Back Orifice


Name: Back Orifice
Aliases: BO, cdc-BO, BoServe, BoClient, Orifice.dr, Trojan.Win32.BO, Body Odor, BackOrifice, Windows Trojan, Backdoor-N,
Ports: 31337 (UDP), 31338 (UDP) (ports can be changed) - 31337 (= eleet in hacker slang)
Files: Bo120.zip - 574,178 bytes Bo13.zip - Bo121unix.tgz - 27,642 bytes Bo121unix.tar - 122,880 bytes Boclient.exe - 57,856 bytes Boclient.exe - 707,072 bytes Boconfig.exe - 28,672 bytes Boserve.exe - 124,928 bytes Bogui.exe - 284,160 bytes Melt.exe - 29,184 bytes Freeze.exe - 33,280 bytes Windll.dll - Systray.exe -
Created: Aug 1998
Requires: -----
Actions: Remote Access
Registers: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\
Notes: Works on Windows 95 and 98. There exists several hacked versions of Back Orifice. There are also client versions for Unix and Macintosh. Boclient 57,856 bytes is DOS-client.
Country: written in the US
Program: Written in Visual C++.

© Copyright von Braun Consultants. This information may include technical inaccuracies or typographical errors. If you have any questions or further information about the actual trojan above, please contact Joakim von Braun at <joakim.von.braun@risab.se>