ADM

An underground exploit-development crew that never held a press conference, never got a marquee bust, and never much cared whether you'd heard of it. What ADM left behind was code: a DNS spoofer, an SNMP brute-forcer, and one of the first worms ever to crawl the Linux internet on its own — plus an attitude that hardened, downstream, into a whole movement's creed. They built the tools the security industry got paid to defend against, released them for free, and treated the industry itself as the mark. Most of them are still just handles. That's the point.

ADMsnmp is an snmpd audit scanner … ADMsnmp is very easy to use and designed with speed in mind!

From the ADMsnmp readme, as carried in the FreeBSD ports description — the crew's whole ethos in one line: ship a fast, usable attack tool, no apology attached

WHO
ADM — an underground exploit-development crew, active ~1997–early 2000s; the name is later glossed as Association De Malfaiteurs ("Criminals' Association") FACT
SCENE
Pseudonymous elite tool-builders whose orbit overlapped w00w00, TESO, and the exploit-dev diaspora; a documented DEF CON 1999 page defacement and an August party in Berlin hint at a partly German crew. See Crew Rivalries and the Antisecurity Movement
THE DRAMA
Less a feud than a posture. ADM built release-quality attack tools and gave them away, held the security industry in open contempt, and — per Phrack's own history — seeded the antisecurity ethos that later crews (~el8, h0no, PHC) turned into a war on whitehats
RECORD
No group prosecution on the public record. Shipped ADMw0rm (one of the first Linux worms), ADMkillDNS / ADMsniffID (DNS spoofing), ADMsnmp (SNMP audit), ADMid, and other tools archived on Packet Storm. Associate "K2" wrote ADMmutate FACT
STATUS
DISBANDED — dormant since the early 2000s; the tools live on in ports trees and audit distros, the members mostly stayed handles

A note on honesty before the timeline: ADM's individual-drama record is thin, and this file will not pretend otherwise. There is no arrest saga, no on-camera meltdown, no doxxable roster to hang a soap opera on — because the crew was disciplined about staying anonymous and let the code do the talking. So the story here is the code and the creed: landmark tools, given away; an industry treated as the enemy; and a straight line from that contempt to the antisecurity movement that came after. Where the record is a legend rather than a receipt, we say so.

the drama timeline

ACT I — THE TOOLKIT (late 1990s)

Before the worm, the crew's reputation was built the boring way: a shelf of tools that worked, released for anyone to run.

  1. late 1990s

    Release-quality attack tools, free to all

    ADM ships a run of polished offensive tools that circulate the scene and land in the permanent archive: ADMsnmp (an SNMP community-string brute-forcer and audit scanner), ADMkillDNS and ADMsniffID (DNS spoofing — sniff a LAN and answer DNS queries with forgeries before the real nameserver can), ADMid, and more. These weren't proofs-of-concept; they were usable, documented, and fast, and several outlived the crew — ADMsnmp is still carried as a package in the FreeBSD ports tree.

ACT II — THE WORM (1998–1999)

Then the crew wrote something that didn't need a human to run it. It ran itself, across the internet, and rewrote your homepage on the way out.

  1. ~1998

    ADMw0rm — one of the first Linux worms

    ADMw0rm is a self-propagating shell-script worm for Linux x86. It scans random address space for a machine running a vulnerable BIND nameserver, fires a buffer overflow in named (the 4.9.6 IQUERY bug) over TCP port 53 to get root, then downloads ADMw0rm.tgz, creates a passwordless w0rm account and a suid-root shell at /tmp/.w0rm, wipes /etc/hosts.deny, and — the signature flourish — hunts for index.html files and overwrites them with its own. It is one of the earliest fully autonomous Linux worms, and a direct code ancestor of the Ramen (2001) and Lion worms that followed.

  2. MAR 1999

    Caught in the wild

    The worm turns up loose on the internet. Ben Cantrick posts it to Bugtraq on March 25, 1999 after a compromised Red Hat box starts port-scanning — the sighting reportedly surfaced when a Russian admin noticed an American machine sweeping his subnet. The post catalogs the now-familiar worm behavior: propagate, wipe logs, drop a suid root shell, and deface web roots with the contents of its SAY variable. A crew that built quiet audit tools had shipped something that announced itself on every server it touched.

  3. 1999

    The DEF CON defacement

    By the Virus Encyclopedia's account, the crew may be "just as famous" for a 1999 stunt as for the worm: defacing the DEF CON convention's own web page with a joke about airline prices and the U.S. president attending the con. The same writeup notes a group party in Berlin that August — the thin thread of evidence that ADM was, at least in part, a German crew. This is the closest the record comes to a personality; take it as legend with a footnote, not a rap sheet.

ACT III — THE LINEAGE (early 2000s)

The tools were the visible output. The invisible one was an attitude — and it turned out to be the more durable release.

  1. early 2000s

    Association De Malfaiteurs — the antisec seed

    By Phrack's own history of the international scene, ADM — glossed as Association De Malfaiteurs, "Criminals' Association" — was "one of the most influential" groups of the era, and the crew that "under additional influences, gave a new life to the antisecurity movement in the early 2000, by creating public web forums to justify the non-disclosure of exploit software." The forum was anti.security.is. ADM sits upstream of the whole "own the whitehats" current that ran through ~el8, h0no, and the Phrack High Council — documented in full in the Antisecurity Movement file.

  2. c. 1999–2001

    Overlapping benches — ADMmutate and the diaspora

    ADM's membership blurred into the rest of the elite tool scene — crews like TESO and w00w00 shared the same air. The associate "K2" — author of ADMmutate, described by him as likely "the first public polymorphic shellcode ever" — is named as ADM in the antisec disclosure wars, an adversary's framing he disputed. His code is the substance; the label is the drama. See K2 and the Disclosure Wars.

ACT IV — THE AFTERLIFE (present)

The crew went quiet. The code didn't.

  1. 2000s–

    Disbanded, but still in the toolbox

    ADM winds down as its people scatter, and — true to form — almost nobody's real name goes with it. The residue is in the archives and the audit distros: ADMsnmp still ships in the FreeBSD ports tree and in penetration-testing toolkits decades later, and the ADM group directory on Packet Storm remains a small museum of late-90s offensive craft. The worm became a footnote in the origin story of every Linux worm that followed; the attitude became a movement. Not bad for a crew that mostly refused to introduce itself.

both sides, on the record

The prosecution's read: this was a crew that wrote and released a self-propagating worm and a shelf of ready-to-run attack tools into the open, where anyone — script kiddie or otherwise — could point them at a stranger's server. ADMw0rm hit machines in the wild, dropped root shells, and defaced web roots. Handing that out for free is not a neutral act [1] [2].

The contempt was the brand: ADM didn't just decline to help the security industry — per Phrack's history it helped stand up the forums arguing that industry was the enemy. The anonymity that makes this file thin on personal drama is also what let the "own the whitehats" ethos spread without a face to hold accountable [5].

The tools were also defensive: ADMsnmp is an audit scanner — the same tool that finds a weak SNMP community string for an attacker finds it for the admin who's supposed to fix it. Released code, publicly archived, that a generation of defenders learned from. The ports maintainers didn't keep it around by accident [3].

The worm exposed a real hole: ADMw0rm didn't invent the BIND named IQUERY overflow — it weaponized a vulnerability that already existed and that admins were ignoring. Worms are how the internet learned to patch. The uncomfortable teacher is still a teacher [1] [2].

No group rap sheet: there is no marquee ADM prosecution, no named victim ledger, on the public record. The crew's legacy is measured in ports packages and citations, not indictments — and its members, tellingly, were never publicly identified to be charged [4].

YOU DECIDE

Strip the mystique and ADM is a small, disciplined, pseudonymous crew that shipped landmark code — one of the first Linux worms, a clutch of DNS and SNMP tools — and an attitude that outlived the code: that the security industry was a mark, not an ally. The individual-drama file is genuinely thin, and we've said so. What's not thin is the lineage. Draw the line from anti.security.is forward and you get ~el8, h0no, the Phrack High Council, and eventually Operation AntiSec. ADM is where the "own the whitehats" story starts.

The archive does not deify. But it keeps receipts — and ADM's receipts are readme files, a worm in a Bugtraq post, and a package still sitting in a ports tree twenty-five years on.

evidence locker

PRIMARY / REFERENCE

  1. Bugtraq — "ADM Worm. Worm for Linux x86 found in wild." (Mar 25, 1999) FACT — the contemporaneous wild-sighting report by Ben Cantrick: portscanning, log-wiping, suid-root shell, and the SAY-variable HTML defacement. Primary evidence the worm was live. seclists.org/bugtraq/1999/Mar/165
  2. Virus Encyclopedia — Adm FACT — the technical writeup: the BIND named 4.9.6 IQUERY overflow over TCP 53, the w0rm account and /tmp/.w0rm shell, the March 1999 wild infection, the ADM crew as short-lived (late 90s–early 2000s), the DEF CON page defacement, the Berlin party, and ADMw0rm as precursor to Ramen and Lion. virus.wikidot.com/adm
  3. FreeBSD ports — security/ADMsnmp FACT — the ADM SNMP audit scanner, still packaged decades later; source of the first-party readme quote ("very easy to use and designed with speed in mind"). freshports.org/security/ADMsnmp
  4. Packet Storm — ADM group archive FACT — the permanent archive of ADM's released tools (ADMsnmp, ADMkillDNS, ADMid, and the rest); the crew's body of work in one directory. packetstormsecurity.com/groups/ADM

LINEAGE & CROSS-LINKS

  1. Phrack #64 — International scenes (ADM history) ATTRIBUTED — the primary retrospective naming ADM as Association De Malfaiteurs and crediting it with giving "new life to the antisecurity movement" via public forums (anti.security.is). The lineage claim, in the scene's own zine. phrack.org/issues/64/15
  2. troll.fan — Antisecurity Movement CROSS-LINK — the full ADM → ~el8 / h0no / PHC → Operation AntiSec lineage, with the movement's own published arguments. troll.fan/dossiers/antisecurity-movement.html
  3. troll.fan — K2 / w00w00 / Disclosure Wars CROSS-LINK — the ADMmutate author named as ADM in the disclosure wars (his handle kept, framing flagged as the adversary's), and the overlapping elite-crew scene. troll.fan/dossiers/k2.html
The standard. ADM is a documented underground crew; its released tools and their dates are matters of public record via Bugtraq, Packet Storm, the FreeBSD ports tree, and the Virus Encyclopedia, given here at full strength as FACT. The lineage claim — that ADM seeded the antisecurity movement — is attributed to Phrack's own retrospective and cross-linked to the Antisecurity file, not asserted as the crew's self-account. Membership was pseudonymous and is left that way: no real legal names appear, and the one named associate, "K2," is kept as his handle and credited only with his own self-published work. The DEF CON-defacement and German-crew details are flagged as the Virus Encyclopedia's account. Where the individual-drama record is thin, the file says so rather than inventing a feud. If a line here couldn't survive scrutiny, it wouldn't be on the page.