Within Access Methods

Lateral Movement Rou

One of the most important features of the Gary McKinnon case was that he did not need to connect directly to every military or NASA computer from his home internet connection.

29 sources 3 graphics
Preview for Lateral Movement Rou

Introduction

One of the most important features of the Gary McKinnon case was that he did not need to connect directly to every military or NASA computer from his home internet connection. According to US indictments and the House of Lords judgment summarising the allegations, once he had administrative access to a vulnerable computer he could use that trusted machine as a new starting point for finding additional systems, installing remote-access software, copying account information and moving deeper into connected government networks.[UK Parliament]publications.parliament.ukUK Parliament House of LordsUK ParliamentHouse of Lords - Mckinnon V Government of The United States of America and AnotherJuly 30, 2008…Published: July 30, 2008

Lateral Movement Rou illustration 1

This mechanism—known today as lateral movement—helps explain why a single poorly protected computer could become the gateway to many others. Rather than repeatedly attacking isolated internet-facing systems, a compromised host effectively became an internal platform from which other military and NASA computers were easier to discover and reach.

Using a Compromised Host as a New Launch Point

The allegations against McKinnon describe a progression rather than a series of unrelated break-ins. After obtaining administrative privileges on one computer, he allegedly installed the commercial remote administration package RemotelyAnywhere together with other software that enabled continued access and concealed his activities. From that position he could search for additional computers that shared the same weaknesses.[UK Parliament]publications.parliament.ukUK Parliament House of LordsUK ParliamentHouse of Lords - Mckinnon V Government of The United States of America and AnotherJuly 30, 2008…Published: July 30, 2008

The House of Lords judgment states that the installed software allowed him to scan more than 73,000 US government computers for other susceptible systems. It further explains that he was able to “lever himself from network to network”, illustrating that each successful compromise increased his ability to identify and reach further machines.[UK Parliament]publications.parliament.ukUK Parliament House of LordsUK ParliamentHouse of Lords - Mckinnon V Government of The United States of America and AnotherJuly 30, 2008…Published: July 30, 2008

This mattered because an internal computer occupies a different position from an external attacker. Once a machine is trusted by its surrounding network, communications originating from it may reach servers, administrative tools or shared resources that are not directly exposed to the public internet. Even where individual systems remained separately protected, an attacker operating from inside the environment often has better visibility of addresses, services and network relationships than someone scanning from outside.

The Role of Copied Usernames and Password Files

Administrative access also enabled the alleged theft of authentication data. According to the US indictments, McKinnon copied files containing usernames and encrypted passwords from compromised systems, including approximately 950 passwords from servers connected to the Naval Weapons Station Earle network. The House of Lords judgment similarly records allegations that account names and encrypted password files were copied from multiple Army, Navy and NASA computers.[Department of Justice]justice.govDepartment of JusticeBritish National Charged with Hacking Into N.J. Naval Weapons Station Computers, Disabling Network After Sept. 11 (N…

These password files did not necessarily reveal every password immediately. However, they provided valuable information in several ways:

  • They identified legitimate user and administrator accounts.
  • They could potentially be subjected to password-cracking techniques offline.
  • They revealed which credentials existed across different systems.
  • They reduced the need to rely solely on discovering new vulnerable internet-facing machines.

The Virginia indictment also alleges that after copying password files from an Army computer, McKinnon installed tools intended to obtain unauthorised access to additional computers. This illustrates that credential collection was treated as part of expanding access rather than an isolated act of data theft.[Wikisource]en.wikisource.orgUS v Gary Mc Kinnon IndictmentUS v Gary McKinnon Indictment - Wikisource, the free online library…

Lateral Movement Rou illustration 2

Why Broad Internal Connectivity Increased the Damage

Government organisations rarely operate as collections of completely isolated computers. Military bases, administrative offices and research facilities depend on networks that allow systems to exchange information, authenticate users and manage shared services.

The McKinnon allegations suggest that weaknesses in this internal connectivity amplified the consequences of the initial compromise. Once one machine became available, it could serve as:

  • a platform for discovering additional hosts;
  • a trusted location from which to launch further scans;
  • a repository of account information useful elsewhere;
  • a persistent access point through installed remote-control software.

This helps explain how prosecutors alleged that McKinnon ultimately accessed 97 computers across the US Army, Navy, Air Force, Department of Defense and NASA despite beginning with far fewer entry points. The significance lay less in sophisticated exploitation than in repeatedly extending access from one compromised system to the next.[Department of Justice]justice.govDepartment of JusticeLondon, England Hacker Indicted Under Computer Fraud and Abuse Act For Accessing Military Computers (November 12, 2002)…Published: November 12, 2002

Why Internal Trust Was Such a Critical Weakness

Modern cybersecurity guidance often assumes that internal network traffic should not automatically be trusted. During the period covered by the McKinnon allegations, many enterprise networks relied much more heavily on the assumption that machines already inside the organisation were comparatively trustworthy.

As a result, compromising a single administrative workstation or server could expose:

  • network shares;
  • directory information;
  • administrative utilities;
  • password databases;
  • additional remote management services.

The McKinnon case became a well-known example because prosecutors argued that exactly this sequence occurred: an initial compromise led to administrative control, administrative control enabled credential collection and remote administration, and those capabilities made further compromises progressively easier.[UK Parliament]publications.parliament.ukUK Parliament House of LordsUK ParliamentHouse of Lords - Mckinnon V Government of The United States of America and AnotherJuly 30, 2008…Published: July 30, 2008

Lateral Movement Rou illustration 3

What the Mechanism Revealed

The importance of this aspect of the case extends beyond the specific allegations against McKinnon. It demonstrated that the greatest risk did not necessarily come from breaching dozens of independent systems individually. Instead, one inadequately protected computer could become a stepping stone into many others.

For that reason, the case is frequently discussed as an illustration of lateral movement: the process by which an attacker converts one successful intrusion into wider access by exploiting trusted network relationships and harvested credentials. The allegations that McKinnon scanned from compromised hosts, copied password files and used installed remote-access software all fit this mechanism, helping explain how relatively ordinary security weaknesses could produce access across multiple military and NASA networks.[parliament.uk]publications.parliament.ukUK Parliament House of LordsUK ParliamentHouse of Lords - Mckinnon V Government of The United States of America and AnotherJuly 30, 2008…Published: July 30, 2008

Amazon book picks

Further Reading

Books and field guides related to Lateral Movement Rou. Use these as the next step if you want deeper reading beyond the article.

BookCover for The Cuckoo's Egg

The Cuckoo's Egg

By Cliff Stoll

This is the true story of how a systems manager at Lawrence Berkeley Lab singlehandedly tracked down and helped capture a computer hacker...

BookCover for Windows Internals

Windows Internals

By Pavel Yosifovich, Mark E. Russinovich et al.

The definitive guide–fully updated for Windows 10 and Windows Server 2016 Delve inside Windows architecture and internals, and see how co...

eBay marketplace picks

Marketplace Samples

Live-tested eBay searches with available results related to this page.

UsingUSA

Selected fromhacker t shirt oneBay.co.uk.

Endnotes

1. Source: publications.parliament.uk
Title: UK Parliament House of Lords
Link:https://publications.parliament.uk/pa/ld200708/ldjudgmt/jd080730/mckinn-1.htm

Source snippet

UK ParliamentHouse of Lords - Mckinnon V Government of The United States of America and AnotherJuly 30, 2008...

Published: July 30, 2008

2. Source: justice.gov
Link:https://www.justice.gov/archive/criminal/cybercrime/press-releases/2002/mckinnonIndict.htm

Source snippet

Department of JusticeLondon, England Hacker Indicted Under Computer Fraud and Abuse Act For Accessing Military Computers (November 12, 2002)...

Published: November 12, 2002

3. Source: justice.gov
Link:https://www.justice.gov/archive/criminal/cybercrime/press-releases/2002/mckinnonIndict2.htm

Source snippet

Department of JusticeBritish National Charged with Hacking Into N.J. Naval Weapons Station Computers, Disabling Network After Sept. 11 (N...

4. Source: en.wikisource.org
Title: US v Gary Mc Kinnon Indictment
Link:https://en.wikisource.org/wiki/US_v_Gary_McKinnon_Indictment

Source snippet

US v Gary McKinnon Indictment - Wikisource, the free online library...

5. Source: parliament.uk
Title: Update following cyber security incident
Link:https://www.parliament.uk/mps-lords-and-offices/offices/commons/media-relations-group/news/update-following-cyber-attack/

Source snippet

UK ParliamentJuly 20, 2017 — UPDATE FOLLOWING CYBER SECURITY INCIDENT 20 July 2017 Jul 20 2017 Image: PC-Westminster-palace-standard.png...

Published: July 20, 2017

6. Source: hansard.parliament.uk
Title: uk Commons Chamber
Link:https://hansard.parliament.uk/html/Commons/2009-12-01/CommonsChamber

Source snippet

David Burrowes (Enfield, Southgate) (Con) (Urgent Question): To ask the Secretary of State for the Home Department if he will make a stat...

7. Source: GOV.UK
Title: latest on gary mckinnon case
Link:https://www.gov.uk/government/news/latest-on-gary-mckinnon-case

Source snippet

on Gary McKinnon case - GOV.UKNovember 4, 2010 — LATEST ON GARY MCKINNON CASE Find out the latest position on the Glasgow-born systems ad...

Published: November 4, 2010

Additional References

8. Source: sooperkanoon.com
Link:https://sooperkanoon.com/case/amp/945113/mckinnon-appellant-vs-government-respondents

Source snippet

GOVERNMENT OF THE UNITED STATES OF AMERICA (RESPONDENTS) AND ANOTHER - COURT JUDGMENT SooperKanoon Citation | sooperkanoon.com/945113 Cou...

9. Source: vlex.co.uk
Title: Mc Kinnon v United States of America
Link:https://vlex.co.uk/vid/mckinnon-v-usa-818719549

Source snippet

McKinnon v United States of America - vLex United KingdomJuly 30, 2008 — MCKINNON V UNITED STATES OF AMERICA [Jurisdiction]({{ 'jurisdiction/' | relative_url }}) | England & Wal...

Published: July 30, 2008

10. Source: youtube.com
Title: Detecting Lateral Movement with Splunk
Link:https://www.youtube.com/watch?v=a47KDhIOUJw

Source snippet

This list provides directly relevant documentaries and technical breakdowns explaining how attackers use initial access to pivot and move...

11. Source: youtube.com
Title: Hacking for UFOs and fighting for his life. Who is Gary Mc Kinnon?
Link:https://www.youtube.com/watch?v=OImdnvQx7sQ

Source snippet

Lateral Movement Explained | How Hackers Quietly Take Over Networks...

12. Source: youtube.com
Title: Lateral Movement Explained | How Hackers Quietly Take Over Networks
Link:https://www.youtube.com/watch?v=fDy3G5BBkVI

Source snippet

How Hackers Pivot with SSH (Dynamic Port Forwarding Explained)...

13. Source: casemine.com
Link:https://www.casemine.com/judgement/uk/5a8ff75e60d03e7f57eabd29

14. Source: casemine.com
Link:https://www.casemine.com/judgement/uk/5a8ff75e60d03e7f57eabd29/amp

15. Source: theguardian.com
Link:https://www.theguardian.com/technology/2002/nov/13/hacking.internetcrime

16. Source: youtube.com
Title: The Man Who Hacked the U.S. Government
Link:https://www.youtube.com/watch?v=ND0zQX1rGdg

Source snippet

Hacking for UFOs and fighting for his life. Who is Gary McKinnon?...

17. Source: theguardian.com
Link:https://www.theguardian.com/technology/2008/jun/16/hacking.internationalcrime