Back Orifice 2000 (bo2k) was released in July 1999 by the cDc -- the same group that created the first BO trojan last year (see my Back Orifice and BO References pages). Those who were interested enough to be the first to get bo2k (either on a CD or from mirror websites) found that it was infected with the deadly CIH virus! (For Symantec's bulletin about CIH: Click here.) This was later confirmed as being true by the cDc after they received many complaints about it!
Unlike BO, bo2k can infect and be used to control a Windows NT machine! (This bo is a completely new program from a different author.)
My first attempts to infect an old
Windows95 machine with bo2k failed. This new version of their
trojan is more difficult use in many ways. Finally, after spending enough
time trying various combinations of parameters in their configuration
program, I did succeed in running the bo2k server and bogui
client on my old computer. As with the old BO trojan, there are bound
to be some who will show others step by step details on how to infect a
victim's computer. (Clue: don't ask me; I do not condone any
network cracking!)
There are a number of features which seem to be defective in bo2k at the
time of this writing! The effort appears to be focused primarily on Win NT
machines, but the fact that their source code is open for all to examine
means that they'll probably get the "bugs" out eventually. (Note
that any cracker who's foolish enough to try using it illegally might be
caught due to some "bug" in the present software; and I'd be
glad to see that happen too!)
For those who wish to see more details about the bo2k trojan itself,
especially if you are a Windows NT user, take this link to:
Symantec's Anti-Virus Research Center bulletin on Back Orifice 2000.
Hopefully, Net awareness
has generally been raised to a level where people realize that the best
defense against any trojan (or virus) is to practice "safe
computing." (See my page on How To Keep
Viruses / Trojans Out of Your Computer.)
Those
who are too quick to execute programs coming from unreliable sources
usually get hit with a trojan/virus sooner or later! If you're at
risk, you should definitely read my page Is your
computer Free of All Trojans ?