Within Access Methods

Blank Admin Password

Gary McKinnon's account of entering US military and NASA systems has often been portrayed as the work of an exceptionally skilled hacker.

17 sources 3 graphics
Preview for Blank Admin Password

What investigators and McKinnon said about passwordless accounts

The exact method used against every compromised computer has never been described in complete technical detail in public court records. Even so, the available evidence is remarkably consistent on one point: weak administrator credentials were central to the intrusions.

Blank Admin Password illustration 1

McKinnon repeatedly stated that he scanned government address ranges looking for Windows computers whose administrator accounts had blank passwords. In one interview he recalled that, after scanning thousands of machines, “there were always a few hundred with blank passwords”. In another, he described using software that automatically identified administrator accounts with no password configured.[The Guardian]theguardian.comThe Guardian Gary Mc Kinnon | Life and style | The GuardianThe GuardianGary McKinnon | Life and style | The GuardianApril 21, 2007…Published: April 21, 2007

US prosecutors described the same events in more formal language. The Virginia indictment alleged that McKinnon scanned military networks, obtained administrative privileges, installed remote administration software, copied password files and then used compromised systems to locate additional victims. The legal documents do not rely solely on the phrase “blank password”, but they consistently describe unauthorised acquisition of administrator-level access before further activity occurred.[Department of Justice]justice.govDepartment of JusticeLondon, England Hacker Indicted Under Computer Fraud and Abuse Act For Accessing Military Computers (November 12, 2002)…Published: November 12, 2002

These accounts are not contradictory. Security investigators and journalists have reported that different computers were exposed in different ways. Some administrator accounts apparently had no password at all, while others used default or easily guessed passwords. The common feature was that authentication was so weak that no sophisticated exploit was required.[The Guardian]theguardian.comThe GuardianHacker's progress: how McKinnon pierced Pentagon security | UK news | The GuardianApril 3, 2007…Published: April 3, 2007

Why administrator access gave such broad control

A Windows administrator account is fundamentally different from an ordinary user account. It has permission to install software, change security settings, create or delete user accounts, inspect almost every file on the system and manage network services.

Once an attacker authenticates as an administrator, the operating system generally treats that person as a trusted system manager rather than an outsider. In practical terms, this meant that McKinnon did not need to exploit additional software vulnerabilities after logging in. The account itself already possessed the authority to perform powerful administrative actions.

According to the indictment, administrator privileges allowed him to:

  • install the commercial remote-control program RemotelyAnywhere;
  • copy files containing account names and encrypted passwords;
  • add or remove software;
  • delete user accounts and operating system files; and
  • use one compromised computer to search for additional military systems.[justice.gov]justice.govDepartment of JusticeLondon, England Hacker Indicted Under Computer Fraud and Abuse Act For Accessing Military Computers (November 12, 2002)…Published: November 12, 2002

This distinction is important. The damage alleged by prosecutors flowed largely from legitimate administrative capabilities being exercised without authorisation, rather than from bypassing technical restrictions after entry.

Blank Admin Password illustration 2

How weak passwords turned isolated flaws into wider exposure

A single passwordless administrator account could become much more significant than a single vulnerable computer.

Once logged into one trusted machine, an attacker could examine network information, identify connected systems and sometimes use existing trust relationships between computers. McKinnon himself described moving from one machine to another after first gaining access to an exposed system, while prosecutors alleged that compromised computers were used to locate further military and NASA targets.[theguardian.com]theguardian.comThe Guardian Gary Mc Kinnon | Life and style | The GuardianThe GuardianGary McKinnon | Life and style | The GuardianApril 21, 2007…Published: April 21, 2007

The problem became even worse when organisations deployed many computers from the same standard system image. McKinnon later claimed that he encountered networks in which thousands of computers inherited identical administrator configurations from a master installation. Investigators interviewed years later said they observed examples where insecure administrator settings had indeed been replicated across large numbers of machines through cloned system images. Although precise numbers cannot be independently verified from court records, the mechanism is technically plausible and consistent with common Windows deployment practices of the period.[Future Intelligence]futureintelligence.co.ukFuture Intelligence"Gary McKinnon was unlucky. He's not even a very good hacker" - Future IntelligenceOctober 18, 2012…Published: October 18, 2012

This meant that correcting one insecure configuration was often not enough. If the same blank administrator password had been copied onto hundreds or thousands of systems, every deployed machine inherited the same weakness.

Why this reflected wider security problems rather than a unique trick

The success of blank-password logins also reflected the broader state of US government cyber security in the early 2000s.

At the time, multiple federal reviews criticised weak password management, inconsistent security policies and poor system administration across government agencies. Contemporary reporting highlighted that even basic measures such as changing default passwords were sometimes neglected on systems connected to important government networks.[theguardian.com]theguardian.comThe GuardianHacker's progress: how McKinnon pierced Pentagon security | UK news | The GuardianApril 3, 2007…Published: April 3, 2007

This context helps explain why McKinnon’s methods appeared surprisingly unsophisticated. His case is frequently remembered because of his stated search for evidence relating to UFOs, but from a technical perspective it demonstrated something more mundane: critical government systems were often relying on authentication practices that failed at the most basic level.

Blank administrator passwords did not magically expose military computers. They removed the principal barrier designed to distinguish authorised administrators from everyone else. Once that barrier disappeared, the operating system granted an outsider the same authority that had been intended for trusted system staff, allowing routine administrative functions to become the basis for far more extensive network compromise.[theguardian.com]theguardian.comThe Guardian Game over | Gary Mc Kinnon | The GuardianThe Guardian Game over | Gary Mc Kinnon | The Guardian

Blank Admin Password illustration 3

Amazon book picks

Further Reading

Books and field guides related to Blank Admin Password. Use these as the next step if you want deeper reading beyond the article.

BookCover for Windows Internals

Windows Internals

By Pavel Yosifovich, Mark E. Russinovich et al.

The definitive guide–fully updated for Windows 10 and Windows Server 2016 Delve inside Windows architecture and internals, and see how co...

eBay marketplace picks

Marketplace Samples

Live-tested eBay searches with available results related to this page.

UsingUSA

Selected fromhacker t shirt oneBay.co.uk.

Endnotes

1. Source: publications.parliament.uk
Title: UK Parliament House of Lords
Link:https://publications.parliament.uk/pa/ld200708/ldjudgmt/jd080730/mckinn-1.htm

Source snippet

UK ParliamentHouse of Lords - Mckinnon V Government of The United States of America and AnotherJuly 30, 2008...

Published: July 30, 2008

2. Source: justice.gov
Link:https://www.justice.gov/archive/criminal/cybercrime/press-releases/2002/mckinnonIndict.htm

Source snippet

Department of JusticeLondon, England Hacker Indicted Under Computer Fraud and Abuse Act For Accessing Military Computers (November 12, 2002)...

Published: November 12, 2002

3. Source: justice.gov
Link:https://www.justice.gov/archive/criminal/cybercrime/press-releases/2002/mckinnonIndict2.htm

Source snippet

Department of JusticeBritish National Charged with Hacking Into N.J. Naval Weapons Station Computers, Disabling Network After Sept. 11 (N...

4. Source: wired.com
Title: Brit Fights Hacking Extradition | WIRED
Link:https://www.wired.com/2002/11/brit-fights-hacking-extradition/

Source snippet

Brit Fights Hacking Extradition | WIRED...

5. Source: wired.com
Title: Accused Pentagon Hacker in Court | WIRED
Link:https://www.wired.com/2005/06/accused-pentagon-hacker-in-court/

Source snippet

Accused Pentagon Hacker in Court | WIRED...

6. Source: wired.com
Title: dot mil hackers download mistake
Link:https://www.wired.com/2002/11/dot-mil-hackers-download-mistake/

7. Source: theguardian.com
Title: The Guardian Game over | Gary Mc Kinnon | The Guardian
Link:https://www.theguardian.com/theguardian/2005/jul/09/weekend7.weekend2

8. Source: theguardian.com
Title: The Guardian Gary Mc Kinnon | Life and style | The Guardian
Link:https://www.theguardian.com/theobserver/2007/apr/22/features.magazine7

Source snippet

The GuardianGary McKinnon | Life and style | The GuardianApril 21, 2007...

Published: April 21, 2007

9. Source: theguardian.com
Link:https://www.theguardian.com/uk/2007/apr/03/politics.usa

Source snippet

The GuardianHacker's progress: how McKinnon pierced Pentagon security | UK news | The GuardianApril 3, 2007...

Published: April 3, 2007

10. Source: futureintelligence.co.uk
Link:https://www.futureintelligence.co.uk/2012/10/18/gary-mckinnon-was-unlucky-hes-not-even-a-good-hacker/

Source snippet

Future Intelligence"Gary McKinnon was unlucky. He's not even a very good hacker" - Future IntelligenceOctober 18, 2012...

Published: October 18, 2012

11. Source: schneier.com
Title: Gary Mc Kinnon
Link:https://www.schneier.com/?p=2390

Source snippet

Tags: courts, hacking, law enforcement, military, UK Posted on August 4, 2008 at 12:58 PM • 37 Comments COMMENT...

Published: August 4, 2008

12. Source: theguardian.com
Link:https://www.theguardian.com/technology/2008/jun/16/hacking.internationalcrime

Additional References

13. Source: youtube.com
Link:https://www.youtube.com/watch?v=b-3RhyfYk58

Source snippet

This selection provides direct background context on how systems administrator Gary McKinnon exploited blank default administrator passwo...

14. Source: youtube.com
Title: Ancient Aliens: Hacking NASA Secrets (Season 12, Episode 9)
Link:https://www.youtube.com/watch?v=20rWFDfh68Y

Source snippet

Ancient Aliens: TOP 10 ALIEN ENCOUNTERS OF 2023 | PART 2...

15. Source: youtube.com
Title: Gary Mc Kinnon BBC Interview
Link:https://www.youtube.com/watch?v=IhUC80M8X1s

Source snippet

Ancient Aliens: Hacking NASA Secrets (Season 12, Episode 9)...

16. Source: youtube.com
Title: The Interview They Tried to Erase From the Internet
Link:https://www.youtube.com/watch?v=WvILY-h-6_Y

Source snippet

Gary McKinnon BBC Interview - Eyes on Cinema...

17. Source: youtube.com
Title: The Man Who Hacked the U.S. Government
Link:https://www.youtube.com/watch?v=ND0zQX1rGdg

Source snippet

The Interview They Tried to Erase From the Internet...