Port 31337Back Orifice RAT
Back Orifice is a notorious remote administration tool released in the late 1990s, primarily known for its exploitation as a Trojan horse. It allows remote control of a Windows system, often without the user’s knowledge or consent, enabling malicious actors to access files, monitor user activity, and manipulate system configurations. Due to its ease of deployment and stealthy capabilities, it has historically been a popular choice for attackers targeting vulnerable systems..
- transport
- tcp
- in transit
- cleartext
- assignment
- unofficial
- risk
- 4/10
- lookups
- 21,322
single transport
payload readable on path
used by convention
caution
rank 110 of 993 · top 11%
Technical Details
what runs on :31337Back Orifice (often abbreviated as BO) is a software tool originally developed by the hacker collective Cult of the Dead Cow. Designed ostensibly as a legitimate remote administration tool for Windows systems, it quickly gained infamy as a Remote Access Trojan (RAT) due to its ability to install itself surreptitiously on a victim’s machine. Once active, it allows the remote controller to execute commands, browse the file system, manipulate processes, and perform keylogging, among other functions.
Operating primarily over TCP port 31337, Back Orifice establishes a backdoor which listens for connections initiated by the attacker’s client interface. Communication occurs via a custom binary protocol which supports various administrative commands. The tool’s server component is typically installed covertly on the victim’s system, exploiting social engineering techniques or other malware to gain an initial foothold.
Since its release, Back Orifice has served as a prototype for many subsequent RATs, highlighting fundamental remote exploitation techniques that are still employed today. Although the tool itself is now largely obsolete, its design and operational concepts continue to resonate in modern malware families targeting remote administration vulnerabilities.
Security Information
exposure of :31337risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
security averages 3.8 across 216 ports — this one sits 0.2 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
unofficial
used by convention, not registered — what answers here varies by deployment
reachable over
tcp
every listening transport is another surface to filter at the edge
security overview
Common Vulnerabilities:
- Unauthorized remote access enabling data theft, file manipulation, and keylogging
- Cloaked installation via social engineering or email phishing exploiting user trust
- Persistence mechanisms that allow the RAT to survive reboots and system updates
- Use of unencrypted communication channels that can enable interception or manipulation by third parties
Mitigations:
- Maintain up-to-date antivirus and endpoint protection capable of detecting RAT signatures
- Employ network firewalls and IDS/IPS solutions to block inbound connections on uncommon ports like 31337
- Conduct user education focusing on the risks of executing unknown files and email attachments
- Regularly audit system processes and network traffic for unusual or unauthorized activity
- Implement application whitelisting and least privilege user policies to restrict unauthorized software installation
Related Ports
the 8 most looked-up other ports in security — 216 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :8881 | Atlasz Secure Server | TCP | Web Services | caution | 67.6k |
| :443 | HTTPS | TCPtls | Web Services | caution | 65.9k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Squid Proxy HTTP | TCP | Web Services | caution | 45.8k |
| :8080 | HTTP Alternate | TCPtls | Web Services | caution | 44.9k |
| :7000 | Vuze HTTPS Tracker | TCPtls | Security | caution | 28.9k |
risk mix of the 8 listed
- caution100%
3 of 8 encrypted