Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
AT&T builds $23M IPv6 network for U.S. military
Nearly 1 million jobs could be created by IT stimulus package, think tank says
Mumbai gunmen used U.S. VoIP service to talk to their superiors during their spree
Rogue SSL certificate exploit puts VeriSign on the spot
Apple lacks broad corporate strategy but still sees gains
Sun buys cloud-computing vendor Q-layer
Data breaches rose sharply in 2008, says study
Cisco: Huge international interest in developer contest
Group's plan for Inauguration Day: Telework
'Leap second' snafu affects Oracle clusterware
Microsoft makes Muglia server/tools president
Microsoft layoff rumors continue their swirl
Network failure spurs IT overhaul at law school
Twitter Hack: How It Happened and What's Being Done
HP says netbook can run for up to 8 hours between charges
/

Tool for attacking NT servers released this weekend: Is your network safe from the Cult of the Dead Cow?

Today's breaking news
Send to a friendFeedback

Advertisement:

They're baaaack! That bad-boy hacker group Cult of the Dead Cow will unleash another menace this Saturday. Last year the group authored the "Back Orifice" Trojan horse designed to help their pals take over your network.

At the Def Con conference, generally attended by hundreds of hackers and nearly as many cops, the Cult of the Dead Cow members will take the wraps off Back Orifice 2000.

An unkind cut at Microsoft's Back Office suite; Back Orifice 2000 lets hackers sneak into your network via your server as well as your Windows 95 or 98 desktop (the mode used by the first Back Orifice).

The original Back Orifice was bad enough. In fact, once a hacker was able to sneak in (usually virtually rather than physically) and install Back Orifice on your desktop, he had complete remote control of your network and files. And it's was very hard to detect because this Trojan horse was encrypted in a pretty artful manner.

The Cult of the Dead Cow says that the server side upgrade of Back Orifice 2000 offers another way to commandeer a network - right through your NT server. (You can read their description of it at www.cultdeadcow.com. But don't believe everything you read-this is hacker software, not a remote administration tool you would want to use it on your network yourself, regardless of what they say).

Security experts familiar with the inner workings of the first Back Orifice say it's a dangerous program and most easily installed by simply inserting a floppy disk with the Cult of the Dead Cow's application somehow snuck onto it.

Bob Olsen, vice president of marketing at security vendor Network-1 Security Solutions, says the original Back Orifice can also be dumped onto the network remotely by sending the victim an e-mail message using a hacker add-on built for Back Orifice called "saran wrap." This add-on installs Back Orifice onto the desktop using a .exe file attachment masquerading as something harmless, like a greeting.

The entire security industry will be watching for the shipment of Back Orifice 2000, which will be available for download at www.bo2k.com. Network-1 says it will ensure that its NT firewall can guard against it by detecting it and shutting down ports it tries to use. A slew of other vendors are sure to have something to say about guarding against Back Orifice 2000 as well.

Network-1's Olsen does fault Microsoft to some extent for the ease with which a Trojan horse such as Back Orifice can exploit NT.

"Windows is designed for maximum connectivity, which is the opposite of a security model," Olsen notes. "Microsoft should have a kernel-mode network-access service and intrusion detection in NT." Something like that would help prevent the maliciously inventive, such as the folks from the Cult of the Dead Cow, from finding their work so easy, Olsen says.

RELATED LINKS

Contact Senior Editor Ellen Messmer

Other recent articles by Messmer

Cult of the Dead Cow Web site

Reaction: Here's what some Fusion users are saying about this article: What do you think? Add your comments to the thread


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.