before http (ncsa mosaic is march 1993), I was using gopher, newsgroups and xarchie. When you saw a reference to a program in a newsgroup, it was often easy with xarchie to find a public ftp mirror where you could download it. I remember reading CERT advisories on gopher and having noticed that at my school, the vulnerable command xloadmodule was present (sunOS 4.3). I warned the admin and after 15 days of no reaction and no answer, I became root of all the servers. Good old days ;-)