2.2 Implants: Types, Ways of Injection, and Methods of Protection
143
Back Orifice was written by user Dildog from a white hacker’s organization Cult
of the dead cow group. It was first presented at the DefCon 7 conference a long time
ago, in 1999.
Some time later, its creators released a more powerful version of Back Orifice
named Back Orifice 2000 (or Bo2k) as a so-called open-source project. They called
this system “a remote administration system,” since it can be installed on a client
machine without any prompt; many users run this application in their systems, and
the antivirus they used demonstrated a standard alarm signal. Bo2k is one of such
means that can be used both for good and for bad purpose. Even today (as of the
moment of publication of this book), many companies use Bo2k as a cheap solution
for remote control of their systems.
Of course, Bo2k is fairly limited in terms of abilities. For example, the sequence
of commands of the Bo2k client only takes about 100 kb, and it can be easily installed
even with very old modems and limited bandwidth. Of course, the size of the code
can also be changed by adding more properties in order to ensure better control on
a remote machine. It can use various types of authentication, encryption algorithms,
and protocols. The latest versions also provided the possibilities for running it as
reverse client or adding certain characteristics of the Kernel rootkit in order to hide the
task. Bo2k capabilities can be expanded by adding some other programs connected
both to the customer part and the server part of the application. In general, it is
possible to design a similar custom plugin program for operation under Bo2k system
control.
As soon as the Bo2k application loads, it is possible to use bo2kcfg (Bo2k configuration application) to configure the Bo2k client. It is possible to open a Bo2k file and
pre-configure it for further use. During this stage, it is also possible to add TCP/UDP
protocols to standard mechanisms of communication, authentication, and encryption, as well as the address of a specific port to be used by default in the future. After
configuring this client, as soon as the system is booted on any machine, it will be
possible to connect to this machine using the bo2kcfg interface for remote control
of the client’s system.
It is also possible to use multiple other linking applications for connection of
the Bo2k client with another program. After the resulting Bo2k program launches,
the user can start working without realizing that this Bo2k program is operating in
parallel. For example, Elite Wrap, Saran Wrap, and Silk Rope are only several of
simple known programs that were widely used to connect the Bo2k client to other
applications.
Therefore, understanding the principle of work of Trojans and implants and their
potential danger to the system, the user can independently create more protected
systems and protect the user information from the simplest attacks.
Précédent

- 164/839

Suivant