Illuminati Online
Illuminati Online of Austin TX, aka IOCOM Corporation (chuckle), died with a whimper when it was sold to Prismnet.com in August, 2004. It's domain name was finally sold off in June, 2011 to a storage provider who wanted a short trophy alias.
This modest Internet Service Provider was launched with the money won in court years after the USA Secret Service raided Steve Jackson Games and seized everything with an electrical cord including their busy Bulletin Board System. After years of pressure, the Secret Service eventually claimed that SJG was literally designing a mainframe hacking course "disguised" as a role-playing game. They insisted on this, right up until the bloody end. Well, it turned out that it was just a board game and success was determined by rolling dice. A "cyberpunk" styled choose-your-own-adventure game.
As the year 2001 began, IO had around 4,850 customers, 18 staff, and raised a bit over $1M/yr in revenues. IO consisted of around thirty servers, mostly 200MHz PPRO and 233MHz PII desktop systems which were mounted in bargain basement beige ATX cases.
IO also colocated TX Governor George W. Bush's server cabinet until just before his candidacy for President was announced. I can't explain why he chose to use a hosting company whose theme was based on conspiracies, political elite, and secret societies, and which was on the Secret Service's permanent shit list.
You could telnet to password.io.com from anywhere in the world, and log on as guest. Lynx, a text-only web browser, was configured as the shell, and you would then be presented with a sparse version of the web-based customer account tools found at http://password.io.com/. This was so customers could reset their own password, update their address, set their PLAN file, etc.
THE HOLE
IO forgot to disable browsing the filesystem (press g, period, enter). Also, IO never enforced uniform file and directory permissions or audited active accounts. As a result, through 2004, after IO was taken over by Prismnet (or later), you could roam around and directly view many customer's private files, email spools, within /public_html, and IO's own sensitive system areas. You could also open the Lynx config to define a custom "editor" and thus actually edit files, or run executables. This was a direct back-door into everything! This continued a full two years after IOCOM "hardened" their network to sell network security services.
For more details, visit my clone of IO's old website at io.fondoo.net via archive.org around February 2023. As I write this, archive.org seems to be over capacity. The snapshot does contain lots of pages and images though if you can come back at a better time. The white side on the left is just as the company designed, and the text written on the purple side on the right is my insider's commentary.