Notes on: bo2k
( Back Orifice 2000 )

( Updated: Friday, August 6, 1999 )
( Revised: Monday, February 8, 2000 )

Back Orifice 2000 (bo2k) was released in July 1999 by the cDc -- the same group that created the first BO trojan last year (see my Back Orifice and BO References pages). Those who were interested enough to be the first to get bo2k (either on a CD or from mirror websites) found that it was infected with the deadly CIH virus! (For Symantec's bulletin about CIH: Click here.) This was later confirmed as being true by the cDc after they received many complaints about it!

Unlike BO, bo2k can infect and be used to control a Windows™ NT machine! (This bo is a completely new program from a different author.)

My first attempts to infect an old Windows™95 machine with bo2k failed. This new version of their trojan is more difficult use in many ways. Finally, after spending enough time trying various combinations of parameters in their configuration program, I did succeed in running the bo2k server and bogui client on my old computer. As with the old BO trojan, there are bound to be some who will show others step by step details on how to infect a victim's computer. (Clue: don't ask me; I do not condone any network cracking!)

There are a number of features which seem to be defective in bo2k at the time of this writing! The effort appears to be focused primarily on Win NT machines, but the fact that their source code is open for all to examine means that they'll probably get the "bugs" out eventually. (Note that any cracker who's foolish enough to try using it illegally might be caught due to some "bug" in the present software; and I'd be glad to see that happen too!)

For those who wish to see more details about the bo2k trojan itself, especially if you are a Windows™ NT user, take this link to:
Symantec's Anti-Virus Research Center bulletin on Back Orifice 2000.


Is your computer free of all Trojans ?

   Hopefully, Net awareness has generally been raised to a level where people realize that the best defense against any trojan (or virus) is to practice "safe computing." (See my page on How To Keep Viruses / Trojans Out of Your Computer.)
   Those who are too quick to execute programs coming from unreliable sources usually get hit with a trojan/virus sooner or later! If you're at risk, you should definitely read my page Is your computer Free of All Trojans ?


The Starman's 'generic' BO Trojan page.