

  STCPIO Stealthy TCP IO Plugin for Back Orifice 2000
  
  Copyright (C) 1999, Daniel Roethlisberger
  
  Version 2.0, August 29th, 1999



------[ Description ]---------------------------------------------------

  This is a plugin for the remote administration suite Back Orifice
  2000 (BO2K) from the one and only, the Cult of the Dead Cow (cDc).
  Released at DEFCON 7, BO2K was subject to massive hype even weeks
  before the actual release of it.
  
  When using the standard IO modules (TCPIO and UDPIO) that come with
  BO2K, the network traffic can be easily identified as BO2K data.
  There is security software around that can identify BO2K packets by
  traffic analysis.
  
  Stealthy TCPIO (STCPIO) on the other hand generates traffic that is
  unidentifyable as BO2K traffic. This is extremely helpful if you run
  BO2K on a network with high end security software. With STCPIO, the
  software wont create bunchs of false alerts when you administer a
  server using BO2K.
  
  There is absolutely no way to identify a STCPIO packet as BO2K
  traffic for sure, if, and only if, the underlying enc module is
  secure. So far, ISS have not come up with any idea to overcome
  STCPIO.
  
  Please note: The strength of STCPIO greatly depends on the strength
  of the encryption plugin used. If there is any pattern in the output
  of the encryption module, there will be a way to detect it. Thus XOR
  is a bad choice here, as it is very weak.



------[ What's New? ]---------------------------------------------------

  v2.0, August 29th 1999  Redesigned the whole thing. Now actually
                          encrypting the length field using an enc
                          engine. Filesize reduced to two thirds. Bug
                          causing crash of the BO PEEP VidStream
                          removed. Not experimental anymore.
                          Renamed dll to io_stcpio for consistency.
  
  v1.3, August 28th 1999  Fixed some randomizer problems and created a
                          context struct for each calling function.
  
  v1.2, August 23rd 1999  Strengthened security a lot at the cost of
                          speed and 500 byte filesize.
  
  v1.1, August 22nd 1999  Changed the key generation procedure for
                          improved security.
  
  v1.0, August 21st 1999  First release. Is a little too bulky yet for
                          my taste.



------[ Usage / Installation ]------------------------------------------

  Add the plugin to both the client and the server, be sure to
  configure matching packet header encryption engines and ports. You
  should now be able to select STCPIO from any IO module drop-down
  menu, and you can specify STCPIO in any IO module setting; where you
  specified TCPIO you can now use STCPIO. Please be sure to use STCPIO
  both in the client and the server, otherwise it wont work (surprise,
  surprise).
  
  I suggest using my Serpent or CAST-256 strong encryption plugins
  along with STCPIO for top security.
  
  If you can't figure out how to add plugins I suggest you go to your
  local software store and acquire a copy of PC Anywhere [tm], so you
  wont have to coap with the tremendous difficult task of adding a
  plugin :-P



------[ Tech Stuff ]----------------------------------------------------

  Any BO2K traffic can be identified as such if sent through the
  standard TCPIO and UDPIO modules. The reason: they send a packet
  header (length field) *unencrypted* along the way. So when analysing
  sniffed traffic in a network, you can take the first DWORD of a
  packet, assume it the length of the following data, and if there is
  in fact exactly that much data following, you know it's a BO2K
  packet. This technique is used by the ISS network security software,
  and possibly others as well.
  
  STCPIO simply encrypts the length field using the configured
  encryption engine.
  
  This procedure makes identifying BO2K packets as such impossible,
  effectively hiding it from all network analysers, sniffers and
  similar security software.
  
  For details on how BO2K traffic can be detected, see the ISS
  X-Force's Security Alert on BO2K, which can be found at their
  website: http://xforce.iss.net/alerts/advise31.php3 .



------[ Legal Crap ]----------------------------------------------------

  This software contains no strong encryption - it merely uses
  external encryption modules. Therefore this plugin constitutes no
  violation of the U.S. ITAR export regulations whatsoever.
  
  In Switzerland, export of cryptographic software is legal and not
  subject to export restrictions, as long as it is available for free
  to anyone, and no additional services from the manufacturer are
  required to use the product. Thus this software is exportable
  without restrictions.



------[ License ]-------------------------------------------------------

  This program is free software; you can redistribute it and/or modify
  it under the terms of the GNU General Public License as published by
  the Free Software Foundation; either version 2 of the License, or
  (at your option) any later version.
  
  This program is distributed in the hope that it will be useful, but
  WITHOUT ANY WARRANTY; without even the implied warranty of
  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  General Public License for more details.
  
  You should have received a copy of the GNU General Public License
  along with this program; if not, write to the Free Software
  Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-1307
  USA
  
  If you do redistribute or modify it, please let me know.



------[ Thanx To ]------------------------------------------------------

  DilDog
    for answering (most) of my mails and for making BO2K possible
  the rest at cDc
    for being the rest at cDc
  Maw~ and Ryan
    for the developers talk
  Chris, Brian, Sean, Christian and Irwan
    for the good bug reporting and helpful suggestions



------[ Contact ]-------------------------------------------------------

  Get the latest version of this plugin at the official distribution
  site http://www.roe.ch/download/bo_stcpio.shtml
  
  Feel free to contact me, but please remember: I can and will not
  offer any support for BO2K itself. I can only answer questions
  directly related to any of my plugins. Send email to Daniel
  Roethlisberger <admin@roe.ch> . Alternatively, you can contact me
  through the ICQ network, my UIN is 4646931 . Do not ask me to teach
  you how to hack hotmail or anything like that. Bullshit like that
  will be deleted immediately.
  
  I recommend to encrypt all email traffic with Pretty Good Privacy or
  S/MIME. Get my PGP-Key with ID 0x8DE543ED at
  ldap://certserver.pgp.com or from my website.
  
  Don't forget to visit the official BO2K site at http://www.bo2k.com



------[ Over and Out ]--------------------------------------------------

  <<better than any handle>>