HOME

TheInfoList



OR:

Milw0rm is a group of
hacktivists Hacktivism (or hactivism; a portmanteau of ''hack'' and ''activism''), is the use of computer-based techniques such as hacking as a form of civil disobedience to promote a political agenda or social change. A form of Internet activism with roots ...
best known for penetrating the computers of the
Bhabha Atomic Research Centre The Bhabha Atomic Research Centre (BARC) is India's premier nuclear research facility, headquartered in Trombay, Mumbai, Maharashtra, India. It was founded by Homi Jehangir Bhabha as the Atomic Energy Establishment, Trombay (AEET) in January 1954 ...
(BARC) in
Mumbai Mumbai ( ; ), also known as Bombay ( ; its official name until 1995), is the capital city of the Indian state of Maharashtra. Mumbai is the financial capital and the most populous city proper of India with an estimated population of 12 ...
, the primary nuclear research facility of
India India, officially the Republic of India, is a country in South Asia. It is the List of countries and dependencies by area, seventh-largest country by area; the List of countries by population (United Nations), most populous country since ...
, on June 3, 1998. The group conducted hacks for political reasons, including the largest mass hack up to that time, inserting an
anti-nuclear The Anti-nuclear war movement is a social movement that opposes various nuclear technologies. Some direct action groups, environmental movements, and professional organisations have identified themselves with the movement at the local, n ...
weapons agenda and peace message on its hacked websites. The group's logo featured the slogan "Putting the power back in the hands of the people." The BARC attack generated heated debate on the security of information in a world prevalent with countries developing nuclear weapons and the information necessary to do so, the ethics of "hacker activists" or "hacktivists," and the importance of advanced security measures in a modern world filled with people willing and able to break into insecure international websites. The exploit site milw0rm.com and str0ke are unaffiliated with the milw0rm hacker group.


Members

Little is known about the members of milw0rm, which is typical of hacking groups, which often conceal members' identities to avoid prosecution. The international hacking team "united only by the
Internet The Internet (or internet) is the Global network, global system of interconnected computer networks that uses the Internet protocol suite (TCP/IP) to communicate between networks and devices. It is a internetworking, network of networks ...
" was composed of teenagers who went by the aliases of JF, Keystroke, ExtreemUK, savec0re, and VeNoMouS. VeNoMouS, 18, hailed from New Zealand, ExtreemUK and JF, 18, from England, Keystroke, 16, from the US and Savec0re, 17, from the Netherlands. JF went on to achieve a modicum of notoriety when
MTV MTV (an initialism of Music Television) is an American cable television television channel, channel and the flagship property of the MTV Entertainment Group sub-division of the Paramount Media Networks division of Paramount Global. Launched on ...
"hacked" its own website intentionally and graffitied the words "JF Was Here" across the page, at the same time that JF was under investigation for the milw0rm attacks by
Scotland Yard Scotland Yard (officially New Scotland Yard) is the headquarters of the Metropolitan Police, the territorial police force responsible for policing Greater London's London boroughs, 32 boroughs. Its name derives from the location of the original ...
. Hundreds of pages hosted on MTV.com sported the new JF logo, including one page that read, "JF was here, greets to milw0rm". MTV later confirmed that the alleged JF "hack" was a publicity stunt to promote the appearance of a commentator named Johnny Fame at the 1998 MTV Video Music Awards. Many were puzzled by the apparent hack committed by JF since the hacker was "known for relatively high ethical standards." VeNoMouS claimed that he learned to crack into systems from Ehud Tenenbaum, an Israeli hacker known as The Analyzer.


BARC attack

On the night of June 3, 1998, the group used a US military .mil machine to break into the LAN of BARC and gained root access. The group gained access to five megabytes of confidential emails and documents. These emails included correspondence between the center's scientists relating to the development of nuclear weapons. Savec0re erased all the data on two servers as a protest against the center's nuclear capabilities. They changed the center's webpage to display a mushroom cloud along with an anti-nuclear message and the phrase "Don't think destruction is cool, coz its not". The group of teenagers were from the
United States The United States of America (USA), also known as the United States (U.S.) or America, is a country primarily located in North America. It is a federal republic of 50 U.S. state, states and a federal capital district, Washington, D.C. The 48 ...
,
United Kingdom The United Kingdom of Great Britain and Northern Ireland, commonly known as the United Kingdom (UK) or Britain, is a country in Northwestern Europe, off the coast of European mainland, the continental mainland. It comprises England, Scotlan ...
and
New Zealand New Zealand () is an island country in the southwestern Pacific Ocean. It consists of two main landmasses—the North Island () and the South Island ()—and List of islands of New Zealand, over 600 smaller islands. It is the List of isla ...
. Milw0rm then came forward with the security flaws they exploited in BARC's system, along with some of the thousands of pages of documents they had lifted from the server, concerning India's last five nuclear detonations. After the attack Keystroke claimed that the breach had taken "13 minutes and 56 seconds" to execute. Though it was later reported that Keystroke meant this as a lighthearted answer. The invasion took careful planning, routing through servers throughout the world from three different continents, and took days to execute.


Attack aftermath

The security breach was first reported by ''
Wired Wired may refer to: Arts, entertainment, and media Music * ''Wired'' (Jeff Beck album), 1976 * ''Wired'' (Hugh Cornwell album), 1993 * ''Wired'' (Mallory Knox album), 2017 * "Wired", a song by Prism from their album '' Beat Street'' * "Wired ...
'' News. JF and VeNoMouS claimed credit by emailing ''Wired'' reporter James Glave with documents they had obtained from the BARC servers as proof. After first denying that any incident had occurred, BARC officials admitted that the center had indeed been hacked and emails had been downloaded. It was reported that the security flaw resulted from "a very normal loophole in Sendmail". ''Forbes'' wrote that perhaps up to 100 hackers had followed milw0rm's footsteps into the BARC servers once they were revealed as insecure. The website was shut down while its security was upgraded. BARC officials said that none of the emails contained confidential information, the group did not destroy data, and that the computers they have that contain important data were isolated from the ones broken into. The milw0rm attack caused other groups to heighten their security to prevent invasion by hackers. The U.S. Army announced, without giving evidence as to why they believed this to be the case, that the hacks might have originated in
Turkey Turkey, officially the Republic of Türkiye, is a country mainly located in Anatolia in West Asia, with a relatively small part called East Thrace in Southeast Europe. It borders the Black Sea to the north; Georgia (country), Georgia, Armen ...
. Later,
Khalid Ibrahim Abdul Khalid bin Ibrahim (; 14 December 1946 – 31 July 2022) was a Malaysian politician who served as the 14th Menteri Besar of Selangor from 2008 to 2014. He was the Member of the Selangor State Assembly (MLA) for Ijok from 2008 to 2013, ...
approached members of milw0rm and attempted to buy classified documents from them. According to savec0re, Ibrahim threatened to kill him if the hacker did not turn over the classified documents in question. Savec0re told
Kevin Mitnick Kevin David Mitnick (August 6, 1963 – July 16, 2023) was an American computer security consultant, author, and convicted hacker. In 1995, he was arrested for various computer and communications-related crimes, and spent five years in prison ...
that Ibrahim first approached him posing as a family member of an
FBI The Federal Bureau of Investigation (FBI) is the domestic Intelligence agency, intelligence and Security agency, security service of the United States and Federal law enforcement in the United States, its principal federal law enforcement ag ...
agent who could grant immunity to the members of milw0rm. The
Electronic Disturbance Theater The Electronic Disturbance Theater (EDT), established in 1997 by performance artist and writer Ricardo Dominguez, is an electronic company of cyber activists, critical theorists, and performance artists. History The Electronic Disturbance Theat ...
released a statement in support of JF, applauding him for his hacktivism and maintaining that computer break-ins of this sort were not cyber-terrorism as some claim.


Other attacks

One month after the BARC incident, in July 1998, milw0rm hacked the British web hosting company Easyspace, putting their anti-nuclear mushroom cloud message on more than 300 of Easyspace's websites, along with text that read: "This mass takeover goes out to all the people out there who want to see peace in this world." ''Wired'' reported that this incident was perhaps the "largest 'mass hack' ever undertaken." The
United States Department of Defense The United States Department of Defense (DoD, USDOD, or DOD) is an United States federal executive departments, executive department of the federal government of the United States, U.S. federal government charged with coordinating and superv ...
adviser John Arquilla later wrote that it was one of the largest hacks ever seen. Some of the sites hacked in the incident were for the
World Cup A world cup is a global sporting competition in which the participant entities – usually international teams or individuals representing their countries – compete for the title of world champion. The event most associated with the name is ...
,
Wimbledon Wimbledon most often refers to: * Wimbledon, London, a district of southwest London * Wimbledon Championships, the oldest tennis tournament in the world and one of the four Grand Slam championships Wimbledon may also refer to: Places London * W ...
, the Ritz Casino,
Drew Barrymore Drew Blythe Barrymore (born February 22, 1975) is an American actress, talk show host, and businesswoman. A member of the Barrymore family of actors, she has received multiple List of awards and nominations received by Drew Barrymore, awards a ...
, and the Saudi royal family. The text placed on the sites read in part, "This mass takeover goes out to all the people out there who want to see peace in this world... This tension is not good, it scares you as much as it scares us. For you all know that this could seriously escalate into a big conflict between India and Pakistan and possibly even World War III, and this CANNOT happen... Use your power to keep the world in a state of PEACE." While scanning a network for weaknesses, members of the group came across EasySpace, a British company which hosted many sites on one server. Along with members of the fellow hacking group Ashtray Lumberjacks, milw0rm had the revised mushroom cloud image and text on all of Easyspace's websites in less than one hour. Vranesevich said that the mass hack was rare in its effect and its intention: the hackers seemed to be more interested in political purposes than exposing computer security flaws. It was also reported that milw0rm broke into a Turkish nuclear facility in addition to BARC.


See also

*
Hacktivism Hacktivism (or hactivism; a portmanteau of ''hack'' and ''activism''), is the use of computer-based techniques such as hacking as a form of civil disobedience to promote a political agenda or social change. A form of Internet activism with roots ...
* 1984 Network Liberty Alliance


References


External links


Mirrors of hacked sites


BARC hack
{{Hacking in the 1990s Hacker groups Anti–nuclear weapons movement Hacking (computer security) Cybercrime in India Nuclear history of India Nuclear weapons programme of India Indian nuclear weapons testing Anti-nuclear movement in India