March 07, 2021

The MoA Week In Review - OT 2021-019

Last week's posts at Moon of Alabama:

> [Steven Adair, president of Volexity,] said his firm tracked the malicious activity back to early January, though researchers in Taiwan identified Exchange software bugs as far back as December.

For much of January and February, the Chinese theft of email seemed stealthy and targeted, Adair said. Then suddenly about a week ago, shortly before Microsoft issued its patch, the activity exploded. The hackers seemed to be dropping webshells on anyone running an Exchange server, he said. It was, he said, almost as if they suspected a patch was forthcoming. <

Other issues:

March 06, 2021

Is China Hacking Random Servers To Put Itself Into A Bad Light?

When I was an IT manager I never liked Mircosoft's Exchange email servers. Like many other Microsoft products it is overloaded with useless niche features and legacies from previous versions. I am thereby not astonished that it was seemingly quite easy to hack.

A currently ongoing hacking campaign that by now has effected hundred thousands of system was first found by Volexity, a cyber security company in Reston, Va.:

In January 2021, through its Network Security Monitoring service, Volexity detected anomalous activity from two of its customers’ Microsoft Exchange servers. Volexity identified a large amount of data being sent to IP addresses it believed were not tied to legitimate users. A closer inspection of the IIS logs from the Exchange servers revealed rather alarming results.
Through its analysis of system memory, Volexity determined the attacker was exploiting a zero-day server-side request forgery (SSRF) vulnerability in Microsoft Exchange (CVE-2021-26855). The attacker was using the vulnerability to steal the full contents of several user mailboxes. This vulnerability is remotely exploitable and does not require authentication of any kind, nor does it require any special knowledge or access to a target environment. The attacker only needs to know the server running Exchange and the account from which they want to extract e-mail.

The hackers used four different zero-day security holes in Exchange Server products. A zero-day security hole is one that was previously unknown and has never been used before. To find new zero-day security holes is difficult and expensive. But after they are found and made operational they are often easy to use. Whoever did this hack has invested quite some effort. 

Besides extracting emails the hackers also installed backdoors that give them remote access to the hacked Exchange systems.

On March 2 Microsoft released patches for the four security holes. In its release it accused China of being behind the hack:

March 05, 2021

On 'Shia Backed', 'Iran Backed' Nonsense And Other Warmongering Journalism

The recent U.S. airstrike at the Syrian-Iraqi border and the missile attacks on U.S. bases in Iraq were followed by many examples of bad journalism.

U.S. media, as FAIR documents, have purged inconvenient facts from their coverage of Biden's 'first' airstrike:

The less clear the US population is about the frequency and scale of murderous violence its government carries out, the easier it is for the US ruling class to go about its wars. Fortunately for the US state, corporate media help manufacture collective amnesia by expunging US aggression from the record.
Securing consent for running a lethal, worldwide empire requires unremitting propaganda: Redacting the historical record and playing the victim are two useful strategies.

The dozens of examples in the FAIR piece are telling. FAIR gets one thing wrong though. The attack was not in Syria, as the U.S. claimed, but on the Iraqi side of the border.

Elijah J. Magnier @ejmalrai - 6:01 UTC · Mar 3, 2021
Analysts keep making this mistake: 1st Biden's bombing was in #Iraq not #Syria. An Iraqi military delegation sent by @MAKadhimi verified & confirmed that the #US bombed Iraqi security forces on the Iraqi borders with #Syria and not on Syrian territory.

Nearly all U.S. media use 'Iran-backed militia' when describing the groups that allegedly launched the missiles. The Pentagon now wants to change that. A press briefing with spokesman John F. Kirby had several exchanges about that:

Q: Just going back to -- to the rocket attack, could you describe roughly the distance that the rockets were coming from? And what does that say about the tactics -- and how does that -- of the -- whoever fired those? And to what degree does this resemble previous attacks by the Iranian-backed militia?

MR. KIRBY: I'm not qualified to do the forensics, Dan, on -- on -- on how this equates to previous attacks, other than obviously it's a rocket attack and we have seen rocket attacks come from Shia-backed militia groups in the past. So in that way, it certainly -- it certainly coincides with our past experience here.

... [lots of unrelated stuff] ...

Open Thread 2021-018

News & views ...

March 04, 2021

Biden's "Nothing Will Fundamentally Change" Promise Extends To His Foreign Policy

"America is back" claimed Joe Biden to no ones amusement. But the world has changed after four years of Trump and after a pandemic upset the world. The U.S. position in this world and its role in it have thereby also changed. To just claim one is back without adopting to the new situation promises failure.

As candidate Joe Biden promised that there would be no changes.

Joe Biden to rich donors: "Nothing would fundamentally change" if he's elected

Former Vice President Joe Biden assured rich donors at a ritzy New York fundraiser that “nothing would fundamentally change” if he is elected.

Biden told donors at an event at the Carlyle Hotel in Manhattan on Tuesday evening that he would not “demonize” the rich and promised that “no one’s standard of living will change, nothing would fundamentally change,” Bloomberg News reported.

That Biden statement destroyed the illusion of those who had hoped that he would lift the standard of living for the average Amercian.

Biden stayed true to his words at the fundraiser. There will be no rise in the minimum wage. The $2,000 checks he promised to all voters will now be only $1,400 checks. They will also be heavily means tested. Those who made more than $80,000 in 2019 but lost their income in 2020 will get no check at all.

Even as they hold the White House and the House and Senate majorities the Democrats are unable or unwilling to deliver basic progress. This will likely cost them their House majority in 2022 and the presidency in 2024.

Biden's "nothing will fundamentally change" attitude extends into foreign policy.

Secretary Pompeo @SecPompeo - 0:29 UTC · Dec 21, 2019
Today, the #ICC prosecutor raised serious questions about the ICC’s jurisdiction to investigate #Israel. Israel is not a state party to the ICC. We firmly oppose this unjustified inquiry that unfairly targets Israel. The path to lasting peace is through direct negotiations.
Secretary Antony Blinken @SecBlinken - 1:34 UTC · Mar 4, 2021
The United States firmly opposes an @IntlCrimCourt investigation into the Palestinian Situation. We will continue to uphold our strong commitment to Israel and its security, including by opposing actions that seek to target Israel unfairly.

With that, and with its lack of punishment for the Saudi clown prince, the Biden administration has blinked on human rights which it had emphasized in earlier statements.

That nothing will change is also expressed in two policy papers the Biden administration released yesterday. The early emphasis on human rights, which distinguished it from the Trump administration, is already gone.

The common theme is now 'democracy' as if that were not just a form of government but a value in itself.

The White House published an Interim National Security Strategic Guidance (pdf). The paper is dripping with ideological LGBTQWERTY librulism. Its central claim is that 'democracy' is under threat:

March 03, 2021

By Following Trump's Policies Biden's 'Deterrence' Predictably Fails

U.S. politicians and military love to claim that they are acting to restore deterrence:

When the president illegally ordered the assassination of Soleimani in January of this year, administration officials eventually lined up behind the excuse that it was intended to “restore deterrence” against rocket attacks from Iranian-backed Iraqi militias. Even though these attacks have continued throughout the year much the same as before, we are back to the same old tired issuing of threats of military action in response to attacks that would not be happening if it were not for the president’s own reckless actions.
Were it not for the president’s “maximum pressure” campaign, U.S. forces in Iraq would face far fewer risks than they do today, and conflict between our governments would be much less likely. Had it not been for the president’s decision to order the illegal and provocative attack that killed Soleimani and an Iraqi militia leader, tensions between the U.S. and Iran would not be as great as they are now. Trump’s approach to Iran for the last two and a half years has been to pick a fight and then blame the other side for responding to his provocations. Far from deterring attacks from Iranian-backed militias and the Iranian military itself, the Trump administration has been provoking and inviting them.

President Joe Biden and his administration continue, without any change, the Trump administration's policies towards Syria, Iraq and Iran.

Just like Trump Biden has claimed that last week's airstrike on Iraqi security forces at the Iraqi-Syrian border was designed to deter from further missile strikes on U.S. forces in Iraq:

President Joe Biden said Friday that Iran should view his decision to authorize U.S. airstrikes in Syria as a warning that it can expect consequences for its support of militia groups that threaten U.S. interests or personnel. “You can’t act with impunity. Be careful,” Biden said when a reporter asked what message he had intended to send with the airstrikes, which the Pentagon said destroyed several buildings in eastern Syria but were not intended to eradicate the militia groups that used them to facilitate attacks inside Iraq.
At the Pentagon, [chief spokesperson John] Kirby said the operation was “a defensive strike” on a waystation used by militants to move weapons and materials for attacks into Iraq. But he noted that while it sent a message of deterrence and eroded their ability to strike from that compound, the militias have other sites and capabilities.

It is quite obvious that such "messaging" by airstrikes is nonsense that only guarantees that the cycle of violence escalates. As we noted after the recent strike:

The Biden administration has yet to learn the lesson the Trump learned when he tired to provoke Iran and its allies. It is the resistance that has escalation dominance in the Middle East. It can control the pace of further steps up the escalation ladder. It is willing to step up higher than the U.S. It knows how to use that ability.

Today the U.S. received proof that the "message" it sent did not have the desired effect:

March 01, 2021

Biden Breaks Campaign Promise On MbS Punishment - Psaki Lies To Hide That - Guardian Fakes Quote To Hide Psaki's Lie

Updated below (and headline changed to reflect that)

During his campaign President Joe Biden promised to punish Saudi Arabia's clown prince Mohammad bin Salman for ordering the murder of the Muslim Brotherhood propagandist Jamal Khashoggi. Like with most of his other campaign promises Biden of course never had the intention to follow through on that.

Biden's press secretary Jen Psaki, known for bullshit spoken in an assertive tone, defended Biden's falsehood with another lie:

The White House on Sunday defended its decision to not target Saudi Crown Prince Mohammed bin Salman after a U.S. intelligence report linked the royal to the 2018 murder of journalist Jamal Khashoggi.

"Historically and even in recent history, Democratic and Republican administrations, there have not been sanctions put in place for the leaders of foreign governments where we have diplomatic relations and even where we don't have diplomatic relations," White House press secretary Jen Psaki said during an interview on CNN's "State of the Union" program.

Here is the video clip of Biden's and Paski's lies. Her quote starts at 1:58 min.

The Office of Foreign Assets Control has a Sanction List Search feature which allows anyone to look up entities and persons who are under U.S. sanctions.

The pic below shows the entry for one LUKASHENKA, Alyaksandr Hryhoryavich, who's title is noted as 'President'.


The pic below shows the entry for one MADURO MOROS, Nicolas, who's title is noted as 'President of the Bolivarian Republic of Venezuela'.

February 28, 2021

The MoA Week In Review - OT 2021-017

Last week's posts at Moon of Alabama:

1TVNewsAF @1TVNewsAF - 6:32 UTC · Feb 28, 2021
Sirajuddin Haqqani warns of never-seen-before fight if foreign troops don't exit Afghanistan by May.
"Today...we have the technology to use drones, we have our own missiles. This time if the Mujahideen resume fighting the enemies, it would be something they have never seen before."
Glenn Greenwald @ggreenwald - 15:03 UTC · Feb 24, 2021
It took only two years to go from disappearing Milo and Alex Jones to banning content said to "amplify narratives that undermine faith in NATO."
Imagine where the line will be two years from now.
Censorship is an intoxicating power that endlessly expands until it's smashed.

Other issues:

February 27, 2021

Covid-19 - Surfing The Third Wave

The second wave of the ongoing Covid-19 pandemic has receded and the people have had enough of restrictions. There is immense pressure to end the lockdowns and many politicians will do as their voters wish. But there will be a third wave and it is likely to become larger than the second one. Below I try to explain why that is the case and what it means for our societies. My conclusions may sound alarmist, and I may be all wrong, but the scenario is neither impossible nor am I the only one who thinks it is likely.

The Spanish Flu came in three waves spread over 18 month. By summer 1919 most populations had gained some immunity against it. During the winter flu season of 1919 the new disease was no longer a public danger.

Deaths per thousand people during the Spanish Flu


Here is the similar curve for the United States during the Covid-19 pandemic.

The U.S. just finished what - in comparison to 1918/19 - is the second wave of the pandemic.

Source - bigger

The situation is similar in large parts of the world. The Covid-19 pandemic has just finished its second wave.

February 26, 2021

After U.S. Attack In Syrian Iran Demonstrates Its Escalation Dominance

Last night the U.S. escalated the situation in Iraq by bombing Iraqi government security forces at the Iraqi-Syrian border station near Abu-Kamal/Al-Qaim. One Iraqi soldier, a Sunni, was killed. Other sources claim that as many as 22 were killed.

The Pentagon spinmasters and their stenographers in the media use Orwellian language to justify the crime. The official press release says:

U.S. Conducts Defensive Precision Strike

Feb. 25, 2021

(Attributable to Pentagon Press Secretary John Kirby)

“At President Biden’s direction, U.S. military forces earlier this evening conducted airstrikes against infrastructure utilized by Iranian-backed militant groups in eastern Syria. These strikes were authorized in response to recent attacks against American and Coalition personnel in Iraq, and to ongoing threats to those personnel. Specifically, the strikes destroyed multiple facilities located at a border control point used by a number of Iranian-backed militant groups, including Kait’ib Hezbollah (KH) and Kait’ib Sayyid al-Shuhada (KSS).

This proportionate military response was conducted together with diplomatic measures, including consultation with Coalition partners. The operation sends an unambiguous message: President Biden will act to protect American and Coalition personnel. At the same time, we have acted in a deliberate manner that aims to de-escalate the overall situation in both eastern Syria and Iraq.”

The last attack on U.S. units in Iraq happened on February 15 against a U.S. position in Erbil, Iraq. Some three small rockets were fired by an unknown group of provocateurs.

To call an attack with seven 500 pound bombs on a border station guarded by official Iraqi security forces against ISIS attacks hundreds of miles away from Erbil "defensive" and "in response" is of course ridiculous.

Kataeb Hizbullah al-Iraq (not related to Hizbullah in Lebanon) and KSS are under command of the Iraqi prime minister. They were founded with help from Iran in 2014 to fight against ISIS. Since 2018 they are regular Iraqi forces paid and equipped by the Iraqi government, not by Iran. This attack will escalate the situation in Iraq. More attacks against U.S. and other foreign units there are now assured.

Together with the deliberate steps to make a return to the nuclear deal with Iran more complicate this attack can be seen as a deliberate escalation against the 'resistance axis' of Iran, Syria, Hizbullah in Lebanon and their supporters.

The Biden administration has yet to learn the lesson the Trump learned when he tired to provoke Iran and its allies. It is the resistance that has escalation dominance in the Middle East. It can control the pace of further steps up the escalation ladder. It is willing to step up higher than the U.S. It knows how to use that ability.

Here is proof for that:

