At about half past eight on the evening of 2 November 1988, Robert Tappan Morris, a first-year graduate student in computer science at Cornell, logged into a machine at the MIT Artificial Intelligence Laboratory and released a program he had been writing for weeks. Its leading edge was tiny: a 99-line bootstrap in C, compiled on each victim, whose only job was to haul down the real engine behind it, a relocatable object file that would later decompile to more than 3,200 lines. By the next morning it had replicated onto machines from Berkeley to Baltimore, clogging mail queues, freezing servers and driving load averages so high that operators could not log in to kill it. The General Accounting Office reported that press accounts put the toll at roughly 6,000 systems, about 10 per cent of an internet that then numbered just over 60,000 hosts.

The worm did not destroy data. It did not harvest passwords for profit. It simply copied itself, again and again, in a way its author had not fully modelled, and in doing so it forced the loose federation of Unix administrators who ran the early internet to admit they had no plan for what to do when something went wrong at machine speed. Twelve days later, the Defense Advanced Research Projects Agency stood up the first computer emergency response team at Carnegie Mellon. The modern security-response industry begins there. The FBI still lists the incident among its famous cases.

Four doors into a Unix machine

The worm was engineered to spread through four distinct weaknesses, as Purdue computer scientist Eugene Spafford documented in his 1988 dissection. The first was a buffer overflow in fingerd, the daemon that answered queries about who was logged in on a remote host. The daemon read requests into a 512-byte buffer on the stack using a library routine that checked nothing; Donn Seely at the University of Utah traced how the worm sent 536 bytes instead, the surplus 24 overwriting the stack frame and redirecting execution into VAX machine code that asked the system for a shell.

The second was a debugging back door in sendmail, the mail transport agent that then ran on almost every Unix system on the network. If sendmail had been compiled with DEBUG enabled, and many vendors shipped it that way, a remote client could issue a command that piped mail directly into a shell instead of a mailbox. The worm used this to hand itself a running process on the target.

The third was not a bug at all. It was rsh and rexec, the remote-shell utilities that trusted any machine listed in a user’s .rhosts file or in /etc/hosts.equiv. Convenience, not carelessness: nobody wanted to retype a password to reach a machine down the corridor. The worm harvested those trust relationships from hosts it had already compromised and walked them outwards.

The fourth was a password guesser. It tried the obvious permutations first, the username, the username doubled, the surname reversed, then worked through a compiled-in list of 432 likely passwords and finally the system dictionary at /usr/dict/words. On machines where /etc/passwd still held hashed passwords in a world-readable file, which was the default, the worm cracked accounts in minutes.

It also took some trouble to stay invisible. On arrival it renamed its own process to sh, so it would sit unremarkably in a process listing. It seeded its random number generator from the clock, turned off core dumps so it could not be caught in a post-mortem file, and deleted its temporary files after reading them into memory.

The test that broke the internet

None of this would have mattered as much if Morris had not made a single catastrophic choice about population control. He anticipated that administrators might inoculate their machines by running a dummy process that answered yes when the worm asked whether a copy was already present. A worm that believed such an answer would politely die, and the epidemic would end.

So he built in an escape hatch. Seely’s decompilation found the test at the top of the routine: one worm in seven skipped population control altogether, never negotiating with anything, never volunteering to die. Those copies were effectively immortal. Because hosts were probed by many peers in quick succession, a busy machine accumulated immortal copies faster than it shed them, each one forking children, each opening sockets, each trying to spread.

The effect was indistinguishable from a fork bomb. Load averages on infected VAXes and Sun-3s climbed into the double digits. Mail queues backed up. Systems exhausted their process tables and refused new logins, which meant the administrator trying to intervene could not get a shell to intervene with.

How many machines is a question the record still will not settle. The 6,000 figure that entered folklore came from a single MIT estimate that a tenth of its own machines were infected, extrapolated across the network. GAO noted at the time that not every site had MIT’s proportion of vulnerable hardware, and that a Harvard researcher who canvassed users over the network put the real figure between 1,000 and 3,000. No organisation was responsible for counting, so nobody counted.

The money is equally slippery. Individual sites reported what they could: NASA’s Ames Research Center put its losses at $72,500 and Lawrence Livermore National Laboratory at $100,000, almost all of it staff time. The trial record would later put clean-up costs at anywhere from $200 to more than $53,000 per installation.

A network that could not phone itself

What made the response so chaotic was that the internet of 1988 had no coordinating body for security incidents. There was no CERT, no vendor patch pipeline, no agreed channel for saying “this is real, here is the fix, install it now.” Administrators at Berkeley, MIT, Purdue and the University of Utah reverse-engineered the worm in parallel through the night of 3 November, exchanging notes on mailing lists that were themselves failing because sendmail was overwhelmed.

Thirty-four minutes after midnight, Andy Sudduth at Harvard sent a warning that a virus might be loose on the internet, with instructions for closing the holes. It reached MIT, three miles away, twenty-six hours later. William Scherlis, one of two DARPA scientists coordinating the response, has described the period as the moment scale overtook trust.

Keith Bostic and the Computer Systems Research Group at Berkeley had a sendmail patch out by Thursday morning and both holes closed by late that night. At MIT, Mark Eichin and Jon Rochlis were pulling the binary apart in parallel. But the delivery mechanism was the same network the worm was choking, and some sites had already disconnected from the ARPANET to stop reinfection, which meant they could not receive the fixes. A few institutions resorted to carrying tapes between buildings.

The vendors were slower than the universities. Sun Microsystems published a fix within five days. GAO found that almost a month after the incident, several vendors still had not supplied patches for the sendmail and fingerd holes, and a number of sites had still not reconnected their machines.

On 8 November, more than seventy-five researchers and administrators gathered for a post-mortem hosted by the National Computer Security Center, the National Security Agency division whose chief scientist was Robert Morris Sr, the author’s father. The attendees, from Harvard, MIT, Berkeley, DARPA and the national laboratories, came to the same conclusion: the network needed a centralised place to report problems to and collect solutions from.

By 38 minutes past midnight on 11 November, a fully decompiled and commented copy of the worm’s source was installed at Berkeley. It had taken eight days to read a program that had taken one night to spread.

Twelve days to a phone number

DARPA moved before the decompilation was finished. Six days after the release, Scherlis and Stephen Squires sent a confidential memo to the agency’s director proposing a round-the-clock National Computer Infection Action Team, a focal point for prevention, coordination and awareness. The name did not survive. The institution did.

On 14 November 1988, the Software Engineering Institute at Carnegie Mellon was asked to establish what became the CERT Coordination Center. Its nucleus, GAO recorded a few months later, was five people, backed by more than a hundred computer specialists on call in their areas of expertise. It had no authority whatsoever. It could only recommend, and its founders knew its entire value depended on the Internet community deciding to trust it.

That was the design, and it was deliberate. A single trusted address, staffed by people who could authenticate a patch, work with competing vendors on the same flaw without leaking who reported it, and reach administrators through channels that did not depend on the network being healthy. GAO, unconvinced that one team was enough, recommended in June 1989 that the President’s Science Advisor convene an interagency group as a permanent security focal point.

What actually happened was proliferation. FIRST, the Forum of Incident Response and Security Teams, formed in 1990 to coordinate between the response teams that were by then multiplying, and it now spans more than 800 member teams in over 110 countries, some national, some corporate, some tied to a single police force or power grid.

The legal thread ran longer. Morris was indicted in 1989, the first person charged under the Computer Fraud and Abuse Act of 1986. A jury in Syracuse convicted him on 22 January 1990, and in May he was sentenced to three years of probation, 400 hours of community service, and $10,050, a $10,000 fine plus a $50 assessment, along with the cost of his supervision at $91 a month. The Second Circuit affirmed on 7 March 1991, holding that exploiting a flaw in a program counts as access without authorisation, and that the government need not prove he intended the damage he caused.

He went on to co-found Viaweb, then the startup accelerator Y Combinator, and became a tenured professor at MIT. His father’s agency had hosted the post-mortem on his program.

What took twenty years to close

The four specific holes were shut within weeks. The deeper problems took longer. Buffer overflows remained the dominant class of remote exploit for two decades, because compilers and operating systems did not adopt stack canaries, non-executable stacks or address-space layout randomisation until the 2000s. World-readable password files gave way to shadow files. Debug modes stopped shipping enabled.

Trust based on hostname alone, the .rhosts model, outlived all of it. It was finally displaced by cryptographic authentication in SSH, which Tatu Ylönen wrote at Helsinki University of Technology and released as freeware in July 1995 after a password sniffer was found on his university’s network. By the end of that year it had 20,000 users in fifty countries.

The Morris worm is usually introduced as the first internet worm, which is true and slightly beside the point. Its more precise legacy is institutional. It is the moment the network stopped being a research collegium and started being infrastructure, with uptime obligations, incident reports and a number to call at three in the morning. A similar cascade in February 2017 shows how little the underlying pattern has changed, even as the scale has grown by orders of magnitude.


Ninety-nine lines of bootstrap. Three thousand two hundred lines of engine. One test at the top of one function, set to fire one time in seven. Somewhere tonight a duty phone is ringing in Pittsburgh, and the arithmetic that made it necessary has not changed at all.