Port 31337Back Orifice RAT

Back Orifice is a notorious remote administration tool released in the late 1990s, primarily known for its exploitation as a Trojan horse. It allows remote control of a Windows system, often without the user’s knowledge or consent, enabling malicious actors to access files, monitor user activity, and manipulate system configurations. Due to its ease of deployment and stealthy capabilities, it has historically been a popular choice for attackers targeting vulnerable systems..

transport
tcp

single transport

in transit
cleartext

payload readable on path

assignment
unofficial

used by convention

risk
4/10

caution

lookups
21,322

rank 110 of 993 · top 11%

Technical Details

what runs on :31337

Back Orifice (often abbreviated as BO) is a software tool originally developed by the hacker collective Cult of the Dead Cow. Designed ostensibly as a legitimate remote administration tool for Windows systems, it quickly gained infamy as a Remote Access Trojan (RAT) due to its ability to install itself surreptitiously on a victim’s machine. Once active, it allows the remote controller to execute commands, browse the file system, manipulate processes, and perform keylogging, among other functions.

Operating primarily over TCP port 31337, Back Orifice establishes a backdoor which listens for connections initiated by the attacker’s client interface. Communication occurs via a custom binary protocol which supports various administrative commands. The tool’s server component is typically installed covertly on the victim’s system, exploiting social engineering techniques or other malware to gain an initial foothold.

Since its release, Back Orifice has served as a prototype for many subsequent RATs, highlighting fundamental remote exploitation techniques that are still employed today. Although the tool itself is now largely obsolete, its design and operational concepts continue to resonate in modern malware families targeting remote administration vulnerabilities.

Security Information

exposure of :31337

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

security averages 3.8 across 216 ports — this one sits 0.2 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

unofficial

used by convention, not registered — what answers here varies by deployment

reachable over

tcp

every listening transport is another surface to filter at the edge

security overview

Common Vulnerabilities:

  • Unauthorized remote access enabling data theft, file manipulation, and keylogging
  • Cloaked installation via social engineering or email phishing exploiting user trust
  • Persistence mechanisms that allow the RAT to survive reboots and system updates
  • Use of unencrypted communication channels that can enable interception or manipulation by third parties

Mitigations:

  • Maintain up-to-date antivirus and endpoint protection capable of detecting RAT signatures
  • Employ network firewalls and IDS/IPS solutions to block inbound connections on uncommon ports like 31337
  • Conduct user education focusing on the risks of executing unknown files and email attachments
  • Regularly audit system processes and network traffic for unusual or unauthorized activity
  • Implement application whitelisting and least privilege user policies to restrict unauthorized software installation

the 8 most looked-up other ports in security — 216 ports carry that label.

risk mix of the 8 listed

  • caution100%

3 of 8 encrypted