GadgetGlowBytes: Your go-to hub for in-depth gadget reviews, breaking tech news, and expert tips to supercharge your everyday tech experience.
The Night the Internet Caught a Cold: How a One-in-Seven Rule Brought Down a Tenth of the Net
Get link
Facebook
X
Pinterest
Email
Other Apps
-
Tech History — Saturday, October 3, 2026
The Night the Internet Caught a Cold: How a One-in-Seven Rule Brought Down a Tenth of the Net
The Morris worm of November 1988, rebuilt from the people who took it apart
GB
GadgetGlow Bytes Editorial
Published October 3, 2026 · 9 min read · How we work
The ratio at the heart of the worm: one in every seven “already infected” answers was ignored. Graphic: GadgetGlow Bytes
Most computer disasters arrive with a bang. This one arrived as a slight slowdown. On the evening of Wednesday, November 2, 1988, administrators at universities and research labs began to notice that their Unix machines were sluggish, then sluggish in a way that made no sense, then so overloaded that they could not be logged into at all. The network those machines belonged to connected roughly 60,000 computers at academic, corporate and government research sites, according to the opening of the MIT analysis that became the standard account of the event. By the next morning, a meaningful fraction of them were running a program nobody had asked for, copying itself onto neighbours faster than anyone could pull the cables.
This is the story of the Morris worm, and it is worth retelling in 2026 for a reason that has little to do with nostalgia. Almost every mechanism in it, the convenience feature left switched on, the trust relationship nobody audited, the guessable password, the defender whose own communications channel was part of the attack surface, is still with us. The only thing that has changed is the vocabulary. We have leaned on the two best primary accounts, written within weeks by the engineers who took the program apart.
1. One Wednesday Night
The chronology kept by the MIT team is unusually precise, because the people involved were writing it down as they went. It records the program as “tested or launched” at Cornell at 5:01:59 p.m. on that Wednesday, with a second machine infected three minutes later. Popular summaries often say the worm was released at 8:30 p.m. from MIT; the secondary sources we checked repeat that figure, while the engineers’ own timeline shows infections already under way earlier in the evening and notes that the copy reaching Stanford at about 9:00 p.m. appeared to come from a machine at MIT, prep.ai.mit.edu. In other words, MIT was a relay rather than the point of origin.
From there the spread follows the geography of the early Internet. By 9:30 p.m. a machine named wombat.mit.edu was found running with the debug option of its mail server switched on. The University of Maryland was hit at 10:54 p.m., Berkeley at 11:00, and SRI International by midnight. Lawrence Livermore National Laboratory was assembling a response team by 2:00 a.m. Thursday. At 2:28 a.m., Peter Yee of NASA Ames sent what the MIT chronology treats as the first public mention of the problem to the TCP-IP mailing list, and at 5:58 a.m. Keith Bostic of Berkeley posted the first workaround: recompile the mail server without its debug command, and rename the system compiler and linker so the worm could not use them.
~60,000
Hosts on the Internet, per MIT
5:01 pm
First recorded run, Nov 2
~13 hrs
Launch to first public fix
4
Distinct ways in
The network’s own response was almost as damaging as the worm. Administrators who realised that the infection was travelling by e-mail disconnected their mail servers, which is exactly what the MIT authors describe as an indirect attack: sites cut themselves off from the channel through which the fix was being distributed. The Media Lab was isolated at 11:30 a.m. on Thursday and the military network bridges were shut down. A program that never deleted a single file had still managed to degrade the one thing defenders needed most, which was the ability to talk to each other.
2. Four Doors, Three of Them Unlocked on Purpose
Here is the detail that makes the worm a better teaching case than most modern malware. It did not need a single zero-day vulnerability in the sense we would use the term today. It used four doors, and three of them were features that worked exactly as designed.
Door
What it abused
Why it worked
sendmail DEBUG
A testing option in the mail server that let the sender name a command to run on the receiving machine
Left enabled on production systems; it was a convenience for administrators
fingerd overflow
A library call that read input with no length check, overflowing a stack buffer and letting the worm run its own code
Only 4.3BSD VAX machines were vulnerable to this variant, per the MIT analysis
Password guessing
Usernames from the world-readable password file, tried against a 432-word built-in list, then the system dictionary
Spafford noted experience suggested such choices may work on up to 30% of naive accounts
rsh / rexec trust
The hosts.equiv and .rhosts files, which let one machine vouch for another by network address
The remote host is identified only by an address, which can be forged
Compiled by GadgetGlow Bytes from the MIT (Eichin and Rochlis) and Purdue (Spafford) analyses, 1988.
Notice the pattern. Debug mode existed to test mail delivery, finger to tell colleagues who was logged in, and the trust files to spare lab users a password prompt. Each traded security for convenience in a world where the people on the network mostly knew each other.
Once on a machine, the worm sent a small C program, which the MIT authors call the grappling hook, back to the sender. It was compiled on the victim, run, and used to fetch the full worm in Sun and VAX versions. To stay hidden it disguised its process as an ordinary shell, deleted its files right after loading them, and kept its main body encrypted in memory.
3. The Seventh Answer
If you take one technical idea from this story, take this one. Before infecting a machine, the worm asked it whether a copy of the worm was already running. If the answer was yes, it was supposed to leave the machine alone. The sensible design is to stop there.
But the author evidently worried that a defender could simply fake the answer. If a clever administrator started a dummy process that told every caller “yes, already infected,” the worm would pass them by and the cheap defence would work. So the program was written to ignore the “yes” roughly one time in seven and to infect the machine anyway. The federal appeals court that later heard the case described it in those terms: the worm would duplicate “every seventh time” it received a “yes.” Spafford’s Purdue analysis puts the effect in the language of the engineers: one in every seven worms became effectively immortal.
Seven turned out to be far too many. On a local network where each machine can be reached by dozens of others, a one-in-seven chance of reinfecting a machine that is already infected means the load compounds with every pass. Multiple copies piled up on the same host, each one hunting for passwords and probing neighbours, until the machine had no capacity left for its legitimate work. That is why the first symptom was a slow system, and the second a machine nobody could log in to.
Spafford’s conclusion about the programmer is worth quoting in spirit rather than letter: he judged the author a moderately experienced Unix programmer, not the wizard that early press coverage imagined, and thought the worm’s success owed more to luck than to skill. The MIT team found the first bug, in a memory-clearing call, at 1:55 a.m. on Friday. The worm did not need to be clever to be devastating; it only needed a network that had never been asked to resist anything.
4. Strangers, a Mailing List and a Television Crew
The response is the part of the story that engineers still tell each other, because it worked despite having no one in charge. At 8:00 a.m. Thursday, Ed Wang at Berkeley worked out the finger mechanism, and Mark Reinhold at MIT powered down network equipment in the Laboratory for Computer Science. Gene Spafford at Purdue started a mailing list, phage, at 9:20 that evening so analysts could share findings without relying on the infected mail systems. Ted Ts’o wrote a program to decode the worm’s obfuscated text strings. The worm led the 11 p.m. news that night, and at 11:40 p.m. the serious decompilation began at MIT.
What strikes a modern reader is how improvised it was: no standing team, no designated contact, fixes passed along by phone and mailing list. That is the gap the federal government set out to close. According to the standard summary of its history, which cites Carnegie Mellon’s Software Engineering Institute, DARPA directed the creation of the CERT Coordination Center in November 1988 in Pittsburgh, making it the first organisation of its kind. In June 1989 the Government Accountability Office, then the General Accounting Office, issued report IMTEC-89-57 on the incident and recommended that the President’s Science Advisor coordinate an interagency group to serve as the Internet’s security focal point.
5. A Statute Meets a Program
The law had no ready script for what had happened. The program changed no data and stole nothing. It simply used other people’s computers without permission and, by accident, made them unusable. The prosecution proceeded under the Computer Fraud and Abuse Act of 1986, and Robert Tappan Morris, a Cornell graduate student, was convicted at trial. On appeal, in a decision dated March 7, 1991, the Second Circuit held in United States v. Morris that the word “intentionally” in the statute applied to the unauthorised access, not to the resulting damage, so prosecutors did not have to prove he meant to cause the harm. The sentence was three years of probation, 400 hours of community service and a fine of $10,050.
$200+
Low-end cost per site, per the court
$53,000+
High-end cost per site, per the court
400 hrs
Community service
$10,050
Fine
How many machines were infected is still argued over. The figure repeated in most summaries is about 6,000, which is the product of a guess at the size of the network and an estimate that a tenth of it was hit. Cliff Stoll, as quoted in the secondary literature, put it at only a couple of thousand. The appeals court avoided the headcount and instead cited cleanup costs ranging from $200 to more than $53,000 per installation. We treat 6,000 as a convention, not a measurement.
Morris went on to a career that is hard to reconcile with the headline. He co-founded the web-store company Viaweb, is listed as a retired founder at Y Combinator, and is a professor in MIT’s electrical engineering and computer science department and its Computer Science and Artificial Intelligence Laboratory, where his research has covered routers and Internet traffic.
6. Why a 1988 Worm Still Matters
It would be comforting to file this under ancient history, when the Internet was small and trusting. The details say otherwise. The convenience defaults we leave on today are different objects with the same shape: remote management ports, permissive cloud storage links, default administrator accounts, browser extensions with broad permissions, apps that were granted access once and never reviewed. The password problem has not gone away; it has merely moved from a 432-word list to the credential dumps of the last decade. And the information-flow problem is perhaps the sharpest echo. When an identity provider or a chat platform is the thing under attack, the channel you need to coordinate the fix is the channel you cannot trust.
The unglamorous response is short: turn off services you do not use, replace trust-by-address with real authentication, and keep an out-of-band way to reach your team when the usual channel is down. We have written about auditing what is already connected to your accounts, and about protocols built to survive failing networks; both are linked below.
Our Read
The popular lesson of the Morris worm is that a single bug can take down a network. The more useful lesson is about the reinfection rule, because it is a design decision that looks wise in isolation and ruinous in aggregate. The author’s instinct, that a defender might lie, was correct. The remedy, ignoring the answer one time in seven, was a fix that made every individual node more resilient and the whole system fragile. We see the same pattern whenever a retry policy, a crawler, a build system or an autonomous software agent is told to try again when it hears no. Each caller behaves sensibly; together they produce a stampede. If you are building anything that retries, the question to ask is not whether one copy behaves, but what happens when seven thousand do. Our second observation is that three of the four doors were features, not flaws, which is why no patch could ever have closed them all. Security that depends on removing convenience will always be late; the worm was the first demonstration, and the first of many.
What we still don’t know: the true number of infected machines, which no source we found measured directly, and the author’s precise reasoning for the one-in-seven constant, which we have inferred from the programs’ behaviour rather than from a statement by Morris that we could verify. We have also not examined the original source code ourselves.
Figures verified October 3, 2026. Where our sources disagree, such as the number of infected machines, we say so in the text. GadgetGlow Bytes does not test hardware or software for this article and does not receive products from manufacturers for coverage.
Top 3 Best-Selling Mini PCs on AliExpress in 2025 – Which One Is Worth It? Hey everyone! In today’s post, we’re diving into the top 3 best-selling mini PCs on AliExpress up until June 2025. We'll take a close look at their advantages, disadvantages, performance, and even some of the funniest (and most helpful) customer reviews. If you’re looking for a compact, affordable, and surprisingly powerful mini computer, this post is for you. Let’s start with the first one on our list: the famous GMKtec G3 . According to AliExpress, this model has already sold over 10,000 units — and it’s not hard to see why. It comes with an Intel Alder Lake N100 processor , reaching up to 3.4 GHz, and is available with 8 GB or 16 GB of DDR4 RAM , and a 256 GB or 512 GB M.2 PCIe SSD , depending on the version you choose. Aliexpress Link: https://s.click.aliexpress.com/e/_oC43Wwa One standout feature is its two HDMI 2.0 ports , allowing you to connect dual 4K moni...
Best tablet controller for iPad Pro 13-inch, the Razer Kishi V3 Pro XL snaps onto larger tablets to deliver console-level comfort and precision for cloud gaming and native apps. Design & Compatibility Built from anodized aluminum and reinforced polymer, the Kishi V3 Pro XL stretches to fit iPad Pro and Air models up to 13” as well as Android tablets with USB-C from 10” to 13”. Its full-size thumbsticks feature drift-free TMR sensors, Hall Effect triggers ensure instant responsiveness, and a USB-C passthrough keeps you powered through marathon sessions. Two programmable rear macros round out the controls for custom loadout shortcuts. For IPAD: https://amzn.to/4kLrG9c For Iphone: https://amzn.to/4eaKYlS Evolving from the Smartphone Version Where the standard Razer Kishi V3 Pro handled screens up to 8”, the XL ups the ante with beefier grips, premium finishes and seamless support for full-size tablets without sacrificing haptic feedback on Android or PC remote-play...
Tech Gadgets Daily Morning Brief Edition: January 17, 2026 | Hilarious Real Tech Fact: The CES 2026 Robot That Face-Planted a Journalist | Curated by Grok The Epic Fail: Zeroth Jupiter Humanoid Goes Down Hard on Live Demo At CES 2026, the Zeroth Jupiter humanoid robot (170 pounds of "advanced" engineering) was demoed by The Verge journalist Jennifer Pattison Tuohy. Everything seemed fine... until the bot suddenly froze mid-movement, stiffened, and then flopped forward face-first—right toward the journalist! She dodged just in time, but the moment was captured on video and instantly went viral. The robot, meant to showcase "autonomous capabilities," instead demonstrated the classic "robot existential crisis" by collapsing like it had given up on life. This wasn't scripted; it was pure, unfiltered tech comedy gold. Context: CES 2026 was flooded with humanoid robots promising to "handle chores reliably" (laundry, cooking, ...
Comments
Post a Comment