Within UFO Hackers

How Were Military Networks Left So Exposed?

Weak passwords, exposed remote access, and inconsistent security reportedly allowed a lone intruder to move through sensitive systems.

70 sources 3 graphics
Preview for How Were Military Networks Left So Exposed?

On this page

  • Password weaknesses and remote access
  • Moving between connected systems
  • Security lessons from the intrusions

Introduction

Gary McKinnon entered United States military and NASA computers primarily because ordinary, internet-connected systems had been left with weak authentication and exposed administrative services. According to the official account accepted in British extradition proceedings, he searched government address ranges for Windows computers with open connections, obtained administrative account details and passwords, then installed commercial remote-control software that gave him continuing access. From compromised machines, he searched for further vulnerable systems, allowing one poorly protected computer to become a route into others.[UK Parliament]publications.parliament.ukUK Parliament House of LordsUK ParliamentHouse of Lords - Mckinnon V Government of The United States of America and Another…

Overview image for Access Methods

The striking feature was not an unknown technical breakthrough. McKinnon’s own descriptions, contemporary reporting and the US allegations all point towards automated scanning, blank or easily guessed passwords, internet-exposed Windows services and ordinary remote-administration software. The case therefore belongs as much to the history of weak government network management as to the story of a UFO enthusiast searching restricted systems.

Password weaknesses and exposed remote access

McKinnon began by looking for computers that could be reached directly from the public internet. The House of Lords described him as identifying US government machines with an open Microsoft Windows connection, then extracting the identities of administrative accounts and their associated passwords. Contemporary US officials said he used readily available automated software to scan tens of thousands of military addresses for weaknesses in Windows NT systems.[UK Parliament]publications.parliament.ukUK Parliament House of LordsUK ParliamentHouse of Lords - Mckinnon V Government of The United States of America and Another…

Accounts differ slightly over exactly how every initial login was obtained. The formal legal summary refers to administrative identities and passwords, while McKinnon and journalists who interviewed him repeatedly emphasised machines with blank administrator passwords. One contemporary profile reported that he used software to locate Windows computers whose administrator accounts had no password at all. Investigators also told reporters that some compromised machines used passwords simple enough to guess. These explanations are compatible rather than mutually exclusive: different systems could have been exposed through absent passwords, weak passwords or badly configured administrative connections.[theguardian.com]theguardian.comThe GuardianGame over | Gary McKinnon9 Jul 2005 — He downloaded a program that searched for computers and pinpointed administrator user n…

A blank local administrator password was especially serious because an administrator account normally has authority to alter software, inspect files, create users and change system settings. Once McKinnon obtained those privileges, he was not confined to reading whatever a normal user could see. The Virginia indictment alleged that, on at least one Army computer, he reached administrator level, copied a file containing usernames and encrypted passwords and installed additional access tools.[Department of Justice]justice.govDepartment of Justice

The weakness was magnified by the way computers were deployed. McKinnon later described encountering groups of machines apparently created from the same Windows installation image, sometimes carrying the same insecure administrator configuration. Although his broadest claims about thousands of identically configured computers rest on interview testimony rather than a completed trial, the mechanism is credible: cloning one poorly secured system image can reproduce the same vulnerability across an entire office or network.[Tarr Daniel]tarrdaniel.comTarr DanielUFO - Ufology - The Gary McKinnon CaseOn this particular network the image had been made with a blank administrator password…

This was not occurring in an otherwise exemplary federal security environment. In 2001, congressional assessments gave the US government an overall failing grade for computer security, with the Department of Defense among the agencies receiving an “F”. Contemporary audits found weak password practices, inadequate controls over software installation and inconsistent security management across federal departments.[WIRED]wired.comgovt networks get an fgovernment an "F" for the protection of federal computer networks, down from a "D-minus" in 2000. The failing grades were based on assess…

Access Methods illustration 1

How remote-control software turned entry into persistence

Initial access was only the first stage. The US indictment and the House of Lords judgment state that McKinnon installed RemotelyAnywhere, a legitimate remote-administration product. Once installed on a host computer, the software permitted control of that machine through the internet, including access to files and administrative functions. It therefore converted a one-off opening into a reusable remote doorway.[Department of Justice]justice.govDepartment of Justice

Using a commercial administration package had practical advantages for an intruder. It was designed to perform the same tasks that legitimate support staff needed: remote control, file transfer and system management. Contemporary reporting noted that it was less likely to trigger antivirus warnings than notorious hacker “back doors”, because the program itself had lawful uses. The problem was not that remote-administration software was inherently malicious, but that it had been installed without authorisation on machines whose existing controls had already failed.[WIRED]wired.comDot-Mil Hacker's Download MistakeDot-Mil Hacker's Download Mistake

The House of Lords account said the software could operate without attracting attention because it presented itself as part of the Windows environment. The US allegations further stated that McKinnon installed tools intended both to facilitate additional compromises and to conceal activity. These details were prosecutorial allegations, not findings reached after a full US criminal trial, but McKinnon admitted unauthorised access and did not dispute the broad fact that he used remote-control software.[UK Parliament]publications.parliament.ukUK Parliament House of LordsUK ParliamentHouse of Lords - Mckinnon V Government of The United States of America and Another…

RemotelyAnywhere also illustrates why “remote access” and “weak passwords” cannot be treated as separate failures. Weak authentication allowed the initial administrator login; administrator privileges then allowed persistent software to be installed; persistent access gave the intruder time to browse, copy account information and search for more systems. A single neglected password could therefore initiate a much longer chain of exposure.

The same software eventually helped investigators trace him. Records associated with his download reportedly contained an English internet address and his girlfriend’s email address, while the downloaded version matched the software found on compromised military computers. A tool that helped him remain on the networks also left evidence outside those networks.[WIRED]wired.comDot-Mil Hacker's Download MistakeDot-Mil Hacker's Download Mistake

Moving between connected systems

McKinnon did not need every government computer to be vulnerable from his home connection. Once he controlled one machine, he could use its position and network access to look for additional targets. The Department of Justice alleged that he used compromised computers to locate further military and NASA systems. The House of Lords described the process as “levering” himself from one network to another after scanning more than 73,000 government computers for similar weaknesses.[Department of Justice]justice.govDepartment of JusticeLondon, England Hacker Indicted Under Computer Fraud and Abuse Act For Accessing Military Computers (November 12, 2002)…Published: November 12, 2002

This method is commonly understood today as lateral movement: an intruder enters one system and then uses its access, stored information or network relationships to reach others. In McKinnon’s case, the alleged process included copying account and password files, installing further tools and scanning from inside compromised environments. The legal summary said his home computer contained material supporting the allegations, including files copied from Army, Navy and NASA computers.[UK Parliament]publications.parliament.ukUK Parliament House of LordsUK ParliamentHouse of Lords - Mckinnon V Government of The United States of America and Another…

Broad connectivity made this progression possible. Military organisations had adopted networked Windows computers for routine administration, communications and operational support, but security controls were not uniformly applied across every workstation and server. A highly sensitive organisation could therefore contain many ordinary computers whose configuration depended on local administrators, inherited settings and uneven maintenance.

The scale of the scanning should not be confused with the number of successful entries. US officials said McKinnon examined tens of thousands of addresses but compromised roughly a hundred government systems. That means most machines he encountered apparently resisted his methods. Nevertheless, finding even a small vulnerable fraction was enough to produce access across the Army, Navy, Air Force, Department of Defense and NASA.[WIRED]wired.comattempts to extradite him for charges related to what is described as the largest successful hacking effort against American military net…

The case also exposed weaknesses in detection and coordination. Investigators reportedly noticed suspicious activity months before the intrusions ended, but a Navy warning directing administrators to search for the relevant tools was not circulated until March 2002. A 2001 Government Accountability Office review had already found that the Department of Defense faced difficulties coordinating incident reporting, assessing attacks and sharing information among its computer-response organisations.[WIRED]wired.comattempts to extradite him for charges related to what is described as the largest successful hacking effort against American military net…

Access Methods illustration 2

What is established and what remains alleged

The broad access mechanism is better documented than many of McKinnon’s UFO-related claims. Official records, the indictment and his own interviews all support the central sequence: he scanned internet-connected Windows systems, exploited weak authentication, obtained administrator privileges, installed remote-control software and used compromised machines to search for more targets.[parliament.uk]publications.parliament.ukUK Parliament House of LordsUK ParliamentHouse of Lords - Mckinnon V Government of The United States of America and Another…

However, precision matters. The Virginia indictment was an accusation, and extradition judgments summarised the American case rather than determining guilt at trial. McKinnon admitted entering US government computers but disputed allegations that he deliberately caused the extensive disruption and damage attributed to him. Because extradition was eventually blocked and no completed prosecution tested the evidence before a jury, claims about individual deletions, exact intentions and particular incidents should remain attributed to US authorities.[UK Parliament]publications.parliament.ukUK Parliament House of LordsUK ParliamentHouse of Lords - Mckinnon V Government of The United States of America and Another…

There is also no basis for portraying the networks as one unified classified military system. Many of the computers were internet-facing, and US officials described information taken in some incidents as sensitive but unclassified. McKinnon said his aim was ultimately to find classified material, but the fact that he reached government machines does not establish that he penetrated the most protected classified networks.[WIRED]wired.comattempts to extradite him for charges related to what is described as the largest successful hacking effort against American military net…

That distinction makes the security failure no less important. Unclassified systems can still hold personnel data, operational records, network credentials and connections useful for further intrusion. The alleged disruption to email, user accounts and naval support networks showed how ordinary administrative computers could affect real government functions even when they did not contain the most secret intelligence.

Security lessons from the intrusions

The McKinnon case demonstrates how several modest weaknesses can combine into a serious compromise. No single failure explains the full intrusion. The risk arose from the sequence:

  • Internet-facing administrative services made government computers discoverable and reachable.
  • Blank, weak or recoverable passwords allowed some administrator accounts to be entered.
  • Excessive administrator privileges let an intruder install software and inspect credential files.
  • Remote-management tools provided persistent control using apparently legitimate software.
  • Connected networks allowed compromised computers to become launching points for further searches.
  • Uneven monitoring and delayed warning gave the activity time to continue across many systems.

The most important lesson is that network sensitivity does not compensate for poor basic security. A military organisation may possess sophisticated intelligence systems while still being exposed through ordinary Windows machines, copied deployment images and neglected local accounts. The intruder follows the easiest route available, not the route that best reflects an institution’s prestige or resources.

Modern defences address this chain through layered controls: strong and unique administrator credentials, multi-factor authentication, restricted remote access, rapid patching, network segmentation, central software controls, detailed logging and alerts for unusual scanning or account use. Segmentation is particularly important because it limits how far an attacker can travel after one machine is compromised.

The episode also shows why legitimate administration software must be monitored by behaviour and authorisation, not merely by whether antivirus software labels it malicious. A remote-control program used by approved support staff may be harmless; the same program installed unexpectedly on a military server is a security incident. Application allow-listing, installation logs and central endpoint monitoring can reveal that difference.

McKinnon’s access was therefore less a display of extraordinary hacking than a demonstration of accumulated institutional neglect. His UFO-searching motive made the case famous, but the route he used was prosaic: exposed computers, weak credentials, broad connectivity and inadequate oversight. That ordinariness is precisely what made the intrusions so revealing.

Access Methods illustration 3

Amazon book picks

Further Reading

Books and field guides related to How Were Military Networks Left So Exposed?. Use these as the next step if you want deeper reading beyond the article.

BookCover for The Cuckoo's Egg

The Cuckoo's Egg

By Cliff Stoll

This is the true story of how a systems manager at Lawrence Berkeley Lab singlehandedly tracked down and helped capture a computer hacker...

BookCover for Ghost in the Wires

Ghost in the Wires

By Kevin Mitnick

In this "intriguing, insightful and extremely educational" novel, the world's most famous hacker teaches you easy cloaking and counter-me...

eBay marketplace picks

Marketplace Samples

Live-tested eBay searches with available results related to this page.

UsingUSA

Selected fromhacker t shirt oneBay.co.uk.

Endnotes

1. Source: publications.parliament.uk
Title: UK Parliament House of Lords
Link:https://publications.parliament.uk/pa/ld200708/ldjudgmt/jd080730/mckinn-1.htm

Source snippet

UK ParliamentHouse of Lords - Mckinnon V Government of The United States of America and Another...

2. Source: justice.gov
Link:https://www.justice.gov/archive/criminal/cybercrime/press-releases/2002/mckinnonIndict.htm

Source snippet

Department of JusticeLondon, England Hacker Indicted Under Computer Fraud and Abuse Act For Accessing Military Computers (November 12, 2002)...

Published: November 12, 2002

3. Source: wired.com
Link:https://www.wired.com/2002/11/brit-fights-hacking-extradition

Source snippet

attempts to extradite him for charges related to what is described as the largest successful hacking effort against American military net...

4. Source: justice.gov
Title: Department of Justice
Link:https://www.justice.gov/archive/usao/nj/Press/files/pdffiles/Older/edva_mckinnon_indictment.pdf

5. Source: wired.com
Title: govt networks get an f
Link:https://www.wired.com/2001/11/govt-networks-get-an-f

Source snippet

government an "F" for the protection of federal computer networks, down from a "D-minus" in 2000. The failing grades were based on assess...

6. Source: wired.com
Title: Dot-Mil Hacker’s Download Mistake
Link:https://www.wired.com/2002/11/dot-mil-hackers-download-mistake

7. Source: justice.gov
Link:https://www.justice.gov/archive/criminal/cybercrime/press-releases/2002/mckinnonIndict2.htm

8. Source: wired.com
Title: ufo hacker tells what he found
Link:https://www.wired.com/2006/06/ufo-hacker-tells-what-he-found/

9. Source: hansard.parliament.uk
Title: uk Gary Mc Kinnon (Extradition)
Link:https://hansard.parliament.uk/commons/2009-12-01/debates/09120144000002/GaryMckinnon%28Extradition%29

10. Source: committees.parliament.uk
Link:https://committees.parliament.uk/writtenevidence/53322/html/

11. Source: malicious.life
Link:https://malicious.life/episode/us_vs_gary_mckinnon/

12. Source: time.com
Title: hack attack 2
Link:https://time.com/archive/6943962/hack-attack-2/

13. Source: theguardian.com
Link:https://www.theguardian.com/theguardian/2005/jul/09/weekend7.weekend2

Source snippet

The GuardianGame over | Gary McKinnon9 Jul 2005 — He downloaded a program that searched for computers and pinpointed administrator user n...

14. Source: tarrdaniel.com
Link:https://www.tarrdaniel.com/documents/Ufology/gary_mckinnon_case.html

Source snippet

Tarr DanielUFO - Ufology - The Gary McKinnon CaseOn this particular network the image had been made with a blank administrator password...

15. Source: GOV.UK
Title: gary mckinnon extradition case home secretarys statement
Link:https://www.gov.uk/government/speeches/gary-mckinnon-extradition-case-home-secretarys-statement

16. Source: youtube.com
Link:https://www.youtube.com/watch?v=FIlHu3YUBN4

17. Source: theguardian.com
Title: gary mckinnon feels set free
Link:https://www.theguardian.com/world/2012/oct/17/gary-mckinnon-feels-set-free

18. Source: theguardian.com
Link:https://www.theguardian.com/uk/2007/apr/03/politics.usa

19. Source: theguardian.com
Link:https://www.theguardian.com/technology/2008/aug/28/hacking.security

20. Source: theguardian.com
Link:https://www.theguardian.com/technology/2005/jul/27/hacking.internetcrime

21. Source: theguardian.com
Link:https://www.theguardian.com/world/2008/jul/27/internationalcrime.hacking

22. Source: Wikipedia
Title: Gary Mc Kinnon
Link:https://en.wikipedia.org/wiki/Gary_McKinnon

23. Source: GOV.UK
Title: latest on [gary mckinnon case]({{ ‘mc-kinnon-case/’ | relative_url }})
Link:https://www.gov.uk/government/news/latest-on-gary-mckinnon-case

24. Source: assets.publishing.service.gov.uk
Title: public views 4
Link:https://assets.publishing.service.gov.uk/media/5a7aaeb5e5274a34770e661b/public-views-4.pdf

25. Source: abcnews.com
Link:https://abcnews.com/International/story?id=1945581&page=1

Additional References

26. Source: medium.com
Link:https://medium.com/the-lindberg-interviews/interview-with-ufo-hacker-gary-mckinnon-5aa5d366828b

Source snippet

Interview with UFO hacker Gary McKinnonGetting access wasn't difficult as many local administrator passwords were shockingly left b...

27. Source: youtube.com
Title: Gary Mc Kinnon: No hacking charges in UK
Link:https://www.youtube.com/watch?v=xAhzZRa2aws

Source snippet

The Man Who Hacked the U.S. Government This video provides detailed context on how Gary McKinnon scanned and accessed unsecured U.S. gove...

28. Source: youtube.com
Title: Hacking for UFOs and fighting for his life. Who is Gary Mc Kinnon?
Link:https://www.youtube.com/watch?v=OImdnvQx7sQ

Source snippet

The Most Dangerous File the Hacker Found on NASA Servers... (Aliens?!)...

29. Source: gao.gov
Link:https://www.gao.gov/products/gao

30. Source: webmasterworld.com
Link:https://www.webmasterworld.com/foo/3963063-2-30.htm

31. Source: reddit.com
Link:https://www.reddit.com/r/worldnews/comments/wtabz/computer_hacker_gary_mckinnon_has_no_choice_but/

32. Source: linkedin.com
Link:https://www.linkedin.com/posts/davidewers_cybersecurity-informationsecurity-governance-activity-7483543500316168192-nIRi

33. Source: reddit.com
Link:https://www.reddit.com/r/hacking/comments/1etqs6b/how_gary_mckinnon_did_what_he_did/

34. Source: hackcur.io
Link:https://hackcur.io/raising-the-bar-how-the-uk-extradition-laws-were-put-to-the-test/

35. Source: cybereason.com
Link:https://www.cybereason.com/blog/malicious-life-podcast-the-u.s-vs.-gary-mckinnon