How did a single computer worm written by a Cornell graduate student in November 1988 crash roughly 6,000 machines and force the internet to invent security?

How did a single computer worm written by a Cornell graduate student in November 1988 crash roughly 6,000 machines and force the internet to invent security?

On the evening of 2 November 1988, a Cornell graduate student named Robert Tappan Morris uploaded a small C program to a machine at the MIT Artificial Intelligence Laboratory and set it loose on the internet. Within hours, computers at Berkeley, Stanford, Princeton, NASA Ames, the RAND Corporation, Lawrence Livermore and dozens of other sites were grinding to a halt, spawning hundreds of copies of a mysterious process that ate every spare cycle of CPU time. By the following afternoon, system administrators across the United States were pulling network cables out of the wall in self-defence. It was the first time the internet, then a research network of roughly 60,000 hosts, had encountered a self-replicating attack — and the first time most of its operators realised how little protected it.

The best contemporary reconstruction is the Purdue technical report by Eugene Spafford, published weeks after the incident. Spafford estimated that around 6,000 machines — roughly a tenth of the internet at the time — were affected. Nothing was destroyed, no files were altered, no data was stolen. The damage was entirely a matter of load: the worm forked copies of itself so aggressively that infected computers became too busy to do anything else.

The first alarms rang at Berkeley. According to the FBI’s later account, a programmer there emailed colleagues late that night with a stark warning — “We are currently under attack” — as the campus’s workstations slowed to a crawl and refused new logins. Within a day the same symptoms had surfaced at research sites across the country, and administrators began comparing notes by telephone, trying to work out whether they were looking at a hardware fault, a runaway program, or something deliberate.

What the worm actually did

Morris’s program was designed to spread quietly and count how far it reached. To move from one machine to another, it exploited four separate weaknesses in the Unix systems then standard on the ARPANET and its offspring. The most infamous was a buffer overflow in fingerd, the daemon that answered queries about which users were logged in. By sending a carefully crafted 536-byte string, the worm overran a fixed-size buffer on VAX machines running BSD and jumped into shellcode it had smuggled in behind the overflow — a technique that would define offensive security for the next three decades.

It also used a debug feature left enabled in most installations of sendmail, the internet’s mail transport program, which allowed a remote sender to pipe a message directly into a shell. It tried a dictionary of about 400 common passwords against user accounts, plus variations on each user’s login name and real name, to break into further hosts through rsh and rexec. And it exploited the trust relationships that Unix administrators had cheerfully wired between their machines: once it owned one computer in a lab, the others usually let it in without further checks.

Any one of these tricks would have been serious. Combined into a single program that carried them from host to host, they were catastrophic. The US Government Accountability Office report issued the following June estimated cleanup and lost-productivity costs at between $100,000 and $10 million, and noted that no one really knew, because no one had ever had to measure such a thing before.

For all its reach, the worm was a small piece of software. Its documented internals describe a 99-line bootstrap program written in C that, once it gained a foothold, pulled across a larger main body and went to work. It was built to stay hidden: it masked its text strings, cleaned up its own files, and disguised its running process so that a curious administrator would struggle to find it. The design was less that of a vandal than of a naturalist trying to cross a forest without being seen.

The bug that made it a disaster

Morris had anticipated that a self-replicating program might infect the same machine repeatedly, so he included a check: before installing itself, the worm asked whether another copy was already running. If yes, it would usually exit. But he worried that administrators would defeat this by writing a fake responder, so he added a twist — one time in seven, the worm ignored the answer and installed itself anyway.

One in seven was far too often. On heavily connected machines, the worm was being probed constantly, and the dice-roll meant new copies piled up faster than old ones could exit. Machines quickly accumulated dozens of instances, each fighting for CPU and network bandwidth. What Morris had imagined as a slow census of the internet became, within an hour, a denial-of-service attack on itself.

The arithmetic was merciless. Well-connected machines were queried so often that a one-in-seven reinfection rate stacked up copies faster than any system could shed them. In her history of digital weapons, Countdown to Zero Day, the journalist Kim Zetter records that computers at the University of Pennsylvania were hit roughly 210 times in twelve hours. Each fresh copy competed for processor time and memory until the host simply gave up.

How the internet fought back

There was no procedure for this. There was no CERT, no vendor security team, no coordinated disclosure list — the very concepts did not yet exist. What existed instead was a small community of Unix programmers who mostly knew one another and could reach each other by telephone. Over the night of 2–3 November, informal groups at Berkeley, MIT and Purdue disassembled captured copies of the worm’s binary, worked out what it was doing, and posted patches to the Usenet groups and mailing lists that still functioned. Keith Bostic at Berkeley circulated a fix for sendmail; a team at MIT reverse-engineered the password logic; Spafford at Purdue coordinated much of the write-up afterwards.

There is a bitter irony buried in the timeline. Once Morris grasped what his program was doing, he asked a friend to send an anonymous message across the network explaining how to stop it. But the network was already so congested by the worm that the instructions arrived too late to help. The cure could not travel faster than the disease it was meant to treat.

The internet itself, ironically, made the response harder. Many sites had disconnected from the network to stop the infection, which meant they could not receive the fixes. Some patches travelled by long-distance phone calls and hand-carried tapes. By 8 November, most systems were clean.

The worm broke a different kind of containment, too. One of Morris’s friends telephoned the New York Times, hoping to explain that the release had been an accident; in the course of those conversations he let slip the author’s initials, RTM. Reporters used them to identify Robert Tappan Morris within days, and the story moved from mailing lists to front pages.

Inventing security afterwards

The Defense Advanced Research Projects Agency, which still funded much of the network, responded within weeks. In November 1988 it commissioned the Software Engineering Institute at Carnegie Mellon to create a permanent response team, and the CERT Coordination Center opened its doors before the end of the year. Its job — new at the time, obvious in retrospect — was to be a phone number and mailbox that anyone dealing with a network intrusion could contact, and to coordinate the disclosure of vulnerabilities to vendors before attackers found them.

The technical lessons were absorbed more slowly. Buffer overflows would remain the dominant class of remote exploit for another twenty years, until stack canaries, address-space layout randomisation and non-executable memory became standard in mainstream operating systems in the 2000s. The sendmail debug hole was closed almost immediately, but the broader problem — trusting network input by default — would take a generation to unlearn. The idea that a program could and should treat every byte arriving over the wire as hostile was, in 1988, genuinely novel.

Morris himself became the first person prosecuted under the 1986 Computer Fraud and Abuse Act. He was convicted in 1990 and sentenced to three years’ probation, 400 hours of community service and a $10,050 fine; a federal appeals court upheld the conviction in 1991, in a ruling that helped fix how the new law would be read for years afterward.

The case carried an almost novelistic twist. Morris’s father, Robert Morris Sr., was at that moment chief scientist at the National Security Agency’s National Computer Security Center — one of the country’s foremost authorities on exactly the kind of Unix password security his son’s worm had defeated. The elder Morris had, years earlier at Bell Labs, helped design the scheme that encrypted Unix passwords in the first place.

Morris’s later life was gentler than the headlines of 1988 suggested. He went on to co-found the online-store company Viaweb, which Yahoo bought in 1998, helped start the startup accelerator Y Combinator, and became a professor at MIT — the same institution whose machine he had used as a launch pad. A floppy disk holding a decompiled copy of the worm now sits, small and unremarkable, in the collection of the Computer History Museum.

Why the story still matters

Before the Morris worm, security on the internet was a matter of politeness. Machines trusted one another because their operators trusted one another, and the network’s designers had focused on resilience against equipment failure, not against malicious code. In a single evening, one graduate student demonstrated that a program written in a dorm room could reach almost every computer on the network and bring most of them to a stop.

The incident also forced an argument the young network had been avoiding. Was the worm a naive experiment that escaped its author, or a reckless demonstration of flaws that everyone already knew about? The contemporary record shows professional bodies rushing to publish their first codes of conduct — statements that the deliberate disruption of a shared network, experimental or not, could never be excused. Computer ethics, until then an afterthought, suddenly had teeth.

The numbers make the point on their own. The network the worm nearly halted carried perhaps 60,000 machines; the one it helped secure now connects billions of devices and moves the world’s banking, medicine and conversation. The institutions improvised in the panic of that first week — a number to call, a team to disassemble the next attack, a norm that vulnerabilities get disclosed and patched — are the reason a comparable outbreak today would be met with something other than a scramble of late-night phone calls.

Every subsequent piece of internet security infrastructure — coordinated disclosure, patch Tuesdays, bug bounties, intrusion-detection systems, the entire discipline of incident response — traces back, in one line or another, to the phone calls made on the night of 2 November 1988. The network that carries almost all human communication today, including the 550-odd undersea cables that move roughly 99 per cent of international traffic, is protected by institutions that did not exist before that week. The worm did not destroy anything. It simply made it impossible to pretend, ever again, that the internet was a private club.

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Make Tech Easier Editorial Team Avatar

Read next

In 1947, Harvard’s Mark II ran on roughly 13,000 electromechanical relays, stored numbers across 100 registers, and read instructions from punched paper tape, turning thousands of clicking metal switches into a Navy calculator vulnerable to dust, loose contacts, and one famously misplaced moth
In 1971, engineer Ray Tomlinson sent the first networked email between two computers sitting side by side in the same room — he chose the @ symbol to separate user from machine because it was the only punctuation on the keyboard nobody was using
When you tilt a smartphone, gravity shifts microscopic silicon fingers inside its accelerometer by only a few nanometres, changing the capacitance between them and producing the electrical imbalance the phone reads as a new direction for down
A microwave oven works because water molecules have a slight positive and negative end — the magnetron flips an electric field 2.45 billion times a second, and the molecules twist back and forth so fast the friction becomes heat
The retina of the mantis shrimp carries twelve types of colour receptor to the human eye’s three — and yet experiments suggest it sees colour worse than we do, using the extra channels for speed instead of subtlety
When a lightning return stroke heats a channel only centimetres wide to roughly 30,000 kelvin, about five times the temperature of the Sun’s visible surface, the air expands so violently that the pressure wave rolls across the ground as thunder
In October 1957, a beachball-sized aluminium sphere called Sputnik 1 began sending 0.3-second pulses on two radio frequencies from orbit, signals amateur operators around the world could receive, making the space age suddenly audible from Earth
In 1968, Douglas Engelbart sat before roughly 1,000 computing professionals in San Francisco and demonstrated the mouse, hypertext, video conferencing and shared-screen editing in one 90-minute session, a concentrated glimpse of the interactive computer future later remembered as the Mother of All Demos