The Internet Worm of 1988
cs.unc.edu
cs.unc.edu
So I called a friend, who is now a physics professor at MIT, and said “Our machines are infected, could you please break in, go root, clean the infection, and send an email to our sysadmin explaining to him you did this at my request?” All he said was “Ok, get some sleep” and yes even though we’d just spent almost 24 hours locking down every possible attack vector into our machines and network we woke up to clean machines with a polite email in the sysadmin’s inbox. I never have figured out whether that was more a measure of the state of network security in the late 1980’s or of the kind of mad skills it takes to become tenure track at a place like MIT.
There is a good telling of the worm story in the final chapters of Cliff Stoll’s amazing book on discovering a case of internet-hacking meets East-German-spies meets 2400-baud-modems and three-letter-agencies back in the mid 1980’s (which spent 42 weeks on the NYTimes bestseller list and is a ton of fun to read)[0]
[0]https://www.amazon.com/Cuckoos-Egg-Tracking-Computer-Espiona...
One of the people he was working alongside, Karl Koch, was selling military information to the KGB in exchange for cocaine. He developed some form of paranoid psychosis and seemed to believe he was fighting the Illuminati.
There was a German film made about this called "23" (Koch was obsessed with the cult classic conspiracy fiction novel Illuminatus, and used the pseudonym "hagbard" after a character in the book).
He was found burned to death in woodland; it was ruled suicide.
.com: https://imgur.com/a/R6tcW .co.uk: https://imgur.com/a/iNuKR
The US site does actually offers an audio cassette for $100, but I'm going to assume that's not really what he wanted when he lamented the lack of a non-paper edition :-)
One of the classic books on the history of computers is Clifford Stoll's "The Cuckoo's Egg". It's a great book in general, and it mentions Robert Morris and Paul Graham, which I was surprised to find when I read it (it's not about the worm, but about a hacking incident).
And lastly, Clifford Stoll is apparently pretty active on YouTube, which I discovered when seeing a video of his for Numberphile, and finding out that it is, indeed, that Clifford Stoll.
http://catless.ncl.ac.uk/Risks/7.69.html#subj1
It's now 3:45 AM on Wednesday 3 November 1988. I'm tired, so don't believe everything that follows... Apparently, there is a massive attack on Unix systems going on right now.
I did a tribute to RISKS on it's 30th over at Metafilter
http://www.metafilter.com/151727/Complex-Systems-Break-in-Co...
which includes links to
http://docs.lib.purdue.edu/cgi/viewcontent.cgi?article=1701&...
https://en.m.wikipedia.org/wiki/Robert_Morris_(cryptographer...
I doubt RTM ever wrote any commentary about the worm's creation but I think that would be really interesting to read. No doubt it's something he'd probably rather be forgotten, but it would be interesting to hear him talk about it.
My favorite part of those efforts was when Spafford posted a tongue in cheek bugfix patch to the attack code midway through the attack (at a time when the only people in the world with the source code were his team, Mark and Jon, and of course RTM since he wrote it). I couldn’t find the patch but it’s somewhere in the RISKS archives from that era.
I wonder what the equivalent would be in todays terms .. some sort of Facebook-crippling JS injection, or so? I think its hard to come up with an example in the modern era- the scales are much higher, so the chances of making such a huge impact a lot lower.
You mean like the Samy worm (https://samy.pl/popular/)?
Plus 12 years ago can hardly be considered "modern day" in computer terms. ;)
Flat adressing was surely the feature I mostly envied from the Motorola 68000.
However it doesn't bring much over MMU configuration regarding read and write accesses, right?
My Windows 3.x days have long faded away.