T1#security#outage#regulation
The Morris Worm — The First Large-Scale Internet Attack

Metadata
- Date
- Decade
- 1980s
- Tier
- T1
- Timelines
- A History of Cybersecurity
- Sources
- 06
- Connections
- 01
- Tags
- #security#outage#regulation
On the evening of 2 November 1988 — around 20:30 US Eastern time, by the usual account — a program was launched from a machine in MIT's AI Laboratory, prep.ai.mit.edu. Built as a two-stage system, a 99-line C bootstrap that pulled down a precompiled body for VAX and Sun-3, it crippled hosts at universities, military sites and medical research facilities across the country within hours. The GAO's report records the first trouble reports arriving from several sites at 9 p.m. Eastern Standard Time that day. Its author was Robert Tappan Morris, a 23-year-old computer-science graduate student at Cornell University; the appellate opinion found that MIT was chosen as the launch point to disguise the fact that the worm came from Morris at Cornell.
This was the Morris Worm, the first large-scale worm incident in the history of the Internet.
The Attack Surface
Both the GAO report and the appellate opinion enumerate four routes. The targets were VAX and Sun-3 machines running BSD-derived UNIX, and the worm attacked peripheral utilities rather than the operating-system kernel.
- sendmail's DEBUG mode. The sendmail mail-transport daemon shipped, on many vendor installs, with a debug mode that allowed remote command execution.
- fingerd buffer overflow. The
fingerdaemon calledgets()without bounds-checking, overwriting the stack to execute arbitrary code — one of the first publicly demonstrated, practical buffer-overflow exploits. - Trusted hosts. Hosts that trusted each other through
.rhostscould execute commands without passwords. This was not a bug but a convenience feature, which is precisely why one compromised machine let the worm sweep a local network. - Password guessing. A 432-word built-in dictionary plus candidates derived from
/etc/passwd; a hit let the worm masquerade as that user and move on.
On successful entry, the worm sent in a small bootstrap (a "grappling hook"), then copied over the main binary — available both for VAX and Sun-3 — and ran it.
The Design Bug That Took Down the Network
Morris's intent, by all accounts, was a quiet experiment in measuring the size of the worm's spread. To prevent the worm from re-infecting hosts indefinitely, he added a check: ask the host whether a copy was already present, and exit if so. To keep researchers from neutralising the worm by lying about that check, he added an escape hatch — one in seven times, ignore the answer and infect anyway.
That fraction was far too high. The Second Circuit found that Morris had underestimated how often the question would be asked, so the one-in-seven ratio produced far more copying than he anticipated. Hosts ended up running many worm processes at once, exhausting CPU, memory, and the process table. Servers became unresponsive; the network effectively went down.
Every Number Here Is an Estimate
Neither the count of infected machines nor the cost was ever officially tallied, and the GAO's June 1989 report (IMTEC-89-57) says so plainly.
- Machines. Press accounts put it at about 6,000. The GAO explains that this figure was extrapolated from an MIT estimate that 10% of MIT's own machines had been infected, and cautions that not all sites had MIT's proportion of vulnerable machines. A Harvard University researcher who polled users over the Internet argued that 1,000–3,000 was closer to the truth.
- Money. The same report gives that Harvard researcher's estimate of US$100,000 to US$10 million. Few government sites reported figures individually: NASA's Ames Research Center put its losses at US$72,500 and the Department of Energy's Lawrence Livermore National Laboratory at US$100,000, both attributed mainly to lost staff time.
- The appellate opinion states that the estimated cost of dealing with the worm at each installation ranged from US$200 to more than US$53,000.
The GAO also recorded that the worm did no lasting damage: it did not destroy or alter files, intercept mail, reveal passwords, or corrupt databases. What was lost was processing time and human time.
Legal Consequences — The First CFAA Conviction
In July 1989, Morris was indicted under the Computer Fraud and Abuse Act (CFAA) — specifically 18 U.S.C. § 1030(a)(5)(A) — passed only two years earlier. He became the first person convicted under that statute. A federal jury found him guilty in January 1990; sentence was handed down on 4 May 1990: three years of probation, 400 hours of community service, a fine of US$10,050, and the costs of his supervision. Prosecutors had asked for five years' imprisonment and a US$250,000 fine. He served no prison time.
The Second Circuit upheld the conviction in United States v. Morris, 928 F.2d 504 (2d Cir. 1991) — argued 4 December 1990, decided 7 March 1991. The contested question was whether "intentionally" modified only the access or also the resulting damage; the court held it modified only the access. The case remains the early interpretation of the CFAA's "accesses ... without authorization" language.
Morris himself returned to academia, later co-founded the start-up Viaweb (acquired by Yahoo! for roughly US$49 million in 1998 to become Yahoo! Store), became a professor at MIT, and went on to co-found Y Combinator with Paul Graham.
The Birth of CERT/CC
Within days of the incident, in November 1988, DARPA tasked Carnegie Mellon University's Software Engineering Institute with standing up the CERT Coordination Center (CERT/CC) — a public clearinghouse that could collect and disseminate information across organisations during incidents of this kind. The SEI's own account of its history describes DARPA asking it to establish a computer emergency response team in the aftermath of the worm.
CERT/CC went on to establish the CERT Advisory series and the working practice of coordinated vulnerability disclosure, brokering between finders, vendors and users, and became the model for the national CSIRTs that exist today. The CVE numbering scheme was not its product: MITRE launched that separately in 1999.
Without the Morris Worm, the profession we now call "incident response" would not look quite the way it does.
The Night Security Became Necessary
Technically, the worm delivered several lessons at once: (1) buffer overflows are real, practical attack vectors; (2) "debug" features should never ship enabled by default; (3) dictionary attacks against weak passwords must be defended against; (4) self-replicating code escapes its author's intent.
Socially, it shifted the Internet — irreversibly — from a network of cooperating researchers to an infrastructure in which malice also circulates. Before November 1988, almost none of the concepts that make up the contemporary security industry — firewalls, intrusion detection, security audit, CVE, the SOC — were considered necessary. After 2 November 1988, they were.
Any honest history of cybersecurity opens its first chapter on that night.
Questions this page answers
- When was the Morris worm released?
- On the night of 2 November 1988. Robert Tappan Morris, then a graduate student at Cornell, released a worm that self-replicated by chaining four routes: sendmail's DEBUG feature, a fingerd buffer overflow, trusted-host relationships and password guessing.
- How many computers did the Morris worm infect?
- No official count exists. The widely cited figure of about 6,000 came from contemporaneous press reports; the GAO's 1989 report describes it as an extrapolation from MIT's estimate that 10% of its own machines were hit, and records a Harvard researcher's counter-estimate of 1,000 to 3,000.
- What happened to Robert Morris?
- Indicted in July 1989, he became the first person convicted under the 1986 Computer Fraud and Abuse Act. In May 1990 he received three years' probation, 400 hours of community service and a US$10,050 fine, with no prison term.
Sources
TertiaryMorris worm — Wikipedia
Last updated: