Within Early Insecurity

How One Missed Patch Opened Government Networks

Solar Sunrise showed how a known software flaw could open government systems when available security patches were not installed.

39 sources 3 graphics
Preview for How One Missed Patch Opened Government Networks

On this page

  • The known Solaris flaw attackers exploited
  • How root access enabled traffic capture
  • Why available patches had not been applied

Introduction

The 1998 Solar Sunrise intrusions became one of the clearest early demonstrations that government networks could be compromised not because attackers discovered a revolutionary new technique, but because known security updates had not been installed. Occurring only a few years before Gary McKinnon’s better-known intrusions, the incident illustrated the same underlying weakness: internet-connected government systems often depended on individual administrators applying vendor patches consistently across thousands of machines. When that routine maintenance failed, attackers could exploit publicly known vulnerabilities to obtain administrator privileges, monitor network traffic and move between systems. Solar Sunrise therefore became an important historical warning that poor patch management, rather than sophisticated offensive capability alone, could expose sensitive government networks.[kb.cert.org]kb.cert.orgVU#41870 - Sun Solstice AdminSuite ships with insecure default configurationSeptember 19, 2003…Published: September 19, 2003

Solar Sunrise illustration 1

The Known Solaris Flaw Attackers Exploited

Investigators concluded that the Solar Sunrise attackers targeted vulnerable Sun Solaris systems that had not been updated against publicly disclosed security weaknesses. Rather than developing a previously unknown exploit, they relied on flaws for which vendors had already released security information and corrective patches.

One particularly significant weakness involved Solaris’ remote administration infrastructure, including the sadmind service. In insecure default configurations, or on systems that had not been properly updated and hardened, attackers could send forged requests that were accepted with superuser privileges. Because the service was designed for legitimate remote administration, successful exploitation immediately granted extensive control over the affected machine.[kb.cert.org]kb.cert.orgVU#41870 - Sun Solstice AdminSuite ships with insecure default configurationSeptember 19, 2003…Published: September 19, 2003

This reflected a broader problem of the late 1990s. Security advisories, mailing lists and vendor bulletins routinely announced vulnerabilities together with the patches needed to correct them. Once those advisories became public, attackers could search the internet for systems that administrators had failed to update. As a result, the period between patch release and widespread deployment increasingly became an opportunity for intrusion rather than protection.[SecLists]seclists.orgBugtraq: Sun Security Bulletin #00162February 10, 1998…Published: February 10, 1998

How Root Access Enabled Traffic Capture

Obtaining root access transformed a vulnerable workstation or server into a powerful observation point inside the network.

With administrator privileges, intruders could:

  • install packet-sniffing software to capture usernames, passwords and other network traffic;
  • modify system files to preserve access;
  • create additional privileged accounts;
  • use the compromised machine as a trusted launch point against neighbouring systems; and
  • conceal their presence by altering logs or system configurations.

In Solar Sunrise, this ability to capture credentials mattered as much as the initial exploit. Networks in the late 1990s still relied heavily on protocols that transmitted authentication information with limited protection. Once attackers controlled a strategically placed Solaris host, they could collect credentials belonging to legitimate users and administrators, making lateral movement significantly easier without repeatedly exploiting software vulnerabilities. The initial missed patch therefore became the starting point for much broader compromise.[kb.cert.org]kb.cert.orgVU#41870 - Sun Solstice AdminSuite ships with insecure default configurationSeptember 19, 2003…Published: September 19, 2003

This pattern closely foreshadowed later incidents involving UFO-motivated hackers such as Gary McKinnon. In both cases, the first foothold often proved more valuable than the original vulnerability because administrative control enabled continued exploration of interconnected government systems.

Solar Sunrise illustration 2

Why Available Patches Had Not Been Applied

The most enduring lesson from Solar Sunrise was not that patches were unavailable, but that organisations struggled to deploy them consistently.

Several practical factors contributed:

  • Decentralised administration. Different military units and agencies managed their own systems, making uniform updates difficult.
  • Operational concerns. Administrators sometimes delayed installing patches because they feared disrupting mission-critical applications.
  • Limited asset visibility. Organisations frequently lacked accurate inventories showing which machines required updates.
  • Rapid network growth. Government networks expanded faster than security management practices matured.

During this period, applying patches remained largely a manual process. Centralised vulnerability management tools were immature, and many organisations depended on local administrators to monitor security bulletins, obtain vendor fixes and install them individually. Missing even one update could leave an internet-facing server exposed long after the vulnerability had become publicly known. Sun Microsystems’ own security bulletins repeatedly urged customers to install affected patches immediately, illustrating that vendor guidance existed but was not always translated into operational practice.[SecLists]seclists.orgBugtraq: Sun Security Bulletin #00162February 10, 1998…Published: February 10, 1998

A Turning Point for Government Cybersecurity

Solar Sunrise influenced how government agencies viewed routine system maintenance. The incident demonstrated that vulnerability management was not merely an administrative task but a central element of national security.

Several lessons emerged:

  • published vulnerabilities quickly became operational attack tools;
  • patch deployment speed was often as important as the quality of the patch itself;
  • internet-connected systems required continuous inventory and configuration management; and
  • successful defence depended on organisational discipline as much as technical innovation.

These conclusions helped reinforce later federal efforts to improve vulnerability assessment, centralised security management and routine patch compliance across government networks. Although Solar Sunrise is often remembered for the uncertainty surrounding its attribution during the investigation, its longer-lasting technical legacy was showing how ordinary maintenance failures could create extraordinary security risks.[kb.cert.org]kb.cert.orgVU#41870 - Sun Solstice AdminSuite ships with insecure default configurationSeptember 19, 2003…Published: September 19, 2003

Solar Sunrise illustration 3

Solar Sunrise in the Context of Early Internet Insecurity

Within the broader history of early internet insecurity behind UFO-related hacking cases, Solar Sunrise occupies an important place because it exposed a recurring pattern rather than an isolated mistake. The attackers did not have to overcome an impenetrable defensive system. They benefited from government computers running software that administrators already knew required updates.

That same pattern helps explain why later intrusions by individuals such as Gary McKinnon could succeed against numerous government computers. Different motivations drove different attackers, but both episodes demonstrated that inconsistent patching, combined with interconnected networks and widespread administrator privileges, could allow relatively modest technical methods to produce disproportionately significant security breaches.[kb.cert.org]kb.cert.orgVU#41870 - Sun Solstice AdminSuite ships with insecure default configurationSeptember 19, 2003…Published: September 19, 2003

Amazon book picks

Further Reading

Books and field guides related to How One Missed Patch Opened Government Networks. Use these as the next step if you want deeper reading beyond the article.

BookCover for Dark Territory

Dark Territory

By Fred M. Kaplan

"The never-before-told story of the computer scientists and the NSA, Pentagon, and White House policymakers who invented and employ the w...

BookCover for Security Engineering

Security Engineering

By Ross Anderson

Rating: 4.5/5 from 7 Google Books ratings

Now that there's software in everything, how can you make anything secure? Understand how to engineer dependable systems with this newly...

eBay marketplace picks

Marketplace Samples

Live-tested eBay searches with available results related to this page.

UsingUSA

Selected fromRoswell UFO patch oneBay.co.uk.

Endnotes

1. Source: kb.cert.org
Link:https://www.kb.cert.org/vuls/id/41870

Source snippet

VU#41870 - Sun Solstice AdminSuite ships with insecure default configurationSeptember 19, 2003...

Published: September 19, 2003

2. Source: seclists.org
Link:https://seclists.org/bugtraq/1998/Feb/48

Source snippet

Bugtraq: Sun Security Bulletin #00162February 10, 1998...

Published: February 10, 1998

3. Source: seclists.org
Link:https://seclists.org/bugtraq/1998/Nov/236

Source snippet

Bugtraq: Sun Security Bulletin #00179...

4. Source: seclists.org
Link:https://seclists.org/bugtraq/1998/Jul/155

Source snippet

Bugtraq: Sun Security Bulletin #00173...

5. Source: kb.cert.org
Link:https://kb.cert.org/vuls/id/351219

6. Source: seclists.org
Link:https://seclists.org/bugtraq/1998/Dec/15

7. Source: justice.gov
Link:https://www.justice.gov/archives/jm/criminal-resource-manual-29-electronic-surveillance-title-iii-affidavits

Additional References

8. Source: justice.gov
Link:https://www.justice.gov/archives/opa/pr/department-justice-statement-solarwinds-update

Source snippet

January 6, 2021 — Press Release DEPARTMENT OF JUSTICE STATEMENT ON SOLARWINDS UPDATE Wednesday, January 6, 2021 For Immediate Release Off...

Published: January 6, 2021

9. Source: muckrock.com
Title: Solar Sunrise (Department of Justice, National Security Division) • Muck Rock
Link:https://www.muckrock.com/foi/united-states-of-america-10/solar-sunrise-department-of-justice-national-security-division-102086/

Source snippet

Solar Sunrise (Department of Justice, National Security Division) • MuckRockSeptember 14, 2020 — * * * # Solar Sunrise (Department of Jus...

Published: September 14, 2020

10. Source: dockets.justia.com
Link:https://dockets.justia.com/docket/district-of-columbia/dcdce/1%3A2026cv00028/288215

Source snippet

BURGUM et al 1:2026cv00028 | U.S. District Court for the District of Columbia | JustiaJanuary 6, 2026 — SUNRISE WIND LLC v. BURGUM et al...

Published: January 6, 2026

11. Source: cert.europa.eu
Title: eu CER T-EU
Link:https://cert.europa.eu/publications/security-advisories/2020-055/

Source snippet

europa.euCERT-EU - Critical Vulnerability in the Solaris PAM LibraryNovember 5, 2020 — SECURITY ADVISORY 2020-055 Release Date: 05-11-202...

Published: November 5, 2020

12. Source: muckrock.com
Title: Solar Sunrise (Federal Bureau of Investigation) • Muck Rock
Link:https://www.muckrock.com/foi/united-states-of-america-10/solar-sunrise-federal-bureau-of-investigation-102085/

13. Source: diamd.usdoj.gov
Title: changing access sunrise sunset dates
Link:https://diamd.usdoj.gov/doc/help/help/lcm/changing_access_sunrise_sunset_dates.htm

14. Source: nsarchive.gwu.edu
Title: 19178 national security archive federal bureau
Link:https://nsarchive.gwu.edu/document/19178-national-security-archive-federal-bureau

15. Source: umbra.nascom.nasa.gov
Title: prelim and background rept
Link:https://umbra.nascom.nasa.gov/soho/prelim_and_background_rept.html

16. Source: ammrl.org
Title: Nov_Dec-99: [Fwd: CERT Advisory CA-99.16
Link:https://www.ammrl.org/archives/Nov_Dec-99/0118.html

17. Source: washingtonpost.com
Title: U.S. STUDIES NEW THREAT: CYBER ATTACK
Link:https://www.washingtonpost.com/archive/politics/1998/05/24/us-studies-new-threat-cyber-attack/d91743ac-700d-46d3-ae58-5009ae91ec74/