| I am a hacker. My weopon of choice, 'internet'. My mission is to brake into as many computers as I can, without ever being know that I was upon these computers. My reason,'Information'. I feel that information upon the internet(world wide web, www, super highway, etc) should be free to anyone that can access it. I do not destroy the computers that I access nor do any of the other hackers in my group. We simply visit a computer take something to shown we been there and leave it like it is. Why am I making this web page about BO & NB? Simple, to many wantta be hackers can easily use these things and blame the real hackers for destroing peoples machine(box). I am tied of people blaming me for the action of those who don't know the code of a hacker. Just recently about 3 months ago a virii was released called the mallisa virii and the press blamed it on a hacker. NO! He wasn't a hacker. First off the word 'Hacker' comes from back when the orginal network was inventted at the pentigon. The coders would spent entire day's banging away at the keyboard or hacking at the keyboard (the downward motion of the hand on the key's ie hacking a piece of wood to bits ie hacker <-- Meaning One. Ok, so I bored you enough. I just wantted to get my point access that it isn't hackers who destroy, but those wantta be people that wouldn't know how to use linux, unix, or just know VB or QB for a programming language. BO & NB! The: WHO? WHY? WHAT? WHEN? WHERE? Who? Anyone with Win95 or Win98! What? What can they do? Start any .com .exe .bat on any drive on your computer. Make your HD into a web server. http:\\??? Log your keystrokes. Download anything from your computer. Upload anything from your computer. Send you message boxes. View your password file. Capture your desktop If you got a video camera or scanner (turned on take pictures from that also) Delete files/directory's Move files/directory's Give them a DOS prompt. Add/delete from your registery and alot more! Like they are at your Computer! When? Anytime you download a file from the internet and run it upon your computer. They could contain this virii. It can run without you knowing it was run. and Ctrl-Alt-Del to view the programs that are running will not show you that it is running and it addes itself to the registey's to autorun everytime you restart windows! Where? Any website that allows you to download from there WebPages Or a .zip file with and .exe That has and .exe file! Why? People think they are kewl, cause they know how to use a simple program. They think that by doing so they earn the right to be called a hacker. Or simply to hurt others. Why is it so dangerous. Lets say you have a .doc on your computer with all your friends names, phone #, and addresses. Boom they just have access to that. Oh, tax time so people will have there Checking info upon there computer. Alittle side note ( I did this once to see if it would work. Someone had there Check Books on the computer. I called up AOL and got an FREE account using there name and checking information. AOL didn't even flinch. I called up the next day to disconnect my account and ask them why they let me do it. 'Cause we thought you were really him'. ) Just an example of the danger on the internet. Oh, say you have some xxx pics of you and your wife (for your personal collection) well, they could be all over the web for everyone to see. Hrm, also there is just to many reason to name. Is Bo Legal. No, simply because the creator intended for this purpose to show people that they could get upon other peoples computer and show how unstable Windows really is to Internet Attacks. Is NB Legal. Yes, the author stats that it should be used as a adminstor tool. Like for those people that run a computer network and don't have the money to buy and expensive product (sometimes 100$). He has alot of options also on how it should be installed. If it should be installed without people knowing it or that it should show it's self in the Ctrl-Alt- Delete part of Win95 or Win98, but he does add that it could be used for a prank against people. Ok, again let me tell you how people can get it. There is a file named SilkRope that will combine BO to a file. Run BO without you knowing it and then run the file it was combined onto. Kinda like a piggy back effect OR the TROJAN HORSE effect. ie trojan(virii). Now, Silk Rope only boost that it works with bo, but it also can work with NB. All the wantta be hackers would have to do after it was installed without you knowing it is find out your IP! Well, your saying that is a toughy they couldn't know what my IP is. After all 255^255^255^255 = infinate number of computer's with mine being just one of them. Plus, my IP's changes each time I get upon the web. '^' means 255*1+255*2+ to 255*254+255*255 etc. A BIG NUMBER! Anyhow, no it's rather easy. Also there is program that is called Butt-Trumpet that will send that person that installed it and e-mail everytime you get upon the web with your IP. Oh, ok. that sucks, but can't I see it in my E-Mail client. No! the Butt-trumpet is an e-mail client of it's own!. Ok, but if they have it upon 30 peoples computer they will have to wait at least an 1hr to get my IP cause my mail is slow to send and I only get on for 30min(s) at a time. Hrm, he can still get you. Cause there is something called ??? can't recall the lame thing right now, but it will log you onto a IRC (internet relay chat) server and tell everyone in #BO_OWNED your IP, and that happens when your first get upon the Internet. Or if they are alittle smartter they would set-up there own IRC on there computer. Use dhs.org to redirect you to there computer and have it log onto there irc server and then they have your IP anytime they and your are on. Sorry, did I lose you there. Tring to keep it rather simple for those who don't know how to program a .bat file or know dos commands. One more thing. You think your virii's program is going to detect these. Uhm, wrong. I played around with NB and BO alittle and 85% of the computer's I ran into had a virii protector on it running!!! Simply what am I saying. Your at risk anytime you download a file that you don't know a brand name WebSite is giving your it. For those who get wares off the IRC, AOL, and ETC. Any .EXE file not over 5MB's can contain these virus's. ? a .ZIP file that is 10MB's big can it contain this virii? Yes and No. If it has an .EXE in it that is less then 5MB's in size then it can if all the .EXE's are over 5MB's then it can't. How do I protect myself or see if I have it already. Well, I could give you a couple of websites with protector and detectors that will tell you if you have it, but then you will not learn anything will you. Plus, I figure why do you need just another file to take up space on your computer when you can read a .TEXT. and do it yourself without the risk of infectting yourself with another .EXE. How To Check for BackOrifice and get ride of it. 1: Get pen and paper. 2: Start your Computer. 3: Start/Run type in: regedit.exe 4: Look Under HKEY/CURRENTUSER/MICROSOFT/WINDOWS/CURRENTVERSION/RUNSERVICEONCE 5: Write down all the .exe you see. The Names and Descriptions 6: Close regedit (registery editor) 7: Goto a MS/DOS Prompt 8: type in at the C:\> prompt this: cd\windows\system or cd\your_windows_direcotry ie cd\win95 cd\win98 etc. followed by \system ie cd\win95\system ie cd\win98\system 9: type in: dir and after dir type in the .exe's names ie dir patch.exe if it's .exe type in: dir EXE~1 and if the file is 100,000 Btyes or 100 KB to 130 KB then it is BO. (want to look for those ones without a description or wierd descriptions) 10: Next Go Back to Start/Run regedit.exe HKEY etc and delete that entry. 11: Restart your computer 12: Goto MS/DOS prompt or C:\> cd\windows\system and del that file name. and if you did all that I said you will not have BO anymore. If there are more the ONE file that is 100 KB - 130 KB big you might have MORE then ONE bo's on your computer. How To Check for NetBus and get ride of it. 1: Get pen and paper. 2: Start your Computer. 3: Start/Run type in: regedit.exe 4: Look Under ?? HKEY/CURRENTUSER/MICROSOFT/WINDOWS/CURRENTVERSION/RUNSERVICEONCE 5: Write down all the .exe you see. The Names and Descriptions 6: Close regedit (registery editor) 7: Goto a MS/DOS Prompt 8: type in at the C:\> prompt this: dir /s then the .exe's name ie: dir /s patch.exe ie dir /s html.exe then it will try to find that file on your computer. When it comes to that directory that it is in then write directory down c:\that_Directory> ie c:\progra~1\netscape> then cd\ to that directory. ie cd\that_Directory ie cd\progra~1\netscape. then when your at that directory: dir then the files name. And if it's 400 KB - 500 KB your might be infectted. (Look for those with patch.exe /nomsg as a description or wierd file name or descriptions) 10: Next Go Back to Start/Run regedit.exe HKEY etc and delete that entry. 11: Restart your computer 12: Goto MS/DOS prompt or C:\> CD or Change Directory( CD ) back to that direcotry you wrote down as it being in and delete that file And your clean of NetBus. If your still not sure or just want to take the easy way out, but run a risk of being infectted. There are .exe's that will tell your about it. Net Bustter will stop NetBus NoBo or NO BO will stop BO I think the NOBO link is dead, but I havn't had time to check to see where there are others. Just search WebCrawler with these keyword. BACKORIFICE +TROJAN +PROTECT and you should run upon the protection website. I just hope everyone stops blaming HACKERS for messing up there computers. I look for harder way's to seek out information to enhance my mind. Not some two bit easy to use and lame thing anyone with two weeks knowlegde about computers could use. Final Words... I hope this was helpfull to everyone out there! L8rz and try not to fuck anyone UP!! gler |