{"id":768,"date":"2013-02-27T20:49:06","date_gmt":"2013-02-28T04:49:06","guid":{"rendered":"http:\/\/e-olio.com\/cknow\/cms\/?p=768"},"modified":"2013-05-07T22:17:42","modified_gmt":"2013-05-08T05:17:42","slug":"back-orifice","status":"publish","type":"post","link":"https:\/\/www.cknow.com\/cms\/vtutor\/back-orifice.html","title":{"rendered":"Back Orifice"},"content":{"rendered":"<p><div class=\"simplePullQuote right\"><p><strong>Back Orifice is a Trojan that provides a backdoor into your computer when active and you are connected to the Internet.<\/strong><\/p>\n<\/div>Back Orifice is a Trojan that provides a backdoor into your computer when active and you are connected to the Internet. The original program came out in August 1998 with an update called BO-2000 later.<\/p>\n<p>The name is a play on Microsoft&#8217;s Back Office and the program is advertised as a network management program. It is produced by the group <a rel=\"prettyPhoto[iframes]\" href=\"https:\/\/www.cknow.com\/cms\/wp-content\/uploads\/2013\/03\/cultofthedeadcow.html?iframe=true&#038;width=75%&#038;height=75%\">Cult of the Dead Cow<\/a><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.cknow.com\/cms\/wp-content\/uploads\/2013\/02\/webpopup.png\" alt=\"Web Popup\" width=\"16\" height=\"16\" class=\"alignnone size-full wp-image-8\" \/> (cDc). Even though it does what it&#8217;s advertised to do, the fact that it installs silently, can&#8217;t be easily detected once run, and potentially allows a remote user to take complete control of your computer without your permission when it is installed has caused the AV companies to call it a Trojan and they have developed detection routines for the program.<\/p>\n<p>BO is distributed as several programs and documentation. The original programs run on Win95\/98 only; Bo-2000 also runs on NT. Indications are BO can be attached to other executables in the same style as viruses. When run, BO silently installs itself (you can&#8217;t even see it in the task list &#8212; see <a href=\"https:\/\/www.cknow.com\/cms\/vtutor\/stealth-viruses-and-rootkits.html\">rootkit<\/a>) and, when the computer is connected to a TCP\/IP network (e.g., the Internet) it sits in the background and just listens. What it&#8217;s listening for are commands starting with *!*QWTY? from a remote computer. The commands themselves are encrypted (in the US version; an international version does not use strong encryption). When a command is received BO is capable of many things; some benign, others quite destructive and\/or intrusive. A short list includes: computer info, list disk contents, file manipulation (including updating itself!), compressing &amp; decompressing files, get and send cached passwords, terminate processes, display messages, access the registry, plus store and send keyboard input while users are logging into other services. BO even supports HTTP protocols and emulates a web server so others can access the user&#8217;s computer using a web browser. If that&#8217;s not enough, BO can expand its abilities using plug-ins (which, of course, it can be commanded to download to itself).<\/p>\n<p>As evil as I&#8217;ve made Back Orifice sound, it has legitimate uses for network maintenance and even functions in a manner similar, although much more extensively, to various remote control utilities (e.g., Carbon Copy). The main difference is that they make themselves known while BO completely hides itself.<\/p>\n<p>You probably want to know if Back Orifice is on your system so keep your AV software up to date and make certain detection of programs like it is turned on.<\/p>\n<p>Microsoft has released a security bulletin on BO that fairly well dismisses the program. The cDc have released a point-by-point rebuttal of Microsoft&#8217;s bulletin. For a bit of entertainment, take a look at:<\/p>\n<p align=\"center\">http:\/\/www.cultdeadcow.com\/tools\/bo_msrebuttal.html<\/a> [Sorry, isn&#8217;t there any longer.]<\/p>\n<p>BO-2000 even supplies a plug-in that allows a remote user to see what is on your screen and take control of the mouse and keyboard. Since BO was written with a flexible architecture other plug-ins can be written and remotely installed.<\/p>\n<p>Even when I ran the Zone Alarm firewall software and only connected via a dial-up connection I often would see a Back Orifice inquiry against my current IP address in the Zone Alarm logs.<\/p>\n<p>You probably don&#8217;t want this beast running in the background on your computer.<\/p>\n<table style=\"margin: 0pt; width: 100%;\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\" align=\"center\">\n<tbody>\n<tr align=\"center\">\n<td style=\"padding: 0 0 0 0;\" colspan=\"2\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.cknow.com\/cms\/wp-content\/uploads\/2013\/02\/arrow_up.png\" alt=\"Up Arrow\" width=\"16\" height=\"16\" class=\"alignnone size-full wp-image-579\" \/> <a href=\"https:\/\/www.cknow.com\/cms\/vtutor\/some-virus-threat-details.html\">Some Virus Threat Details<\/a> <img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.cknow.com\/cms\/wp-content\/uploads\/2013\/02\/arrow_up.png\" alt=\"Up Arrow\" width=\"16\" height=\"16\" class=\"alignnone size-full wp-image-579\" \/><\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 0 0 0 0;\" align=\"right\"><a href=\"https:\/\/www.cknow.com\/cms\/vtutor\/some-virus-threat-details.html\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.cknow.com\/cms\/wp-content\/uploads\/2013\/02\/arrow_prior.gif\" alt=\"Prior Page\" width=\"48\" height=\"32\" class=\"alignnone size-full wp-image-578\" \/><\/a><\/td>\n<td style=\"padding: 0 0 0 0;\" align=\"left\"><a href=\"https:\/\/www.cknow.com\/cms\/vtutor\/spacefiller-cavity-viruses.html\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.cknow.com\/cms\/wp-content\/uploads\/2013\/02\/arrow_next.gif\" alt=\"Next Page\" width=\"48\" height=\"32\" class=\"alignnone size-full wp-image-577\" \/><\/a><\/td>\n<\/tr>\n<tr>\n<td style=\"padding-right: 20px; text-align: right; width: 50%;\"><a href=\"https:\/\/www.cknow.com\/cms\/vtutor\/some-virus-threat-details.html\">Some Virus Thread Details<\/a> <\/td>\n<td style=\"padding-left: 20px; width: 50%; text-align: left;\"> <a href=\"https:\/\/www.cknow.com\/cms\/vtutor\/spacefiller-cavity-viruses.html\">CIH Spacefiller<\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>Back Orifice is a Trojan that provides a backdoor into your computer when active and you are connected to the Internet. The original program came out in August 1998 with an update called BO-2000 later. The name is a play on Microsoft&#8217;s Back Office and the program is advertised as a network management program. It [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-768","post","type-post","status-publish","format-standard","hentry","category-vtutor","entry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Back Orifice - C-Know Media<\/title>\n<meta name=\"description\" content=\"Back Orifice is a Trojan that provides a backdoor into your computer when active and you are connected to the Internet.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.cknow.com\/cms\/vtutor\/back-orifice.html\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Back Orifice - C-Know Media\" \/>\n<meta property=\"og:description\" content=\"Back Orifice is a Trojan that provides a backdoor into your computer when active and you are connected to the Internet.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.cknow.com\/cms\/vtutor\/back-orifice.html\" \/>\n<meta property=\"og:site_name\" content=\"C-Know Media\" \/>\n<meta property=\"article:published_time\" content=\"2013-02-28T04:49:06+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2013-05-08T05:17:42+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.cknow.com\/cms\/wp-content\/uploads\/2013\/02\/webpopup.png\" \/>\n<meta name=\"author\" content=\"DaBoss\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"DaBoss\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/vtutor\\\/back-orifice.html#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/vtutor\\\/back-orifice.html\"},\"author\":{\"name\":\"DaBoss\",\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/#\\\/schema\\\/person\\\/47944007814fe46e32a1ebee5954638f\"},\"headline\":\"Back Orifice\",\"datePublished\":\"2013-02-28T04:49:06+00:00\",\"dateModified\":\"2013-05-08T05:17:42+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/vtutor\\\/back-orifice.html\"},\"wordCount\":596,\"image\":{\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/vtutor\\\/back-orifice.html#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/wp-content\\\/uploads\\\/2013\\\/02\\\/webpopup.png\",\"articleSection\":[\"VTutor\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/vtutor\\\/back-orifice.html\",\"url\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/vtutor\\\/back-orifice.html\",\"name\":\"Back Orifice - C-Know Media\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/vtutor\\\/back-orifice.html#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/vtutor\\\/back-orifice.html#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/wp-content\\\/uploads\\\/2013\\\/02\\\/webpopup.png\",\"datePublished\":\"2013-02-28T04:49:06+00:00\",\"dateModified\":\"2013-05-08T05:17:42+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/#\\\/schema\\\/person\\\/47944007814fe46e32a1ebee5954638f\"},\"description\":\"Back Orifice is a Trojan that provides a backdoor into your computer when active and you are connected to the Internet.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/vtutor\\\/back-orifice.html#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.cknow.com\\\/cms\\\/vtutor\\\/back-orifice.html\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/vtutor\\\/back-orifice.html#primaryimage\",\"url\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/wp-content\\\/uploads\\\/2013\\\/02\\\/webpopup.png\",\"contentUrl\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/wp-content\\\/uploads\\\/2013\\\/02\\\/webpopup.png\",\"width\":16,\"height\":16,\"caption\":\"Web Popup\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/vtutor\\\/back-orifice.html#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Back Orifice\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/#website\",\"url\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/\",\"name\":\"C-Know Media\",\"description\":\"Fun media for all\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/#\\\/schema\\\/person\\\/47944007814fe46e32a1ebee5954638f\",\"name\":\"DaBoss\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d4ba3f829b22682345f1dec9f43e839d822e1b4c570d7ce15475db8b4d5ce111?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d4ba3f829b22682345f1dec9f43e839d822e1b4c570d7ce15475db8b4d5ce111?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d4ba3f829b22682345f1dec9f43e839d822e1b4c570d7ce15475db8b4d5ce111?s=96&d=mm&r=g\",\"caption\":\"DaBoss\"},\"url\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/author\\\/daboss-2\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Back Orifice - C-Know Media","description":"Back Orifice is a Trojan that provides a backdoor into your computer when active and you are connected to the Internet.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.cknow.com\/cms\/vtutor\/back-orifice.html","og_locale":"en_US","og_type":"article","og_title":"Back Orifice - C-Know Media","og_description":"Back Orifice is a Trojan that provides a backdoor into your computer when active and you are connected to the Internet.","og_url":"https:\/\/www.cknow.com\/cms\/vtutor\/back-orifice.html","og_site_name":"C-Know Media","article_published_time":"2013-02-28T04:49:06+00:00","article_modified_time":"2013-05-08T05:17:42+00:00","og_image":[{"url":"https:\/\/www.cknow.com\/cms\/wp-content\/uploads\/2013\/02\/webpopup.png","type":"","width":"","height":""}],"author":"DaBoss","twitter_misc":{"Written by":"DaBoss","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.cknow.com\/cms\/vtutor\/back-orifice.html#article","isPartOf":{"@id":"https:\/\/www.cknow.com\/cms\/vtutor\/back-orifice.html"},"author":{"name":"DaBoss","@id":"https:\/\/www.cknow.com\/cms\/#\/schema\/person\/47944007814fe46e32a1ebee5954638f"},"headline":"Back Orifice","datePublished":"2013-02-28T04:49:06+00:00","dateModified":"2013-05-08T05:17:42+00:00","mainEntityOfPage":{"@id":"https:\/\/www.cknow.com\/cms\/vtutor\/back-orifice.html"},"wordCount":596,"image":{"@id":"https:\/\/www.cknow.com\/cms\/vtutor\/back-orifice.html#primaryimage"},"thumbnailUrl":"https:\/\/www.cknow.com\/cms\/wp-content\/uploads\/2013\/02\/webpopup.png","articleSection":["VTutor"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.cknow.com\/cms\/vtutor\/back-orifice.html","url":"https:\/\/www.cknow.com\/cms\/vtutor\/back-orifice.html","name":"Back Orifice - C-Know Media","isPartOf":{"@id":"https:\/\/www.cknow.com\/cms\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.cknow.com\/cms\/vtutor\/back-orifice.html#primaryimage"},"image":{"@id":"https:\/\/www.cknow.com\/cms\/vtutor\/back-orifice.html#primaryimage"},"thumbnailUrl":"https:\/\/www.cknow.com\/cms\/wp-content\/uploads\/2013\/02\/webpopup.png","datePublished":"2013-02-28T04:49:06+00:00","dateModified":"2013-05-08T05:17:42+00:00","author":{"@id":"https:\/\/www.cknow.com\/cms\/#\/schema\/person\/47944007814fe46e32a1ebee5954638f"},"description":"Back Orifice is a Trojan that provides a backdoor into your computer when active and you are connected to the Internet.","breadcrumb":{"@id":"https:\/\/www.cknow.com\/cms\/vtutor\/back-orifice.html#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.cknow.com\/cms\/vtutor\/back-orifice.html"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cknow.com\/cms\/vtutor\/back-orifice.html#primaryimage","url":"https:\/\/www.cknow.com\/cms\/wp-content\/uploads\/2013\/02\/webpopup.png","contentUrl":"https:\/\/www.cknow.com\/cms\/wp-content\/uploads\/2013\/02\/webpopup.png","width":16,"height":16,"caption":"Web Popup"},{"@type":"BreadcrumbList","@id":"https:\/\/www.cknow.com\/cms\/vtutor\/back-orifice.html#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.cknow.com\/cms\/"},{"@type":"ListItem","position":2,"name":"Back Orifice"}]},{"@type":"WebSite","@id":"https:\/\/www.cknow.com\/cms\/#website","url":"https:\/\/www.cknow.com\/cms\/","name":"C-Know Media","description":"Fun media for all","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.cknow.com\/cms\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.cknow.com\/cms\/#\/schema\/person\/47944007814fe46e32a1ebee5954638f","name":"DaBoss","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/d4ba3f829b22682345f1dec9f43e839d822e1b4c570d7ce15475db8b4d5ce111?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/d4ba3f829b22682345f1dec9f43e839d822e1b4c570d7ce15475db8b4d5ce111?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d4ba3f829b22682345f1dec9f43e839d822e1b4c570d7ce15475db8b4d5ce111?s=96&d=mm&r=g","caption":"DaBoss"},"url":"https:\/\/www.cknow.com\/cms\/author\/daboss-2"}]}},"_links":{"self":[{"href":"https:\/\/www.cknow.com\/cms\/wp-json\/wp\/v2\/posts\/768","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cknow.com\/cms\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cknow.com\/cms\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cknow.com\/cms\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cknow.com\/cms\/wp-json\/wp\/v2\/comments?post=768"}],"version-history":[{"count":0,"href":"https:\/\/www.cknow.com\/cms\/wp-json\/wp\/v2\/posts\/768\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.cknow.com\/cms\/wp-json\/wp\/v2\/media?parent=768"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cknow.com\/cms\/wp-json\/wp\/v2\/categories?post=768"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cknow.com\/cms\/wp-json\/wp\/v2\/tags?post=768"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}