Threat Picture
Latest Cybersecurity News

Dan Farmer: Why SATAN Made System Administrators Nervous

A scanner that showed administrators their own weaknesses also showed attackers where to look. Its release put him at odds with his employer.
By Charles Joseph · Updated
Share
Share
Copy URL

Dan Farmer wrote the first vulnerability scanner because he needed one more class to graduate.

Six years later he wrote the second one with Wietse Venema, named it SATAN, released it on his birthday, and walked out of a job at Silicon Graphics rather than let the company bury it. The press said it was like "randomly mailing automatic rifles" to people. The internet survived.

Three decades on, he's still at it, publishing tools that poke at the secret computers hidden inside every server. The tools changed. The contrariness never did.

Dan Farmer at a Glance

  • The Morris worm hit the internet in November 1988, just before Farmer finished at Purdue. A summer course with professor Gene Spafford produced COPS, the first Unix security auditing tool, which he gave away for free in 1989.
  • COPS got him hired as roughly the sixth employee of the newly formed CERT. He later moved west to Sun's new security team.
  • In 1993 he and Venema published "Improving the Security of Your Site by Breaking Into It," then spent two years building SATAN, a network scanner with the first browser-based interface.
  • SATAN shipped in April 1995 amid a media frenzy. Silicon Graphics, where Farmer was security chief, gave him a choice of shelving it or leaving. He left.
  • With Venema he built The Coroner's Toolkit in 2000, the first forensic analysis tools for Unix, and wrote the book Forensic Discovery in 2004.
  • He co-founded Elemental Security as its CTO and served as security architect for four Fortune 500 companies, including Symantec, which laid him off.
  • A DARPA Cyber Fast Track grant led him to IPMI, the insecure management protocol inside servers. In 2026 he's still releasing tools for taking it apart.
Sponsored

The Life of Dan Farmer

Farmer's Early Years

By his own description Dan Farmer was "not a good student." He loved the spy-versus-spy stories in movies and books, but there seemed to be no way to make a living at it outside Washington, and he "wasn't cut out to live inside the Beltway."

Then, in November 1988, the Morris worm crashed through the young internet while he was finishing at Purdue. "The network was getting slammed and people were running around in the halls trying to figure out what was going on," he recalled. "If computers could do this, there was hope yet."

He needed one more course to graduate, so he walked into the office of Gene Spafford, who'd written one of the two definitive papers on the worm, and asked for a summer project in security. Spafford agreed. "It felt like the first time in my life that I had a purpose."

COPS

There was almost nothing to read. After months of searching Farmer had found one book, a small pile of articles and one gem, an MIT thesis on an expert system that probed security. He "cobbled together everything I could into one program," named it COPS, the Computer Oracle and Password System, and "put it out on the Internet for free."

COPS checked a Unix machine for the mistakes that got systems broken into: bad permissions, weak passwords, dangerous configurations. Nobody had shipped anything like it.

"People started assuming I was some sort of security expert rather than an obsessed young lad," Farmer said, and after a USENIX paper on COPS he was offered a job at CERT, the response team created after the worm. He was, he reckons, its sixth or seventh hire.

Sponsored

Sun, and Breaking In

CERT was a good place to work, but Farmer wanted to study worms and malware up close, and CERT didn't. "One of my personality defects is my almost pathological contrariness," he said. "If people tell me to stay away from something it's something akin to dropping a cardboard box in front of a housecat."

When Sun Microsystems went looking for "a technical head thug" for its new security team, he headed for Silicon Valley, where "nearly twice the salary didn't hurt either."

In 1993 he and a Dutch programmer named Wietse Venema wrote a paper with a title that still gets quoted: "Improving the Security of Your Site by Breaking Into It." The idea that the best way to find your holes was to attack yourself was radical then. It's now called penetration testing.

SATAN

The paper's logical next step was a program that did the breaking in for you. Farmer and Venema spent "the next couple of years writing, talking, and traveling to visit each other," while the security world waited. SATAN, the Security Administrator Tool for Analyzing Networks, "was perhaps the first security vaporware, the Duke Nukem Forever of its time."

It finally shipped in April 1995, on Farmer's birthday. CERT had already issued an advisory about the beta on April 3, and the press "had a field day."

SATAN would scan a network, find the weak services and explain them, through what Farmer believes was the first browser-based interface any program had. "Fortunately, the Internet survived."

The name didn't help. Farmer had, by then, taken a job as what he calls the "Security Czar" of Silicon Graphics, and had told his boss about the program before he was hired.

The Devil at SGI

Just before the release, Farmer was called into a meeting and "found myself alone with a vice president and a couple of lawyers, who claimed no prior knowledge of my work." They gave him options: release SATAN only to SGI customers, drop it, or let SGI turn it into a product. "Or I could walk."

"Another character flaw of mine is saying what I think rather than perhaps being a bit more politic," he said. "I refused their offers to take off with our work and never set foot at SGI again."

He went back to Sun, where he proposed a system for centralized security management. After a prototype was shown to Eric Schmidt, then a Sun executive, the order came to productize it with Farmer running the show, which was exactly what he'd said he didn't want. "So I quit."

In 1998 he returned with Titan, a lockdown tool for Solaris written with Brad Powell and Matt Archibald.

Sponsored

The Coroner's Toolkit

Farmer and Venema's next collaboration looked at the other end of an intrusion: what to do after it's happened. The Coroner's Toolkit, released in 2000, was the first set of forensic analysis tools for Unix, and it introduced ideas that every digital investigator now takes for granted: timelines built from file access times, recovering deleted data, carving evidence out of raw disk.

The two turned a series of columns into Forensic Discovery, published in December 2004, while Farmer served as chief technology officer of Elemental Security, the enterprise software company he co-founded. Over the years he was security architect for four Fortune 500 companies; the last of them, Symantec, dissolved its entire architecture group and laid him off.

Fast Track to IPMI

That layoff left him with free time just as his old friend Mudge, Peiter Zatko, was running DARPA's Cyber Fast Track program, which promised a yes or no on a research proposal within seven working days. Farmer submitted one "pretty much as a lark." It worked exactly as Mudge had claimed.

His favorite project was IPMI, "a rather obscure and, as it turns out, insecure out-of-band management protocol that servers speak," the firmware computer that can reboot and control a server even when it's switched off. The contract was a few months; he "spent nearly all my free time on it" and published papers in 2013 and 2014 that put the problem on the map.

He never stopped. On his blog, in the summer of 2026, he released zipmi, "a pure-Python IPMI/BMC stack" for inspecting and mangling every byte of the protocol, a collection of emulated server controllers for others to experiment on, and notes on unpacking Dell's iDRAC firmware.

Dan Farmer: Contrary by Design

Farmer's career runs on a single stubborn idea: that you can't protect a system you're forbidden to attack, and that the people who tell you not to look are usually the ones with something to hide.

He paid for it at SGI and in a dozen quieter rooms since. His personal site devotes as much space to his cats as to his code, and signs off with a note that one of them likes to sit on his desk while he works.

Somewhere in a data center tonight, a management controller is being probed by a tool he wrote because somebody told him not to.

QUOTE:

"Amateurs hack systems, professionals hack people."