By November 2, 1988, the self-replicating program written by Cornell graduate student Robert Tappan Morris had infected an estimated 6,000 computers — roughly 10 percent of machines then connected to the internet. Intended by its creator as a harmless experiment to gauge the network's size, a coding flaw caused it to replicate uncontrollably, forcing universities and research labs to disconnect from the network entirely and prompting the first felony conviction under the newly passed Computer Fraud and Abuse Act.
Robert Tappan Morris released his worm from a computer at MIT rather than his own Cornell terminal, hoping to obscure its origin. The program exploited known vulnerabilities in Unix sendmail and finger daemon programs, and was designed to check whether a machine was already infected before copying itself over — but Morris, worried that system administrators might kill copies by faking that check, programmed it to occasionally reinfect systems anyway, at a rate that spiraled out of control.
Within hours, machines at Stanford, Berkeley, Princeton, and NASA slowed to a crawl or crashed entirely under the load of thousands of duplicate processes. Panicked administrators at major research institutions, unable to communicate over the very network that was failing, phoned each other and, in some cases, physically unplugged systems from the ARPANET to stop the spread. Cleanup costs were later estimated in the millions of dollars.
Morris was identified within days and became the first person convicted under the 1986 Computer Fraud and Abuse Act, receiving three years' probation, a $10,050 fine, and community service. The incident also led directly to the creation of the CERT Coordination Center at Carnegie Mellon, the first organization dedicated to responding to internet security emergencies — an institutional legacy that far outlived the worm itself.
Key people: Robert Tappan Morris