Within Early Insecurity
How One Missed Patch Opened Government Networks
Solar Sunrise showed how a known software flaw could open government systems when available security patches were not installed.
On this page
- The known Solaris flaw attackers exploited
- How root access enabled traffic capture
- Why available patches had not been applied
Page outline Jump by section
Introduction
The 1998 Solar Sunrise intrusions became one of the clearest early demonstrations that government networks could be compromised not because attackers discovered a revolutionary new technique, but because known security updates had not been installed. Occurring only a few years before Gary McKinnon’s better-known intrusions, the incident illustrated the same underlying weakness: internet-connected government systems often depended on individual administrators applying vendor patches consistently across thousands of machines. When that routine maintenance failed, attackers could exploit publicly known vulnerabilities to obtain administrator privileges, monitor network traffic and move between systems. Solar Sunrise therefore became an important historical warning that poor patch management, rather than sophisticated offensive capability alone, could expose sensitive government networks.[kb.cert.org]kb.cert.orgVU#41870 - Sun Solstice AdminSuite ships with insecure default configurationSeptember 19, 2003…
The Known Solaris Flaw Attackers Exploited
Investigators concluded that the Solar Sunrise attackers targeted vulnerable Sun Solaris systems that had not been updated against publicly disclosed security weaknesses. Rather than developing a previously unknown exploit, they relied on flaws for which vendors had already released security information and corrective patches.
One particularly significant weakness involved Solaris’ remote administration infrastructure, including the sadmind service. In insecure default configurations, or on systems that had not been properly updated and hardened, attackers could send forged requests that were accepted with superuser privileges. Because the service was designed for legitimate remote administration, successful exploitation immediately granted extensive control over the affected machine.[kb.cert.org]kb.cert.orgVU#41870 - Sun Solstice AdminSuite ships with insecure default configurationSeptember 19, 2003…
This reflected a broader problem of the late 1990s. Security advisories, mailing lists and vendor bulletins routinely announced vulnerabilities together with the patches needed to correct them. Once those advisories became public, attackers could search the internet for systems that administrators had failed to update. As a result, the period between patch release and widespread deployment increasingly became an opportunity for intrusion rather than protection.[SecLists]seclists.orgBugtraq: Sun Security Bulletin #00162February 10, 1998…
How Root Access Enabled Traffic Capture
Obtaining root access transformed a vulnerable workstation or server into a powerful observation point inside the network.
With administrator privileges, intruders could:
- install packet-sniffing software to capture usernames, passwords and other network traffic;
- modify system files to preserve access;
- create additional privileged accounts;
- use the compromised machine as a trusted launch point against neighbouring systems; and
- conceal their presence by altering logs or system configurations.
In Solar Sunrise, this ability to capture credentials mattered as much as the initial exploit. Networks in the late 1990s still relied heavily on protocols that transmitted authentication information with limited protection. Once attackers controlled a strategically placed Solaris host, they could collect credentials belonging to legitimate users and administrators, making lateral movement significantly easier without repeatedly exploiting software vulnerabilities. The initial missed patch therefore became the starting point for much broader compromise.[kb.cert.org]kb.cert.orgVU#41870 - Sun Solstice AdminSuite ships with insecure default configurationSeptember 19, 2003…
This pattern closely foreshadowed later incidents involving UFO-motivated hackers such as Gary McKinnon. In both cases, the first foothold often proved more valuable than the original vulnerability because administrative control enabled continued exploration of interconnected government systems.
Why Available Patches Had Not Been Applied
The most enduring lesson from Solar Sunrise was not that patches were unavailable, but that organisations struggled to deploy them consistently.
Several practical factors contributed:
- Decentralised administration. Different military units and agencies managed their own systems, making uniform updates difficult.
- Operational concerns. Administrators sometimes delayed installing patches because they feared disrupting mission-critical applications.
- Limited asset visibility. Organisations frequently lacked accurate inventories showing which machines required updates.
- Rapid network growth. Government networks expanded faster than security management practices matured.
During this period, applying patches remained largely a manual process. Centralised vulnerability management tools were immature, and many organisations depended on local administrators to monitor security bulletins, obtain vendor fixes and install them individually. Missing even one update could leave an internet-facing server exposed long after the vulnerability had become publicly known. Sun Microsystems’ own security bulletins repeatedly urged customers to install affected patches immediately, illustrating that vendor guidance existed but was not always translated into operational practice.[SecLists]seclists.orgBugtraq: Sun Security Bulletin #00162February 10, 1998…
A Turning Point for Government Cybersecurity
Solar Sunrise influenced how government agencies viewed routine system maintenance. The incident demonstrated that vulnerability management was not merely an administrative task but a central element of national security.
Several lessons emerged:
- published vulnerabilities quickly became operational attack tools;
- patch deployment speed was often as important as the quality of the patch itself;
- internet-connected systems required continuous inventory and configuration management; and
- successful defence depended on organisational discipline as much as technical innovation.
These conclusions helped reinforce later federal efforts to improve vulnerability assessment, centralised security management and routine patch compliance across government networks. Although Solar Sunrise is often remembered for the uncertainty surrounding its attribution during the investigation, its longer-lasting technical legacy was showing how ordinary maintenance failures could create extraordinary security risks.[kb.cert.org]kb.cert.orgVU#41870 - Sun Solstice AdminSuite ships with insecure default configurationSeptember 19, 2003…
Solar Sunrise in the Context of Early Internet Insecurity
Within the broader history of early internet insecurity behind UFO-related hacking cases, Solar Sunrise occupies an important place because it exposed a recurring pattern rather than an isolated mistake. The attackers did not have to overcome an impenetrable defensive system. They benefited from government computers running software that administrators already knew required updates.
That same pattern helps explain why later intrusions by individuals such as Gary McKinnon could succeed against numerous government computers. Different motivations drove different attackers, but both episodes demonstrated that inconsistent patching, combined with interconnected networks and widespread administrator privileges, could allow relatively modest technical methods to produce disproportionately significant security breaches.[kb.cert.org]kb.cert.orgVU#41870 - Sun Solstice AdminSuite ships with insecure default configurationSeptember 19, 2003…
Amazon book picks
Further Reading
Books and field guides related to How One Missed Patch Opened Government Networks. Use these as the next step if you want deeper reading beyond the article.
Dark Territory
"The never-before-told story of the computer scientists and the NSA, Pentagon, and White House policymakers who invented and employ the w...
Security Engineering
Rating: 4.5/5 from 7 Google Books ratings
Now that there's software in everything, how can you make anything secure? Understand how to engineer dependable systems with this newly...
Where Wizards Stay Up Late
Rating: 3.8/5 from 11 Google Books ratings
In 1990, the ARPANET itself was shut down, fully merged by then with the Internet it had spawned.
Countdown to Zero Day
Top cybersecurity journalist Kim Zetter tells the story behind the virus that sabotaged Iran’s nuclear efforts and shows how its existenc...
eBay marketplace picks
Marketplace Samples
Live-tested eBay searches with available results related to this page.
Selected fromRoswell UFO patch oneBay.co.uk.
Endnotes
1.
Source: kb.cert.org
Link:https://www.kb.cert.org/vuls/id/41870
Source snippet
VU#41870 - Sun Solstice AdminSuite ships with insecure default configurationSeptember 19, 2003...
Published: September 19, 2003
2.
Source: seclists.org
Link:https://seclists.org/bugtraq/1998/Feb/48
Source snippet
Bugtraq: Sun Security Bulletin #00162February 10, 1998...
Published: February 10, 1998
3.
Source: seclists.org
Link:https://seclists.org/bugtraq/1998/Nov/236
Source snippet
Bugtraq: Sun Security Bulletin #00179...
4.
Source: seclists.org
Link:https://seclists.org/bugtraq/1998/Jul/155
Source snippet
Bugtraq: Sun Security Bulletin #00173...
5.
Source: kb.cert.org
Link:https://kb.cert.org/vuls/id/351219
6.
Source: seclists.org
Link:https://seclists.org/bugtraq/1998/Dec/15
7.
Source: justice.gov
Link:https://www.justice.gov/archives/jm/criminal-resource-manual-29-electronic-surveillance-title-iii-affidavits
Additional References
8.
Source: justice.gov
Link:https://www.justice.gov/archives/opa/pr/department-justice-statement-solarwinds-update
Source snippet
January 6, 2021 — Press Release DEPARTMENT OF JUSTICE STATEMENT ON SOLARWINDS UPDATE Wednesday, January 6, 2021 For Immediate Release Off...
Published: January 6, 2021
9.
Source: muckrock.com
Title: Solar Sunrise (Department of Justice, National Security Division) • Muck Rock
Link:https://www.muckrock.com/foi/united-states-of-america-10/solar-sunrise-department-of-justice-national-security-division-102086/
Source snippet
Solar Sunrise (Department of Justice, National Security Division) • MuckRockSeptember 14, 2020 — * * * # Solar Sunrise (Department of Jus...
Published: September 14, 2020
10.
Source: dockets.justia.com
Link:https://dockets.justia.com/docket/district-of-columbia/dcdce/1%3A2026cv00028/288215
Source snippet
BURGUM et al 1:2026cv00028 | U.S. District Court for the District of Columbia | JustiaJanuary 6, 2026 — SUNRISE WIND LLC v. BURGUM et al...
Published: January 6, 2026
11.
Source: cert.europa.eu
Title: eu CER T-EU
Link:https://cert.europa.eu/publications/security-advisories/2020-055/
Source snippet
europa.euCERT-EU - Critical Vulnerability in the Solaris PAM LibraryNovember 5, 2020 — SECURITY ADVISORY 2020-055 Release Date: 05-11-202...
Published: November 5, 2020
12.
Source: muckrock.com
Title: Solar Sunrise (Federal Bureau of Investigation) • Muck Rock
Link:https://www.muckrock.com/foi/united-states-of-america-10/solar-sunrise-federal-bureau-of-investigation-102085/
13.
Source: diamd.usdoj.gov
Title: changing access sunrise sunset dates
Link:https://diamd.usdoj.gov/doc/help/help/lcm/changing_access_sunrise_sunset_dates.htm
14.
Source: nsarchive.gwu.edu
Title: 19178 national security archive federal bureau
Link:https://nsarchive.gwu.edu/document/19178-national-security-archive-federal-bureau
15.
Source: umbra.nascom.nasa.gov
Title: prelim and background rept
Link:https://umbra.nascom.nasa.gov/soho/prelim_and_background_rept.html
16.
Source: ammrl.org
Title: Nov_Dec-99: [Fwd: CERT Advisory CA-99.16
Link:https://www.ammrl.org/archives/Nov_Dec-99/0118.html
17.
Source: washingtonpost.com
Title: U.S. STUDIES NEW THREAT: CYBER ATTACK
Link:https://www.washingtonpost.com/archive/politics/1998/05/24/us-studies-new-threat-cyber-attack/d91743ac-700d-46d3-ae58-5009ae91ec74/



