w00w00

An invite-only security crew that lived on an IRC channel and is routinely called the most influential hacker group nobody's heard of. It never robbed a bank or crashed a network. It wrote advisories, argued about heap overflows, and quietly incubated the people who would build Napster and WhatsApp. Two of the most consequential consumer apps of the era came out of the same channel — and the crew that raised them stayed so far underground that the press only noticed in 2014, when Facebook paid $19 billion for what one of them had made.

Heap/BSS-based overflows are fairly common in applications today; yet, they are rarely reported. Therefore, we felt it was appropriate to present a "heap overflow" tutorial.

Matt Conover ("Shok") & the w00w00 Security Team, opening "w00w00 on Heap Overflows," January 1999 — the paper that put heap exploitation on the map

WHO
w00w00 (pronounced "whoo-whoo") — a private computer-security research group / think tank, founded ~1996 FACT
SCENE
An IRC-based, invite-only crew that grew to 30+ participants across 12 countries on five continents; a fixture at DEF CON. See Crew Rivalries and the Antisecurity Movement
THE DRAMA
The influence-to-obscurity ratio. Prolific vulnerability research and a landmark heap-overflow paper — and alumni who went on to found Napster and WhatsApp and to lead security at major companies, while the group itself stayed all but invisible
RECORD
No group prosecution, no marquee bust. Published defensive research (heap overflows, early SQL injection, common-service advisories). Alumni companies include WhatsApp, Napster, Arbor Networks, Duo Security, and the nmap project FACT
STATUS
DISBANDED — dormant since the early 2000s; the alumni network long outlived the channel

This file is not an accusation; there is barely a charge to answer. It is a record of what a small, private, unglamorous crew can seed. The through-line is the gap between the myth — a shadowy elite hacker cabal — and the paperwork, which shows a mailing list, an IRC channel, a stack of advisories, and a founders' bench that reshaped how a couple of billion people message each other. The drama is that almost nobody outside security has ever heard the name.

the drama timeline

ACT I — THE CHANNEL (1996–1998)

A think tank forms where think tanks don't: on an IRC channel, invite-only, spread across a dozen countries.

  1. ~1996

    w00w00 is founded

    A computer-security think tank forms and takes root on IRC. It will grow to over 30 active participants spanning 12 countries on five continents — a genuinely global crew years before that was ordinary. Matt Conover ("Shok") is among the founding members.

  2. 1996–99

    Advisories, not exploits-for-hire

    The crew focuses on finding vulnerabilities in widely deployed software and publishing advisories — weaknesses in common Unix services like wu-ftpd and the like. Member Jeff Forristal becomes one of the first people to publicly document SQL injection. The output is defensive-research flavored: find it, write it up, ship it.

ACT II — THE PAPER (1999)

One document does more for the crew's reputation than a hundred break-ins ever could.

  1. JAN 1999

    "w00w00 on Heap Overflows"

    Matt Conover and the w00w00 Security Team publish "w00w00 on Heap Overflows" — a tutorial on a class of bug the field had underrated next to stack smashing. It becomes a canonical, endlessly-cited reference in exploitation research. This is the crew's signature: not a heist, a paper. Influence measured in citations, not indictments.

ACT III — THE ALUMNI (1999–2014)

The founders' bench. Same channel; two of the era's defining apps.

  1. 1999

    Napster comes out of the crew

    Shawn Fanning — listed among w00w00's participants — launches Napster, the file-sharing service that detonated the music industry. Fellow travelers Sean Parker and Jordan Ritter, also named in the w00w00 orbit, are part of the Napster story. The channel's first world-changing spin-off.

  2. 2000

    The crew has its own back

    Jan Koum — then responsible for security at Yahoo, and a w00w00 participant — is grappling with a denial-of-service attack knocking Yahoo offline. By the widely-reported account, the group comes to his aid. Crew culture in one anecdote: the channel shows up when a member's under fire.

  3. 2009–14

    WhatsApp — and the $19B footnote

    Jan Koum co-founds WhatsApp in 2009. In 2014 Facebook buys it for roughly $19 billion — and the press finally clocks the pattern, running the "elite security posse that spawned WhatsApp and Napster" story. The most influential crew you never heard of gets about one news cycle of daylight.

  4. 2000s–

    Security's quiet bench

    Beyond the two famous apps, the roster reads like a who's-who of the defensive industry: Dug Song (Arbor Networks, later Duo Security), Gordon Lyon ("Fyodor," author of nmap), Dragos Ruiu (CanSecWest / Pwn2Own), among many others. Wikipedia's tally: participants who "have spawned more than a dozen IT companies."

ACT IV — THE FEUD FOOTNOTE (2002–)

Even a legendary crew has a scene-politics footnote. One member's name shows up in the disclosure wars.

  1. 2002

    K2, named as w00w00

    In the antisec disclosure wars, a PHC statement names K2 — author of the ADMmutate polymorphic shellcode engine — as "a member of numerous underground organizations including ADM and w00w00." It's an adversary's framing inside a live feud, but it places the crew's name squarely in the great whitehat-vs-blackhat argument of the era (see K2 and the Antisecurity Movement).

  2. early 2000s

    The channel goes quiet

    w00w00 winds down as its people scatter into companies, conferences, and careers. The name lingers in citations and in the origin stories of half the security industry — and in the trivia answer to "what do Napster and WhatsApp have in common." The crew disbands; the network doesn't.

both sides, on the record

The skeptic's read: this was still an invite-only crew with the mystique to match, and not every member was a tidy whitehat. At least one participant, K2, is tangled in the antisec disclosure wars, self-identified as a blackhat, and accused of narcing on rivals. "Legendary security crew" and "underground hacker channel" describe the same room [6].

The obscurity was partly a choice: private channel, no public roster, no manifesto. The group cultivated exactly the kind of low profile that later let it be re-mythologized on its own terms. Mystique is a form of PR.

The output was defensive and public: advisories on common software, early SQL-injection documentation, and a heap-overflow paper that made a hard subject teachable. This is research that helped the field, published for anyone to read [1] [2].

The influence is real and net-positive: alumni built WhatsApp and Napster, founded Arbor Networks and Duo Security, wrote nmap, and ran the conferences that trained a generation. Reuters didn't invent the pattern in 2014; it just finally noticed it [3].

No group rap sheet: there is no marquee bust, no crashed network, no victim ledger. The scandal here is that a crew this consequential stayed this obscure for this long [1].

YOU DECIDE

Strip the mystique and you're left with a mailing list, an IRC channel, a stack of advisories, and a founders' bench that seeded WhatsApp, Napster, and a chunk of the modern security industry. The only genuine controversy is a scene-politics footnote — one member's name in the antisec crossfire. Measured in influence per press mention, w00w00 may be the most lopsided crew in the archive.

The archive does not deify. But it does keep receipts — and this crew's receipts are advisories and IPOs, not indictments.

evidence locker

PRIMARY / REFERENCE

  1. Wikipedia — w00w00 ATTRIBUTED — founding (~1996), scale (30+ participants, 12 countries, five continents), member roster (Conover, Fanning, Koum, Song, Lyon, Parker, Ritter, Ruiu, Forristal), and alumni companies (WhatsApp, Napster, Arbor Networks, Duo Security, nmap). en.wikipedia.org/wiki/W00w00
  2. w00w00 — "on Heap Overflows" (Jan 1999) FACT — the group's signature paper, by Matt Conover ("Shok") & the w00w00 Security Team; source of the first-party quote above. cgsecurity.org/exploit/heaptut.txt

PRESS & CROSS-LINKS

  1. Reuters — "Elite security posse fostered founders of WhatsApp, Napster" (2014) ATTRIBUTED — the definitive press account of the crew: IRC/DEF CON culture, Koum's Yahoo years, and the group coming to his aid during the 2000 Yahoo DoS. finance.yahoo.com/news/elite-security-posse-fostered-founders-110613185.html
  2. TechCrunch — w00w00 (Mar 2, 2014) ATTRIBUTED — contemporaneous tech-press coverage of the crew after the WhatsApp/Facebook deal. techcrunch.com/2014/03/02/w00w00/
  3. Wikipedia — Jan Koum / Shawn Fanning ATTRIBUTED — the two marquee alumni: WhatsApp co-founder and Napster founder. en.wikipedia.org/wiki/Jan_Koum
  4. troll.fan — K2 / Antisecurity Movement CROSS-LINK — the PHC statement naming K2 as an ADM/w00w00 member, in the context of the disclosure wars. First-party antisec source; an adversary's characterization. troll.fan/k2.html
  5. w00w00.org — w00c0n FIRST-PARTY — the crew's own live domain, now fronting w00c0n ("w00w00 presents"), an invite-only cyber-intelligence conference in Las Vegas (Aug 7–10) — puzzle-gated bus pickup, redacted schedule, a w00w00 Slack and tee for the verified. Its tagline, "Altruistic Meritocracy," is the crew's founding ethos, still running. w00w00.org
The standard. w00w00 is a documented security group; its founding, scale, research output, and alumni are matters of public record via Wikipedia and 2014 press coverage, given here at full strength. Membership of famous alumni (Koum, Fanning, Parker, Ritter, Song, Lyon, Conover) is asserted only where those sources support it, and attributed. The one adversarial claim — K2's w00w00 membership — comes from a hostile first-party antisec statement and is flagged as such, not adopted as the crew's own account. No private data; nothing beyond the record is asserted. If a line here couldn't survive scrutiny, it wouldn't be on the page.

The signal still finds its own. The IRC channel is long gone, but the name is not: w00w00.org today fronts w00c0n — "w00w00 presents" — an invite-only cyber-intelligence conference in Las Vegas, still flying the crew's founding two words as its tagline: altruistic meritocracy. The most influential crew you never heard of never quite disbanded; it just stopped publishing the channel.