Welcome | Sign In
ECommerceTimes.com
News

E-Commerce Security Alert: BO2K Hacking Tool

Print Version
E-Mail Article
Reprints
E-Commerce Security Alert: BO2K Hacking Tool


While hacker group Cult of the Dead Cow (CDC) held a press conference, announcing the release of Back Orifice 2000 (BO2K) to a throng of celebrants attending the DEFCON convention in Las Vegas, researchers were anxiously awaiting their own copy in order to provide users with a defense.

Consisting of a server and client application, BO2K is a backdoor trojan horse program that, once installed on a Windows-based system, allows remote access for monitoring and controlling activity. The program is a new version of Back Orifice released last year by the same group.

BO2K, however, not only does Windows, it now works with NT. This means, of course, that businesses -- including e-commerce operations -- could be impacted. The program is open-source, so there will possibly be multiple variations. Additionally, stronger encryption included with this new version will make it more difficult to detect.

Good Advices

BO2K spreads largely by way of e-mail contact, and thus has the potential to proliferate across the web in the manner of W32/ExploreZip.worm. Security experts advise a number of obvious measures that individuals and e-businesses can take to prevent infection, which include avoiding e-mail attachments -- particularly from unfamiliar sources.

Users are also advised to have proper security options when connected to the Internet with network file sharing enabled, to set e-mail client software security settings to high and not to accept files from Internet chat systems. But, if the worst-case scenario does occur -- the program is designed to be invisible to the user -- assistance is available.

Online Solutions

As they have done with other recent virus-like threats that have spread online, utility software vendors -- after receiving a copy of BO2K -- raced to analyze and post a solution on their Web sites. Symantec (Nasdaq: SYMC), (Nasdaq: SYMC) for instance, quickly posted technical and specific removal notes through its AntiVirus Research Center.

Network Associates (Nasdaq: NETA) dispatched their Anti-Virus Emergency Response Team, who also promptly made protection available. Trend Micro and Internet Security Systems (Nasdaq: ISSX) are among the other companies who have responded to the threat.

One Million Dollars and A Monster Truck

Well before its weekend release into the wild, Microsoft (Nasdaq: MSFT) had been actively campaigning against BO2K while security and Antivirus software vendors were communicating with CDC trying to obtain advance copies to study.

CDC representative Reid Fleming sarcastically answered one such software company request: "we are willing to provide you with the software you desire if and only if you will, in exchange, grant us one million dollars and a monster truck."

BO2K is a legitimate security administration tool for network analysis, according to CDC. Experts predictably dispute such claims. Members of CDC maintain that antivirus programs are inefficient, and that their own security solutions are currently in development.


Print Version E-Mail Article Reprints More by Matthew W. Beale


See Related Stories
Microsoft and Secure Computing Don A Black Hat and Hit Vegas (7/12/99)
E-Commerce Security Debate: Server-Based vs. Desktop Solutions (7/9/99)
Verisign Puts Clamp On E-Commerce Security (6/30/99)
Microsoft Announces Steps to Increase E-Commerce Security (6/28/99)
Microsoft Puts Patch On Server Security Holes (6/23/99)
Security Team Discovers New Microsoft Server Vulnerability (6/18/99)
E-Commerce Security Advisories Go Unheeded (6/2/99)
Is Online Security Worth Loss of Privacy? (5/21/99)
Lloyds of London Offers Anti-Hacker Insurance (5/3/99)
Polaroid Puts the Finger on E-Commerce Security (2/18/99)
IIS Teams with Microsoft for New E-Comm Solution (1/8/99)
Equifax Launches E-Commerce Services (1/7/99)
New Equifax Services Will Reduce E-Commerce Fraud (1/7/99)

More by Matthew W. Beale

One Year Ago: Red Hat and Dell Pump Up Linux Agreement
December 05, 2000
Dell Computer's deal with Red Hat increases the computer maker's Linux offerings.
One Year Ago: Intel Expands Linux Investment
November 27, 2000
Intel is adding SuSe to a series of investments in Linux companies.
One Year Ago:
Christmas Day Virus Warning Issued

November 20, 2000
The Prilissa virus is expected to hit on Christmas.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network