Behind the Internet Wheels of Steel - Recording Live From Somewhere - Mixing the Fresh Beats of Technology, Intelligence, Science & Security together with the occasional bass-heavy break of Humor.
"There is no security on this earth, there is only opportunity"
- General Douglas MacArthur (1880-1964)
Saturday, March 22, 2008
Google Summer of Code 2008
All participating mentoring organizations for 2008 have provided additional information for their would-be students, including a list of sample project ideas. Take a look and see which ones most closely match your skills and interests, then start talking to your would-be mentors! We'll begin accepting student applications on Monday, March 24, 2008, so you have a full week to get to know more about what your would-be mentors are looking for and to hone your proposal ideas. Remember, the more a mentoring organization knows about you, and you about their code base and community, the more likely it is that your application will be attractive to your potential mentors.
http://code.google.com/soc/2008/
--------------------
Over 170 organizations are taking part in SoC 2008.
Let the fresh ideas of the youth come to life, in the world of open-source.
FBI Looks at Chinese Role in Darfur Site Hack
The U.S. Federal Bureau of Investigation is looking into a possible China connection in the hack of a nonprofit group created to draw attention to the ongoing genocide in western Sudan's Darfur region.
The Save Darfur Coalition called in the FBI earlier this week after discovering that someone had gained unauthorized access to its e-mail and Web server, according to Allyn Brooks-LaSure, a spokesman with the group.
Brooks-LaSure doesn't know who is behind the attacks, but he said the Internet Protocol addresses of the computers that had hacked his organization were from China. "Someone in Beijing is trying to send us a message," he said.
The hackers seemed to be primarily interested in gathering data on his group, Brooks-LaSure said. Save Darfur has been trying to get China to pressure Sudan's government into stopping the mass killings in Darfur's ongoing civil war. China is one of Sudan's largest trading partners.
Computers in China have been the source of many attacks in recent years, although security experts say that sometimes China-based machines are simply used as jumping-off points for attackers who actually reside in other countries such as the U.S. or Russia.
Friday, March 21, 2008
Latest Blu-Ray Copy Protection Cracked
The latest effort at blocking unofficial copying of Blu-ray movies has been undone, the developers of a cracking utility claim. AnyDVD 6.4.0.0 adds the ability to bypass BD+ encoding, used on a number of discs to prevent either direct copying, or ripping to a hard drive. This change is said to particularly affect releases from 20th Century Fox, who have led the adoption of BD+, while other companies continue with variants of AACS. AnyDVD is now also better compatible with regular DVDs using Arccos protection.
The movie industry has tried unsuccessfully for years to limit disc copying; after early failures with DVD, both Blu-ray and HD DVD were designed to be impenetrable. HD DVD was exposed within months of its launch however, and Blu-ray followed shortly thereafter, forcing companies to devise new DRM techniques. The unlocking of BD+ may be considered a serious setback to industry moguls, who argue that piracy causes considerable harm to profits.
----------------------
DRM == Defective by Design
DoD Report on Captured Iraqi Documents
Via Secrecy News -
A Defense Department-sponsored report that examined captured Iraqi documents for indications of links between Saddam Hussein and terrorist organizations is now available online.
The five-volume report affirmed that there was “no ’smoking gun’ (i.e., direct connection) between Saddam’s Iraq and al Qaeda.” But it also said there was “strong evidence that links the regime of Saddam Hussein to regional and global terrorism.”
Although the report was publicly released on March 13, the Department of Defense declined to publish it online, offering instead to provide copies on disk. The full five-volume study has now been posted on the Federation of American Scientists web site. See “Iraqi Perspectives Project: Saddam and Terrorism: Emerging Insights from Captured Iraqi Documents,” Institute for Defense Analyses, November 2007, redacted and released March 2008.
Microsoft Security Advisory (950627) - New Vulnerability in Microsoft Jet Database Engine
Microsoft is investigating new public reports of very limited, targeted attacks using a vulnerability in the Microsoft Jet Database Engine that can be exploited through Microsoft Word.
Customers running Windows Server 2003 Service Pack 2, Windows Vista, and Windows Vista Service Pack 1 are not vulnerable to the buffer overrun being attacked, as they include a version of the Microsoft Jet Database Engine that is not vulnerable to this issue.
Customers using Microsoft Word 2000 Service Pack 3, Microsoft Word 2002 Service Pack 3, Microsoft Word 2003 Service Pack 2, Microsoft Word 2003 Service Pack 3, Microsoft Word 2007, and Microsoft Word 2007 Service Pack 1 on Microsoft Windows 2000, Windows XP, or Windows Server 2003 Service Pack 1 are vulnerable to these attacks.
Microsoft is investigating the public reports and customer impact. We are also investigating whether the vulnerability can be exploited through additional applications. Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs.
At this time, we are aware only of targeted attacks that attempt to use this vulnerability. Current attacks require customers to take multiple steps in order to be successful; we believe the risk to be limited.
Microsoft Office Excel Code Execution Exploit (MS08-014)
This security update resolves several privately reported and publicly reported vulnerabilities in Microsoft Office Excel that could allow remote code execution if a user opens a specially crafted Excel file. An attacker who successfully exploited these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
-------------------------------------
Exploit uploaded by zha0:
http://www.milw0rm.com/exploits/5287
Thursday, March 20, 2008
Burger King's Royal Taster Found Dead
ROYAL FOOD COURT OF THE BURGER KING—Gabriello di Mangiagrasso, the King of Burger's royal food taster since 1986, was found dead in his private booth in the Palace Dining Room, the king's foresters somberly reported Monday. "Woe, woe, the king's royal assayer hath perished this morning with a single bite of a BK Stacker sandwich, and with him the safety and security of this very court!" said Constable Ernesto Regulio, who did not know whether di Mangiagrasso had taken a sip of his strawberry milkshake before his death. "Gabriello was a fine taster who loved chicken tenders and gave his very life to protect our glorious king, who though gratefully alive, is dreadfully hungry!" An autopsy revealed no traces of poison in the taster's body, but investigators say his death could be linked to 22 years of built-up plaque in his coronary arteries rupturing and releasing fats and cholesterol into his bloodstream, causing severe clotting, and cutting off blood flow to the heart.
--------------------
We love this video at the office....
http://www.youtube.com/watch?v=PZGj6kYnc38
Internet Addiction May be Classified as Mental Illness
An editorial piece in the March issue of the American Journal of Psychiatry says compulsive internet use which can include "excessive gaming, sexual pre-occupations and e-mail/text messaging" should be classified as a mental illness, under the parameters of addiction.
Similar to addicts of other behaviors or substances, users experience cravings, withdrawal, and tolerance which only lead to more of a dependence on the activity and increased hours on the interwebs. Some users even neglect basic human needs like eating or sleeping.
Dr. Jerald Block, a psychiatrist at the Oregon Health and Science University in Portland says about 86% of internet addicts have some other additional mental illness but unless a psychiatrist is looking for it, they could easily miss the internet component.
British psychiatrists said last year that a mere 5-10% of internet users are addicts but China and South Korea are already addressing the problem after 10 people died in internet cafés in South Korea from cardiopulmonary-related deaths. It's reported that 7 of them died due to online gaming and the South Korean officials have since trained more than 1,000 counselors in the treatment of internet addiction.
canada.com: Recognize Internet addiction as a mental illness, MD urges
We at G4's TheFeed are conscientious about the effect the internet can have on one's life. Please locate the following resources online if you or someone you love is struggling with internet addiction:
Internet Helpline Online
Addiction Helpcentre Forums
Blog Addicts Anonymous
Apple Succeeds By Defying 5 Core Valley Principles
Google's famous catchphrase, "Don't be evil," has become a shorthand mission statement for Silicon Valley, encompassing a variety of ideals that proponents say are good for business and good for the world: Embrace open platforms. Trust decisions to the wisdom of crowds. Treat your employees like gods. It's ironic, then, that one of the Valley's most successful companies ignored all these tenets. Here's how Apple succeeds by defying five core Valley principles.
----------------------
See the link above for all the rules and how Apple ignores them...
Awesome article.
Clearly, Apple is spiking their kool-aid with elfin magic...
Wednesday, March 19, 2008
New Usama bin Laden Audio Speech Released
May Our Mothers Be Bereaved Of Us If We Fail to Help Our Prophet” – An Audio Speech by Usama bin Laden from As-Sahab
The audio was released in three different formats or sizes, with the largest being a 16.4 MB Realmedia file. This file was password protected inside of a RAR archive.
I haven't listened to the audio yet, I don't have Realmedia player installed...and since I don't know Arabic, it wouldn't really help anyways.
The NEFA has released a full translation of the tape (PDF).
UPDATE - Ok, I installed Realmedia player and took a quick peek at the audio tape. The audio tape includes video translation of the audio along with some flashy graphics, which is pretty common for As-Sahab releases.
Apple Megapatch Includes Long Lost Fixes
In one swing, Apple unleashes a tally of security updates that nearly surpasses all of the patches it released last year.
In Security Update 2008-002, Apple is fixing 87 security flaws that span 30 separate applications, a number of functions in OS X, as well as other platforms that range from Apache to X11.
This service pack-sized patch follows on the heels of an update to both the Windows and Mac versions of its Safari browser, with fixes for more than a dozen vulnerabilities.
The flaws in question create the usual software hazards, such as buffer overruns and the ability to inject malicious code into an unpatched system.
One of the more interesting fixes involves a cross-realm authentication issue with AFP Server. In this flaw, attackers may be able to create unauthorized connections to the server.
I installed both the updated version of Safari, as well as the Security Update on both a MacBook Pro and a Mac Pro each running Leopard.
So far, so good.
The patches can be downloaded manually from Apple's download support page, or via software update.
----------------------------------
The funny part about Apple patches is that they commonly fix issues which have been known about and fixed in the open source world for quite sometime. Sure, OS X isn't perfect and it will have flaws. Windows has flaws as well...but there is a key difference.
Apple patches fix issues which are already fixed in the open source world....sometimes patched years before Apple got around to patching them.
Lets look at two of the oldest CVEs noted in the latest Apple patch:
CVE-2005-3352 - Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.
When was CVE-2005-33352 patched by other vendors?
Redhat issued a patch for this issue on Jan 5th, 2006.
IBM issued a patch for their IHS on June 13th, 2006.
So Apple is about 2 years behind other vendors that use open-source products at their core.
CVE-2006-3334 - Buffer overflow in the png_decompress_chunk function in pngrutil.c in libpng before 1.2.12 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors related to "chunk error processing," possibly involving the "chunk_name"
This vulnerabilities was patched in libpng 1.2.12 (released on Jun 27th, 2006).
So I think the real question should be....why does it take Apple almost 2 years to release patches for publicly known vulnerabilities?
These aren't some privately reported closed-source flaws...these are vulnerabilities which are known to the world....complete with patched open-source for anyone to RCE.
Apple should be glad there isn't a financial market for global exploitation of Macs....because at this point, I don't believe Apple has a true handle on backporting open source patches into their product line.
What if they were under direct attack from international crime groups?
Remember, I only looked at the oldest of near 90 vulnerabilities....
Nigerian Scammers Put Victims on Their Calendars
Those pesky Nigerian spam artists are at it again, and this time they're targeting companies like yours.
Nigerian scammers are targeting the corporate world by sending their scam "hooks" as meeting invites in Google Calendar, security vendor BitDefender warns today in an advisory. The emails are personalized, with a different link sent to each recipient, making URL-based filtering harder, the vendor says.
"This is a new and untried social engineering approach," said BitDefender CTO Bogdan Dumitru. "The fact that these things are being spammed in huge numbers is a bit odd -- usually there is a testing phase to evaluate the response rate. Normally, after testing, some techniques are found ineffective and never get used again. This one's different."
The Nigerian scam works by informing the victim that they have inherited or are otherwise due a large amount of money from an unlikely source. The spammer then tells the victim to send a payment in order to "set up the delivery" of the large sum.
Google support has been notified to block the accounts used in the scam, BitDefender said, and the attack has been added to the spam signatures database, which will help anti-spam vendors to filter and block it.
Tuesday, March 18, 2008
TrueCrypt Developers Consider Complaint Against Microsoft
The developers of the TrueCrypt open source encryption tool are considering submitting a complaint against Microsoft to the EU Commission if Microsoft is not prepared to lay open the Windows hibernation API. From version 5.1 TrueCrypt supports hibernation for encrypted system partitions. Potential vulnerabilities that could allow the hibernation file to be written to the disk in unencrypted form have been reported in this version in recent weeks. This would allow attackers to read the key and thus decrypt the partition or container.
In response to an enquiry from heise Security on this, the developers were cagey. They stated that the author of the security advisory had clearly incorrectly analysed the TrueCrypt source code, as the routines executed were incorrect and anyway TrueCrypt does not allow encryption of partitions under Windows 2000. Nevertheless, the developers confirmed that with certain storage drivers, the hibernation file could be written to the disk unencrypted. However, they see this as a problem for all vendors of drive encryption systems, as no documentation is available for the hibernation API and it is therefore necessary to adapt Windows components. This could be undone by Microsoft at any time, however, through the automatic update system for example, which would adversely affect the reliable functioning of products from other manufacturers.
The TrueCrypt developers state that they are currently preparing an official complaint against Microsoft. Should this fail to lead to disclosure, they are planning to submit an anti-competition complaint to the EU. Microsoft offers a system partition encryption system under Windows Vista in the form of BitLocker.
-------------------------I have been using TrueCrypt to protect semi-sensitive files on my personal laptop for quite some time now. I say "semi-sensitive" because if the files were really sensitive, I wouldn't have it on my laptop anyways. GPG keys and tax return PDFs don't go on laptops..lol
I recently formatted and reinstalled my personal laptop (running Windows XP SP2), so I took the chance to start off with a clean encrypted drive. I installed TrueCrypt 5.1 and encrypted the whole drive with AES-256.
It took around 2 hours to encrypted the full 80GB drive, but I was working during the encrypting process....and even had to pause it a few times. When I say working, I mean chatting and clicking refresh on Myspace faster than you can blink your little eyes.
So far, no problems...but I never sleep or hibernation my laptops.
As I was writing this blog, I noticed that TrueCypt 5.1a was released just yesterday. Time to patch and hopefully see some improved boot times.
California Mortgage Fraud Ring Busted
California authorities said Tuesday they filed a lawsuit and made seven arrests in a mortgage fraud case involving seven companies and thousands of homebuyers in Southern California.
Attorney General Jerry Brown said his office was seeking penalties and restitution of more than $20 million in the bait-and-switch scam led by 25-year-old real estate agent Eric Pony.
"This is among the worst we've ever seen," Brown said. "This is not just exaggeration and puffing. This is straight out deliberate stealing and fraud."
The case, filed under seal Monday in Los Angeles Superior Court, alleges the group tricked consumers into agreeing to excessive loans, unaffordable home payments and exorbitant fees.
The suspects are accused of forging signatures when consumers would not sign paperwork.
The seven suspects were arrested on charges including conspiracy, grand theft, forgery and elder abuse, San Bernardino District Attorney Michael Ramos said.
The attorney general shut down the companies and seized 16 properties in Los Angeles, Las Vegas and San Antonio worth more than $6 million.
Prosecutors also froze multiple bank accounts and seized at least 10 luxury cars, including four Mercedes Benzes, two Ferraris and a Bentley.
Pony remained at large. The suspects in custody included Carol Pencille, 57, an escrow officer and chief executive of Olympic Escrow Inc., and Sibpum Armpornpet, 31, an Olympic principal in whose office authorities said they found documents with cut-and-pasted signatures of consumers.
The attorney general said the companies, Lifetime Financial Inc., Nations Mortgage Inc. and Greenleaf Lending Inc. arranged loans that often resulted in payments higher than the consumer's entire monthly income. Many customers lost their homes because of the transactions.
Monday, March 17, 2008
Apple Safari (Webkit) Remote Denial of Service Exploit (iPhone/OSX/Win)
old code is still finding new bugs.
iphone fw:1.1.4 : locks up
safari win32 : crashes
safari osx : crashes
looped the x's on milw0rm to find the bug.
original firefox vuln: http://milw0rm.com/exploits/1233
/str0ke
http://www.milw0rm.com/exploits/5268
UK ISP Confesses Lies Over Secret Phorm Experiments
BT has admitted that it secretly used customer data to test Phorm's advertising targeting technology last summer, and that it covered it up when customers and The Register raised questions over the suspicious redirects.
The national telecoms provider now faces legal action from customers who are angry their web traffic was compromised.
Stephen Mainwaring, a BT Business customer in Weston-super-Mare, believes sensitive banking data relating to his online horse racing business was press-ganged into a trial of an unproven technology. He suffered sleepless nights after detecting the dodgy DNS requests, and said today: "It is very likely that I and others will take legal action against BT for what they did last summer."
In a statement, BT said: "We conducted a very small scale technical test of a prototype advertising platform on one exchange in June 2007. The test was specifically conducted to evaluate the functional and technical performance of the platform.
"Absolutely no personally identifiable information was processed, stored or disclosed during this trial. As with all service providers, it is important for BT to ensure that, before any potential new technologies are employed, they are robust and fit for purpose."
Speaking to El Reg on Friday, Stephen agreed: "Absolutely, new technologies should be stringently tested, but not using mine and my customers' data. If they wanted to run a trial, they should have asked. I would have told them I did not want to be part of it.
"I note the statement, 'absolutely no personally identifiable information was processed, stored or disclosed'. That means that all my information was processed, stored or disclosed but the personal bits were filtered out. Clearly that was unlawful."
Stephen has already filed a complaint with the Information Commissioner's Office and is consulting on how to proceed through the courts with other BT subscribers who believe their connection was subject to illegal Phorm tests.
Today, he and a fellow BT customer also disputed the claim that only one exchange was involved in the covert testing.
Spike, a Reg reader based in Brighton and Hove, also noticed dodgy redirects of his web traffic last July to sysip.net, a domain owned by Phorm. He wrote about the mystery here at the time.
Spike and Stephen urged other BT customers who believe they may have been co-opted into last summer's secret trials to speak out.
We first asked BT about its relationship with Phorm in July 2007, when it was widely known as 121Media, a firm deeply involved in spyware. BT denied any testing and said customers whose DNS requests were being redirected must have a malware problem.
It wasn't until 14 February this year, when the deals between BT, Virgin Media and Carphone Warehouse to pimp customer web browsing were announced, that a cover-up was revealed. You can read the original story here.
BT's belated confession that it secretly used its customers' traffic to test the safety of ad targeting technology can only add to the distrust around Phorm, whose executive team includes a former BT Retail CTO. Several security firms have confirmed plans to classify Phorm's cookies - both for opting in and opting out of Webwise - as adware.
As part of its admission that it lied over the 2007 trials, BT also said it will follow Carphone Warehouse's lead and develop an opt-out that does not involve cookies and means no data will be mirrored to a profiling server, even if it is ignored. It follows serious concerns raised by experts on the Regulation of Investigatory Powers Act 2000 (RIPA) that Phorm's plan to use cookies to exclude people who opt-out is illegal.
BT repeated its insistence that the technology is legal, however. It said: "We are already developing an opt-out solution that would remove the need for opt-out cookies altogether. We have carried out significant due diligence in this area, and informed consent from our customers will satisfy the necessary legal requirements."
Yet some authorities on RIPA have argued that ISPs would also need permission from website owners to profile the content of their pages. BT has not responded to our questions on this point.
ISP data pimping has also invoked the ire of the Greatest Living Briton™. Today the BBC reports that Sir Tim Berners-Lee, inventor of the web, has spoken out against ISP ad targeting. He summed up public opposition to the system: "It's [web traffic] mine - you can't have it. If you want to use it for something, then you have to negotiate with me. I have to agree, I have to understand what I'm getting in return."
Meanwhile, the Downing Street petition against Phorm has now garnered almost 5,000 signatures.
Carphone Warehouse has said it will ensure that its subscribers are opted out of Phorm and Webwise by default. BT and Virgin Media have made no such promise.
You can follow all our reporting of Phorm over the last three weeks here.Iran's Internet Censorship Tightened Ahead of Election
As Iranians head to the polls, the existing government has tightened its grip on the internet and even turned its firewall against politicians close to the current rulers, say researchers who have detected a shift in the kind of sites blocked over the last two weeks. But a total shut down of the web on election day – rumoured last week – has so far failed to materialise.
According to the OpenNet Initiative, an international organization that investigates internet filtering and surveillance, Iran employs the greatest degree of filtering of any country it monitors.
While there was not a massive jump in the number of blocked sites in the days preceding the election, the type of sites filtered has taken a more political turn, says Mahmood Enayat, who is studying Iran's filtering at Oxford University's Internet Institute in the UK.
Pornographic and politically dissenting sites have always been subject to web blocks. But over the last few days the Iranian government has for the first time targeted political and religious groups that are relatively close to its own political stance.
Enayat says that at least four political websites belonging to elements of the ruling conservatives critical of current president Mahmoud Ahmadinejad have been blocked during the last two weeks. Even the personal website of Fatemeh Rajabi, wife of Ahmadinejad's spokesman and chief of staff, Gholam Hossein Elham, has been blocked.
Fatemeh Rajabi has a track record of criticising key figures from all political factions within the current Iranian regime, including Ahmadinejad, his predecessor as President Mohammad Khatami and the head of Iran's judiciary Mahmoud Shahroudi.
Enayat also discovered increased filtering of sites belonging to ethnic groups inside Iran and groups outside the country that promote religions other than Shiite Islam, which is supported by the Iranian state. He says these changes show that the government is starting to use the web as a tool to contain political rivals to the established conservative administration and keep a close eye on the activities of ethnic and religious groups.
Targeting websites belonging to non-Shiite religious groups is most likely a response to the perception that the US is using them to undermine the existing government, he adds.
Babak Rahimi, a reseacher at the Program for the Study of Religion, University of California, San Diego, US, points out that the Iranian government not only uses filtering to control the web. "The government slow the internet down and forbid ISP's to provide transfer rates above 128 kilobytes per second," he says.
Since the Iranian government's filtering of the web began in 2001-2 anti-filtering software from Dubai and Turkey has been in high demand, he adds, although it can do nothing to get around the speed limits.
UCLA Medical Center Employees Fired for Peeking at Britney Spears Records
UCLA Medical Center is taking steps to fire 13 employees who tried to peek at the medical records of pop star Britney Spears while she was hospitalized there for psychiatric care.
Six doctors are also facing disciplinary charges for sneaking a look at the records, according to a Los Angeles Times report.
Officials at the hospital say it isn't the first time employees have been fired over the violation of Spears's medical records. Job terminations occurred when Spears was hospitalized in 2005 for the birth of her son, they said.
The employees were identified by studying access control information, according to Carole Klove, chief compliance and privacy officer at UCLA Medical Center.
"Right from the minute [Spears] came in, audits were continually being done," Klove told the LA Times. "We watch this all the time. We have people dedicated to looking at records to monitor access."
Ironically, the snoopers probably did not see what they had hoped to see. The psychiatric records have an extra level of authentication and Spears's records can only be viewed by workers in the neuropsychiatric hospital, Klove said. Other workers would only be able to see Spears's health history from previous visits to the hospital.
---------------------------
Regardless of what you think about Miss Spears, she has the same right to medical privacy as everyone else.
If my records were accessed without authorization, I would expect (make that demand) action be taken against those that violated the rules.
To make manners worse, these people might have intended to sell whatever information they could find on Miss Spears' medical condition...which takes it to a whole other ballpark.
Google News, YouTube Blocked in China Amid Tibet Riots
Beijing appears to have taken a page out of Myanmar's playbook by blocking some Internet access amid rioting in Tibet that has already seen as many as 80 people killed, according to the Tibetan government in exile.
China has blocked access to Google News and YouTube in an apparent attempt to stop the spread of video footage related the rioting going on in several cities in Tibet, including the capital Lhasa. Demonstrations in the city started on March 10, a day commemorating the anniversary of a 1959 uprising against Chinese rule after which the spiritual leader of the country, the Dalai Lama, fled to India.
China has said the Dalai Lama is to blame for rioting in the country, and puts the civilian death toll at 13, while adding that police and security forces have also suffered casualties.
The Dalai Lama has denied involvement in the rioting, and said he has "no such power to stop it," in a video of a recent news conference posted on his Web site.
"Whether the Chinese government admits it or not, there is a problem," he said "The Tibetan nation, an ancient nation with an ancient cultural heritage, is actually dying."
China's decision to block access to the sites follows similar government censorship of protests by Myanmar. Last September, Myanmar cut off Internet access entirely to block people from viewing pictures and videos or sending them out of the country. Some analysts at the time said the protests likely spread through the help of the Web, in addition to winning global condemnation of the violent crackdown on protesters there.
Two videos about the situations in Tibet posted on YouTube by the user Amdo2007 both appear to show peaceful demonstrations. The first shows a public gathering, including Tibetan monks in their distinctive saffron robes, while the second video shows what appears to be peaceful marching.
Some videos, including one from Amdo2007, have been "flagged by YouTube's user community" so that users have to verify they are 18 or older by logging in or signing up. The video shows bodies on the streets, protesters throwing rocks at Chinese army vehicles and other images. It may have the most hits, over 80,000 so far, on the subject.
Chinese media and international media have shown footage of buildings burning and crowds damaging store-fronts. Some stations, such as the BBC , picked up photos and other contributions from tourists in Tibet.
Foreign media have been banned from Tibet, according to a CNN video , which says the station has not been able to send a team to report the news. China's own press is run by the state.
