The Morris Worm Is Released, Knocking Out an Estimated 10% of the Internet
What happened on November 2, 1988, how the Morris Worm propagated, why it overloaded hosts, and how the incident changed internet security coordination.
At approximately 8:30 PM on November 2, 1988, a self-replicating program was released onto the internet from a computer at MIT — within 24 hours, an estimated 6,000 of the roughly 60,000 machines then connected to the entire internet had been affected.
Who released it and why
Robert Tappan Morris, a graduate student at Cornell University, wrote and released what became known as the Morris Worm — released from MIT’s network rather than Cornell’s, reportedly in an attempt to obscure its point of origin. According to Morris’s own later account, the program was intended as an experiment to gauge the size of the internet, not as a deliberate attack, though a bug in its replication logic caused it to infect the same machines repeatedly, compounding its impact far beyond whatever Morris had actually planned.
What it actually did to infected systems
The worm exploited vulnerabilities in fingerd, sendmail, and weak rsh/rexec trust configurations to spread between VAX and Sun systems running BSD-derived Unix — its repeated, unintended re-infection of already-compromised machines caused those systems to slow to a crawl under the compounding load, rather than any deliberate destructive payload.
The legal outcome
Morris was prosecuted and convicted under the Computer Fraud and Abuse Act of 1986 — the first felony conviction secured under that law, establishing significant early legal precedent for treating unauthorized, disruptive computer intrusion as serious federal crime.
The institutional response
The incident directly led to the creation of the CERT Coordination Center at Carnegie Mellon University, funded by DARPA specifically because the Morris Worm had exposed the absence of any coordinated body for responding to internet-scale security incidents.
A chronology of November 2–3, 1988
The program began spreading on the evening of November 2. It tested several routes into Unix hosts, copied a small bootstrap, fetched larger components, and attempted to conceal obvious artifacts. Administrators initially saw load averages rise, mail and login service degrade, and machines become reinfected after cleanup. Disconnecting from the network slowed propagation but also made coordination and distribution of fixes harder.
Researchers at Berkeley and elsewhere captured and disassembled copies during the night. By November 3, technical details and defensive guidance were circulating through the same still-small research network the worm had disrupted. The incident demonstrated that incident response required trusted out-of-band contacts, shared analysis, and a mechanism for distributing verified mitigations—not merely a competent administrator at each individual site.
The immediate institutional and legal aftermath
DARPA funded the CERT Coordination Center at Carnegie Mellon after the incident exposed the absence of a standing coordination function. Federal prosecutors charged Robert Tappan Morris under the Computer Fraud and Abuse Act. The Second Circuit’s published 1991 opinion affirmed his conviction and interpreted the statute’s unauthorized-access and damage provisions; the case became an early appellate landmark in U.S. computer-crime law.
Contemporary estimates of affected hosts and cost vary, so “10% of the internet” should be read as an order-of-magnitude description based on a network of roughly sixty thousand connected computers, not a precise telemetry measurement. The firmly supported news event is that thousands of systems were impaired within about a day and that the response changed both security coordination and federal enforcement.
Primary and official sources: FBI retrospective, CERT/CC history, published appellate opinion, United States v. Morris, 928 F.2d 504.
Related:
- The Morris Worm: The Internet’s First Real Security Wreck
- The World Wide Web Is Announced to the Public
Sources: