NetBus

NetBus
NetBus
NetBus153.png
Screenshot of NetBus 1.5.3 client
This file is a candidate for speedy deletion. It may be deleted after Monday, 28 November 2011.
Developer(s) Carl-Fredrik Neikter
Stable release 2.01 Pro
Operating system Microsoft Windows
Type remote administration
License shareware

NetBus or Netbus is a software program for remotely controlling a Microsoft Windows computer system over a network. It was created in 1998 and has been very controversial for its potential of being used as a backdoor.

NetBus was written in Delphi by Carl-Fredrik Neikter, a Swedish programmer in March 1998. It was in wide circulation before Back Orifice was released, in August 1998. The author claimed that the program was meant to be used for pranks, not for illegally breaking into computer systems. Translated from Swedish, the name means "NetPrank".

However, use of NetBus has had serious consequences. In 1999, NetBus was used to plant child pornography on the work computer of a law scholar at Lund University. The 3,500 images were discovered by system administrators, and the law scholar was assumed to have downloaded them knowingly. He lost his research position at the faculty, and following the publication of his name fled the country and had to seek professional medical care to cope with the stress. He was acquitted from criminal charges in late 2004, as a court found that NetBus had been used to control his computer.[1]

There are two components to the client–server architecture. The server must be installed and run on the computer that should be remotely controlled. It was an .exe file with a file size of almost 500 KB. The name and icon varied a lot from version to version. Common names were "Patch.exe" and "SysEdit.exe". When started for the first time, the server would install itself on the host computer, including modifying the Windows registry so that it starts automatically on each system startup. The server is a faceless process listening for connections on port 12345 (in some versions, the port number can be adjusted). Port 12346 is used for some tasks, as well as port 20034.

The client was a separate program presenting a graphical user interface that allowed the user to perform a number of activities on the remote computer. Examples of its capabilities:

  • Keystroke logging
  • Keystroke injection
  • Screen captures
  • Program launching
  • File browsing
  • Shutting down the system
  • Opening / closing CD-tray
  • Tunneling protocol (NetBus connections through a number of systems.)

The NetBus client was designed to support the following operating system versions:

Netbus client (v1.70) works fine in Windows 2000 and in Windows XP as well. Major parts of the protocol, used between the client and server interaction (in version 1.70) are textual. Thus the server can be controlled by typing human understandable commands over a raw TCP connection. It is more difficult than using the client application yet allows one to administrate computers with NetBus from operating environments other than Windows, or when original client is not available. Features (such as screen capture) require an application with ability of accepting binary data, such as netcat. Most of more common protocols (like the Internet Relay Chat protocol, POP3 SMTP, HTTP) can also be used over a raw connections in a similar way.

NetBus 2.0 Pro was released in February 1999. It was marketed commercially as a powerful remote administration tool. It was less stealthy, but special hacked versions exist that make it possible to use it for illegal purposes.

All versions of the program were widely used by "script kiddies" and was popularized by the release of Back Orifice. Because of its smaller size, Back Orifice can be used to gain some access to a machine. The attacker can then use Back Orifice to install the NetBus server on the target computer. Most anti-virus programs detect and remove NetBus.

Also existing is a tool called NetBuster. It pretends to be a running NetBus server, but causes connecting NetBus clients to crash. Additionally, a program called NetBusterBuster could be used to crash a remote NetBuster.

External links

References

  1. ^ "Offer för porrkupp" (in Swedish). Expressen. November 28, 2004. http://www.expressen.se/1.153215. 

Wikimedia Foundation. 2010.

Игры ⚽ Поможем решить контрольную работу

Look at other dictionaries:

  • Netbus — Entwickler: Carl Fredrik Neikter Aktuelle Version: 2.10 Pro Betriebssystem: Microsoft Windows Kategorie: Fernwartung Lizenz …   Deutsch Wikipedia

  • NetBus — Entwickler Carl Fredrik Neikter Aktuelle Version 2.10 Pro Betriebssystem Microsoft Windows Kategorie Fernwartung Lizenz S …   Deutsch Wikipedia

  • NetBus — или Netbus  программа дистанционного управления компьютерной системой Microsoft Windows по сети. Она была создана в марте 1998 года на Delphi Карлом Фредриком Неиктером. Автор утверждал, что его программа создавалась, как «шутка», а не как… …   Википедия

  • NetBus — Este artículo o sección necesita referencias que aparezcan en una publicación acreditada, como revistas especializadas, monografías, prensa diaria o páginas de Internet fidedignas. Puedes añadirlas así o avisar …   Wikipedia Español

  • SpectorSoft — Infobox Company company name = SpectorSoft, Inc. company company type = Private Company (Google Finance: [http://finance.google.com/finance?cid=16068060 Profile Page] ) company slogan = Automatically Record Everything They Do Online. foundation …   Wikipedia

  • Script kiddie — In hacker culture, a script kiddie (as opposed to speed kiddie Fact|date=August 2008), occasionally script bunny , skiddie , script kitty , script running juvenile (SRJ) , or similar) is a derogatory term used for an inexperienced malicious… …   Wikipedia

  • Sub7 — Infobox Software name = Sub7 caption = developer = mobman operating system = Microsoft Windows latest release version = 2.2.0 Beta latest release date = programming language = Delphi genre = remote administration license = freeware website =… …   Wikipedia

  • Números de puerto — Anexo:Números de puerto Saltar a navegación, búsqueda Números de puerto bien conocidos usados por TCP y UDP. También se añade algún otro puerto no asignado oficialmente por IANA, pero de interés general dado el uso extendido que le da alguna… …   Wikipedia Español

  • Anexo:Números de puerto — Números de puerto bien conocidos usados por TCP y UDP. También se añade algún otro puerto no asignado oficialmente por IANA, pero de interés general dado el uso extendido que le da alguna aplicación. Puerto/protocolo Descripción n/d / GRE GRE… …   Wikipedia Español

  • Sub7 — SubSeven Entwickler: Mobman Aktuelle Version: 2.1.5 Legend Betriebssystem: Microsoft Windows Kategorie: Fernwartung Lizenz …   Deutsch Wikipedia

Share the article and excerpts

Direct link
Do a right-click on the link above
and select “Copy Link”