HOME

TheInfoList



OR:

The WANK Worm was a
computer worm A computer worm is a standalone malware computer program that replicates itself in order to spread to other computers. It often uses a computer network to spread itself, relying on security failures on the target computer to access it. It wil ...
that attacked DEC
VMS #REDIRECT VMS {{redirect category shell, {{R from other capitalisation{{R from ambiguous page ...
computers in 1989 over the
DECnet DECnet is a suite of network protocols created by Digital Equipment Corporation. Originally released in 1975 in order to connect two PDP-11 minicomputers, it evolved into one of the first peer-to-peer network architectures, thus transforming DEC ...
. It was written in
DIGITAL Command Language DIGITAL Command Language (DCL) is the standard command language adopted by many of the operating systems created by Digital Equipment Corporation. DCL had its roots in IAS, TOPS-20, and RT-11 and was implemented as a standard across most of Digit ...
.


Origin

The worm is believed to have been created by
Melbourne Melbourne ( ; Boonwurrung/Woiwurrung: ''Narrm'' or ''Naarm'') is the capital and most populous city of the Australian state of Victoria, and the second-most populous city in both Australia and Oceania. Its name generally refers to a met ...
-based hackers, the first to be created by an Australian or Australians. The
Australian Federal Police The Australian Federal Police (AFP) is the national and principal federal law enforcement agency of the Australian Government with the unique role of investigating crime and protecting the national security of the Commonwealth of Australia. Th ...
thought the worm was created by two
hackers A hacker is a person skilled in information technology who uses their technical knowledge to achieve a goal or overcome an obstacle, within a computerized system by non-standard means. Though the term ''hacker'' has become associated in popu ...
who used the names
Electron The electron ( or ) is a subatomic particle with a negative one elementary electric charge. Electrons belong to the first generation of the lepton particle family, and are generally thought to be elementary particles because they have no kn ...
and
Phoenix Phoenix most often refers to: * Phoenix (mythology), a legendary bird from ancient Greek folklore * Phoenix, Arizona, a city in the United States Phoenix may also refer to: Mythology Greek mythological figures * Phoenix (son of Amyntor), a ...
.
Julian Assange Julian Paul Assange ( ; Hawkins; born 3 July 1971) is an Australian editor, publisher, and activist who founded WikiLeaks in 2006. WikiLeaks came to international attention in 2010 when it published a series of leaks provided by U.S. Army inte ...
may have been involved, but this has never been proven.Bernard Lagan
"International man of mystery,"
''
The Sydney Morning Herald ''The Sydney Morning Herald'' (''SMH'') is a daily compact newspaper published in Sydney, New South Wales, Australia, and owned by Nine. Founded in 1831 as the ''Sydney Herald'', the ''Herald'' is the oldest continuously published newspaper ...
'', 10 April 2010. Retrieved 17 March 2014.


Political message

The WANK worm had a distinct political message attached, and it was the first major worm to have a political message. WANK in this context stands for Worms Against Nuclear Killers. The following message appeared on infected computer's screen: The worm coincidentally appeared on a
DECnet DECnet is a suite of network protocols created by Digital Equipment Corporation. Originally released in 1975 in order to connect two PDP-11 minicomputers, it evolved into one of the first peer-to-peer network architectures, thus transforming DEC ...
network operated by
NASA The National Aeronautics and Space Administration (NASA ) is an independent agency of the US federal government responsible for the civil space program, aeronautics research, and space research. NASA was established in 1958, succeeding t ...
days before the launch of a NASA
Space Shuttle The Space Shuttle is a retired, partially reusable low Earth orbital spacecraft system operated from 1981 to 2011 by the U.S. National Aeronautics and Space Administration (NASA) as part of the Space Shuttle program. Its official program na ...
carrying the ''
Galileo Galileo di Vincenzo Bonaiuti de' Galilei (15 February 1564 – 8 January 1642) was an Italian astronomer, physicist and engineer, sometimes described as a polymath. Commonly referred to as Galileo, his name was pronounced (, ). He was ...
'' spacecraft. At the time, there were protests by anti-nuclear groups regarding the use of the plutonium-based power modules in ''Galileo''. The protesters contended that if this shuttle blew up as ''Challenger'' did three years earlier in 1986, the
plutonium Plutonium is a radioactive chemical element with the symbol Pu and atomic number 94. It is an actinide metal of silvery-gray appearance that tarnishes when exposed to air, and forms a dull coating when oxidized. The element normally exhibi ...
spilled would cause widespread death to residents of Florida. The worm propagated through the network pseudo-randomly from one system to the other by using an algorithm which converted the victim machine's system time into a candidate target node address (composed of a DECnet Area and Node number) and subsequently attempted to exploit weakly secured accounts such as SYSTEM and DECNET that had password identical to the usernames. The worm did not attack computers within DECnet area 48, which was
New Zealand New Zealand ( mi, Aotearoa ) is an island country in the southwestern Pacific Ocean. It consists of two main landmasses—the North Island () and the South Island ()—and over 700 smaller islands. It is the sixth-largest island count ...
. A comment inside the worm source code at the point of this branch logic indicated that New Zealand was a nuclear-free zone. New Zealand had recently forbidden U.S. nuclear-powered vessels from docking at its harbours, thus further fueling the speculation inside NASA that the worm attack was related to the anti-nuclear protest. The line "You talk of times of peace for all, and then prepare for war" is drawn from the lyrics of the
Midnight Oil Midnight Oil (known informally as "The Oils") are an Australian rock band composed of Peter Garrett (vocals, harmonica), Rob Hirst (drums), Jim Moginie (guitar, keyboard) and Martin Rotsey (guitar). The group was formed in Sydney in 1972 by ...
song " Blossom and Blood". Midnight Oil are an Australian rock band known for their political activism and opposition to both nuclear power and nuclear weapons. The process name of the second version of the worm to be detected was "oilz", an Australian shorthand term for the band.


Playful nature

DECnet networks affected included those operated by the NASA Space Physics Analysis Network (SPAN), the
US Department of Energy The United States Department of Energy (DOE) is an executive department of the U.S. federal government that oversees U.S. national energy policy and manages the research and development of nuclear power and nuclear weapons in the United State ...
's High Energy Physics Network (
HEPnet HEPnet or the High-Energy Physics Network is a telecommunications network for researchers in high-energy physics. It originated in the United States, but that has spread to most places involved in such research. Well-known sites include Argonne ...
),
CERN The European Organization for Nuclear Research, known as CERN (; ; ), is an intergovernmental organization that operates the largest particle physics laboratory in the world. Established in 1954, it is based in a northwestern suburb of Gene ...
, and Riken. The only separation between the networks was a prearranged division of network addresses (DECnet "Areas"). Thus, the worm, by picking a random target address, could affect all infected networks equally. The worm code included 100 common VAX usernames that were hard-coded into its source code. In addition to its political message, the worm contained several features of an apparently playful nature. The words "wank" and "wanked" are slang terms used in many countries to refer to
masturbation Masturbation is the sexual stimulation of one's own genitals for sexual arousal or other sexual pleasure, usually to the point of orgasm. The stimulation may involve hands, fingers, everyday objects, sex toys such as vibrators, or combinatio ...
. In addition, the worm contained "over sixty" randomizable messages that it would display to users, including "Vote anarchist" and "The FBI is watching YOU". The worm was also programmed to trick users into believing that files were being deleted by displaying a file deletion dialogue that could not be aborted, though no files were actually erased by the worm.


anti-WANK and WANK_SHOT

R. Kevin Oberman (from DOE) and John McMahon (from NASA) wrote separate versions of an anti-WANK procedure and deployed them into their respective networks. It exploited the fact that before infecting a system, WANK would check for , that is a copy of its own, in the process table. If one was found, the worm would destroy itself. When anti-WANK was run on a non-infected system, it would create a process named and just sit there. anti-WANK only worked against the earlier version of the worm, though, because the process name of the worm in a later version was changed to . A second version of WANK was released on October 22. Unlike the previous version of WANK, this version was designed to actually damage the computers it infected, rather than only falsely claim to do so, and would alter the passwords of infected computers. Like the previous version of WANK, this program would utilise the RIGHTSLIST database to find new computers to infect. The program WANK_SHOT was designed by Bernard Perrow of the Institut de physique nucléaire d'Orsay, to rename RIGHTLIST and replace it with a dummy database. This would cause WANK to go after the dummy, which could be designed with a hidden
logic bomb A logic bomb is a piece of code intentionally inserted into a software system that will set off a malicious function when specified conditions are met. For example, a programmer may hide a piece of code that starts deleting files (such as a sala ...
. WANK_SHOT was then provided to the system administrators of affected networks to be installed onto their computers. It still took weeks for the worm to be completely erased from the network.


See also

* Father Christmas (computer worm)


References


External links

*
Advisory from Virus Test Center, University of Hamburg, Germany
* *
"Juvenile Delinquents or International Saboteurs?"
presented by Suelette Dreyfus at the Internet Crime conference held in Melbourne, 16–17 February 1998, by the Australian Institute of Criminology *
"Hacktivism and Politically Motivated Computer Crime"
- Written by one of the Digital Equipment Corporation investigators; disputes the WANK worm had any political motivation but was rather a play on the British meaning of the word "wank" {{Hacking in the 1980s Computer worms Wikipedia articles with ASCII art Hacking in the 1980s