Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Android, Apple Own 80% of Global Smartphone Market; Microsoft's Share, 2.2%
Proposed New York Legislation Would Ban Anonymous Online Comments
Supercomputer to connect to 400PB of storage via Ethernet
Sales of unused IPv4 addresses gathering steam
Customizable cloud SLAs on the way, researchers predict
Google chairman pledges to fund Raspberry Pi availability in U.K. schools
Obama orders agencies to optimize Web content for mobile
Are CEOs getting the social media thing?
Managing Mobile Mania
Google's Android did not infringe Oracle patents, jury finds
HP to trim 27,000 jobs as part of restructuring program
VMware acquires desktop management company Wanova
Privacy advocates fear CISPA
Groups launch gigabit-per-second broadband project
Windows 8 touchscreen devices to be priced higher, Dell says
/

Tool for attacking NT servers released this weekend: Is your network safe from the Cult of the Dead Cow?

Today's breaking news
Send to a friendFeedback

They're baaaack! That bad-boy hacker group Cult of the Dead Cow will unleash another menace this Saturday. Last year the group authored the "Back Orifice" Trojan horse designed to help their pals take over your network.

At the Def Con conference, generally attended by hundreds of hackers and nearly as many cops, the Cult of the Dead Cow members will take the wraps off Back Orifice 2000.

An unkind cut at Microsoft's Back Office suite; Back Orifice 2000 lets hackers sneak into your network via your server as well as your Windows 95 or 98 desktop (the mode used by the first Back Orifice).

The original Back Orifice was bad enough. In fact, once a hacker was able to sneak in (usually virtually rather than physically) and install Back Orifice on your desktop, he had complete remote control of your network and files. And it's was very hard to detect because this Trojan horse was encrypted in a pretty artful manner.

The Cult of the Dead Cow says that the server side upgrade of Back Orifice 2000 offers another way to commandeer a network - right through your NT server. (You can read their description of it at www.cultdeadcow.com. But don't believe everything you read-this is hacker software, not a remote administration tool you would want to use it on your network yourself, regardless of what they say).

Security experts familiar with the inner workings of the first Back Orifice say it's a dangerous program and most easily installed by simply inserting a floppy disk with the Cult of the Dead Cow's application somehow snuck onto it.

Bob Olsen, vice president of marketing at security vendor Network-1 Security Solutions, says the original Back Orifice can also be dumped onto the network remotely by sending the victim an e-mail message using a hacker add-on built for Back Orifice called "saran wrap." This add-on installs Back Orifice onto the desktop using a .exe file attachment masquerading as something harmless, like a greeting.

The entire security industry will be watching for the shipment of Back Orifice 2000, which will be available for download at www.bo2k.com. Network-1 says it will ensure that its NT firewall can guard against it by detecting it and shutting down ports it tries to use. A slew of other vendors are sure to have something to say about guarding against Back Orifice 2000 as well.

Network-1's Olsen does fault Microsoft to some extent for the ease with which a Trojan horse such as Back Orifice can exploit NT.

"Windows is designed for maximum connectivity, which is the opposite of a security model," Olsen notes. "Microsoft should have a kernel-mode network-access service and intrusion detection in NT." Something like that would help prevent the maliciously inventive, such as the folks from the Cult of the Dead Cow, from finding their work so easy, Olsen says.

RELATED LINKS

Contact Senior Editor Ellen Messmer

Other recent articles by Messmer

Cult of the Dead Cow Web site

Reaction: Here's what some Fusion users are saying about this article: What do you think? Add your comments to the thread


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.