The Register® — Biting the hand that feeds IT

Feeds

The 30-year-old prank that became the first computer virus

Elk Cloner creator Rich Skrenta looks back

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

To the author of ‪Elk Cloner‬, the first computer virus to be released outside of the lab, it’s sad that, 30 years after the self-replicating code's appearance, the industry has yet to come up with a secure operating system.

When Rich Skrenta, created Elk Cloner as a prank in February 1982, he was a 15-year-old high school student with a precocious ability in programming and an overwhelming interest in computers. The boot sector virus was written for Apple II systems, the dominant home computers of the time, and infected floppy discs.

If an Apple II booted from an infected floppy disk, Elk Cloner became resident in the computer’s memory. Uninfected discs inserted into the same computer were given a dose of the malware just as soon as a user keyed in the command catalog for a list of files.

Infected computers would display a short poem, also written by Skrenta, on every fiftieth boot from an infected disk:

Elk Cloner: The program with a personality
It will get on all your disks It will infiltrate your chips Yes it's Cloner!
It will stick to you like glue It will modify ram too Send in the Cloner!

Elk Cloner, which played other, more subtle tricks every five boots, caused no real harm but managed to spread widely. Computer viruses had been created before, but Skrenta’s prank app was the first to spread in the wild, outside the computer system or network on which it was created.

Rich Skrenta

Rich Skrenta today

“I was a geek and a computer nerd, interested in all aspects of technology,” he says. “I wanted to build a robot but there was no kit available and I had no mechanical skills. At elementary school, I used to experiment with vacuum tube radios but the slightest mistake during construction meant they didn’t work. I didn’t even find it easy putting together railway sets.”

“With programming I discovered a way to mimic things I saw in the movies,” Skrenta says, noting that some of his favourite films at the time were 2001: A Space Obyssey and Colossus: The Forbin Project.

“The physical stuff was frustrating by comparison,” he added.

Skrenta received an Apple II Computer as a Christmas gift in 1980. “It took over my life. I spent every waking hour immersed in computer games and programming.”

Skrenta wrote his own text-based adventure game, the opening of which placed the gamer into the role of a survivor of an airliner crash. This taught him to program in Basic and he later picked up assembly language skills.

The Apple II came with two floppy disk drives, and enthusiasts shared software and games through computer clubs. Software piracy was rife, and Skrenta was right in the middle of the scene.

“I was a member of a computer club in Pittsburgh. I used to copy software and share it with friends. There was a thriving pirate software market and people used to exchange games and software on floppy discs,” he explains.

It was this that got him thinking about how he could use this mechanism to play tricks on his pals. He sometimes altered the floppy discs he shared with friends so that they would display on-screen messages or shut down thier computer.

Booby trap

“I decided to booby trap new games to put up a message,” he recalls. “I gave a floppy to one of the guys at the computer club, and it worked. At the time I though it was hysterically funny.

“I did a couple of more pranks before people wouldn't let me touch their discs any more.”

This got him thinking: could he alter the contents of a floppy disc without touching it? His experiments led him to develop program that would run in the background, checking for the presence of a new disk and, if it found one, could modify files stored on the disk.

The result of this work was a program that, in effect, was coded to hop from disk to disk, propagating itself from machine to machine. The first virus, Elk Cloner, was born.

“Tech books on hacking the Apple II covered system entry points, such as turning on the disc drive motor. One of the core applications, System Monitor, had holes in it. Elk Cloner used those holes.”

Brain virus disk

Floppy target: Brain A was the first Windows virus
Source: Mykko Hypponen, F-Secure

Elk Cloner took about two weeks to write in assembly language, Skrenta recalls. And if it’s mode of operation sounds simple, making it actually happen was quite a technical challenge. His earlier adventure game took longer but was more creative, like making a puzzle.

“It worked like a charm and spread all over the place,” Skrenta remembers with a chuckle. His cousins in Batimore and - years later, he discovered - a friend in the US Navy were among those whose computers caught the virus.

Not that there weren’t ways of avoiding infection.

“Elk Cloner created a rattling noise when the program started. If a disc was infected you could hear it. If you inserted an infected disc in an Apple II you can hear the head swoosh sound, an audible signature.

“It would infect a new disc if machine wasn’t rebooted. If an Apple II was rebooted every time, Elk Cloner wouldn’t have spread. But, given people computer habits, it spread like crazy,” Skrenta explained.

Agentless Backup is Not a Myth

Next page: Collaring the culprit

The Multics cookie monster

> created Elk Cloner as a prank in February 1982

Ahem, in the late 70's (possibly earlier, but that's when I first encountered it) there was a "daemon" running around on Multics systems. Briefly, if you became it's lucky victim, it would take over your console and type up

I wanna cookie

on your screen (yes, we did have VDUs back then). Typing "cookie" would get it to go away for a while. Telling it to 'koff would get your session terminated (logged out). From what I recall it was written in PL/1 and was only a couple of pages of lineprinter paper.

Oh and BTW:

> the industry has yet to come up with a secure operating system.

It's not just the O/S that needs to be secure (and there are secure ones around), but the way it's used needs to be secure, too. That's the real problem

16
0
Anonymous Coward

Re: I can claim the fist phishing then?

Oh god, yes, I remember using the <esc>[4;1y sequence to force DEC serial terminals to power-cycle themselves, mostly via a Vax mainframe.

There was one particularly annoying trekkie who wrote an awful DCL scripted "diary" system, who was always nagging people to use it, who logged usage to a file in his home directory (an early form of phoning home). If you used OPEN/APPEND to add to the file, the VMS user-accesible auditing for the file wouldn't show who modified it.. so he got rather a lot of hand crafted ascii animations of a a rather foul nature, which invariably ended with a terminal reset.

(When time was pressing, he'd just get a complimentary copy of system STARLET libraries appended to it, to exhaust his quota).

Fucker, teach him to nag people to use his crappy diary thing, and then try and log what they were doing :)

14
0

Shome mishtake, surely?

Was this article written after a long Christmas lunch? It's peppered with mistakes:

"...if it’s mode of operation..." its

"...he doesn’t know who the teacher latched onto him..." how

"...thought of making this applications..." these applications/this application

"...he had access to mainframe..." a mainframe

"...I didn't want to own IBM PC..." an IBM PC

"...deemed worth of newspaper reports..." worthy

"...For the first ten years [Elk Cleaner] was a non event..." Elk Cloner

10
0

More from The Register

 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
 breaking news
Yahoo! joins! rivals! in! PRISM! data! request! admission!
Keep calm and carry on using American tech firms, folks
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?
 breaking news
'BadNews is malware' says outfit that found it
Google says code harmless but Lookout says code base is evolving