Within UFO Hackers

Why Early Government Networks Were Easy Targets

Poor password practices and loosely connected systems made 1990s and early-2000s government networks unusually vulnerable to persistent outsiders.

127 sources 3 graphics
Preview for Why Early Government Networks Were Easy Targets

On this page

  • Weak authentication practices
  • Trust between connected systems
  • Security reforms after major breaches

Introduction

The UFO-hacker cases of the 1990s and early 2000s were made possible less by extraordinary hacking skill than by an awkward stage in government computing. Military and civilian agencies were rapidly connecting thousands of previously separate machines to wider networks, while password discipline, software patching, monitoring and central oversight lagged behind. An outsider who found one poorly protected computer could sometimes install remote-control software, capture credentials or use the compromised machine as a stepping stone towards other systems.

Overview image for Early Insecurity

Gary McKinnon’s intrusions illustrate this gap particularly clearly. He said he searched for administrator accounts with weak or absent passwords, while US legal proceedings alleged that he obtained privileged access and installed remote-administration software. His UFO interests explain why he looked; the insecure network environment explains how a lone individual using an ordinary internet connection could remain inside government systems for an extended period.[parliament.uk]publications.parliament.ukmckinn 1UK ParliamentMckinnon V Government of The United States of America…30 Jul 2008 — Having gained access to those accounts he installed u…

Weak passwords turned scanning into access

In modern accounts, “hacking the Pentagon” can sound like defeating a single, heavily fortified central system. The reality was more fragmented. The Department of Defense, NASA and their contractors operated large numbers of computers administered by different units, laboratories and support offices. Security depended on the configuration of each exposed machine, and a forgotten server or badly managed account could provide a far easier entry point than a mission-critical system.

McKinnon described systematically scanning ranges of internet addresses and checking Windows computers for administrative accounts that had no password. Contemporary reporting quoted him saying that some administrator usernames were effectively left unprotected. The House of Lords’ account of the extradition case did not independently verify every detail of his public explanation, but it recorded the US allegation that, after obtaining administrator-level access, he installed a program called RemotelyAnywhere, allowing continued control of compromised machines.[The Guardian]theguardian.comThe GuardianGame over | Gary McKinnon9 Jul 2005 —… administrator user names that had no passwords. Basically, what… "Maybe I'd been…

That alleged method fitted a broader federal problem. In August 2001, while McKinnon’s activity was under way, the US General Accounting Office reported that agencies frequently lacked effective controls over access to computer resources. Its review found recurring weaknesses in the protection of powerful programs, sensitive files and administrative functions. A separate GAO survey covering 22 agencies documented access-control deficiencies across the federal government rather than at one isolated department.[GAO]gao.govInformation Security: Code Red, Code Red II, and Sir CamInformation Security: Code Red, Code Red II, and SirCam…August 29, 2001 — 29 Aug 2001 — these attacks have infected millions of com…Published: August 29, 2001

Poor authentication was not simply a matter of users choosing memorable words. The weaknesses included:

  • accounts with blank, default or easily guessed passwords;
  • administrator privileges granted more widely than necessary;
  • obsolete accounts that remained active;
  • credentials transmitted across local networks without encryption;
  • systems permitting unauthenticated connections;
  • limited review of who possessed privileged access.

A 2002 audit of the US Army Corps of Engineers, for example, found that usernames and passwords were still being transmitted unencrypted and that some servers allowed unauthenticated connections. GAO warned that captured credentials could be reused to obtain further privileges or to attack other Department of Defense networks through the Corps’ systems.[GAO]gao.govGAO-02-589 Information Security: Corps of Engineers…June 10, 2002 — 10 Jun 2002 — network could capture usernames and passwords and…Published: June 10, 2002

The distinction matters when assessing UFO hackers such as McKinnon. Their access did not establish that the machines contained extraordinary secrets. It established that ordinary administrative failures could expose government computers to persistent outsiders. The supposed prize might have been exotic, but the entry mechanism was usually mundane.

Early Insecurity illustration 1

Connected systems amplified a single mistake

Weak passwords became more dangerous because government networks were increasingly interconnected. A compromised computer was not merely one lost machine; it could become a trusted launch point for exploring neighbouring systems.

Early networks often relied heavily on the assumption that traffic originating from an internal or recognised host was safer than traffic arriving directly from the public internet. Once an intruder obtained administrator privileges, that assumption could be exploited. The attacker could inspect configuration files, collect account information, install a “sniffer” to capture network traffic, or use the machine to approach systems that would otherwise reject an outside connection.

The 1998 Solar Sunrise incident demonstrated this pattern shortly before McKinnon’s campaign. Two American teenagers and an Israeli hacker exploited a known vulnerability in Sun Solaris systems to obtain root access—the Unix equivalent of full administrative control—on government and private computers. They then placed network-sniffing programs on compromised hosts. A Justice Department planning document noted that the vulnerability was already known, while congressional evidence concluded that the intrusion could have been prevented had available patches been installed.[Department of Justice]justice.govDepartment of Justiceyear interagency counterterrorism and technology crime planDepartment of Justiceyear interagency counterterrorism and technology crime plan

Earlier attacks on the US Air Force’s Rome Laboratory showed an even more striking form of network hopping. GAO’s 1996 investigation concluded that a small group of intruders had been able to take control of systems at the laboratory, monitor activity and use the compromised network to attack numerous additional sites. Rome Laboratory was a major command-and-control research facility, yet weaknesses in administration and detection allowed outsiders to operate through its computers rather than merely visit them once.[National Security Archive]nsarchive2.gwu.eduNational Security Archive AIMD-96-84 Information SecurityNational Security Archive AIMD-96-84 Information Security

This is the crucial mechanism behind the era’s most startling intrusion stories:

  1. Find the weakest exposed host. The initial target might be a support, research or administrative computer rather than a protected operational system.
  2. Obtain elevated privileges. Blank passwords, unpatched software or badly managed accounts could provide administrator or root access.
  3. Create persistence. Remote-control tools or replacement accounts allowed the intruder to return without repeating the original exploit.
  4. Collect local knowledge. Account files, network addresses and captured traffic revealed how other systems were connected.
  5. Move through trusted pathways. The compromised government machine became a platform for approaching further targets.
  6. Avoid or erase scrutiny. Weak logging and decentralised incident reporting made prolonged activity harder to reconstruct.

US prosecutors alleged that McKinnon followed several elements of this model: scanning for vulnerable machines, extracting account information, installing remote-administration software and deleting system logs. McKinnon disputed the government’s portrayal of him as destructive, and the accusations were never tested in a completed US criminal trial. The evidence nevertheless shows why privileged access to a modestly protected machine could be far more consequential than the initial login suggested.[pinsentmasons.com]pinsentmasons.compentagon hacker mckinnon fights extraditionpentagon hacker mckinnon fights extradition

Security teams could not see the whole network

The expansion of internet connectivity also created an organisational problem. Federal computing was dispersed among departments, agencies, commands, laboratories, contractors and local administrators. No single operator necessarily had a complete inventory of internet-facing machines, their software versions or the accounts active on them.

GAO reported in 1996 that the Department of Defense might have experienced as many as 250,000 attacks in the previous year. Of attacks subjected to controlled testing, approximately 65 per cent successfully penetrated systems, while only a small proportion were detected and still fewer were reported. The figures were estimates rather than a complete incident count, but they exposed the imbalance between the number of reachable systems and the department’s ability to monitor them.[GAO]gao.govOpen source on gao.gov.

The same report pointed to inadequate password management, uneven technical expertise among administrators and the absence of effective department-wide security practices. A later GAO review recalled that foreign hackers had penetrated Department of Defense systems as early as 1990–91 because of poor password management and limited administrator expertise.[GAO]gao.govDOD Faces Challenges In Its Cyber ActivitiesDOD Faces Challenges In Its Cyber Activities

Detection was especially difficult when an intruder behaved quietly. A person searching documents, browsing directories or downloading files slowly might generate less obvious disruption than a computer virus or denial-of-service attack. Remote sessions could also be routed through systems in several countries, complicating attribution and delaying cooperation between network owners and law-enforcement agencies. Congressional testimony about Solar Sunrise stressed that attackers could disguise their origin, manipulate logs and pass through numerous jurisdictions before reaching the ultimate target.[GovInfo]govinfo.govCHRG 106shrg63940CHRG 106shrg63940

For a UFO-motivated intruder, patience was an advantage. The objective was generally not to make a public website fail but to remain unnoticed while searching for suggestive filenames, photographs, personnel lists or references to classified projects. A security model focused mainly on keeping services running could therefore miss the quieter theft or examination of information.

Early Insecurity illustration 2

The vulnerability was systemic, not unique to NASA

McKinnon’s story is sometimes framed as proof that NASA or the US military possessed exceptionally careless systems. Contemporary audits suggest a broader conclusion: insecure access controls were a government-wide management problem.

In 1997, GAO formally designated federal information security a government-wide “high-risk” area. By the early 2000s it was still reporting significant weaknesses across all 24 major federal agencies it reviewed. Congressional assessments in 2001 assigned failing security grades to much of the federal government, including major departments, while NASA received only a middling grade.[GAO]gao.govOpen source on gao.gov.

These findings do not mean every federal computer was open or that intruders could freely enter classified networks. Many of the publicly documented compromises involved unclassified systems, research machines, administrative services or network edges. Classified environments were ordinarily separated and subjected to additional controls. Yet “unclassified” did not mean harmless: such machines could contain operational schedules, personnel information, technical research or credentials useful for reaching other systems.

The sprawling scale of Department of Defense computing made consistent protection particularly difficult. Local units had different budgets, technical staff and operational priorities. Connecting systems improved communication and research, but every connection created another configuration to maintain and another pathway whose trust assumptions could be abused.

This helps resolve an apparent contradiction in the UFO-hacker narrative. The institutions being targeted were among the world’s most technically capable, yet some of their computers were penetrated through elementary weaknesses. Technical sophistication in aircraft, space science or weapons research did not automatically produce disciplined password management on every office server.

Major breaches forced security to become a programme

By the late 1990s, recurring intrusions had made it clear that isolated technical fixes were insufficient. Agencies needed security to become a continuous management function: identify every system, assign responsibility, control privileged access, install patches promptly, monitor activity and prepare a coordinated response when compromise occurred.

After Solar Sunrise, Department of Defense measures described to Congress included tighter control over identifying vulnerable systems, patching exposed software, deploying intrusion-detection tools at important network points, expanding emergency response teams and preparing contingency plans for network disruption. These measures directly addressed the mechanisms that had allowed earlier outsiders to remain active.[GovInfo]govinfo.govCHRG 106shrg68563CHRG 106shrg68563

Congress then imposed more systematic obligations. The Government Information Security Reform provisions of 2000 required agencies to establish security programmes and conduct regular evaluations. The Federal Information Security Management Act of 2002, known as FISMA, made information security an agency-wide responsibility and assigned the National Institute of Standards and Technology a central role in developing federal standards and guidance.[WIRED]wired.comAre U.S. Agencies Hacker-Proof?Are U.S. Agencies Hacker-Proof?

The resulting framework did not depend on one defensive product. It required controls covering identification and authentication, access management, audit records, configuration management, incident response, risk assessment and system integrity. Later federal standards formalised these areas as minimum requirements rather than optional practices left entirely to individual administrators.[NIST Publications]nvlpubs.nist.govPublications FIPS 199, Standards for Security Categorization of FederalPublications FIPS 199, Standards for Security Categorization of Federal

In practical terms, the reform agenda aimed to remove the conditions on which persistent outsiders depended:

  • blank and default credentials were to be eliminated;
  • privileged accounts were to be restricted and reviewed;
  • known vulnerabilities were to be patched systematically;
  • logs were to be collected and examined;
  • unusual remote access was to trigger investigation;
  • connections between systems were to be documented and controlled;
  • incidents were to be reported beyond the affected local office.

Implementation remained uneven, and federal auditors continued to identify serious weaknesses after FISMA. The change was nevertheless important. Security was no longer supposed to rest primarily on the vigilance of whichever administrator happened to maintain a particular machine.

Early Insecurity illustration 3

What the UFO-hacker era actually reveals

The enduring lesson of the UFO-hacker cases is not that curiosity could somehow overcome impenetrable national-security technology. It is that, during a period of rapid network growth, determined outsiders could search huge numbers of systems until they found the small minority that had been badly configured.

McKinnon’s claimed UFO discoveries remain unverified because he preserved no independently authenticated files or images from the material he said he viewed. The documented security environment, by contrast, is unusually well supported. Federal audits, court records and congressional investigations consistently describe missing access controls, inadequate password management, delayed patching, weak monitoring and networks whose internal connections magnified the consequences of one compromised machine.[wired.com]wired.comufo hacker tells what he foundWIRED'UFO Hacker' Tells What He Found21 Jun 2006 — The search for proof of the existence of UFOs landed Gary McKinnon in a world of troub…

That distinction is central to understanding the period. The intrusions provide strong evidence of early government-network insecurity. They do not, by themselves, authenticate the UFO interpretations that motivated some of the intruders. The most remarkable verified fact is therefore not what the hackers claimed to find, but how ordinary security failures allowed them to search at all.

Amazon book picks

Further Reading

Books and field guides related to Why Early Government Networks Were Easy Targets. Use these as the next step if you want deeper reading beyond the article.

eBay marketplace picks

Marketplace Samples

Live-tested eBay searches with available results related to this page.

UsingUSA

Selected fromUFO disclosure print oneBay.co.uk.

Endnotes

1. Source: publications.parliament.uk
Title: mckinn 1
Link:https://publications.parliament.uk/pa/ld200708/ldjudgmt/jd080730/mckinn-1.htm

Source snippet

UK ParliamentMckinnon V Government of The United States of America...30 Jul 2008 — Having gained access to those accounts he installed u...

2. Source: wired.com
Title: ufo hacker tells what he found
Link:https://www.wired.com/2006/06/ufo-hacker-tells-what-he-found/

Source snippet

WIRED'UFO Hacker' Tells What He Found21 Jun 2006 — The search for proof of the existence of UFOs landed Gary McKinnon in a world of troub...

3. Source: justice.gov
Link:https://www.justice.gov/archive/usao/nj/Press/files/pdffiles/Older/edva_mckinnon_indictment.pdf

Source snippet

Department of JusticeIndictmentDefendant GARY MCKINNON was an unemployed computer system administrator living in London, England. deleted...

4. Source: gao.gov
Title: Information Security: Code Red, Code Red II, and Sir Cam
Link:https://www.gao.gov/assets/gao-01-1073t.pdf

Source snippet

Information Security: Code Red, Code Red II, and SirCam...August 29, 2001 — 29 Aug 2001 — these attacks have infected millions of com...

Published: August 29, 2001

5. Source: gao.gov
Link:https://www.gao.gov/assets/aimd-00-32r.pdf

Source snippet

AIMD-00-32R Information Security: Weaknesses at 22...In July 1999, we reported that the Department of Agriculture's (USDA) National...

Published: July 1999

6. Source: gao.gov
Link:https://www.gao.gov/assets/gao-02-589.pdf

Source snippet

GAO-02-589 Information Security: Corps of Engineers...June 10, 2002 — 10 Jun 2002 — network could capture usernames and passwords and...

Published: June 10, 2002

7. Source: justice.gov
Title: Department of Justiceyear interagency counterterrorism and technology crime plan
Link:https://www.justice.gov/sites/default/files/oip/legacy/2014/07/23/crime-plan.pdf

8. Source: govinfo.gov
Title: CHRG 106shrg68563
Link:https://www.govinfo.gov/content/pkg/CHRG-106shrg68563/pdf/CHRG-106shrg68563.pdf

9. Source: govinfo.gov
Title: GAOREPORTS AIMD 96 84
Link:https://www.govinfo.gov/content/pkg/GAOREPORTS-AIMD-96-84/html/GAOREPORTS-AIMD-96-84.htm

10. Source: gao.gov
Link:https://www.gao.gov/products/t-aimd

11. Source: gao.gov
Title: DOD Faces Challenges In Its Cyber Activities
Link:https://www.gao.gov/assets/a321824.html

12. Source: gao.gov
Link:https://www.gao.gov/products/t-imtec

13. Source: govinfo.gov
Title: CHRG 106shrg63940
Link:https://www.govinfo.gov/content/pkg/CHRG-106shrg63940/html/CHRG-106shrg63940.htm

14. Source: govinfo.gov
Title: CHRG 106shrg69335
Link:https://www.govinfo.gov/content/pkg/CHRG-106shrg69335/html/CHRG-106shrg69335.htm

15. Source: gao.gov
Link:https://www.gao.gov/assets/a235056.html

16. Source: gao.gov
Link:https://www.gao.gov/assets/a237064.html

17. Source: wired.com
Title: govt networks get an f
Link:https://www.wired.com/2001/11/govt-networks-get-an-f

18. Source: wired.com
Title: Are U.S. Agencies Hacker-Proof?
Link:https://www.wired.com/2001/03/are-u-s-agencies-hacker-proof

19. Source: csrc.nist.gov
Link:https://csrc.nist.gov/topics/laws-and-regulations/laws/FISMA

20. Source: nvlpubs.nist.gov
Title: Publications FIPS 199, Standards for Security Categorization of Federal
Link:https://nvlpubs.nist.gov/nistpubs/fips/nist.fips.199.pdf

21. Source: nvlpubs.nist.gov
Link:https://nvlpubs.nist.gov/nistpubs/fips/nist.fips.200.pdf

22. Source: gao.gov
Title: ocg 99 4
Link:https://www.gao.gov/assets/ocg-99-4.pdf

23. Source: gao.gov
Link:https://www.gao.gov/assets/a301881.html

24. Source: gao.gov
Link:https://www.gao.gov/assets/a280296.html

25. Source: gao.gov
Link:https://www.gao.gov/products/gao

26. Source: gao.gov
Link:https://www.gao.gov/assets/a241727.html

27. Source: gao.gov
Link:https://www.gao.gov/assets/a277718.html

28. Source: gao.gov
Link:https://www.gao.gov/assets/t-aimd-00-330.pdf

29. Source: gao.gov
Link:https://www.gao.gov/assets/a250484.html

30. Source: gao.gov
Link:https://www.gao.gov/assets/a311584.html

31. Source: gao.gov
Link:https://www.gao.gov/assets/a236721.html

32. Source: gao.gov
Link:https://www.gao.gov/assets/gao-02-231t.pdf

33. Source: gao.gov
Title: gao 19 105
Link:https://www.gao.gov/products/gao

34. Source: gao.gov
Title: gao 06 672
Link:https://www.gao.gov/products/gao

35. Source: gao.gov
Link:https://www.gao.gov/assets/a279089.html

36. Source: gao.gov
Link:https://www.gao.gov/assets/t-aimd-00-171.pdf

37. Source: gao.gov
Link:https://www.gao.gov/assets/a237104.html

38. Source: gao.gov
Link:https://www.gao.gov/assets/a246517.html

39. Source: gao.gov
Link:https://www.gao.gov/assets/a301500.html

40. Source: gao.gov
Link:https://www.gao.gov/assets/a237380.html

41. Source: gao.gov
Link:https://www.gao.gov/assets/a275647.html

42. Source: gao.gov
Title: gao 15 509
Link:https://www.gao.gov/assets/gao-15-509.pdf

43. Source: gao.gov
Title: gao 19 384
Link:https://www.gao.gov/products/gao

44. Source: gao.gov
Link:https://www.gao.gov/assets/a157542.html

45. Source: gao.gov
Title: gao 23 105084
Link:https://www.gao.gov/assets/gao-23-105084.pdf

46. Source: gao.gov
Link:https://www.gao.gov/assets/t-aimd-98-312.pdf

47. Source: gao.gov
Title: gao 18 559
Link:https://www.gao.gov/assets/gao-18-559.pdf

48. Source: gao.gov
Title: gao 16 398
Link:https://www.gao.gov/assets/gao-16-398.pdf

49. Source: gao.gov
Title: gao 04 467
Link:https://www.gao.gov/assets/gao-04-467.pdf

50. Source: justice.gov
Link:https://www.justice.gov/archive/criminal/cybercrime/press-releases/2002/mckinnonIndict.htm

51. Source: nvlpubs.nist.gov
Title: SP.800 12r1
Link:https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-12r1.pdf

52. Source: nvlpubs.nist.gov
Title: sp.800 165
Link:https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-165.pdf

53. Source: nvlpubs.nist.gov
Title: SP.800 170
Link:https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-170.pdf

54. Source: nvlpubs.nist.gov
Title: specialpublication800 53
Link:https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-53.pdf

55. Source: nvlpubs.nist.gov
Title: specialpublication800 65
Link:https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-65.pdf

56. Source: csrc.nist.gov
Title: ISPAB Report Adequate Funding NIST CSD
Link:https://csrc.nist.gov/CSRC/media/Projects/ISPAB/documents/correspondence/ISPAB-ReportAdequateFundingNIST-CSD.pdf

57. Source: nvlpubs.nist.gov
Title: specialpublication800 37
Link:https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-37.pdf

58. Source: csrc.nist.gov
Title: federal it saf 2000
Link:https://csrc.nist.gov/files/pubs/other/2000/11/28/federal-information-technology-security-assessment/final/docs/federal-it-saf-2000.pdf

59. Source: nvlpubs.nist.gov
Link:https://nvlpubs.nist.gov/nistpubs/Legacy/FIPS/fipspub112.pdf

60. Source: govinfo.gov
Link:https://www.govinfo.gov/content/pkg/CHRG-111shrg51019/html/CHRG-111shrg51019.htm

61. Source: govinfo.gov
Link:https://www.govinfo.gov/content/pkg/CHRG-107hhrg72833/html/CHRG-107hhrg72833.htm

62. Source: govinfo.gov
Link:https://www.govinfo.gov/content/pkg/CHRG-108hhrg86992/html/CHRG-108hhrg86992.htm

63. Source: govinfo.gov
Link:https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-04-321/html/GAOREPORTS-GAO-04-321.htm

64. Source: govinfo.gov
Link:https://www.govinfo.gov/content/pkg/CHRG-111hhrg50171/html/CHRG-111hhrg50171.htm

65. Source: govinfo.gov
Title: CHRG 107hhrg80481
Link:https://www.govinfo.gov/content/pkg/CHRG-107hhrg80481/html/CHRG-107hhrg80481.htm

66. Source: govinfo.gov
Title: CHRG 112hhrg72221
Link:https://www.govinfo.gov/content/pkg/CHRG-112hhrg72221/pdf/CHRG-112hhrg72221.pdf

67. Source: govinfo.gov
Link:https://www.govinfo.gov/content/pkg/CHRG-113hhrg86391/html/CHRG-113hhrg86391.htm

68. Source: govinfo.gov
Link:https://www.govinfo.gov/content/pkg/GOVPUB-C13-e4c7371bfafbe4abbf11594b6984850c/pdf/GOVPUB-C13-e4c7371bfafbe4abbf11594b6984850c.pdf

69. Source: govinfo.gov
Link:https://www.govinfo.gov/content/pkg/CHRG-113shrg88180/html/CHRG-113shrg88180.htm

70. Source: govinfo.gov
Link:https://www.govinfo.gov/content/pkg/CHRG-106shrg73464/html/CHRG-106shrg73464.htm

71. Source: govinfo.gov
Link:https://www.govinfo.gov/content/pkg/CHRG-106shrg78382/html/CHRG-106shrg78382.htm

72. Source: govinfo.gov
Title: GOVPUB Y4 J89 1 PURL LPS42509
Link:https://www.govinfo.gov/content/pkg/GOVPUB-Y4_J89_1-PURL-LPS42509/pdf/GOVPUB-Y4_J89_1-PURL-LPS42509.pdf

73. Source: govinfo.gov
Link:https://www.govinfo.gov/content/pkg/CHRG-106shrg74729/html/CHRG-106shrg74729.htm

74. Source: govinfo.gov
Link:https://www.govinfo.gov/content/pkg/GOVPUB-PR-PURL-LPS22941/pdf/GOVPUB-PR-PURL-LPS22941.pdf

75. Source: govinfo.gov
Link:https://www.govinfo.gov/content/pkg/GOVPUB-PREX-PURL-LPS18833/pdf/GOVPUB-PREX-PURL-LPS18833.pdf

76. Source: govinfo.gov
Title: CHRG 106shrg69335
Link:https://www.govinfo.gov/content/pkg/CHRG-106shrg69335/pdf/CHRG-106shrg69335.pdf

77. Source: media.defense.gov
Title: Mc Kinnon comphacker
Link:https://media.defense.gov/2002/Nov/12/2001711901/-1/-1/1/McKinnon_comphacker.pdf

78. Source: theguardian.com
Link:https://www.theguardian.com/theguardian/2005/jul/09/weekend7.weekend2

Source snippet

The GuardianGame over | Gary McKinnon9 Jul 2005 —... administrator user names that had no passwords. Basically, what... "Maybe I'd been...

79. Source: nsarchive2.gwu.edu
Title: National Security Archive AIMD-96-84 Information Security
Link:https://nsarchive2.gwu.edu/NSAEBB/NSAEBB424/docs/Cyber-010a.pdf

80. Source: pinsentmasons.com
Title: pentagon hacker mckinnon fights extradition
Link:https://www.pinsentmasons.com/out-law/news/pentagon-hacker-mckinnon-fights-extradition

81. Source: Wikipedia
Title: Gary Mc Kinnon
Link:https://en.wikipedia.org/wiki/Gary_McKinnon

82. Source: nsarchive.gwu.edu
Title: solar sunrise after 25 years are we 25 years wiser
Link:https://nsarchive.gwu.edu/briefing-book/cyber-vault/2023-02-28/solar-sunrise-after-25-years-are-we-25-years-wiser

83. Source: nsarchive.gwu.edu
Link:https://nsarchive.gwu.edu/sites/default/files/documents/5989763/National-Security-Archive-National-Institute-of.pdf

84. Source: theguardian.com
Link:https://www.theguardian.com/uk/2007/apr/03/politics.usa

85. Source: theguardian.com
Link:https://www.theguardian.com/technology/2005/jul/27/hacking.internetcrime

86. Source: theguardian.com
Link:https://www.theguardian.com/technology/2002/nov/13/hacking.internetcrime

87. Source: twingate.com
Title: solar sunrise
Link:https://www.twingate.com/blog/glossary/solar%20sunrise

Additional References

88. Source: instagram.com
Link:https://www.instagram.com/reel/DTveyiaANbn/

89. Source: reddit.com
Link:https://www.reddit.com/r/hacking/comments/1etqs6b/how_gary_mckinnon_did_what_he_did/

90. Source: researchgate.net
Link:https://www.researchgate.net/profile/Faris-Alshubiri/post/What_is_the_best_way_for_assessment_of_management_support_in_success_of_an_organization/attachment/59d621c879197b8077980274/AS%3A298291750293518%401448129703669/download/2.pdf

91. Source: vigilant-inc.com
Link:https://vigilant-inc.com/lessons-learned-critical-infrastructure-disruption/

92. Source: cybereason.com
Link:https://www.cybereason.com/blog/malicious-life-podcast-the-u.s-vs.-gary-mckinnon

93. Source: protelion.com
Link:https://protelion.com/resources/blog/the-cyberhall-of-fame-famous-faces-in-cybersecurity/

94. Source: trulyadventure.us
Link:https://www.trulyadventure.us/the-hacker

95. Source: malicious.life
Link:https://malicious.life/episode/us_vs_gary_mckinnon/

96. Source: instagram.com
Link:https://www.instagram.com/p/DXK5kOhCK3V/?img_index=2

97. Source: federalpremium.com
Link:https://www.federalpremium.com/