Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

TROJAN:BACKORIFICE:BO2K-CONNECT

Severity

Major

Recommended

No

Recommended Action

Drop

Category

TROJAN

Keywords

Back Orifice 2000 Client Connection

Release Date

2003/10/15

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

TROJAN: Back Orifice 2000 Client Connection


This signature detects connections between a Back Orifice 2000 (BO2K) client and server. This indicates that a BO2K client has made a successful connection to a server that is listening on the standard BO2K port. It allows a remote attacker to take control of the infected host.

Extended Description

The web server supplied with the QNX Voyager demo disk contains several vulnerabilities. First, Voyager will follow relative paths passed to it in requests. This includes ../ style paths, which will allow Voyager to serve pages outside of the "document root". Another vulnerability is that the web server does not have sufficient security restrictions - this means that the web server can access any file, including protected files and special /dev entries. As well, due to the integration of the web browser and web server, information used by the Photon GUI is easily exposed by requesting files under /.photon/. Additionally, html files generated by the web browser (error messages, for example) and the QNX configuration interface share the same directory as published html files. While the Voyager web server is not intended to be used in a production environment, and is in fact intended only to be a demo of the QNX OS, users should be aware of these design errors.

Affected Products

  • Qssl voyager 2.0.0 1B

References

  • BugTraq: 1648
  • CVE: CVE-1999-0660
  • URL: http://secunia.com/virus_information/4619
  • URL: http://www.sarc.com/avcenter/venc/data/back.orifice2000.trojan.html

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out