Home / malwarePDF  

Backdoor:W32/Backdoor


First posted on 17 May 2010.
Source: SecurityHome

Aliases :

There are no other names known for Backdoor:W32/Backdoor.

Explanation :

A remote administration utility that bypasses normal security mechanisms to secretly control a program, computer or network.

Additional DetailsWhen searching our Virus Descriptions database for a specific program (e.g., Backdoor:W32/Example.A), you may be directed to this page if the overview below sufficiently describes the program.

Alternatively, you may be directed to this page if no description matching that specific query is currently available. You can submit a sample of the suspect file to our Response Lab for further analysis via:

• Sample Analysis System


About Backdoors

A backdoor program is a remote administration utility that, once installed on a computer, allows a user access and control it over a network or the Internet. A backdoor is usually able to gain control of a system because it exploits undocumented processes in the system's code. These utilities may be legitimate, and may be used for legitimate reasons by authorized administrators, but they are also frequently used by attackers to gain control of a user's machine without their knowledge or authorization.

A typical backdoor consists of 2 components- client and server. An attacker will use the client application to communicate with the server components, which are installed on the victim's system. A backdoor's server components can be installed in numerous ways - as part of a worm or trojan payload, as an email attachment, as a tantalizingly-named file on peer-to-peer networks, etc. Once installed, the server component will open a network port and communicate with the client, to indicate that the computer is infected and vulnerable. An attacker can then use the backdoor to execute commands.

Depending on how sophisticated a client is, it can include such features as sending and receiving files, browsing through the hard drives and network drives, getting system information, taking screenshots, changing the date/time and settings, playing tricks like opening and closing the CD-ROM tray and so on.


IRC Backdoors


A particular type of backdoor is the IRC backdoor, which can be controlled via a specific Internet Relay Chat (IRC) channel under the control of the hacker.


More


For more information, see Encyclopedia: Backdoor.

Last update 17 May 2010

 

TOP