25 years ago this week, the Morris Worm brought the Internet to its knees
washingtonpost.com
washingtonpost.com
I was at Sun at the time and it was an interesting story but you could have completely disconnected Sun from the "internet" (which was being serviced at the time by a single T-1 line, 1.544Mbps baby!) for two or three days and it wouldn't have been the end of the world, and it would not have cut into sales. Due to some better configuration defaults, the impact of the worm on Sun was minimal.
The only real 'protection' was that ip_forwarding was set to 0.
SWAN got T1s (Dallas, D.C., Boston) about the same time.
Then RMTC came on-line with a T1, and Denver-Dallas, and Chicago-Dallas got T1s. Then the SWAN 'ring' got a pair of T1s. The cross-bay link went to a DS3. Lots of offices got upgraded to 10BaseT in the form of AT&T's "starnet" offering.
I left after that.
On the other hand, the Justice Department worried that "if the government treated this as a misdemeanor, a trivial offense, that others would go out and do it," Rasch said. "You had conduct that was planned, premeditated, that was deliberate, over periods of months, that caused massive disruption and expense to a wide number of different individuals." That required a response, the government believed.
So Morris was charged with a single felony count. Rasch says Morris could have been charged with a separate felony for each of the thousands of computers the worm infected. But the lawyer and his colleagues believed that would be overkill. "I don't believe that you over-prosecute someone to send a message," Rasch says. "I don't believe in the head-on-a-stake theory of prosecution."
----
Is that not a contradiction, he seems to be saying that they chose felony over misdemeanor not because of him but to set an example, then goes on to say that they don't do that sort of thing?
He's saying that the felony charge was driven by the objective characteristics of the act -- both the deliberation and the impact -- and that going for a lesser charge given those facts would have sent an undesirable message, but that -- given that the intent was not to cause harm -- prosecuting beyond the single felony charge to send a "tough on computer crime" message was not justified.
The contradiction you are finding is because you are creating overly broad extreme generalities from Rasch's description of balancing different factors.
As near as I can tell, Thomas Lopatic kicked off the era of modern memory corruption exploits in February 1995 with his HPUX NCSA httpd overflow. That was followed shortly by 8lgm's Sendmail 8.6.12 syslog() stack overflow, which 8lgm created a small mania about by explaining roughly how the bug worked but not publishing the exploit, which meant every amateur vulnerability researcher at the time (myself included) spent a couple weeks figuring it out for ourselves.
1988 to 1995 is a long time! During that period, near as I can tell, nobody published or even referenced a modern memory corruption flaw ("modern" meaning "allowed you to upload code into a remote system"; there were overflows prior to 1995, but they worked by overwriting variables in memory to alter program logic). Why did Morris have this technique back in 1988? (Besides the obvious reason). Why did nobody extend the work between '88 and '95? The whole Internet was vulnerable to this bug! And that timeframe was the hacker renaissance; it corresponds to the Sun Devil raids and the LoD/MoD war.
The vulnerability research community in 1995 was very close-knit (not tiny, but you could fit them in a hotel banquet hall for Summercon), and they worked pretty quickly to educate each other about the attack.
It is a little disconcerting to wonder that if the same case happened today, would it result in a katamari of charges meant to steamroll RTM?
http://www.gutenberg.org/ebooks/4686
"Underground: Hacking, madness and obsession on the electronic frontier"
[1]: http://www.amazon.com/CYBERPUNK-Outlaws-Hackers-Computer-Fro...
I'm less sure. Does RTM frequent these boards?
His father authored the relevant unix manual IIRC (they used to be a bunch of binders above a unix hackers desk usually shipped from whoever sold you the system.) I also had in my head that his father was the likely source of the wizard password backdoor in sendmail.
Anyway, would love to know for sure.
Assuming this is the real rtm, then he has an account, but he doesn't comment very often.
Sorry I had to have a peak, I think this is where you can find the source code for the worm:
http://ftp.cerias.purdue.edu/pub/doc/morris_worm/
The first thing I noticed is it's written in K&R C, the ANSI standard came a year later.
There's an analysis that got posted to HN here https://news.ycombinator.com/item?id=5302924
It's probably the single most fascinating event in my personal history with computers.
So I'm holding the phone to my ear and I can see she is logged in to the system and I say "Oh I see her, I'll just finger her to see if she is awake."
I am pretty sure the next sound I heard on the telephone resulted from it being dropped from standing height and having the handset bounce on the floor. It was my first experience with the less than desirable consequences of re-using English words to describe network interactions.
It's a common misconception things go viral due to some sort of premeditative planning "over a period of months". New ideas start fledgling, because that's what it means for ideas to be new. They don't have concrete form in the beginning. Even the person having them can't tell what they can lead to.
Rushing the worm was crucial in making it work. It was more important to see if it had any chance of working. It couldn't have happened had Morris not been rushed, opening doors to a new research field and medium to the general public.
Who could have simulated that?
The defendant, Dade Murphy, who calls himself "Zero Cool", has repeatedly committed criminal acts of a malicious nature. This defendant possesses a superior intelligence, which he uses to a destructive and antisocial end. His computer virus crashed one thousand five hundred and seven computer systems, including Wall Street trading systems, single handedly causing a seven point drop in the New York Stock Market
The SUN workstation-wielding guy in the lab next door to me got hit by this, though we were unscathed. Periodically you could hear him yelling through the wall.
Amusingly (in hindsight), I had recently cleaned up a bunch of virus-choked PCs in some student labs and because of this fell under departmental suspicion (very briefly) of having something to do with these new problems. From then on I left such thankless scut work to someone else.
Another interesting -though brief- account appears in the epilogue of Cliff Stoll's "Cuckoo's Egg" (itself a classic tale from the early Internet days).
A good technical article is "With Microscope and Tweezers: An Analysis of the Internet Virus of November 1988" [1] which was published soonafter.
All I'll say is, I was "there" (meaning affected).
It was also amusing watching the news reports at the time. I remember one of the nightly "world news" shows (ABC, iirc) having it right up front and the anchor and reporter trudging their way through the story, trying to explain this "Internet" thing.
Now it's all just DDoS. Far scarier, and a lot less fun.
I recognize his name from Ars Technica, where he contributed, in my eyes, to the high value of the news site by writing about tech policy.
Contrast this to what they wanted to do to the hackers in the Slatella/Quitner book.