What Was the Morris Worm? The Stealth Feature That Became the Payload

It asked permission first.

Before infecting a machine, the worm checked whether a copy of itself was already running there. If the answer came back yes, it was supposed to stop. That check is the reason the Morris Worm is remembered at all, and not for the reason you would expect.

What was the Morris Worm?

On the evening of 2 November 1988, Robert Tappan Morris, a 23-year-old first-year graduate student at Cornell, released a self-replicating program onto the internet. He launched it from a machine at MIT rather than Cornell, which is the one part of the whole affair that looks like planning.

His stated intent was to gauge the size of the network. Whatever the intent, within hours system administrators across universities, military sites and research labs were watching machines slow to a crawl and then stop, with no idea why, and no obvious way to tell each other — because the mail was in the same trouble as everything else.

Three ways in

The worm did not rely on a single flaw. It carried three, which is unusual for 1988 and is part of why it moved as fast as it did.

A buffer overflow in fingerd. The finger daemon read a request into a 512-byte buffer using gets(), a function with no way to know how large its destination is. The worm sent it 536 bytes: enough to run off the end of the buffer and overwrite the return address on the VAX stack, so that when the function returned it executed a short piece of the worm's own code, which called execve on a shell.

That is a textbook stack smash. It is worth sitting with that the technique was demonstrated at internet scale in 1988, and that the same class of bug was still producing critical CVEs thirty-five years later.

A debug mode in sendmail. Many systems shipped with sendmail compiled with DEBUG enabled. In that mode, a remote sender could specify a program as the recipient of a message instead of a mailbox. The worm used it to pipe in a small bootstrap program, which then pulled down the rest.

Passwords. The worm carried a built-in dictionary of about 432 words, and it also tried the account name itself, obvious permutations of it, and words taken from the user's own gecos field in /etc/passwd — which is to say people's names, in the file that listed them. Cracked credentials were then used across rsh and rexec to reach machines that trusted the compromised one.

The password attack is the one that generalises. Two of the three vectors were patched within a week. The third is still working.

The line that broke it

Morris understood that a worm which politely declines to reinfect an already-infected host has an obvious counter: an administrator can write a small program that always answers yes, I am here, and the worm will pass the machine by.

So he added a counter. Roughly one time in seven, the worm would infect the host regardless of the answer.

One in seven is not a small number. Machines were reachable from many directions at once, and every reachable neighbour rolled the dice independently. Copies accumulated. Each copy consumed processor time and memory, and the machine got slower, and slower, until it was doing nothing else.

The worm did not delete files. It did not encrypt anything, or steal anything, or damage any data. The entire impact of the most famous piece of malware of the 1980s was that too many copies of it ran at once.

How many machines, honestly

You will see “6,000 computers, ten percent of the internet” in essentially every account. It is worth knowing where that comes from before repeating it.

The internet in November 1988 was on the order of 60,000 hosts, and that part is solid. The infection count is not. The US General Accounting Office, reporting to Congress in 1989, put it at an estimated 1,200 to 6,000 systems and noted plainly that no one had a reliable count — there was no mechanism to produce one. The 6,000 figure is the top of a range that has been quoted for thirty-odd years as though it were a measurement.

The damage figures are worse. The GAO found estimates ranging from $100,000 to $10 million, a spread of two orders of magnitude, and declined to endorse any point inside it. Most of the real cost was people's time: administrators disconnecting machines, reading disassembly, and rebuilding.

What it produced

Two things, and both outlasted the worm by decades.

CERT. Within days, DARPA funded a coordination centre at Carnegie Mellon's Software Engineering Institute. The problem the outbreak exposed was not technical, it was organisational: there was no phone number. No one whose job it was to collect reports, correlate them, and tell everyone else what was happening. Every national CERT and CSIRT since descends from that decision.

The first CFAA conviction. Morris was prosecuted under the Computer Fraud and Abuse Act of 1986 and convicted in January 1990 — the first felony conviction under that statute. The sentence was three years' probation, 400 hours of community service, and a fine of $10,050 plus supervision costs. No prison.

The appeal turned on intent, and the outcome shaped US computer crime law for a generation: the court held that the government did not have to prove he intended the damage, only that he intended the unauthorised access.

What is still true

Robert Morris is a tenured professor at MIT and a co-founder of Y Combinator. A floppy disk holding the worm's source sits in the collection of the Computer History Museum.

gets() was finally removed from the C standard in 2011, twenty-three years later.

Further reading

  • Eugene Spafford — The Internet Worm Program: An Analysis (Purdue, 1988). The canonical technical teardown.
  • Donn Seeley — A Tour of the Worm (University of Utah, 1989). The best narrative account of the night itself.
  • GAO/IMTEC-89-57 — Computer Security: Virus Highlights Need for Improved Internet Management (1989). The source for the honest version of the numbers.
  • United States v. Morris, 928 F.2d 504 (2d Cir. 1991), on intent under the CFAA.

EXHIBIT 0008 — MORRIS WORM

We put it on a shirt. Seven machines in a row. Six of them checked off, already infected, correctly skipped. The seventh circled, being infected a second time anyway, with the worm looping back underneath the row to start again.

Most people will read it as a drawing of old computers. A smaller number will count the cabinets first.

That's the whole idea.

View the Morris Worm shirt — EXHIBIT 0008

Back to blog

Leave a comment

Please note, comments need to be approved before they are published.