Robert Tappan Morris and the 1988 Worm That Broke the Early Internet

At about 8:30 on the evening of November 2, 1988, a Cornell graduate student released a program onto the ARPANET from a machine at MIT, a choice that hid where it really came from. Robert Tappan Morris said he only wanted to count how many computers were connected. His father, Robert Morris Sr., was a pioneering cryptographer at the National Security Agency. Within hours the son’s creation was copying itself across VAX computers and Sun-3 workstations running Berkeley Unix, and administrators were pulling network cables out of walls.

This episode takes apart how the Morris worm worked and why it did so much damage on a network built on implicit trust. It walks through the three ways in, the tiny program that hauled the rest of the worm aboard, and the single paranoid design decision that turned a mapping tool into a denial of service attack. It also covers the cleanup, the disputed casualty count, and a trial with almost no precedent.

  • The worm entered through a debug mode left enabled in Sendmail, a buffer overflow in the finger service’s 512 byte buffer, and the trusted remote commands rsh and rexec.
  • A 99 line C program acted as a grappling hook, compiling on the victim machine and then pulling the full worm across.
  • Fearing administrators would fake an already infected reply, Morris made the worm reinfect anyway one time in seven, which piled up copies until machines ground to a halt.
  • The widely cited figure of 6,000 infected machines was disputed by Paul Graham, who said it came from assuming 10 percent of a guessed 60,000 computers.
  • Morris received the first felony conviction under the Computer Fraud and Abuse Act and was sentenced to three years of probation and 400 hours of community service, while DARPA funded a response team at Carnegie Mellon.

Leave a Reply

Discover more from pplpod

Subscribe now to keep reading and get access to the full archive.

Continue reading