64
1 Information Weapon: Concepts, Means, Methods …
• Data files are carefully protected from detection and viewing. Users of
PAPARAZZI must remember (and keep secret) the password and access code.
Not knowing them, it is impossible to run the program or view the pictures.
• After uninstallation, all traces of PAPARAZZI program are completely destroyed.
Back Orifice Program
In essence, Back Orifice (BO) Trojan horse is a powerful utility for remote administration of computers on a network. Back Orifice is a remote administration system
enabling the user to control computers using a conventional console or server graphical shell. In the local network or via the Internet, the BO “provides the user with
more features on a remote Windows computer than the user of that computer has.”
That is what an advertisement on one of the hacker web pages says.
However, there is a peculiarity, which underlines the necessity of classifying BO
as a harmful Trojan: there is no warning about installation and run. When the program
is run, the Trojan installs itself in the system and monitors it, while the user gets no
messages about its actions in the system. Moreover, there is no link on the Trojan in
the list of active applications. As a result, the user of this Trojan may be unaware of
its presence in the system, while its computer is open for remote control.
The Trojan is distributed as a package of several programs and documents.
All programs are written in C++ and compiled by Microsoft Visual C++. All
programs have the Portable Executable format and can only be executed in the Win32
environment.
BOSERVE.EXE is the main program in the package (then this file can be detected
under various names), this is the main “server” component of the Trojan that waits
for calls from remote “clients.”
The second file is BOCONFIG.EXE, which configures the “server” and allows
one to “attach” BOSERVE.EXE to any other files (as viruses do). When launching
such applications, the virus bites them out of the infected file and runs them without
any side effects (Fig. 1.34).
The package also contains two “client” utilities (console and graphical interface),
enabling the “client” to manage the remote “server.” Two more programs are file
compression/decompression utilities—they are used to copy files from/to a remote
“server.”
When run, the Trojan initializes the Windows sockets, creates the WINDLL. DLL
file in the Windows System Directory, determines the addresses of several Windows
APIs, searches for its copy in the memory and, if found, unloads it from the memory
(i.e., gets updated). Then the Trojan saves its copy in the Windows System Directory
and registers in the registry as a daemon process:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
\RunServices.
Then the Trojan intercepts one of the Windows sockets (by default—socket 31337)
and remains in the Windows memory as a hidden application (i.e., with no active
windows and links in the application list). When the main message interception
procedure is over, it waits for commands from the remote client. Command sockets
1 Information Weapon: Concepts, Means, Methods …
• Data files are carefully protected from detection and viewing. Users of
PAPARAZZI must remember (and keep secret) the password and access code.
Not knowing them, it is impossible to run the program or view the pictures.
• After uninstallation, all traces of PAPARAZZI program are completely destroyed.
Back Orifice Program
In essence, Back Orifice (BO) Trojan horse is a powerful utility for remote administration of computers on a network. Back Orifice is a remote administration system
enabling the user to control computers using a conventional console or server graphical shell. In the local network or via the Internet, the BO “provides the user with
more features on a remote Windows computer than the user of that computer has.”
That is what an advertisement on one of the hacker web pages says.
However, there is a peculiarity, which underlines the necessity of classifying BO
as a harmful Trojan: there is no warning about installation and run. When the program
is run, the Trojan installs itself in the system and monitors it, while the user gets no
messages about its actions in the system. Moreover, there is no link on the Trojan in
the list of active applications. As a result, the user of this Trojan may be unaware of
its presence in the system, while its computer is open for remote control.
The Trojan is distributed as a package of several programs and documents.
All programs are written in C++ and compiled by Microsoft Visual C++. All
programs have the Portable Executable format and can only be executed in the Win32
environment.
BOSERVE.EXE is the main program in the package (then this file can be detected
under various names), this is the main “server” component of the Trojan that waits
for calls from remote “clients.”
The second file is BOCONFIG.EXE, which configures the “server” and allows
one to “attach” BOSERVE.EXE to any other files (as viruses do). When launching
such applications, the virus bites them out of the infected file and runs them without
any side effects (Fig. 1.34).
The package also contains two “client” utilities (console and graphical interface),
enabling the “client” to manage the remote “server.” Two more programs are file
compression/decompression utilities—they are used to copy files from/to a remote
“server.”
When run, the Trojan initializes the Windows sockets, creates the WINDLL. DLL
file in the Windows System Directory, determines the addresses of several Windows
APIs, searches for its copy in the memory and, if found, unloads it from the memory
(i.e., gets updated). Then the Trojan saves its copy in the Windows System Directory
and registers in the registry as a daemon process:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
\RunServices.
Then the Trojan intercepts one of the Windows sockets (by default—socket 31337)
and remains in the Windows memory as a hidden application (i.e., with no active
windows and links in the application list). When the main message interception
procedure is over, it waits for commands from the remote client. Command sockets
