Milw0rm
   HOME

TheInfoList



OR:

Milw0rm is a group of
hacktivists In Internet activism, hacktivism, or hactivism (a portmanteau of ''hack'' and '' activism''), is the use of computer-based techniques such as hacking as a form of civil disobedience to promote a political agenda or social change. With roots in ha ...
best known for penetrating the computers of the
Bhabha Atomic Research Centre The Bhabha Atomic Research Centre (BARC) is India's premier nuclear research facility, headquartered in Trombay, Mumbai, Maharashtra, India. It was founded by Homi Jehangir Bhabha as the Atomic Energy Establishment, Trombay (AEET) in January 1 ...
(BARC) in
Mumbai Mumbai (, ; also known as Bombay — List of renamed Indian cities and states#Maharashtra, the official name until 1995) is the capital city of the Indian States and union territories of India, state of Maharashtra and the ''de facto'' fin ...
, the primary nuclear research facility of
India India, officially the Republic of India (Hindi: ), is a country in South Asia. It is the seventh-largest country by area, the second-most populous country, and the most populous democracy in the world. Bounded by the Indian Ocean on the so ...
, on June 3, 1998. The group conducted hacks for political reasons, including the largest mass hack up to that time, inserting an
anti-nuclear The anti-nuclear movement is a social movement that opposes various nuclear technologies. Some direct action groups, environmental movements, and professional organisations have identified themselves with the movement at the local, nationa ...
weapons agenda and peace message on its hacked websites. The group's logo featured the slogan "Putting the power back in the hands of the people." The BARC attack generated heated debate on the security of information in a world prevalent with countries developing nuclear weapons and the information necessary to do so, the ethics of "hacker activists" or "hacktivists," and the importance of advanced security measures in a modern world filled with people willing and able to break into insecure international websites. The exploit site milw0rm.com and str0ke are unaffiliated with the milw0rm hacker group.


Members

Little is known about the members of milw0rm, which is typical of hacking groups, which often conceal members' identities to avoid prosecution. The international hacking team "united only by the
Internet The Internet (or internet) is the global system of interconnected computer networks that uses the Internet protocol suite (TCP/IP) to communicate between networks and devices. It is a '' network of networks'' that consists of private, pub ...
" was composed of teenagers who went by the aliases of JF, Keystroke, ExtreemUK, savec0re, and VeNoMouS. VeNoMouS, 18, hailed from New Zealand, ExtreemUK and JF, 18, from England, Keystroke, 16, from the US and Savec0re, 17, from the Netherlands. JF went on to achieve a modicum of notoriety when MTV "hacked" its own website intentionally and graffitied the words "JF Was Here" across the page, at the same time that JF was under investigation for the milw0rm attacks by Scotland Yard. Hundreds of pages hosted on MTV.com sported the new JF logo, including one page that read, "JF was here, greets to milw0rm". MTV later confirmed that the alleged JF "hack" was a publicity stunt to promote the appearance of a commentator named Johnny Fame at the
1998 MTV Video Music Awards The 1998 MTV Video Music Awards aired live on September 10, 1998, honoring the best music videos from June 17, 1997, to June 12, 1998. The show was hosted by Ben Stiller at Gibson Amphitheatre in Los Angeles. Madonna was the most successful winn ...
. Many were puzzled by the apparent hack committed by JF since the hacker was "known for relatively high ethical standards." VeNoMouS claimed that he learned to crack into systems from
Ehud Tenenbaum Ehud "Udi" Tenenbaum ( he, אהוד "אודי" טננבאום; born August 29, 1979), also known as The Analyzer, is an Israeli hacker. Biography Tenenbaum was born in Hod HaSharon in 1979. He became famous in 1998 when he was arrested for hac ...
, an Israeli hacker known as The Analyzer.


BARC attack

Four days before the incident, the five permanent members of the
United Nations Security Council The United Nations Security Council (UNSC) is one of the six principal organs of the United Nations (UN) and is charged with ensuring international peace and security, recommending the admission of new UN members to the General Assembly, an ...
, the US,
Russia Russia (, , ), or the Russian Federation, is a transcontinental country spanning Eastern Europe and Northern Asia. It is the largest country in the world, with its internationally recognised territory covering , and encompassing one-eig ...
,
United Kingdom The United Kingdom of Great Britain and Northern Ireland, commonly known as the United Kingdom (UK) or Britain, is a country in Europe, off the north-western coast of the European mainland, continental mainland. It comprises England, Scotlan ...
,
France France (), officially the French Republic ( ), is a country primarily located in Western Europe. It also comprises of overseas regions and territories in the Americas and the Atlantic, Pacific and Indian Oceans. Its metropolitan area ...
and China, denounced both
India India, officially the Republic of India (Hindi: ), is a country in South Asia. It is the seventh-largest country by area, the second-most populous country, and the most populous democracy in the world. Bounded by the Indian Ocean on the so ...
and
Pakistan Pakistan ( ur, ), officially the Islamic Republic of Pakistan ( ur, , label=none), is a country in South Asia. It is the world's fifth-most populous country, with a population of almost 243 million people, and has the world's second-lar ...
for unilaterally declaring themselves
nuclear weapon A nuclear weapon is an explosive device that derives its destructive force from nuclear reactions, either fission (fission bomb) or a combination of fission and fusion reactions ( thermonuclear bomb), producing a nuclear explosion. Both bom ...
s states. The day before the attack,
Jacques Gansler Jacques Singleton "Jack" Gansler (November 21, 1934 – December 4, 2018) was an aerospace electronics engineer, defense contracting executive and public policy expert. He served as Under Secretary of Defense for Acquisition, Technology and Logist ...
, US Undersecretary of Defense for acquisition and technology, warned a military conference that teenage hackers posed "a real threat" to national security. On the night of June 3, 1998, from their workstations on three continents, the group used a US military
.mil The domain name mil is the sponsored top-level domain (sTLD) in the Domain Name System of the Internet for the United States Department of Defense and its subsidiary or affiliated organizations. The name is derived from ''military''. It was on ...
machine to break into the LAN, or local area network, of BARC and gained
root access In computing, the superuser is a special user account used for system administration. Depending on the operating system (OS), the actual name of this account might be root, administrator, admin or supervisor. In some cases, the actual name of t ...
. The center's website, connected to the LAN, and their
firewall Firewall may refer to: * Firewall (computing), a technological barrier designed to prevent unauthorized or unwanted communications between computer networks or hosts * Firewall (construction), a barrier inside a building, designed to limit the spr ...
were not secured enough to prevent the group from entering and gaining access to confidential emails and documents. The emails included correspondence between the center's scientists relating to their development of nuclear weapons and analysis of five recent nuclear tests. Milw0rm took control of six servers and then posted a statement of anti-nuclear intentions on the center's website. In the process of the break-in, the multinational group of teenagers – from the
United States The United States of America (U.S.A. or USA), commonly known as the United States (U.S. or US) or America, is a country primarily located in North America. It consists of 50 states, a federal district, five major unincorporated territori ...
,
United Kingdom The United Kingdom of Great Britain and Northern Ireland, commonly known as the United Kingdom (UK) or Britain, is a country in Europe, off the north-western coast of the European mainland, continental mainland. It comprises England, Scotlan ...
and
New Zealand New Zealand ( mi, Aotearoa ) is an island country in the southwestern Pacific Ocean. It consists of two main landmasses—the North Island () and the South Island ()—and over 700 smaller islands. It is the sixth-largest island count ...
– gained access to five megabytes of classified documents pertaining to India's nuclear weapons program. Savec0re erased all the data on two servers as a protest against the center's nuclear capabilities. To display their security breach publicly, they changed the center's webpage to display a mushroom cloud along with an anti-nuclear message and the phrase "Don't think destruction is cool, coz its not". Milw0rm then came forward with the security flaws they exploited in BARC's system, along with some of the thousands of pages of documents they had lifted from the server, concerning India's last five nuclear detonations. The group's purpose for the attack was to protest nuclear testing, according to Savec0re, VeNoMouS and JF, in their correspondence with ''Wireds reporter James Glave. After the attack Keystroke claimed that the breach had taken "13 minutes and 56 seconds" to execute. Many news organizations reported breathlessly how the teenagers had penetrated a nuclear research facility in "less than 14 minutes." However, examining more closely the hacker's wording and tone in the interview, and especially the specificity of the "56 seconds" claim, it is apparent that Keystroke meant this as a lighthearted answer to the question, "Exactly how long did it take you?". The actual invasion took careful planning, routing through servers throughout the world from three different continents, and took days to execute. An Indian news agency reported that downloading thousands of pages from India's slow servers would have taken much longer than 14 minutes.


Attack aftermath

The security breach was first reported by ''
Wired ''Wired'' (stylized as ''WIRED'') is a monthly American magazine, published in print and online editions, that focuses on how emerging technologies affect culture, the economy, and politics. Owned by Condé Nast, it is headquartered in San ...
'' News. JF and VeNoMouS claimed credit by emailing ''Wired'' reporter
James Glave James is a common English language surname and given name: *James (name), the typically masculine first name James * James (surname), various people with the last name James James or James City may also refer to: People * King James (disambiguat ...
with documents they had obtained from the BARC servers as proof. After first denying that any incident had occurred, BARC officials admitted that the center had indeed been hacked and emails had been downloaded. An official at BARC downplayed the severity and importance of the incident, announcing that the security flaw resulted from "a very normal loophole in Sendmail," while going on to state that the center had not bothered to download a new version of the Sendmail program, responsible for the center's email servers. The center also admitted that after milw0rm's breach, the site had been hacked into again, this time with less severe consequences. ''Forbes'' wrote that perhaps up to 100 hackers had followed milw0rm's footsteps into the BARC servers once they were revealed as insecure. The website was shut down while its security was upgraded. Later, a senior US government official told ZDNet that the Indians had known about the flaw and had chosen to ignore it, creating the opportunity for milw0rm to root the servers. BARC officials said that none of the emails contained confidential information, the group did not destroy data, and that the computers they have that contain important data were isolated from the ones broken into. Nevertheless, the breach was a severe one and had the potential to cause an incident of international proportions. ''
Forbes ''Forbes'' () is an American business magazine owned by Integrated Whale Media Investments and the Forbes family. Published eight times a year, it features articles on finance, industry, investing, and marketing topics. ''Forbes'' also r ...
'' called it "potentially the most devastating" hacking incident of 1998. After the attack, members of the group participated in an anonymous
Internet Relay Chat Internet Relay Chat (IRC) is a text-based chat system for instant messaging. IRC is designed for group communication in discussion forums, called '' channels'', but also allows one-on-one communication via private messages as well as chat an ...
(IRC) chat with John Vranesivich, the founder of hacking news website Anti-Online. Keystroke explained how if he wanted to, he could have sent threatening emails from the Indian email server to a Pakistani email server. If the group had possessed malicious intentions, the consequences for both south Asian countries could have been catastrophic. For these reasons, the milw0rm attack caused other groups to heighten their security to prevent invasion by hackers. The U.S. Army announced, without giving evidence as to why they believed this to be the case, that the hacks might have originated in
Turkey Turkey ( tr, Türkiye ), officially the Republic of Türkiye ( tr, Türkiye Cumhuriyeti, links=no ), is a transcontinental country located mainly on the Anatolian Peninsula in Western Asia, with a small portion on the Balkan Peninsula in ...
, noting that "Turkey is the primary conduit for cyber attacks." A senior US official said that the
CIA The Central Intelligence Agency (CIA ), known informally as the Agency and historically as the Company, is a civilian foreign intelligence service of the federal government of the United States, officially tasked with gathering, processing, ...
had obtained the material that milw0rm had purloined and was reviewing it—the official did not mention how the CIA obtained this information. Later, ''
Wired ''Wired'' (stylized as ''WIRED'') is a monthly American magazine, published in print and online editions, that focuses on how emerging technologies affect culture, the economy, and politics. Owned by Condé Nast, it is headquartered in San ...
'' revealed that an Indian national and self-proclaimed terrorist, Khalid Ibrahim, had approached members of milw0rm and other hacker groups on IRC—including Masters of Downloading and the Noid—and attempted to buy classified documents from them. According to savec0re, Ibrahim threatened to kill him if the hacker did not turn over the classified documents in question. Savec0re told
Kevin Mitnick Kevin David Mitnick (born August 6, 1963) is an American computer security consultant, author, and convicted hacker. He is best known for his high-profile 1995 arrest and five years in prison for various computer and communications-related crim ...
that Ibrahim first approached him posing as a family member of an
FBI The Federal Bureau of Investigation (FBI) is the domestic intelligence and security service of the United States and its principal federal law enforcement agency. Operating under the jurisdiction of the United States Department of Justice, t ...
agent who could grant immunity to the members of milw0rm. The Electronic Disturbance Theater released a statement in support of JF, applauding him for his hacktivism and maintaining that computer break-ins of this sort were not cyber-terrorism as some claim. The event received wide international coverage, with reports by
CNN CNN (Cable News Network) is a multinational cable news channel headquartered in Atlanta, Georgia, U.S. Founded in 1980 by American media proprietor Ted Turner and Reese Schonfeld as a 24-hour cable news channel, and presently owned by ...
,
MSNBC MSNBC (originally the Microsoft National Broadcasting Company) is an American news-based pay television cable channel. It is owned by NBCUniversala subsidiary of Comcast. Headquartered in New York City, it provides news coverage and politi ...
and the
Associated Press The Associated Press (AP) is an American non-profit news agency headquartered in New York City. Founded in 1846, it operates as a cooperative, unincorporated association. It produces news reports that are distributed to its members, U.S. ne ...
in the days following.


Other attacks

One month after the BARC incident, in July 1998, milw0rm hacked the British web hosting company Easyspace, putting their anti-nuclear mushroom cloud message on more than 300 of Easyspace's websites, along with text that read: "This mass takeover goes out to all the people out there who want to see peace in this world." ''Wired'' reported that this incident was perhaps the "largest 'mass hack' ever undertaken." The
United States Department of Defense The United States Department of Defense (DoD, USDOD or DOD) is an executive branch department of the federal government charged with coordinating and supervising all agencies and functions of the government directly related to national sec ...
adviser John Arquilla later wrote that it was one of the largest hacks ever seen. Some of the sites hacked in the incident were for the
World Cup A world cup is a global sporting competition in which the participant entities – usually international teams or individuals representing their countries – compete for the title of world champion. The event most associated with the concept i ...
, Wimbledon, the Ritz Casino,
Drew Barrymore Drew Blythe Barrymore (born February 22, 1975) is an American actress, director, producer, talk show host and author. A member of the Barrymore family of actors, she is the recipient of several accolades, including a Golden Globe Award and a ...
, and the Saudi royal family. The text placed on the sites read in part, "This mass takeover goes out to all the people out there who want to see peace in this world... This tension is not good, it scares you as much as it scares us. For you all know that this could seriously escalate into a big conflict between India and Pakistan and possibly even World War III, and this CANNOT happen... Use your power to keep the world in a state of PEACE." While scanning a network for weaknesses, members of the group came across EasySpace, a British company which hosted many sites on one server. Along with members of the fellow hacking group Ashtray Lumberjacks, milw0rm had the revised mushroom cloud image and text on all of Easyspace's websites in less than one hour. Vranesevich said that the mass hack was rare in its effect and its intention: the hackers seemed to be more interested in political purposes than exposing computer security flaws. It was also reported that milw0rm broke into a Turkish nuclear facility in addition to BARC.


See also

*
Hacktivism In Internet activism, hacktivism, or hactivism (a portmanteau of ''hack'' and ''activism''), is the use of computer-based techniques such as hacking as a form of civil disobedience to promote a political agenda or social change. With roots in hac ...
* 1984 Network Liberty Alliance


References


External links


Mirrors of hacked sites


BARC hack
{{Hacking in the 1990s Hacker groups Anti–nuclear weapons movement Hacking (computer security) Cybercrime in India Nuclear history of India Nuclear weapons programme of India Indian nuclear weapons testing Anti-nuclear movement in India