Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Valentine's Day Patch Tuesday: Microsoft to issue 9 patches, 4 critical
Mobile World Congress sneak peek: Quad-core smartphones, Ice Cream Sandwich & more
Microsoft details 'Windows on ARM' program
March debut of 'iPad 3' a sure bet, says analyst
FBI unbolts Steve Jobs 1991 investigation file
Cisco boosted profit, sales in Q2 while cutting costs
Macs take on the enterprise
Four crazy tech ideas from Google's Solve for X project
Obama 2012 campaign playlist revealed courtesy of Spotify
Oracle buying Taleo for US$1.9 billion in direct hit at SAP
Amazon attacks Apple: You get 3 Kindle products for price of iPad 2
Pre-rendered pages highlight latest Google Chrome release
Microsoft exec: Lync-Skype integration a 'compelling opportunity'
The future of hypervisors
/

Good offense is best defense against Back Orifice

Today's breaking news
Send to a friendFeedback


The Cult of the Dead Cow has done a marvelous publicity job. Before Back Orifice 2000's release, the Internet hummed with speculation. The good news is that this new code represents only a small incremental step in PC attack capability. Back Orifice 2000 doesn't exploit vulnerabilities in Windows; it exploits vulnerabilities in your people.

Programs such as Back Orifice create backdoors on Windows PCs. A component runs in the background, waiting for a TCP connection. A remote graphical user interface (GUI) client can start and stop applications; delete, copy or change files; capture keystrokes; dump the screen; and even monitor an attached video camera or microphone.

Although a self-replicating backdoor is likely - especially given the availability of Back Orifice's source code - such hostile code, or "malware," has not yet appeared. Most backdoor infections are in the form of Trojan horses. Screen savers, video games and greeting cards are common on the 'Net, but sometimes a double click results in a surreptitious hostile code installation.

Backdoors listen patiently for connection requests. Their convenient GUI management interfaces can scan a range of IP addresses, automatically finding exploitable hosts. Virtually every IP address reachable on the Internet is regularly scanned.

Firewalls aren't a cure-all for malware. They can reduce successful connection attempts, but hostile code that connects back out from inside a firewall is becoming more common.

Fortunately, while covert code continues to proliferate, effective countermeasures do as well. No single countermeasure is adequate in isolation, but a multipronged approach involving careful systems management and user education is effective.

Install antivirus software on all desktops, configure them to provide real-time protection and ensure that the virus definition files are automatically updated monthly. Virus-wall products that scan incoming e-mail are also useful. Use a different brand of antivirus product on the mail scanner, and remember that antivirus software can only detect known hostile code.

Practice good system administration and only allow users access to what they need. Malware typically exploits the victim's own system privileges. Don't let your NT administrators receive mail or execute office automation software using the same account they use for systems management.

The best defense is user awareness. Train users not to execute software sent through e-mail - even if it's from a reliable source. If users access your LAN remotely through the Internet, then your LAN can be attacked if any remote PC ends up with a back door on it. Prepare your laptop users as well and keep their antivirus software current.

The hostile code threat will continue to steadily increase, and no magic bullet can protect your organization. Fortunately, you can survive hostile code by following best practices for administration and user training.

RELATED LINKS

Heiser is a security consultant in the Falls Church, Va., office of International Network Services, a global provider of network consulting and software solutions. He can be reached at jay_heiser@ins.com.


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.