA to find you.

    --
    Canada: The US's more awesome sibling.
  15. 5 chinese guys for every american. by tjstork · · Score: 0

    With 5 Chinese for every American, the Chinese government could theoretically employ 100 million to spy on us, and still have 900 million left over. The question isn't, why would they spy on New York, but, why not just spy on everyone and everything? People have no idea just how much of an impact China is genuinely going to have on the world, or what that country can do. A billion people is an immense resource.

    --
    This is my sig.
  16. WTF??? by Bearhouse · · Score: 3, Insightful

    "The hackers are apparently using a botnet to make up to 5,000 attempts a day at various unsecured portals into the NYPD's files."

    So, can someone explain why NY's finest have "various unsecured portals" which give access to their files?

    Please tell me it's just sloppy editing, (again)...

    I thought that everybody serious these days, (CIA, FBI...) had at least two internet portals - a 'public face' for external users and wannabee hackers and a private one protected by *very* state of the art stuff. Of course, most of the real stuff would be on secure intranet.

    OK, OK, just me being naÃve again...

  17. Like the Chineese can handle the truth!! by arizwebfoot · · Score: 2, Insightful

    "Qin Gang denied involvement in computer espionage."

    . And the Chinese gymnasts in diapers are still 16.

    --
    Beer is proof that God loves us and wants us to be happy.
    1. Re:Like the Chineese can handle the truth!! by Anonymous Coward · · Score: 0

      And the Chinese gymnasts in diapers are still 16.

      Outta my way, idiots; I gotta real scoop:

      Pope declares God to be real!!!!!

    2. Re:Like the Chineese can handle the truth!! by Anonymous Coward · · Score: 0

      Holy shit... +3 Insightful for racism. Where the hell is my +3 Funny for vulgarity?

    3. Re:Like the Chineese can handle the truth!! by Anonymous Coward · · Score: 0

      What do you mean racism, the chinese proclaimed their gymnasts to be 16 when all the records say 14. I thought there was some serious truthful humor in the parent.

  18. It's the Triads! by GPLDAN · · Score: 5, Funny

    It's criminal overlord Mandarin, controlling his gang of Triads from an underground bunker that can only be accessed via secret door in the base of the Statue of Liberty.

    It will take an epic alliance of Tony Stark and Peter Parker to put aside their past differences, fighting over the woman they both loved, and both lost, to put a stop to this criminal masterplot to end the world as we know it.

    Starring: Jackie Chan as the Mandarin
    Zac Efron as Peter Parker
    and Robert Downey Jr. returns as Tony Stark.

    1. Re:It's the Triads! by Red+Flayer · · Score: 1

      No, no, Jackie Chan can't be the Mandarin. He's got to be a quirky good guy, maybe we can fit him in. And Zac Efron? Puh-lease...

      Revised cast list:

      The Mandarin: Chow Yun-Fat
      Peter Parker: Jake Gyllenhaal
      Mary Jane (option 1): Maggie Gyllenhaal (for some Luke-Leia weirdness)
      Mary Jane (option 2): the cross-dressed resurrected corpse of Heath Ledger for some Brokeback Mandarin action
      Tony Stark: Robert Downey Jr, but in his most drug-addled condition.
      Jim Rhodes: Jackie Chan in blackface

      Only then would we give the Triads true justice.

      --
      "Trolls they were, but filled with the evil will of their master: a fell race..." -- J.R.R. Tolkien on Olog-hai
    2. Re:It's the Triads! by daveime · · Score: 1

      Nah, gotta be Jet Li ... even his smile is sinister as fuck !

    3. Re:It's the Triads! by adavies42 · · Score: 1

      the important thing is fitting lucy liu in somehow

      --
      Media that can be recorded and distributed can be recorded and distributed.
      -kfg
    4. Re:It's the Triads! by daveime · · Score: 1

      the important thing is fitting inside lucy liu somehow

      There, fixed that for you !

    5. Re:It's the Triads! by Anonymous Coward · · Score: 0

      Dude, I so can't wait to get tix for that, but IFF Scarlet Johansen plays the lost love...

  19. NY SHield by josephtd · · Score: 1

    Go check out the NY Shield threat warning/reporting program.

  20. That's so cute! by jtownatpunk.net · · Score: 5, Interesting

    Awwww. The NYPD thinks they're special. :rolleyes:

    I must be special, too, because I log tons of probes. Hundreds, sometimes thousands a day.

    1. Re:That's so cute! by mcrbids · · Score: 3, Informative

      I must be special, too, because I log tons of probes. Hundreds, sometimes thousands a day.

      That was my first thought, too. I got so sick of looking at the log entries for my faux SSH daemon (on port 22) that I quit logging it. Sure, it's fun for a while, 'till you realize that you aren't frustrating anybody, just occupying 0.02% of cpu time on a hacked bot.

      Hundreds/thousands of "hack attempts" per day when you include obvious overrun attempts (8k of "xxxxx" in the apache logs) attempts at accessing Windows sharing (connections to ports 137-139) dictionary hacks on port 22, (none of my stuff allows passwords anyway, and don't work on port 22) and so on.

      Yawn. Welcome to the wild, wooly Intarnets!

      --
      I have no problem with your religion until you decide it's reason to deprive others of the truth.
    2. Re:That's so cute! by Sycraft-fu · · Score: 1

      Ya no shit. The number of scan bots out there is staggering, and they are very tenacious. They don't seem to have checks to say "This system isn't vulnerable, leave it alone."

      For example I host some servers on my home connection, since I have a nice business class line. One of my friends had a server there that had a broken mail server. Basically he'd been messing with some mail filtering tool, don't remember what, and decided to stop playing with it. The end result was port 25 was open, but wouldn't do anything. If you connected to it you just got an error and got disconnected. You couldn't send any mail, since there wasn't actually an SMTP server there.

      However, some spam bots found it and once they did, they never quit. There were 6 IPs, all from China, that would hammer that port all day and night. They probably tried about 5-6 times per hour each. I found out about this when I was playing with my network firewall and was looking at logging. Port 25 was filtered, of course, since the server wasn't using it and I was using default deny rules. Despite the filtering, they never stopped. This was apparently now in their "Open relay IP," and they weren't going to quit. They are probably still hammering it to this day, I dunno I've changed ISPs since then.

    3. Re:That's so cute! by Anonymous Coward · · Score: 0

      Wow, you must be sore with that many probes. How's the prison food?

    4. Re:That's so cute! by Anonymous Coward · · Score: 0

      That sounds like a lot of gang-probing.

      Was it done by aliens when you and your neighbor accidentally got married in Las Vegas?

  21. the NYPD ain't special by Lord+Ender · · Score: 5, Insightful

    Any company with ssh or, really, any common password-protection scheme exposed to the net is going to see thousands of brute-force attempts per day. The majority of the botnet may be in China or Eastern Europe, but that does not indicate that the actual hackers are either Chinese or Russian. It just means those countries have crap IT security overall.

    There is nothing special to see here. The NYPD is inflating its importance, probably for more funding.

    --
    A slashdotter who didn't build his own computer is like a Jedi who didn't build his own lightsaber.
    1. Re:the NYPD ain't special by Anonymous Coward · · Score: 0

      Unless you're looking for donut eating, double parking or evidence planting techniques ...

    2. Re:the NYPD ain't special by Anonymous Coward · · Score: 0

      NYPD Pointy-Haired Boss: "The economy is in a slump so we have to cut back your budget."

      NYPD IT: "Cut our funding? You can't do that!"

      NYPD PHB: "Why not?"

      NYPD IT: "Uhm... Well... Oh yeah, the Chinese! Chinese hackers are trying to hack our network!"

      NYPD PHB: "Really?"

      NYPD IT: "Yeah. Just look at all these attempted connections from Chinese computers!"

      NYPD PHB: "Wow, that is a lot! We should warn people about this!"

  22. Why? by whathappenedtomonday · · Score: 3, Interesting

    Just a wild guess.
    Who trusts IPs, though?

    --
    I hope I didn't brain my damage.
  23. Just drop China by DnemoniX · · Score: 2, Insightful

    If I were the IT Director for the NYPD I would be hard pressed not to just drop all traffic from China. Or for that matter half a dozen other popular sources of malicious activity. If you really must have the website for the NYPD open to these other countries then put it on a standalone network segregated from anything important. I mean duh...

  24. NYPD has well known staples in their system by Anonymous Coward · · Score: 0

    IT's to hold all the tubes together, so when the files go throuugh they don't fall out and hit you on the noggin'.

  25. Secret Chinese government DOS technique by Dishwasha · · Score: 1

    Post a web link to http://www.nyc.gov/ and hope that 0.0000526% of your citizens click on it.

  26. System tracing by oldhack · · Score: 3, Insightful

    Serious question. How concrete are the info on these cyber warfare news? It seems almost always Chinese or Russian being reported as the perps, followed by posts claiming we* do the same to them, etc. With botnet and other multiple indirections involved, how credible are the tracing info?

    * "We" as in the most baddest, most awesomest country in the world. I won't insult your intelligence with further elaboration.

    --
    Fuck systemd. Fuck Redhat. Fuck Soylent, too. Wait, scratch the last one.
    1. Re:System tracing by jofny · · Score: 2, Insightful

      They're not credible. None of these reports has any concrete evidence as to who, what, where, why, or even always how. Mostly they get the "when" :) But even then, not always.

      The attribution in these articles is like saying because someone made a threatening call to you from a payphone in chicago that the city of chicago was threatening you specifically. It COULD be, but it could also be someone who lives there but is just a guy with no affiliation with the city. It could also be someone who doesn't live there but is passing through. They could also be rerouting the call. And whichever of those actors it might be may be targeting you specifically, or they could just be randomly dialing numbers.

      It's dumb FUD spreading.

    2. Re:System tracing by jofny · · Score: 1

      I have to add: I'm not saying bad stuff isn't happening - it is and has been. Just the attribution to state actors is ridiculous speculation.

    3. Re:System tracing by Anonymous Coward · · Score: 0

      Have you heard of operation Titan Rain? It may be speculation sometimes...but not always. Unfortunately, any attempt to actually gather such intelligence legitimately is automatically....
          1) unlawful
          2) classified beyond public discussion if it was lawful

      By definition, you could never trace such an op back to china...if you did, you'd have to be admitting to backhacking...

  27. plausible deniability by bugi · · Score: 0

    plausible deniability

    They took master lessons from the last US President's administration.

    1. Re:plausible deniability by John+Hasler · · Score: 1

      > They took master lessons from the last US President's administration.

      That's odd. I thought they were fairly good at it.

      --
      Warning: this article may contain humor, sarcasm, parody, and perhaps even irony. Read at your own risk.
    2. Re:plausible deniability by bugi · · Score: 1

      You're right. Bush's administration had such a soft target in the senate and house at that time, that the tremendous success they enjoyed can't be counted as them being good at it.

    3. Re:plausible deniability by Shakrai · · Score: 0, Offtopic

      Guantanamo stays open... Hey, you got a Bush Third Term after all!

      Umm, I haven't been known as Obama's biggest fan of late but this remark is simply unfair. Gitmo is going to be closed. What's your problem? The fact that it isn't being closed overnight? What do you do with everybody who is there? Release them all? Bring them all to the US? Or do you take the time to make a careful review of those being held there, rather than imposing one blanket solution on everybody just so you can close the facility faster?

      --
      I want peace on earth and goodwill toward man.
      We are the United States Government! We don't do that sort of thing.
    4. Re:plausible deniability by Anonymous Coward · · Score: 0, Offtopic

      Sadly you're wrong. I happen to be one of those people that believes Bush did everything he could to keep us safe, that Gitmo was a good thing, and that water boarding fuckers that want to blow up our buildings is a good thing too. Unfortunately, the current administration thinks that we're just gonna love on all our enemies and they'll just sit down with us a break out into kumbiya. He doesn't seem to understand that no matter how much you help some people they are going to spit in your face because of who they've made you up to be in their own minds. The president of Iran doesn't seem to really think much of Obama. Neither does Russia, or even Chavez (although he'll smile, shake hands, and give him a book on the benefits of being a leftist asshat to promote his own agenda). Bush did overlook a whole host of domestic issues, and that pisses me off, but then he was dealing with a bunch of foreign morons loosely organized and hell bent on causing death and destruction.

      No this is not Bush's 3rd term. It's going to be far worse.

    5. Re:plausible deniability by Anonymous Coward · · Score: 0

      The fact that you think it will be worse only makes me feel better about the situation. Thanks!

      "Terrorism" is the new Cold War. The govenrment always needs people like you to believe you are being kept safe by them. There have always been people who disagree with our principles and vice versa. The more fanatical both sides get, the worse it gets. Let me guess - it is your belief that all radical muslims be killed. Explain to me how that is ANY different that what they believe?? Hint - if the only reason you can come up with is "Because we are right", you don't have a compelling reason.

    6. Re:plausible deniability by The+Master+Control+P · · Score: 1

      Finding places to put a few hundred people from one prison versus America's five decade military, economic and social entanglement in the Middle East: Bullshit equivocation is bullshit.

    7. Re:plausible deniability by Anonymous Coward · · Score: 0

      Sadly you're wrong. I happen to be one of those people that believes Bush did everything he could to keep us safe, that Gitmo was a good thing, and that water boarding fuckers that want to blow up our buildings is a good thing too.

      Well, I believe in the constitution.. it's a shame Bush never apparently read and/or comprehended it. I'd throw you in with that lot as well.

      No this is not Bush's 3rd term. It's going to be far worse.

      Nah, it's going to hurt.. but it's only going to hurt because we're cleaning up the messes that people like you made.

  28. brute force attempts *yawn* by oneiros27 · · Score: 1

    I've gotten a hell of a lot more than that in a single day. Coming from a botnet, so rate limiting by IP didn't work. They tried about 5 times per common english name as a login in mostly alphabetical order, hitting machines that had SSH open to the world.

    It used to happen every couple of weeks, with thousands of attempts per machine. They'd probably still be trying if the security folks hadn't decided to outlaw us being so promiscuous.

    --
    Build it, and they will come^Hplain.
  29. Mafia? by Anonymous Coward · · Score: 2, Insightful

    I'd think NY mafia would be more interested in this activity.

    1. Re:Mafia? by grumpyman · · Score: 1

      Ah... they outsourced the Chinese hackers to do it, just like WoW.

  30. Oh noeS! They hacked dotslash!!! by Anonymous Coward · · Score: 0

    I see broken links and summaries... it must be hackers. It couldn't be the editors.

  31. Re:The Real Reason? by Icegryphon · · Score: 1

    Don't knock my chinese coder, he does alot of good work.
    Now if I could just figure out why I my credit card keep having KFC purchases on it.

  32. Has anyone else gotten this error? by Hurricane78 · · Score: 2

    To me, the summary looks like this:

    "A network of hackers, most based in China, a href="http://www.nydailynews.com/news/2009/04/22/2009-04-22_international_hackers_lauching

    I really, really, really Wondered, how this went trough all of the firehose, the Slashdot "editors" and everything... Maybe all people at /., are already dead and replaced by very small shell scripts. And the comment submitters are programs too... ...because, that would explain A LOT!

    (Oh, and the preview is broken too. The layout has huge free space in them, and the line breaks are missing.)

    --
    Any sufficiently advanced intelligence is indistinguishable from stupidity.
    1. Re:Has anyone else gotten this error? by drinkypoo · · Score: 1

      I really, really, really Wondered, how this went trough all of the firehose, the Slashdot "editors" and everything...

      Yes, the firehose is quite a trough. I personally just figured that the hackers tried to take the story down, but only managed to fuck up the summary. YOU CAN'T STOP SLASHDOT, BABY. Let's show them who's boss, and slashdot China.

      But anyway, you put "editors" in "quotation marks" so "obviously" you "get it".

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    2. Re:Has anyone else gotten this error? by Anonymous Coward · · Score: 0

      There was a proper summary earlier when the story first posted, and then I come back to see it in the current state. Must be chinese hackers trying to cover up the story...

  33. wouldn't be nice if... by Anonymous Coward · · Score: 1, Insightful

    there was a way to monetize the incoming traffic from zombies and autoprobes?
    lol

  34. I don't know that I'd block based on country by Sycraft-fu · · Score: 4, Insightful

    Just based on ISP. Some ISPs are just massive trouble spots. They don't care what their users do and don't respond to complaints. Now, that will mean blocking some countries, like China, since their state ISP is a problem spot.

    I really think that we need to start just shutting off people who won't play nice on the Internet. I'm not talking demanding perfection, but there are massive differences in ISPs. I work for an ISP, effectively, working for a large university. When we receive a complaint about a computer doing bad shit, the appropriate person gets notified and if the problem isn't cleared up, the connection is shut down. We also take some proactive steps to watch the network and see if someone is doing something bad. That's all I'm asking for is ISPs that will respond when they get contacted by someone saying "Hey you've got a system doing bad shit."

    However many providers don't. You contact them and they ignore you, or lie. The Chinese ISP is one of the liars. They say "That IP isn't ours," even though APNIC shows it is, to any complaint.

    So we need to just start blocking these people. If enough sites/networks do that, well then maybe they'll start playing well with others.

    1. Re:I don't know that I'd block based on country by rackserverdeals · · Score: 1

      I was getting bad activity from a server with ServerBeach. I used their abuse email to send them my logs of the activity and they were very responsive and took the server offline. They kept me informed, without giving me personal information about who was running the server. Others seem to have had similar experieces with them.

      Other places, like ThePlanet, I don't even bother reporting stuff anymore. Nothing happens. I just check ARIN to see if they added any more ip address blocks that I might need to block.

      --
      Dual Opteron < $600
  35. Looks like they got /. by Dynamoo · · Score: 1

    Looks like they got /. judging by the broken A HREF tag. Did yah use use Preview Button? Did yah? Did yah?!

    --
    Never email donotemail@WeAreSpammers.com
  36. Mod Parent Informative by mpapet · · Score: 1

    Parent is 100% right. This is a non-story.

    Anyone who goes to the trouble of checking their logs for nearly all Internet-facing services would be very, very familiar with this.

    --
    http://www.maxineudall.com/2010/02/should-economists-be-sued-for-malpractice.html
  37. easy to fix by teknosapien · · Score: 1

    route add 222.32.0.0/11 127.0.0.1

    --
    no matter how good it is, it is human nature always wants to make things better
  38. Karlan by Anonymous Coward · · Score: 0

    Anyone who has set up any technology common technology, SSH, HTTP, SQL, Finger ;), HTTP/HTML services such as Wordpress, phpBB, whatever know that you will receive thousands of requests from thousands of bots. Regardless of being a young student or a government organization.... Spam/exploits are sent out in just about every Network Layer and protocol... making it hard to see which are valid requests, bruteforce attempts, exploits, and simple mistakes from humans, bots, or combination thereof.

    That being said, malicious traffic specific to NYPD only will most like blur in with all the
    botnets which already bombard you in your every
    day life. Using a distributed network one could
    (1) set a artificial standard of normal network
            level of spam at any given network layer.
    (2) Queue out distributed packets always from
              a unique machine which are directed to
              the machine your attacking.

    My conclusion, if you care or not, you got this far; Its most likely a botnet, but by comparing traffic trends to other departments through out united states you could most likely tell if it
    is specific to NYPD. who know it could be some chinese dude got locked up, or chinese interest in New York because its such a diverse international city..... ..... Hey this is a good sourceforge idea

  39. It's not a fear thing... by tjstork · · Score: 1

    You can mod this down. But its not a fear thing, its an awe thing. I mean seriously, look at how much more the USA can do than a European nation, and that is how much more the Chinese should be able to do. It's just an awesome thing.

    --
    This is my sig.
  40. Re:The Real Reason? by Red+Flayer · · Score: 2

    Because Korporate AmeriKa hasn't offshored ALL the jobs to China yet

    KAK ALL?

    What exactly are you trying to spell? I don't understand.

    Oh... you're trying to make a reference that corporate America is like the Soviet Union. Which makes absolutely no sense. If you're going to use the Russki "K" reference, at least make sure that it's in reference to some kind of fascism, otherwise it's just plain out of context.

    Geez.
    Let me give you a hint: if you want to troll, at least be a *good* troll. You know, add something to the slashdot experience, instead of making no sense. You've been on slashdot long enough that you should have graduated past simple trolls like that. Why not challenge yourself to be the best troll you can be?

    Maybe one day you may just find that you've had an original thought.

    --
    "Trolls they were, but filled with the evil will of their master: a fell race..." -- J.R.R. Tolkien on Olog-hai
  41. Marketing Opportunity by AlHunt · · Score: 1

    >have been making up to 70,000 attempts a day

    Myself, I set up a targeted marketing campaign and feed them 70,000 ads a day.

    --
    1 in 4 Maine children in struggle with hunger.
  42. Really? by sillivalley · · Score: 1

    Really? Are they being targeted, or are they seeing the same crap everyone else does?

    I track probes coming into my home router. I usually see hundreds of probes per day with IP addresses in China banging on the usual ports (7212, 9090, 1026, 1027) as well as the ports do jour (55657). Some of these Chinese IP addresses I've been seeing for a year or more. Go to a site like http:..isc.sans.org/ and look at the stats for the 221.208.x.x block. 221.192.x.x seems to be popular these days as well.

    Depending on what kind of outward facing net presence they have, 70k probes per day doesn't seem to be out of the ordinary based on the usual network scanning that goes on.

  43. The Great Firewall of China by Nom+du+Keyboard · · Score: 1

    Given the Great Firewall of China and their survelance of all Internet traffic, Chinese denials of these hacking attempts ring hollow.

    --
    "It's the height of ridiculousness to say for those 9 lines you get hundreds of millions."
    1. Re:The Great Firewall of China by Culture20 · · Score: 1

      Given the Great Firewall of China and their survelance of all Internet traffic, Chinese denials of these hacking attempts ring hollow.

      The Great Firewall of China doesn't keep out the packets of the Mongol Hordes, it keeps the packets of the Chinese citizens _in_ (but only on port 80).

  44. They are thinking ov visiting NYC by Anonymous Coward · · Score: 0

    And want to know where to buy the best doughnuts.

  45. Don't fell so special by luizd · · Score: 1

    "why are the Chinese so interested in the NYPD computer network?" It is not specific to NYPD. They even try to crack my home computer! It's more like a broadcast attack.

  46. International area? by cstdenis · · Score: 2, Interesting

    Kelly suggested that 'perhaps it is because of the NYPD's reach into the international arena' that they are being targeted for computer hacking

    WTF is the NYPD reaching into the international arena? That's not their job. They shouldn't be doing anything outside of NY.

    --
    1984 was not supposed to be an instruction manual.
    1. Re:International area? by nycguy · · Score: 2, Insightful

      I don't know, genius, but maybe the fact that UN headquarters and a ton of foreign consulates are in NYC has something to do with it. How about hacking to get the itineraries and NYPD protection details for foreign heads of state and other dignitaries? What about getting the plans for coordinating with federal and state agencies in the event of a terrorist attack or other emergency? So maybe it's the international arena reaching into NYC, but either way the NYPD doesn't have to do anything outside of NYC to have international implications.

    2. Re:International area? by Anonymous Coward · · Score: 0

      I work for DIA.

      After 9/11...the commissioner for NYPD created a CT (counterterrorism) bureau. Within that, they had a 10-15 man intelligence unit. That grew to ~30 full time analysts. They have permanent liasions from FBI, the CIA's NCTC, my office (DCHC) and Homeland.

      The intel unit is now a completely separate entity. They like to hire narcs and retired MI types.

      Now, I'm not against the true intent here - to circumvent rules about domestic intel collection. But: that IS the intention.

      I think Slashdot types should understand that's
      a) why it was created, with DOJ blessing
      b) why it's still around
      c) they're not doing anything "illegal" because they are city cops, who in this unit intentionally hire ex-military and ex-intelligence community bodies with high pay ($80K+)to get the training and capability they need

      CIA, et al (DIA included) typically have a lot of hurdles to jump through to gather intelligence domestically. Ask for this, beg for that; pretty please mother may I. Plus, the local/state cops are rarely helpful.

      In this case, NYPD gathers it's own intel, and if something really "suspicious" pops up, or they stumble upon a cell, for example, they turn to the FBI National Security Division or NCTC and say:

      "Hey...check this out."

      They are very professional. More than likely, the attackers are probing the unclassified systems for gateways to the SIPR/JWICS side. NYPD has a SCIF and access to classified networks, so they can see stuff from the NCTC/FBI. The Chinese are after that data.

  47. fixing traffic tickets for their UN diplomats by swschrad · · Score: 1

    that's what the Chinese are up to, ya sure ya betcha then. Sven.

    doesn't NYPD patrol the docks? sounds like China wants their lead and mercury exports to look like baby toys and prime beef.

    --
    if this is supposed to be a new economy, how come they still want my old fashioned money?
  48. All your.... by purpleraison · · Score: 1

    All you base are belong to us!!

    --
    I am open source, and Linux baby!
  49. I am a target too!! by Anonymous Coward · · Score: 0

    Just checked my auth.log and appears that many of the "hack in attempts" are from Chinese domains. Never knew I was interesting to the Chinese "hacker spies"!

    I am sure a small company with a handful of public IP addresses is also getting thousands of such attempts. Way to blowup a routine script kiddie attempts, NYPD!

  50. The Nigerians are looking for the gold by oDDmON+oUT · · Score: 1

    They read about it on the Interwebs, and co-opted their spam partners to do the dirty work.

    Really. Scouts honor.

    --
    Some days it's just not worth
    chewing through my restraints.
  51. Preparation for invasion by Anonymous Coward · · Score: 0

    They are trying to break in to get information on who has access to guns when they invade the united states. knowing the complete make up of the law enforcement structure allows them to integrate the system once their successful invasion occurs and where there would be secondary. Also there could be dumb folks in the department who have access to federal systems. Snooping the less resourced NYPD to access other federal law enforcement resources is easier than trying to blow through some government network.

  52. If the IP is from China then it's Chinese hacker by Anonymous Coward · · Score: 0

    But if the IP is from USA, it's from a botnet controlled by Chinese IP

  53. YHBT by drinkypoo · · Score: 0, Offtopic

    Nobody really cares about gitmo, there's at least a dozen secret U.S. prisons just like gitmo only not internationally infamous.

    Get back to me when the US (or any nation) eliminates all its secret prisons. Then explain to me why you believe 'em.

    --
    "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
  54. Nothing new... by Zarluk · · Score: 1
    One other obvious question might be why is NYPD so interesting in a "China connection"?

    Election time for The Mighty Giuliani (or one of he's pupils, perhaps)?

    Before I switch the default port of ssh to other less obvious I was getting a (failed) login attempt every second... most of them from China, yes. But that gives a ratio of 86400 attemps per day per computer!

    My first approach was to block the whole subnet of the attacker(s). Two weeks later I gave up and switched the ssh port ;-)

    Well... as my computer, certainly, is not in the the list of political hackers, as is a private one and I don't work for the (any) govern, but... I have a fix IP :)

    That might mean that they have a Linux server directly connected to the Internet through the default port.

  55. No it just means by Anonymous Coward · · Score: 0

    that the majority of china and eastern europe use unpatchable pirated micro$oft products! easy botnet targets ... yes no?

    1. Re:No it just means by Lord+Ender · · Score: 1

      I have no doubt that's part of it. If I made $0.75/hr I could not afford a retail copy of Vista, so I would pirate. But I wouldn't visit their update site, cause their "genuine advantage" crap might lock me out of my system. Result: tons of unpatched systems in the third world.

      Microsoft feeds the botnet operators with their policies.

      --
      A slashdotter who didn't build his own computer is like a Jedi who didn't build his own lightsaber.
  56. Its Obvious by Mr.+Lwanga · · Score: 1

    They need access to NYPD personnel records to find the only one who can stop their plans.

    John McClane has an unlisted number.

  57. what about that other trapped in a computer movie? by imhennessy · · Score: 2, Informative

    The Thirteenth Floor.

    Here's an experiment Hollywood does every year:

    make the same movie twice, then see which version the public loves.

    It came out at the same time as the Matrix, but was a lot more interesting, but with fewer really awesome fights.

    --
    Like to brew? Want to talk about it? Brattlebrew: groups.yahoo.com/group/brattlebrew
  58. Quick! Call Jack Bauer! by Zhe+Mappel · · Score: 1
    Kelly suggested that 'perhaps it is because of the NYPD's reach into the international arena' that they are being targeted for computer hacking 'in much the way the Pentagon has been.'

    OK, let's address this calmly. Who has to be tortured to make things right here?

  59. Revenge by darth+dickinson · · Score: 1

    They're still pissed about Jack Bauer raiding the Consulate and killing their Consul.

  60. Re:what about that other trapped in a computer mov by rackserverdeals · · Score: 1

    make the same movie twice,

    Put a superstar and other known actors in one, and a bunch of guys people would say "hey isn't that the guy from that thing?" in the other

    then see which version the public loves.

    --
    Dual Opteron < $600
  61. TOR ? by daveime · · Score: 1

    The other day I saw a comment in an article that said most TOR exit nodes seem to come out in China. Now we see "most hack attempts come from China" ... well duh ...

    Any unsecure proxy is going to get spidered in 24 hours, and then it'll be the source of all attacks until such time as the server admin realises and shuts it down.

    IP addresses are a useless guide to *who* is actually using the connection, regardless of the country it is located in.

    1. Re:TOR ? by TheCarp · · Score: 1

      Of course the scary part about that is.... well... why so many tor exit nodes in china?

      If you control enough exit nodes, some attacks start to become pretty simple, especially given that default tor setups don't really enforce any sort of control over where entry and exit nodes are. A "bad guy" running rogue nodes isn't going to list his node family, so whats to stop your client from picking one of his nodes for entry, and one for exit?

      Of course, if you keep a local list of allowed entry nodes, that could help, but... most tor clients are just wide open and at best select nodes that are "registered". All a person would really need is one unique email address per node to register with.

      I hope its because there are so many people in china, that there are enough people who care about privacy and run nodes. However, its entirely possible this is also an attack on tor. Though, whose to say the NSA doesn't run half the US nodes?

      -Steve

      --
      "I opened my eyes, and everything went dark again"
  62. Just remember by starblazer · · Score: 1

    take out their barracks and mow down the field of those little bastards next to it.

    "Nobody will know that their money is missing!"

  63. New Slogon for Department of Defense by microbee · · Score: 1

    Closed Gates, Open Windows!

    You know it's bad when its secretary has a name "Gates"...

  64. Take the easy out... by Phizzle · · Score: 1

    Ban China! Maybe they don't know about proxies! Wait, what if they do?! Wait, if they knew about proxies, then attacks would not be coming from China! Unless, they knew about proxies, and they knew that NYPD knew that they knew, so NYPD would think that there is no way in hell Chinese hackers would not mask their trail from China and they didn't use proxies at all! Bugger... OK so ban China, oh and ban Canada too, I think they know about proxies also.

    --
    I will not be pushed, filed, stamped, indexed, briefed, debriefed or numbered. My life is my own.
  65. So do I by digitalgimpus · · Score: 1

    I'm starting to think these reports are just agencies who want to feel special. Is getting your ports probed anything special? My home network constantly has traffic from viruses and bots trying to propagate over the internet. Servers constantly having some script kiddie trying to get in via ssh. Does that mean I (and every other /. member) is as important as the DoD and NYPD?

  66. Pen Testing by Anonymous Coward · · Score: 0

    They're just testing the system to see what holes they need to patch, as they own most of the NYC anyway.

  67. Re:what about that other trapped in a computer mov by adavies42 · · Score: 1
    --
    Media that can be recorded and distributed can be recorded and distributed.
    -kfg
  68. The NYPD might do something about it. by Animats · · Score: 1

    The NYPD might be able to do something about this. They have a sizable anti-terrorism operation, over a thousand people. David Cohen, the NYPD's Deputy Commissioner for Intelligence, used to head Clandestine Services at the CIA. Sooner or later, many of the world's conflicts spill over into New York City, and the NYPD has to deal with it. So the NYPD has more capability to deal with external threats than most departments. They're also bigger than the FBI.

    The NYPD is well-connected with infrastructure organizations. They're generally thought of as better organized than U.S. Homeland Security in that area. Homeland Security tends to be political. The NYPD, for better or for worse, is just cops. They also have a large number of people with good connections outside the US and good foreign language skills. The NYPD has liaison officers with key police departments around the the world, and they're willing to put somebody on a plane to go somewhere when necessary.

    Most computer intrusions, once the attacker has been localized, yield to ordinary cop work. Now the attackers have the full attention of the NYPD.

  69. Kind of a misleading statistic by SkOink · · Score: 1

    I have a bone to pick with the phrasing of this and other articles like it.

    When people first read it, they go ZOMFG 70000 WTF, which is clearly the article's intent. However, it's not like there are 70,000 Chinese people sitting in a room all trying to hack the gibson or whatever. I'd bet this is the work of maybe 10 people at the very most. Another thing to keep in mind is that a login 'attempt' is not really a very big deal in of itself. It's much more accurate to say there is one attempt to hack into the network, and the method being used is brute force.

    --
    ---- I'll take you in a Hunt deathmatch any day.
    1. Re:Kind of a misleading statistic by tedgyz · · Score: 1

      Duh! It's a botnet. Nobody is saying there are 70K Chinese people doing this.

      And YES, every login attempt is serious. Especially if they are using methodical attacks. It's not like they are trying to login as c00ldude 70K times. They are trying 70K possibilities, which eventually might find a match.

      --
      "No matter where you go, there you are." -- Buckaroo Banzai
  70. I feel the pain by tedgyz · · Score: 1

    We have spent the last 2 weeks fending off Chinese hackers. They started with a legit login, extracting valuable data from our subscription-only site. Once we locked that down, the attacks started with methodical login attempts. We've blocked IPs, but they have jumped around, apparently using a botnet.

    Thanks to the prevalence of stolen Microsoft operating systems in China, unpatched copies of windows abound, leaving them open to botnet slavery.

    --
    "No matter where you go, there you are." -- Buckaroo Banzai
  71. Only 70,000??? by Anonymous Coward · · Score: 0

    I used to get more attempted logins from .cn addresses than that every day when I set up a linux based email server for my church. What was hilarious was seeing the log files where they tried to log into the Windoze "guest" account on a Linux server. This "Chinese boogie man is out to get us" cr@p is wearing really thin....

  72. Not very wise of the Chinese by boulat · · Score: 0

    The NYPD's computers are so old, any attempt to flood the machine will result in an immediate segfault and a BSOD.

  73. Crash Override called... by sydbarrett74 · · Score: 1

    ...he wants his handle back.

    --
    'He who has to break a thing to find out what it is, has left the path of wisdom.' -- Gandalf to Saruman
  74. Chinese Liars by wshwe · · Score: 1

    I think it's the Chinese government that are lying.

  75. Red China's Goal: F*ck The World by zunipus · · Score: 1

    Major DUH factor that the China foreign ministry LIED: 'Some people outside of China are bent on fabricating lies of so-called Chinese computer spies.'

    The paid hacker arm of the Chinese government, called "The Red Hacker Alliance" has been documented since 1998.

    The fact that Red China declared 'Technological War' on the USA has been known for years.

    And Red China still has US 'Most Favored Nation' status because why? Are we out of our minds?!

  76. Great business model by LostMyBeaver · · Score: 1

    if you can find a way into the NYPD network, I'm sure you also have at least limited access to police radio, warrants as they're issued, patrol car locations, officer records (including where their families live) and even FBI databases. Thanks to Guilliani making the NYPD one of the biggest police departments in history, there are SO many computers that intrusion detection would be difficult on that scale. NYPD is probably the best target in the U.S. for access to records all over the place.

    An organized crime group located in NY would be able to strengthen their defenses against the NYPD 100 fold easily if they had this kind of access.

    So, if you were a hacker able to build a botnet by targeting PCs on an international scale, produce a series of backdoors in the NYPD network and obtain this information, then you could sell these services for millions and move to a sunny island somewhere.

    China just happens to have probably the most unprotected consumer PCs on the planet and is an excellent target for botnet drones.

  77. Manhattan DA is tracking Chinese criminals... by siculars · · Score: 1

    The NYPD is one of the absolute best police departments in the world. Their resources rival the FBI and probably eclipse the military of smaller nations. NYC, being the financial capital of the world, has jurisdiction of all dollar denominated currency transactions. they occur in Manhattan via peering relationships through intermediary banks.

    here is a recent example of the long arm of the manhattan da:

    http://manhattanda.org/whatsnew/press/2009-04-07.shtml

  78. Oh, the question 'WHY?' by Anonymous Coward · · Score: 0

    Oh my GOD, the answer is obvious... How many chinese criminals do you think are in NY? Every single one of them is a potential customer of anyone, who is able to gain access and purge their file. Use your brains, dumbo!

  79. Nationality an issue here? by Grismar · · Score: 1

    I fail to see why it's relevant to suggest that the hackers in question were mostly Chinese. It's not like there is any proof they were put up to it by the Chinese government, so it seems to matter little - if anything - whether they're based in China, Russia, the Netherlands (where I happen to live) or the US even.

    This is just politics and Slashdot merrily joins the choir that sings the anti-Chinese song. Excellent journalism, as usual.

    The only issue here is that China seems to be doing little to fight this type of crime within it's borders on the net. Asking (or even forcing) China to do better is certainly fair, suggesting that its "the Chinese" doing the hacking isn't.

  80. Propaganda alert by jandersen · · Score: 1

    It is good to see the many responses here on /. that show people don't just swallow this kind of propaganda anymore.

    A network of hackers, most based in China, have been making up to 70,000 attempts a day to break into the NYPD's computer system, the city's Commissioner, Raymond Kelly, revealed Wednesday.

    This wording clearly states that "We know that we are dealing with Chinese Hackers" - but how do they know? One of the many features of the internet has traditionally been that there was no actual way of knowing with any certainty where an IP address is, geographically. Even today, AFAIK, there is still only a rather loose arrangement for which IP addresses are used in which country, and there is any number of way to appear to be from another region. My own son in Denmark routinely watches South Park, which I understand should only be watchable to users in the US. What, if anything, did these guys do to verify that the alleged hackers really were from China? Nothing, I'm sure, since 70,000 is quite a large number to go through per day. And what about the Great Firewall of China, that we hear is impenetrable to anything and everything, even to the extent that it catches people speaking about "democracy", that terribly dangerous word?

    And of course, if they are clever enough to hack into a foreign nation's computer systems, why aren't they clever enough to employ the well known tricks of disguise that everybody, even on /. know all about?

    The obvious question is, why are the Chinese so interested in the NYPD computer network?

    No, the question is "Why should they be interested?" - and the answer is most likely: "They aren't". We don't need to even ask a Chinese official; the NYPD is a local police force, of little interest to the Chinese government or the Chinese people in general, except in cases where they cooperate on fighting international crime, or in connection with security operations, in which case they shouldn't have to resort to hacking anyway.

    The REAL obvious question here is: "Who is it that has an interest in spreading this nonsense?" - and it is not difficult to come up with plausible answers. Under the previous administration it could easily have been "sources close to government (ie. Rumsfeld or Cheney)", but I give Obama more credit than that. America is infested with wild-eyed anal-retentives, who are all too willing to believe that everybody in other countries are communists or muslim terrorists out to take away their guns and money - they are more than likely both the source and the target audience for this kind of drivel.

    Another good question is: How did it make its way onto Slashdot? I mean, OK, this is not a top-notch high-brow news-outlet, but still.

  81. The Great Wall of China by prjames · · Score: 0

    If the Chinese wish to completely refute their involvement at Government level perhaps they could use their "Great Wall" to filter out this traffic. It would appear to be good at stopping users inside China from accessing "un-patriotic" content from elsewhere, so let them show willing here and stop criminal activity from coming out. Until then all Asian (& Eastern European) access to my sites is banned >/dev/null and beyond! Would be 2c worth but the GBP ain't so good after the budget!!!

  82. well everybody knows by nimbius · · Score: 1

    all they have to do is make sure they dont start hacking ALL the NYPD webs...and that can be prevented by shutting down the internets of course. die hard made it very clear.

    --
    Good people go to bed earlier.
  83. Yawn, happens to everyone by Anonymous Coward · · Score: 0

    Hate to break your paranoia but if you check pretty much every single business or government department which has enough public facing IT resources will be getting hit by these bots, Chinese or otherwise.

  84. How about... by hesaigo999ca · · Score: 1

    How about following in the military's and FBI's footsteps and not placing those networked systems available to the internet. Seems to me if it does not touch the internet , it must be safe....
    another one is have a special made ethernet card that needs special software to operate, and kill
    all other types of network connections to the computers (in case someone slips in a usb wifi key)

    Seriously, we should be sending this right back at them...DDoS them and make them see ...we won't go down without a fight.

  85. network of hackers? by ShOOf · · Score: 2, Informative

    bots brute forcing logins != hackers

  86. imagine by Anonymous Coward · · Score: 0

    A network of hackers

    Imagine a beowulf cluster of...

  87. All they have to do is walk a few blocks.... by xjerky · · Score: 1

    One Police Plaza is just south of Chinatown.

    --
    A sentence you'll never see on an Internet discussion board: "You know what? You're right."
  88. I wouldn't trust anything out of the mouths... by Anonymous Coward · · Score: 0

    ...of the NYPD, for example, Luke Rudkowski arrested before trying to ask NYC mayor Bloomberg questions about health benefits for first responders in 9/11.

  89. The answer is "Smuggling in Fujianese". by Anonymous Coward · · Score: 0

    As exposed in that book The Fortune Cookie Chronicles, tens of thousands of Chinese from Fujian come to NYC every year as illegal immigrants, virtually emptying their hometowns. (That's also why there are all those Chinatown buses and vans -- to get the illegals cross-country to their new places of employment.) And NYC is the world center of Chinese restaurant staffing, so they come there first.

    So I would expect that the coyotes smuggling in the restaurant people would like to get into the NYPD files, if indeed someone is deliberately trying to break into the NYPD and not just looking for openings at random.

  90. There are more than 9000 attempts per day. by Anonymous Coward · · Score: 0

    You know it!

  91. There is another point... by Anonymous Coward · · Score: 0

    ... what do You think, who made the OS that runs all of these "Chinese" or "Russian" bots?

  92. China Town shops by ehiris · · Score: 1

    Have you ever been to China Town? I can see how the Chinese would want information about NYPD raids and known names related to knock-off dealing.

  93. Never Assume by sgt_doom · · Score: 1

    Let me give you a hint, junior douchebag, never assume as your assumptions are probably as wrong as this one. And I no longer bother attempting to explain myself to the lowbrows - and will you EVER learn the correct definition of troll?

  94. The NYPD protects the UN building in many situati. by cowcabobism · · Score: 1

    The NYPD protects the UN building when heightened security is needed, the NYPD has contact with many diplomats in NY while carrying out their patrols. Also the NYPD currently has hundreds of officers overseas thru the UN training local police forces in places like formerly UN mandated Kosovo. https://cranberry.cc.columbia.edu/cs/ContentServer?childpagename=Bronxbeat%2FJRN_Content_C%2FBBArticleDetail&c=JRN_Content_C&p=1165270050524&pagename=JRN%2FBBWrapper&cid=1175372074098

  95. JACKASS by Anonymous Coward · · Score: 0

    How is that a comeback?