Within UFO Hackers
Why Early Government Networks Were Easy Targets
Poor password practices and loosely connected systems made 1990s and early-2000s government networks unusually vulnerable to persistent outsiders.
On this page
- Weak authentication practices
- Trust between connected systems
- Security reforms after major breaches
Page outline Jump by section
Introduction
The UFO-hacker cases of the 1990s and early 2000s were made possible less by extraordinary hacking skill than by an awkward stage in government computing. Military and civilian agencies were rapidly connecting thousands of previously separate machines to wider networks, while password discipline, software patching, monitoring and central oversight lagged behind. An outsider who found one poorly protected computer could sometimes install remote-control software, capture credentials or use the compromised machine as a stepping stone towards other systems.

Gary McKinnon’s intrusions illustrate this gap particularly clearly. He said he searched for administrator accounts with weak or absent passwords, while US legal proceedings alleged that he obtained privileged access and installed remote-administration software. His UFO interests explain why he looked; the insecure network environment explains how a lone individual using an ordinary internet connection could remain inside government systems for an extended period.[parliament.uk]publications.parliament.ukmckinn 1UK ParliamentMckinnon V Government of The United States of America…30 Jul 2008 — Having gained access to those accounts he installed u…
Weak passwords turned scanning into access
In modern accounts, “hacking the Pentagon” can sound like defeating a single, heavily fortified central system. The reality was more fragmented. The Department of Defense, NASA and their contractors operated large numbers of computers administered by different units, laboratories and support offices. Security depended on the configuration of each exposed machine, and a forgotten server or badly managed account could provide a far easier entry point than a mission-critical system.
McKinnon described systematically scanning ranges of internet addresses and checking Windows computers for administrative accounts that had no password. Contemporary reporting quoted him saying that some administrator usernames were effectively left unprotected. The House of Lords’ account of the extradition case did not independently verify every detail of his public explanation, but it recorded the US allegation that, after obtaining administrator-level access, he installed a program called RemotelyAnywhere, allowing continued control of compromised machines.[The Guardian]theguardian.comThe GuardianGame over | Gary McKinnon9 Jul 2005 —… administrator user names that had no passwords. Basically, what… "Maybe I'd been…
That alleged method fitted a broader federal problem. In August 2001, while McKinnon’s activity was under way, the US General Accounting Office reported that agencies frequently lacked effective controls over access to computer resources. Its review found recurring weaknesses in the protection of powerful programs, sensitive files and administrative functions. A separate GAO survey covering 22 agencies documented access-control deficiencies across the federal government rather than at one isolated department.[GAO]gao.govInformation Security: Code Red, Code Red II, and Sir CamInformation Security: Code Red, Code Red II, and SirCam…August 29, 2001 — 29 Aug 2001 — these attacks have infected millions of com…
Poor authentication was not simply a matter of users choosing memorable words. The weaknesses included:
- accounts with blank, default or easily guessed passwords;
- administrator privileges granted more widely than necessary;
- obsolete accounts that remained active;
- credentials transmitted across local networks without encryption;
- systems permitting unauthenticated connections;
- limited review of who possessed privileged access.
A 2002 audit of the US Army Corps of Engineers, for example, found that usernames and passwords were still being transmitted unencrypted and that some servers allowed unauthenticated connections. GAO warned that captured credentials could be reused to obtain further privileges or to attack other Department of Defense networks through the Corps’ systems.[GAO]gao.govGAO-02-589 Information Security: Corps of Engineers…June 10, 2002 — 10 Jun 2002 — network could capture usernames and passwords and…
The distinction matters when assessing UFO hackers such as McKinnon. Their access did not establish that the machines contained extraordinary secrets. It established that ordinary administrative failures could expose government computers to persistent outsiders. The supposed prize might have been exotic, but the entry mechanism was usually mundane.
Connected systems amplified a single mistake
Weak passwords became more dangerous because government networks were increasingly interconnected. A compromised computer was not merely one lost machine; it could become a trusted launch point for exploring neighbouring systems.
Early networks often relied heavily on the assumption that traffic originating from an internal or recognised host was safer than traffic arriving directly from the public internet. Once an intruder obtained administrator privileges, that assumption could be exploited. The attacker could inspect configuration files, collect account information, install a “sniffer” to capture network traffic, or use the machine to approach systems that would otherwise reject an outside connection.
The 1998 Solar Sunrise incident demonstrated this pattern shortly before McKinnon’s campaign. Two American teenagers and an Israeli hacker exploited a known vulnerability in Sun Solaris systems to obtain root access—the Unix equivalent of full administrative control—on government and private computers. They then placed network-sniffing programs on compromised hosts. A Justice Department planning document noted that the vulnerability was already known, while congressional evidence concluded that the intrusion could have been prevented had available patches been installed.[Department of Justice]justice.govDepartment of Justiceyear interagency counterterrorism and technology crime planDepartment of Justiceyear interagency counterterrorism and technology crime plan
Earlier attacks on the US Air Force’s Rome Laboratory showed an even more striking form of network hopping. GAO’s 1996 investigation concluded that a small group of intruders had been able to take control of systems at the laboratory, monitor activity and use the compromised network to attack numerous additional sites. Rome Laboratory was a major command-and-control research facility, yet weaknesses in administration and detection allowed outsiders to operate through its computers rather than merely visit them once.[National Security Archive]nsarchive2.gwu.eduNational Security Archive AIMD-96-84 Information SecurityNational Security Archive AIMD-96-84 Information Security
This is the crucial mechanism behind the era’s most startling intrusion stories:
- Find the weakest exposed host. The initial target might be a support, research or administrative computer rather than a protected operational system.
- Obtain elevated privileges. Blank passwords, unpatched software or badly managed accounts could provide administrator or root access.
- Create persistence. Remote-control tools or replacement accounts allowed the intruder to return without repeating the original exploit.
- Collect local knowledge. Account files, network addresses and captured traffic revealed how other systems were connected.
- Move through trusted pathways. The compromised government machine became a platform for approaching further targets.
- Avoid or erase scrutiny. Weak logging and decentralised incident reporting made prolonged activity harder to reconstruct.
US prosecutors alleged that McKinnon followed several elements of this model: scanning for vulnerable machines, extracting account information, installing remote-administration software and deleting system logs. McKinnon disputed the government’s portrayal of him as destructive, and the accusations were never tested in a completed US criminal trial. The evidence nevertheless shows why privileged access to a modestly protected machine could be far more consequential than the initial login suggested.[pinsentmasons.com]pinsentmasons.compentagon hacker mckinnon fights extraditionpentagon hacker mckinnon fights extradition
Security teams could not see the whole network
The expansion of internet connectivity also created an organisational problem. Federal computing was dispersed among departments, agencies, commands, laboratories, contractors and local administrators. No single operator necessarily had a complete inventory of internet-facing machines, their software versions or the accounts active on them.
GAO reported in 1996 that the Department of Defense might have experienced as many as 250,000 attacks in the previous year. Of attacks subjected to controlled testing, approximately 65 per cent successfully penetrated systems, while only a small proportion were detected and still fewer were reported. The figures were estimates rather than a complete incident count, but they exposed the imbalance between the number of reachable systems and the department’s ability to monitor them.[GAO]gao.govOpen source on gao.gov.
The same report pointed to inadequate password management, uneven technical expertise among administrators and the absence of effective department-wide security practices. A later GAO review recalled that foreign hackers had penetrated Department of Defense systems as early as 1990–91 because of poor password management and limited administrator expertise.[GAO]gao.govDOD Faces Challenges In Its Cyber ActivitiesDOD Faces Challenges In Its Cyber Activities
Detection was especially difficult when an intruder behaved quietly. A person searching documents, browsing directories or downloading files slowly might generate less obvious disruption than a computer virus or denial-of-service attack. Remote sessions could also be routed through systems in several countries, complicating attribution and delaying cooperation between network owners and law-enforcement agencies. Congressional testimony about Solar Sunrise stressed that attackers could disguise their origin, manipulate logs and pass through numerous jurisdictions before reaching the ultimate target.[GovInfo]govinfo.govCHRG 106shrg63940CHRG 106shrg63940
For a UFO-motivated intruder, patience was an advantage. The objective was generally not to make a public website fail but to remain unnoticed while searching for suggestive filenames, photographs, personnel lists or references to classified projects. A security model focused mainly on keeping services running could therefore miss the quieter theft or examination of information.
The vulnerability was systemic, not unique to NASA
McKinnon’s story is sometimes framed as proof that NASA or the US military possessed exceptionally careless systems. Contemporary audits suggest a broader conclusion: insecure access controls were a government-wide management problem.
In 1997, GAO formally designated federal information security a government-wide “high-risk” area. By the early 2000s it was still reporting significant weaknesses across all 24 major federal agencies it reviewed. Congressional assessments in 2001 assigned failing security grades to much of the federal government, including major departments, while NASA received only a middling grade.[GAO]gao.govOpen source on gao.gov.
These findings do not mean every federal computer was open or that intruders could freely enter classified networks. Many of the publicly documented compromises involved unclassified systems, research machines, administrative services or network edges. Classified environments were ordinarily separated and subjected to additional controls. Yet “unclassified” did not mean harmless: such machines could contain operational schedules, personnel information, technical research or credentials useful for reaching other systems.
The sprawling scale of Department of Defense computing made consistent protection particularly difficult. Local units had different budgets, technical staff and operational priorities. Connecting systems improved communication and research, but every connection created another configuration to maintain and another pathway whose trust assumptions could be abused.
This helps resolve an apparent contradiction in the UFO-hacker narrative. The institutions being targeted were among the world’s most technically capable, yet some of their computers were penetrated through elementary weaknesses. Technical sophistication in aircraft, space science or weapons research did not automatically produce disciplined password management on every office server.
Major breaches forced security to become a programme
By the late 1990s, recurring intrusions had made it clear that isolated technical fixes were insufficient. Agencies needed security to become a continuous management function: identify every system, assign responsibility, control privileged access, install patches promptly, monitor activity and prepare a coordinated response when compromise occurred.
After Solar Sunrise, Department of Defense measures described to Congress included tighter control over identifying vulnerable systems, patching exposed software, deploying intrusion-detection tools at important network points, expanding emergency response teams and preparing contingency plans for network disruption. These measures directly addressed the mechanisms that had allowed earlier outsiders to remain active.[GovInfo]govinfo.govCHRG 106shrg68563CHRG 106shrg68563
Congress then imposed more systematic obligations. The Government Information Security Reform provisions of 2000 required agencies to establish security programmes and conduct regular evaluations. The Federal Information Security Management Act of 2002, known as FISMA, made information security an agency-wide responsibility and assigned the National Institute of Standards and Technology a central role in developing federal standards and guidance.[WIRED]wired.comAre U.S. Agencies Hacker-Proof?Are U.S. Agencies Hacker-Proof?
The resulting framework did not depend on one defensive product. It required controls covering identification and authentication, access management, audit records, configuration management, incident response, risk assessment and system integrity. Later federal standards formalised these areas as minimum requirements rather than optional practices left entirely to individual administrators.[NIST Publications]nvlpubs.nist.govPublications FIPS 199, Standards for Security Categorization of FederalPublications FIPS 199, Standards for Security Categorization of Federal
In practical terms, the reform agenda aimed to remove the conditions on which persistent outsiders depended:
- blank and default credentials were to be eliminated;
- privileged accounts were to be restricted and reviewed;
- known vulnerabilities were to be patched systematically;
- logs were to be collected and examined;
- unusual remote access was to trigger investigation;
- connections between systems were to be documented and controlled;
- incidents were to be reported beyond the affected local office.
Implementation remained uneven, and federal auditors continued to identify serious weaknesses after FISMA. The change was nevertheless important. Security was no longer supposed to rest primarily on the vigilance of whichever administrator happened to maintain a particular machine.
What the UFO-hacker era actually reveals
The enduring lesson of the UFO-hacker cases is not that curiosity could somehow overcome impenetrable national-security technology. It is that, during a period of rapid network growth, determined outsiders could search huge numbers of systems until they found the small minority that had been badly configured.
McKinnon’s claimed UFO discoveries remain unverified because he preserved no independently authenticated files or images from the material he said he viewed. The documented security environment, by contrast, is unusually well supported. Federal audits, court records and congressional investigations consistently describe missing access controls, inadequate password management, delayed patching, weak monitoring and networks whose internal connections magnified the consequences of one compromised machine.[wired.com]wired.comufo hacker tells what he foundWIRED'UFO Hacker' Tells What He Found21 Jun 2006 — The search for proof of the existence of UFOs landed Gary McKinnon in a world of troub…
That distinction is central to understanding the period. The intrusions provide strong evidence of early government-network insecurity. They do not, by themselves, authenticate the UFO interpretations that motivated some of the intruders. The most remarkable verified fact is therefore not what the hackers claimed to find, but how ordinary security failures allowed them to search at all.
Amazon book picks
Further Reading
Books and field guides related to Why Early Government Networks Were Easy Targets. Use these as the next step if you want deeper reading beyond the article.
Hackers, Heroes of the Computer Revolution
The origins and history of electronic intruders that includes the first written "code of ethics" of the computer underground.
Where Wizards Stay Up Late: The Origins of the Internet
Rating: 3.8/5 from 11 Google Books ratings
In 1990, the ARPANET itself was shut down, fully merged by then with the Internet it had spawned.
This Is How They Tell Me the World Ends: The Cyberweapons Arm...
WINNER OF THE FT & McKINSEY BUSINESS BOOK OF THE YEAR AWARD 2021 The instant New York Times bestseller A Financial Times and The Times Bo...
eBay marketplace picks
Marketplace Samples
Live-tested eBay searches with available results related to this page.
Selected fromUFO disclosure print oneBay.co.uk.
Endnotes
1.
Source: publications.parliament.uk
Title: mckinn 1
Link:https://publications.parliament.uk/pa/ld200708/ldjudgmt/jd080730/mckinn-1.htm
Source snippet
UK ParliamentMckinnon V Government of The United States of America...30 Jul 2008 — Having gained access to those accounts he installed u...
2.
Source: wired.com
Title: ufo hacker tells what he found
Link:https://www.wired.com/2006/06/ufo-hacker-tells-what-he-found/
Source snippet
WIRED'UFO Hacker' Tells What He Found21 Jun 2006 — The search for proof of the existence of UFOs landed Gary McKinnon in a world of troub...
3.
Source: justice.gov
Link:https://www.justice.gov/archive/usao/nj/Press/files/pdffiles/Older/edva_mckinnon_indictment.pdf
Source snippet
Department of JusticeIndictmentDefendant GARY MCKINNON was an unemployed computer system administrator living in London, England. deleted...
4.
Source: gao.gov
Title: Information Security: Code Red, Code Red II, and Sir Cam
Link:https://www.gao.gov/assets/gao-01-1073t.pdf
Source snippet
Information Security: Code Red, Code Red II, and SirCam...August 29, 2001 — 29 Aug 2001 — these attacks have infected millions of com...
Published: August 29, 2001
5.
Source: gao.gov
Link:https://www.gao.gov/assets/aimd-00-32r.pdf
Source snippet
AIMD-00-32R Information Security: Weaknesses at 22...In July 1999, we reported that the Department of Agriculture's (USDA) National...
Published: July 1999
6.
Source: gao.gov
Link:https://www.gao.gov/assets/gao-02-589.pdf
Source snippet
GAO-02-589 Information Security: Corps of Engineers...June 10, 2002 — 10 Jun 2002 — network could capture usernames and passwords and...
Published: June 10, 2002
7.
Source: justice.gov
Title: Department of Justiceyear interagency counterterrorism and technology crime plan
Link:https://www.justice.gov/sites/default/files/oip/legacy/2014/07/23/crime-plan.pdf
8.
Source: govinfo.gov
Title: CHRG 106shrg68563
Link:https://www.govinfo.gov/content/pkg/CHRG-106shrg68563/pdf/CHRG-106shrg68563.pdf
9.
Source: govinfo.gov
Title: GAOREPORTS AIMD 96 84
Link:https://www.govinfo.gov/content/pkg/GAOREPORTS-AIMD-96-84/html/GAOREPORTS-AIMD-96-84.htm
10.
Source: gao.gov
Link:https://www.gao.gov/products/t-aimd
11.
Source: gao.gov
Title: DOD Faces Challenges In Its Cyber Activities
Link:https://www.gao.gov/assets/a321824.html
12.
Source: gao.gov
Link:https://www.gao.gov/products/t-imtec
13.
Source: govinfo.gov
Title: CHRG 106shrg63940
Link:https://www.govinfo.gov/content/pkg/CHRG-106shrg63940/html/CHRG-106shrg63940.htm
14.
Source: govinfo.gov
Title: CHRG 106shrg69335
Link:https://www.govinfo.gov/content/pkg/CHRG-106shrg69335/html/CHRG-106shrg69335.htm
15.
Source: gao.gov
Link:https://www.gao.gov/assets/a235056.html
16.
Source: gao.gov
Link:https://www.gao.gov/assets/a237064.html
17.
Source: wired.com
Title: govt networks get an f
Link:https://www.wired.com/2001/11/govt-networks-get-an-f
18.
Source: wired.com
Title: Are U.S. Agencies Hacker-Proof?
Link:https://www.wired.com/2001/03/are-u-s-agencies-hacker-proof
19.
Source: csrc.nist.gov
Link:https://csrc.nist.gov/topics/laws-and-regulations/laws/FISMA
20.
Source: nvlpubs.nist.gov
Title: Publications FIPS 199, Standards for Security Categorization of Federal
Link:https://nvlpubs.nist.gov/nistpubs/fips/nist.fips.199.pdf
21.
Source: nvlpubs.nist.gov
Link:https://nvlpubs.nist.gov/nistpubs/fips/nist.fips.200.pdf
22.
Source: gao.gov
Title: ocg 99 4
Link:https://www.gao.gov/assets/ocg-99-4.pdf
23.
Source: gao.gov
Link:https://www.gao.gov/assets/a301881.html
24.
Source: gao.gov
Link:https://www.gao.gov/assets/a280296.html
25.
Source: gao.gov
Link:https://www.gao.gov/products/gao
26.
Source: gao.gov
Link:https://www.gao.gov/assets/a241727.html
27.
Source: gao.gov
Link:https://www.gao.gov/assets/a277718.html
28.
Source: gao.gov
Link:https://www.gao.gov/assets/t-aimd-00-330.pdf
29.
Source: gao.gov
Link:https://www.gao.gov/assets/a250484.html
30.
Source: gao.gov
Link:https://www.gao.gov/assets/a311584.html
31.
Source: gao.gov
Link:https://www.gao.gov/assets/a236721.html
32.
Source: gao.gov
Link:https://www.gao.gov/assets/gao-02-231t.pdf
33.
Source: gao.gov
Title: gao 19 105
Link:https://www.gao.gov/products/gao
34.
Source: gao.gov
Title: gao 06 672
Link:https://www.gao.gov/products/gao
35.
Source: gao.gov
Link:https://www.gao.gov/assets/a279089.html
36.
Source: gao.gov
Link:https://www.gao.gov/assets/t-aimd-00-171.pdf
37.
Source: gao.gov
Link:https://www.gao.gov/assets/a237104.html
38.
Source: gao.gov
Link:https://www.gao.gov/assets/a246517.html
39.
Source: gao.gov
Link:https://www.gao.gov/assets/a301500.html
40.
Source: gao.gov
Link:https://www.gao.gov/assets/a237380.html
41.
Source: gao.gov
Link:https://www.gao.gov/assets/a275647.html
42.
Source: gao.gov
Title: gao 15 509
Link:https://www.gao.gov/assets/gao-15-509.pdf
43.
Source: gao.gov
Title: gao 19 384
Link:https://www.gao.gov/products/gao
44.
Source: gao.gov
Link:https://www.gao.gov/assets/a157542.html
45.
Source: gao.gov
Title: gao 23 105084
Link:https://www.gao.gov/assets/gao-23-105084.pdf
46.
Source: gao.gov
Link:https://www.gao.gov/assets/t-aimd-98-312.pdf
47.
Source: gao.gov
Title: gao 18 559
Link:https://www.gao.gov/assets/gao-18-559.pdf
48.
Source: gao.gov
Title: gao 16 398
Link:https://www.gao.gov/assets/gao-16-398.pdf
49.
Source: gao.gov
Title: gao 04 467
Link:https://www.gao.gov/assets/gao-04-467.pdf
50.
Source: justice.gov
Link:https://www.justice.gov/archive/criminal/cybercrime/press-releases/2002/mckinnonIndict.htm
51.
Source: nvlpubs.nist.gov
Title: SP.800 12r1
Link:https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-12r1.pdf
52.
Source: nvlpubs.nist.gov
Title: sp.800 165
Link:https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-165.pdf
53.
Source: nvlpubs.nist.gov
Title: SP.800 170
Link:https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-170.pdf
54.
Source: nvlpubs.nist.gov
Title: specialpublication800 53
Link:https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-53.pdf
55.
Source: nvlpubs.nist.gov
Title: specialpublication800 65
Link:https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-65.pdf
56.
Source: csrc.nist.gov
Title: ISPAB Report Adequate Funding NIST CSD
Link:https://csrc.nist.gov/CSRC/media/Projects/ISPAB/documents/correspondence/ISPAB-ReportAdequateFundingNIST-CSD.pdf
57.
Source: nvlpubs.nist.gov
Title: specialpublication800 37
Link:https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-37.pdf
58.
Source: csrc.nist.gov
Title: federal it saf 2000
Link:https://csrc.nist.gov/files/pubs/other/2000/11/28/federal-information-technology-security-assessment/final/docs/federal-it-saf-2000.pdf
59.
Source: nvlpubs.nist.gov
Link:https://nvlpubs.nist.gov/nistpubs/Legacy/FIPS/fipspub112.pdf
60.
Source: govinfo.gov
Link:https://www.govinfo.gov/content/pkg/CHRG-111shrg51019/html/CHRG-111shrg51019.htm
61.
Source: govinfo.gov
Link:https://www.govinfo.gov/content/pkg/CHRG-107hhrg72833/html/CHRG-107hhrg72833.htm
62.
Source: govinfo.gov
Link:https://www.govinfo.gov/content/pkg/CHRG-108hhrg86992/html/CHRG-108hhrg86992.htm
63.
Source: govinfo.gov
Link:https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-04-321/html/GAOREPORTS-GAO-04-321.htm
64.
Source: govinfo.gov
Link:https://www.govinfo.gov/content/pkg/CHRG-111hhrg50171/html/CHRG-111hhrg50171.htm
65.
Source: govinfo.gov
Title: CHRG 107hhrg80481
Link:https://www.govinfo.gov/content/pkg/CHRG-107hhrg80481/html/CHRG-107hhrg80481.htm
66.
Source: govinfo.gov
Title: CHRG 112hhrg72221
Link:https://www.govinfo.gov/content/pkg/CHRG-112hhrg72221/pdf/CHRG-112hhrg72221.pdf
67.
Source: govinfo.gov
Link:https://www.govinfo.gov/content/pkg/CHRG-113hhrg86391/html/CHRG-113hhrg86391.htm
68.
Source: govinfo.gov
Link:https://www.govinfo.gov/content/pkg/GOVPUB-C13-e4c7371bfafbe4abbf11594b6984850c/pdf/GOVPUB-C13-e4c7371bfafbe4abbf11594b6984850c.pdf
69.
Source: govinfo.gov
Link:https://www.govinfo.gov/content/pkg/CHRG-113shrg88180/html/CHRG-113shrg88180.htm
70.
Source: govinfo.gov
Link:https://www.govinfo.gov/content/pkg/CHRG-106shrg73464/html/CHRG-106shrg73464.htm
71.
Source: govinfo.gov
Link:https://www.govinfo.gov/content/pkg/CHRG-106shrg78382/html/CHRG-106shrg78382.htm
72.
Source: govinfo.gov
Title: GOVPUB Y4 J89 1 PURL LPS42509
Link:https://www.govinfo.gov/content/pkg/GOVPUB-Y4_J89_1-PURL-LPS42509/pdf/GOVPUB-Y4_J89_1-PURL-LPS42509.pdf
73.
Source: govinfo.gov
Link:https://www.govinfo.gov/content/pkg/CHRG-106shrg74729/html/CHRG-106shrg74729.htm
74.
Source: govinfo.gov
Link:https://www.govinfo.gov/content/pkg/GOVPUB-PR-PURL-LPS22941/pdf/GOVPUB-PR-PURL-LPS22941.pdf
75.
Source: govinfo.gov
Link:https://www.govinfo.gov/content/pkg/GOVPUB-PREX-PURL-LPS18833/pdf/GOVPUB-PREX-PURL-LPS18833.pdf
76.
Source: govinfo.gov
Title: CHRG 106shrg69335
Link:https://www.govinfo.gov/content/pkg/CHRG-106shrg69335/pdf/CHRG-106shrg69335.pdf
77.
Source: media.defense.gov
Title: Mc Kinnon comphacker
Link:https://media.defense.gov/2002/Nov/12/2001711901/-1/-1/1/McKinnon_comphacker.pdf
78.
Source: theguardian.com
Link:https://www.theguardian.com/theguardian/2005/jul/09/weekend7.weekend2
Source snippet
The GuardianGame over | Gary McKinnon9 Jul 2005 —... administrator user names that had no passwords. Basically, what... "Maybe I'd been...
79.
Source: nsarchive2.gwu.edu
Title: National Security Archive AIMD-96-84 Information Security
Link:https://nsarchive2.gwu.edu/NSAEBB/NSAEBB424/docs/Cyber-010a.pdf
80.
Source: pinsentmasons.com
Title: pentagon hacker mckinnon fights extradition
Link:https://www.pinsentmasons.com/out-law/news/pentagon-hacker-mckinnon-fights-extradition
81.
Source: Wikipedia
Title: Gary Mc Kinnon
Link:https://en.wikipedia.org/wiki/Gary_McKinnon
82.
Source: nsarchive.gwu.edu
Title: solar sunrise after 25 years are we 25 years wiser
Link:https://nsarchive.gwu.edu/briefing-book/cyber-vault/2023-02-28/solar-sunrise-after-25-years-are-we-25-years-wiser
83.
Source: nsarchive.gwu.edu
Link:https://nsarchive.gwu.edu/sites/default/files/documents/5989763/National-Security-Archive-National-Institute-of.pdf
84.
Source: theguardian.com
Link:https://www.theguardian.com/uk/2007/apr/03/politics.usa
85.
Source: theguardian.com
Link:https://www.theguardian.com/technology/2005/jul/27/hacking.internetcrime
86.
Source: theguardian.com
Link:https://www.theguardian.com/technology/2002/nov/13/hacking.internetcrime
87.
Source: twingate.com
Title: solar sunrise
Link:https://www.twingate.com/blog/glossary/solar%20sunrise
Additional References
88.
Source: instagram.com
Link:https://www.instagram.com/reel/DTveyiaANbn/
89.
Source: reddit.com
Link:https://www.reddit.com/r/hacking/comments/1etqs6b/how_gary_mckinnon_did_what_he_did/
90.
Source: researchgate.net
Link:https://www.researchgate.net/profile/Faris-Alshubiri/post/What_is_the_best_way_for_assessment_of_management_support_in_success_of_an_organization/attachment/59d621c879197b8077980274/AS%3A298291750293518%401448129703669/download/2.pdf
91.
Source: vigilant-inc.com
Link:https://vigilant-inc.com/lessons-learned-critical-infrastructure-disruption/
92.
Source: cybereason.com
Link:https://www.cybereason.com/blog/malicious-life-podcast-the-u.s-vs.-gary-mckinnon
93.
Source: protelion.com
Link:https://protelion.com/resources/blog/the-cyberhall-of-fame-famous-faces-in-cybersecurity/
94.
Source: trulyadventure.us
Link:https://www.trulyadventure.us/the-hacker
95.
Source: malicious.life
Link:https://malicious.life/episode/us_vs_gary_mckinnon/
96.
Source: instagram.com
Link:https://www.instagram.com/p/DXK5kOhCK3V/?img_index=2
97.
Source: federalpremium.com
Link:https://www.federalpremium.com/



