<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-791705236799000681</id><updated>2012-02-16T12:14:29.755-08:00</updated><category term='Information of BO and NB'/><category term='Back Orifice'/><title type='text'>The Back Orifice and NetBus</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://bonb2008.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/791705236799000681/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://bonb2008.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Mr. Mandiri</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://bp1.blogger.com/_adyQ_IcPHQQ/R4oEP4siVEI/AAAAAAAAAAM/7sxw9vhJ2kA/S220/SKU00507691_0.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-791705236799000681.post-1655367710952325009</id><published>2008-06-24T18:10:00.000-07:00</published><updated>2008-06-24T18:11:05.664-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Back Orifice'/><title type='text'>Back Orifice</title><content type='html'>&lt;p&gt;&lt;span style="font-size: 13.5pt;"&gt;"Back Orifice" is a hacker's dream, and a Netizen's nightmare. &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-size: 13.5pt;"&gt;Back Orifice is not a virus. It is in essence a &lt;strong&gt;&lt;i&gt;remote administration tool&lt;/i&gt;&lt;/strong&gt;.&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-size: 13.5pt;"&gt;It gives "system admin" type privileges to a remote user by way of the computer's Internet link.&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;i&gt;&lt;span style="font-size: 13.5pt;"&gt;What does this mean?&lt;/span&gt;&lt;/i&gt;&lt;/strong&gt;&lt;span style="font-size: 13.5pt;"&gt; It means that if Back Orifice is running in your computer, a remote operator anywhere on the global Internet can gain access and do &lt;strong&gt;&lt;i&gt;almost anything you can do&lt;/i&gt;&lt;/strong&gt; on &lt;strong&gt;&lt;i&gt;your&lt;/i&gt;&lt;/strong&gt; computer -- and some things you &lt;strong&gt;&lt;i&gt;can't&lt;/i&gt;&lt;/strong&gt; do -- all without any outward indication of his presence.&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-size: 13.5pt;"&gt;Back Orifice can arrive disguised as a component of practically any software installation. It can be attached to other files or programs or run on its own. It must be &lt;strong&gt;run&lt;/strong&gt;, by itself or by another application. It then installs itself in seconds, typically erases the original, then may run a specified program. To the user installing an "infected" application, it will appear that all went normally. But from that moment forward, your system offers easy and comprehensive access anytime it is connected to the Internet.&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-size: 13.5pt;"&gt;In itself, Back Orifice does not cause any malfunction. It runs quite invisibly to the user, consumes insignificant memory and resources, and does little besides simply open up access to standard Windows 95 functions.&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-size: 13.5pt;"&gt;Win95/98 is in essence a networking operating system. It's designed to give access and control to the system administrator on any network to which it is connected. Back Orifice simply implements standard system admin functions and includes a few handy tools for the remote operator's convenience. But it does so very quietly, almost undetectably.&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-size: 13.5pt;"&gt;I've created a &lt;/span&gt;&lt;a href="http://www.nwi.net/%7Epchelp/bo/bobasics.htm"&gt;&lt;span style="font-size: 13.5pt;"&gt;handy page with the basics&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: 13.5pt;"&gt; about Back Orifice in a Q&amp;amp;A format, with links to helpful hints, more in-depth information and step-by step instructions for detection and removal.&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-size: 13.5pt;"&gt;Read on for a broad summary of Back Orifice and its implications, and follow my links, on and off this site, for a comprehensive view of this rather surprising tool.&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-size: 13.5pt;"&gt;A little knowledge can render you virtually free of any threat, and may also nudge you down a road of greater utilization and control of your own computer and its Internet connections.&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/791705236799000681-1655367710952325009?l=bonb2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bonb2008.blogspot.com/feeds/1655367710952325009/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=791705236799000681&amp;postID=1655367710952325009' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/791705236799000681/posts/default/1655367710952325009'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/791705236799000681/posts/default/1655367710952325009'/><link rel='alternate' type='text/html' href='http://bonb2008.blogspot.com/2008/06/back-orifice.html' title='Back Orifice'/><author><name>Mr. Mandiri</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://bp1.blogger.com/_adyQ_IcPHQQ/R4oEP4siVEI/AAAAAAAAAAM/7sxw9vhJ2kA/S220/SKU00507691_0.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-791705236799000681.post-1011025835591649462</id><published>2008-06-24T18:09:00.000-07:00</published><updated>2008-06-24T18:10:24.301-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Information of BO and NB'/><title type='text'>Information of BO and NB</title><content type='html'>&lt;p&gt;The following document provides a detailed technical explanation of the Back Orifice tool. There is another existing tool called NetBus which has capabilities similar to Back Orifice. The currently available definitions of Norton AntiVirus detect both Back Orifice and NetBus. To download these definitions, please go &lt;a href="http://www.symantec.com/avcenter/download.html"&gt;here&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;&lt;b&gt;Back Orifice Overview&lt;/b&gt;&lt;br /&gt;Back Orifice is a tool consisting of two main pieces, a client application and a server application. The client application, running on one machine, can be used to monitor and control a second machine running the server application. The operations that the client application can perform on the target machine (e.g., the machine running the server application) include the following:&lt;/p&gt;  &lt;ul type="disc"&gt;&lt;li class="MsoNormal" style=""&gt;Execute any application on      the target machine.&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;Log keystrokes from the      target machine.&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;Restart the target machine.&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;Lockup the target machine.&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;View the contents of any      file on the target machine.&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;Transfer files to and from      the target machine.&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;Display the screen saver      password of the current user of the target machine. The creators of Back      Orifice also claim to be able to display "cached passwords" for      the current user, but no other passwords were displayed during our      analysis.&lt;/li&gt;&lt;/ul&gt;  &lt;p&gt;&lt;b&gt;Technical Details&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;em&gt;Server application installation&lt;/em&gt;&lt;br /&gt;In order for Back Orifice to work, the server application must be installed on the target machine. This involves executing the server application on the target machine. The server application is a single executable file with a size just over 122 kilobytes. The application creates a copy of itself in the Windows system directory and adds a value containing its filename to the Windows registry under the key:&lt;/p&gt;  &lt;p&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\&lt;br /&gt;Windows\CurrentVersion\RunServices &lt;/p&gt;  &lt;p&gt;The specific registry value which points to the server application is configurable (see section below on configuration). By doing so, the server application always starts whenever Windows starts, and thus is always active. The application will not appear in the Windows task list.&lt;/p&gt;  &lt;p&gt;&lt;em&gt;Target machine requirements&lt;/em&gt;&lt;br /&gt;The target machine must be running either Windows 95 or Windows 98. The server application will not run on Windows NT. The target machine must have TCP/IP network capabilities.&lt;/p&gt;  &lt;p&gt;&lt;em&gt;Communication&lt;/em&gt;&lt;br /&gt;The client application communicates with the server application using TCP with encrypted UDP packets.&lt;/p&gt;  &lt;p&gt;&lt;em&gt;Configuration of the server application&lt;/em&gt;&lt;br /&gt;The server application can be configured with the following parameters:&lt;/p&gt;  &lt;ul type="disc"&gt;&lt;li class="MsoNormal" style=""&gt;Its installed filename&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;The communication port&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;The name of the value it      will add to the registry&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;A password for encrypting      the client/server packets used for communication&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;A custom plugin DLL to run      with the server application&lt;/li&gt;&lt;/ul&gt;  &lt;p&gt;&lt;em&gt;Default configuration&lt;/em&gt;&lt;br /&gt;By default, if the server application has not been otherwise configured, the installed filename is ".exe" (e.g., that's a space followed by ".exe"), the communication port is 31337, the registry value name is empty (e.g., the default registry value entry is used), and no password is used (although the communication is still encrypted).&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Is Back Orifice a Threat?&lt;/b&gt;&lt;br /&gt;Potentially, the tool can be used by an unscrupulous user (e.g., the attacker) to compromise the security of a computer running Windows 95 or Windows 98, for example, to steal secret documents, destroy data, etc. However, the following are obstacles limiting the threat:&lt;/p&gt;  &lt;ul type="disc"&gt;&lt;li class="MsoNormal" style=""&gt;The server application must      be installed on the target machine. This requires the user of the machine      to either deliberately install this application or be tricked into doing      so.&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;The attacker must know the      IP address of the target machine. Although, the attacker can use the      client application to perform a search through a range of IP addresses,      this is infeasible if the attacker can not narrow the range to a small      subset because there are four billion possible IP addresses.&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;A firewall between the      target machine and the attacker virtually makes it impossible for the      attacker to communicate with the target machine. Most corporations have      firewalls in place.&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;By following safe computing      practices, for example, not downloading or running applications from      unknown sources, users can protect themselves from the potential threat.&lt;/li&gt;&lt;/ul&gt;  &lt;p class="MsoNormal"&gt;Source &lt;a href="http://www.symantec.com/avcenter/warn/backorifice.html"&gt;http://www.symantec.com/avcenter/warn/backorifice.html&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/791705236799000681-1011025835591649462?l=bonb2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bonb2008.blogspot.com/feeds/1011025835591649462/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=791705236799000681&amp;postID=1011025835591649462' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/791705236799000681/posts/default/1011025835591649462'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/791705236799000681/posts/default/1011025835591649462'/><link rel='alternate' type='text/html' href='http://bonb2008.blogspot.com/2008/06/information-of-bo-and-nb.html' title='Information of BO and NB'/><author><name>Mr. Mandiri</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://bp1.blogger.com/_adyQ_IcPHQQ/R4oEP4siVEI/AAAAAAAAAAM/7sxw9vhJ2kA/S220/SKU00507691_0.jpg'/></author><thr:total>0</thr:total></entry></feed>
