<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>Backdoor (computing)</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/Backdoor_(computing)"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Backdoor_computing rootpage-Backdoor_computing skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">Backdoor (computing)</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<p>A <b>backdoor</b> is a typically covert method of bypassing normal <a href="Authentication" title="Authentication">authentication</a> or encryption in a computer, product, embedded device (e.g. a <a href="Home_router" class="mw-redirect" title="Home router">home router</a>), or its embodiment (e.g. part of a <a href="Cryptosystem" title="Cryptosystem">cryptosystem</a>, <a href="Algorithm" title="Algorithm">algorithm</a>, <a href="Chipset" title="Chipset">chipset</a>, or even a "homunculus computer"—a tiny computer-within-a-computer such as that found in Intel's <a href="Intel_Active_Management_Technology" title="Intel Active Management Technology">AMT technology</a>).<sup id="cite_ref-Eckersley-2017_1-0" class="reference"><a href="#cite_note-Eckersley-2017-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Hoffman-2017_2-0" class="reference"><a href="#cite_note-Hoffman-2017-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> Backdoors are most often used for securing remote access to a computer, or obtaining access to <a href="Plaintext" title="Plaintext">plaintext</a> in cryptosystems. From there it may be used to gain access to privileged information like passwords, corrupt or delete data on hard drives, or transfer information within autoschediastic networks.
</p><p>In the United States, the 1994 <a href="Communications_Assistance_for_Law_Enforcement_Act" title="Communications Assistance for Law Enforcement Act">Communications Assistance for Law Enforcement Act</a> forces internet providers to provide backdoors for government authorities.<sup id="cite_ref-3" class="reference"><a href="#cite_note-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-4" class="reference"><a href="#cite_note-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup> In 2024, the U.S. government realized that China had been tapping communications in the U.S. using that infrastructure for months, or perhaps longer;<sup id="cite_ref-5" class="reference"><a href="#cite_note-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup> China recorded presidential candidate campaign office phone calls —including employees of the then-vice president of the nation– and of the candidates themselves.<sup id="cite_ref-6" class="reference"><a href="#cite_note-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup>
</p><p>A backdoor may take the form of a hidden part of a program,<sup id="cite_ref-Wysopal-Eng_7-0" class="reference"><a href="#cite_note-Wysopal-Eng-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup> a separate program (e.g. <a href="Back_Orifice" title="Back Orifice">Back Orifice</a> may subvert the system through a <a href="Rootkit" title="Rootkit">rootkit</a>), <a href="Hardware_backdoor" title="Hardware backdoor">code in the firmware</a> of the hardware,<sup id="cite_ref-Zetter-2013_8-0" class="reference"><a href="#cite_note-Zetter-2013-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup> or parts of an <a href="Operating_system" title="Operating system">operating system</a> such as <a href="Microsoft_Windows" title="Microsoft Windows">Windows</a>.<sup id="cite_ref-Ashok-2017_9-0" class="reference"><a href="#cite_note-Ashok-2017-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Microsoft-Back-Doors_10-0" class="reference"><a href="#cite_note-Microsoft-Back-Doors-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Ars-Technica-2017_11-0" class="reference"><a href="#cite_note-Ars-Technica-2017-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup> <a href="Trojan_horse_(computing)" title="Trojan horse (computing)">Trojan horses</a> can be used to create vulnerabilities in a device. A Trojan horse may appear to be an entirely legitimate program, but when executed, it triggers an activity that may install a backdoor.<sup id="cite_ref-Backdoors-and-Trojan-Horses_12-0" class="reference"><a href="#cite_note-Backdoors-and-Trojan-Horses-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup> Although some are secretly installed, other backdoors are deliberate and widely known. These kinds of backdoors have "legitimate" uses such as providing the manufacturer with a way to restore user passwords.
</p><p>Many systems that store information within the cloud fail to create accurate security measures. If many systems are connected within the <a href="Cloud_computing" title="Cloud computing">cloud</a>, hackers can gain access to all other platforms through the most vulnerable system.<sup id="cite_ref-Linthicum_13-0" class="reference"><a href="#cite_note-Linthicum-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup> <a href="Default_password" title="Default password">Default passwords</a> (or other default credentials) can function as backdoors if they are not changed by the user. Some <a href="Debugging" title="Debugging">debugging</a> features can also act as backdoors if they are not removed in the release version.<sup id="cite_ref-Bogus-story_14-0" class="reference"><a href="#cite_note-Bogus-story-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup> In 1993, the United States government attempted to deploy an <a href="Encryption" title="Encryption">encryption</a> system, the <a href="Clipper_chip" title="Clipper chip">Clipper chip</a>, with an explicit backdoor for law enforcement and national security access. The chip was unsuccessful.<sup id="cite_ref-Clipper-a-failure_15-0" class="reference"><a href="#cite_note-Clipper-a-failure-15"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup>
</p><p>Recent proposals to counter backdoors include creating a database of backdoors' triggers and then using <a href="Neural_network_(machine_learning)" title="Neural network (machine learning)">neural networks</a> to detect them.<sup id="cite_ref-Menisov-2022_16-0" class="reference"><a href="#cite_note-Menisov-2022-16"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup>
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="Overview">Overview</h2></div>
<p>The threat of backdoors surfaced when multiuser and networked <a href="Operating_system" title="Operating system">operating systems</a> became widely adopted. Petersen and Turn discussed computer subversion in a paper published in the proceedings of the 1967 AFIPS Conference.<sup id="cite_ref-Petersen-1967_17-0" class="reference"><a href="#cite_note-Petersen-1967-17"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup> They noted a class of active infiltration attacks that use "trapdoor" entry points into the system to bypass security facilities and permit direct access to data. The use of the word <i>trapdoor</i> here clearly coincides with more recent definitions of a backdoor. However, since the advent of <a href="Public_key_cryptography" class="mw-redirect" title="Public key cryptography">public key cryptography</a> the term <i>trapdoor</i> has acquired a different meaning <style data-mw-deduplicate="TemplateStyles:r1033199720">
/* start https://en.wikipedia.org/ */
.mw-parser-output div.crossreference{padding-left:0}
/* end https://en.wikipedia.org/ */
</style><style data-mw-deduplicate="TemplateStyles:r1236090951">
/* start https://en.wikipedia.org/ */
.mw-parser-output .hatnote{font-style:italic}.mw-parser-output div.hatnote{padding-left:1.6em;margin-bottom:0.5em}.mw-parser-output .hatnote i{font-style:normal}.mw-parser-output .hatnote+link+.hatnote{margin-top:-0.5em}@media print{body.ns-0 .mw-parser-output .hatnote{display:none!important}}
/* end https://en.wikipedia.org/ */
</style><span role="note" class="hatnote navigation-not-searchable crossreference">(see: <a href="Trapdoor_function" title="Trapdoor function">Trapdoor function</a>)</span>, and thus the term "backdoor" is now preferred, only after the term trapdoor went out of use. More generally, such security breaches were discussed at length in a <a href="RAND_Corporation" title="RAND Corporation">RAND Corporation</a> task force report published under <a href="DARPA" title="DARPA">DARPA</a> sponsorship by J.P. Anderson and D.J. Edwards in 1970.<sup id="cite_ref-Security-Controls_18-0" class="reference"><a href="#cite_note-Security-Controls-18"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup>
</p><p>While initially targeting the computer vision domain, backdoor attacks have expanded to encompass various other domains, including text, audio, ML-based computer-aided design, and ML-based wireless signal classification. Additionally, vulnerabilities in backdoors have been demonstrated in deep <a href="Generative_model" title="Generative model">generative models</a>, <a href="Reinforcement_learning" title="Reinforcement learning">reinforcement learning</a> (e.g., AI GO), and deep graph models. These broad-ranging potential risks have prompted concerns from national security agencies regarding their potentially disastrous consequences.<sup id="cite_ref-19" class="reference"><a href="#cite_note-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup>
</p><p>A backdoor in a login system might take the form of a <a href="Hard_code" class="mw-redirect" title="Hard code">hard coded</a> user and password combination which gives access to the system. An example of this sort of backdoor was used as a plot device in the <a href="1983_in_film" title="1983 in film">1983</a> film <i><a href="WarGames" title="WarGames">WarGames</a></i>, in which the architect of the "<a href="WOPR" class="mw-redirect" title="WOPR">WOPR</a>" computer system had inserted a hardcoded password-less account which gave the user access to the system, and to undocumented parts of the system (in particular, a video game-like simulation mode and direct interaction with the <a href="Artificial_intelligence" title="Artificial intelligence">artificial intelligence</a>).
</p><p>Although the number of backdoors in systems using <a href="Proprietary_software" title="Proprietary software">proprietary software</a> (software whose <a href="Source_code" title="Source code">source code</a> is not publicly available) is not widely credited, they are nevertheless frequently exposed. Programmers have even succeeded in secretly installing large amounts of benign code as <a href="Easter_egg_(virtual)" class="mw-redirect" title="Easter egg (virtual)">Easter eggs</a> in programs, although such cases may involve official forbearance, if not actual permission.
</p>
<div class="mw-heading mw-heading2"><h2 id="Politics_and_attribution">Politics and attribution</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1251242444">
/* start https://en.wikipedia.org/ */
.mw-parser-output .ambox{border:1px solid #a2a9b1;border-left:10px solid #36c;background-color:#fbfbfb;box-sizing:border-box}.mw-parser-output .ambox+link+.ambox,.mw-parser-output .ambox+link+style+.ambox,.mw-parser-output .ambox+link+link+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+style+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+link+.ambox{margin-top:-1px}html body.mediawiki .mw-parser-output .ambox.mbox-small-left{margin:4px 1em 4px 0;overflow:hidden;width:238px;border-collapse:collapse;font-size:88%;line-height:1.25em}.mw-parser-output .ambox-speedy{border-left:10px solid #b32424;background-color:#fee7e6}.mw-parser-output .ambox-delete{border-left:10px solid #b32424}.mw-parser-output .ambox-content{border-left:10px solid #f28500}.mw-parser-output .ambox-style{border-left:10px solid #fc3}.mw-parser-output .ambox-move{border-left:10px solid #9932cc}.mw-parser-output .ambox-protection{border-left:10px solid #a2a9b1}.mw-parser-output .ambox .mbox-text{border:none;padding:0.25em 0.5em;width:100%}.mw-parser-output .ambox .mbox-image{border:none;padding:2px 0 2px 0.5em;text-align:center}.mw-parser-output .ambox .mbox-imageright{border:none;padding:2px 0.5em 2px 0;text-align:center}.mw-parser-output .ambox .mbox-empty-cell{border:none;padding:0;width:1px}.mw-parser-output .ambox .mbox-image-div{width:52px}@media(min-width:720px){.mw-parser-output .ambox{margin:0 10%}}@media print{body.ns-0 .mw-parser-output .ambox{display:none!important}}
/* end https://en.wikipedia.org/ */
</style>
<p>There are a number of <a href="Cloak_and_dagger" title="Cloak and dagger">cloak and dagger</a> considerations that come into play when apportioning responsibility.
</p><p>Covert backdoors sometimes masquerade as inadvertent defects (bugs) for reasons of <a href="Plausible_deniability" title="Plausible deniability">plausible deniability</a>. In some cases, these might begin life as an actual bug (inadvertent error), which, once discovered are then deliberately left unfixed and undisclosed, whether by a rogue employee for personal advantage, or with executive awareness and oversight.
</p><p>It is also possible for an entirely above-board corporation's technology base to be covertly and untraceably tainted by external agents (hackers), though this level of sophistication is thought to exist mainly at the level of nation state actors. For example, if a <a href="Photomask" title="Photomask">photomask</a> obtained from a photomask supplier differs in a few gates from its photomask specification, a chip manufacturer would be hard-pressed to detect this if otherwise functionally silent; a covert rootkit running in the photomask etching equipment could enact this discrepancy unbeknown to the photomask manufacturer, either, and by such means, one backdoor potentially leads to another.<sup id="cite_ref-20" class="reference"><a href="#cite_note-20"><span class="cite-bracket">[</span>note 1<span class="cite-bracket">]</span></a></sup>
</p><p>In general terms, the long dependency-chains in the modern, <a href="Division_of_labour" title="Division of labour">highly specialized</a> technological economy and innumerable human-elements process <a href="Control_(management)" title="Control (management)">control-points</a> make it difficult to conclusively pinpoint responsibility at such time as a covert backdoor becomes unveiled.
</p><p>Even direct admissions of responsibility must be scrutinized carefully if the confessing party is beholden to other powerful interests.
</p>
<div class="mw-heading mw-heading2"><h2 id="Examples">Examples</h2></div>
<div class="mw-heading mw-heading3"><h3 id="Worms">Worms</h3></div>
<p>Many <a href="Computer_worm" title="Computer worm">computer worms</a>, such as <a href="Sobig" title="Sobig">Sobig</a> and <a href="Mydoom" title="Mydoom">Mydoom</a>, install a backdoor on the affected computer (generally a <a href="IBM_PC_compatible" title="IBM PC compatible">PC</a> on <a href="Broadband" title="Broadband">broadband</a> running <a href="Microsoft_Windows" title="Microsoft Windows">Microsoft Windows</a> and <a href="Microsoft_Outlook" title="Microsoft Outlook">Microsoft Outlook</a>). Such backdoors appear to be installed so that <a href="E-mail_spam" class="mw-redirect" title="E-mail spam">spammers</a> can send junk <a href="Electronic_mail" class="mw-redirect" title="Electronic mail">e-mail</a> from the infected machines. Others, such as the <a href="Sony_BMG_CD_copy_prevention_scandal" class="mw-redirect" title="Sony BMG CD copy prevention scandal">Sony/BMG rootkit</a>, placed secretly on millions of music CDs through late 2005, are intended as <a href="Digital_rights_management" title="Digital rights management">DRM</a> measures—and, in that case, as data-gathering <a href="Software_agent" title="Software agent">agents</a>, since both surreptitious programs they installed routinely contacted central servers.
</p><p>A sophisticated attempt to plant a backdoor in the <a href="Linux_kernel" title="Linux kernel">Linux kernel</a>, exposed in November 2003, added a small and subtle code change by subverting the <a href="Revision_control_system" class="mw-redirect" title="Revision control system">revision control system</a>.<sup id="cite_ref-McVoy_21-0" class="reference"><a href="#cite_note-McVoy-21"><span class="cite-bracket">[</span>20<span class="cite-bracket">]</span></a></sup> In this case, a two-line change appeared to <i>check</i> <a href="Superuser" title="Superuser">root access</a> permissions of a caller to the <kbd>sys_wait4</kbd> function, but because it used assignment <code>=</code> instead of equality checking <code>==</code>, it actually <i>granted</i> permissions to the system. This difference is easily overlooked, and could even be interpreted as an accidental typographical error, rather than an intentional attack.<sup id="cite_ref-An-attempt-to-backdoor_22-0" class="reference"><a href="#cite_note-An-attempt-to-backdoor-22"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Poulsen-2003_23-0" class="reference"><a href="#cite_note-Poulsen-2003-23"><span class="cite-bracket">[</span>22<span class="cite-bracket">]</span></a></sup>
</p>
<p>In January 2014, a backdoor was discovered in certain <a href="Samsung" title="Samsung">Samsung</a> <a href="Android_(operating_system)" title="Android (operating system)">Android</a> products, like the Galaxy devices. The Samsung proprietary Android versions are fitted with a backdoor that provides remote access to the data stored on the device. In particular, the Samsung Android software that is in charge of handling the communications with the modem, using the Samsung IPC protocol, implements a class of requests known as remote file server (RFS) commands, that allows the backdoor operator to perform via modem remote I/O operations on the device hard disk or other storage. As the modem is running Samsung proprietary Android software, it is likely that it offers over-the-air remote control that could then be used to issue the RFS commands and thus to access the file system on the device.<sup id="cite_ref-SamsungGalaxyBackdoor_24-0" class="reference"><a href="#cite_note-SamsungGalaxyBackdoor-24"><span class="cite-bracket">[</span>23<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Object_code_backdoors">Object code backdoors</h3></div>
<p>Harder to detect backdoors involve modifying <a href="Object_code" title="Object code">object code</a>, rather than source code—object code is much harder to inspect, as it is designed to be machine-readable, not human-readable. These backdoors can be inserted either directly in the on-disk object code, or inserted at some point during compilation, assembly linking, or loading—in the latter case the backdoor never appears on disk, only in memory. Object code backdoors are difficult to detect by inspection of the object code, but are easily detected by simply checking for changes (differences), notably in length or in checksum, and in some cases can be detected or analyzed by disassembling the object code. Further, object code backdoors can be removed (assuming source code is available) by simply recompiling from source on a trusted system.
</p><p>Thus for such backdoors to avoid detection, all extant copies of a binary must be subverted, and any validation checksums must also be compromised, and source must be unavailable, to prevent recompilation. Alternatively, these other tools (length checks, diff, checksumming, disassemblers) can themselves be compromised to conceal the backdoor, for example detecting that the subverted binary is being checksummed and returning the expected value, not the actual value. To conceal these further subversions, the tools must also conceal the changes in themselves—for example, a subverted checksummer must also detect if it is checksumming itself (or other subverted tools) and return false values. This leads to extensive changes in the system and tools being needed to conceal a single change.
</p><p>As object code can be regenerated by recompiling (reassembling, relinking) the original source code, making a persistent object code backdoor (without modifying source code) requires subverting the <a href="Compiler" title="Compiler">compiler</a> itself—so that when it detects that it is compiling the program under attack it inserts the backdoor—or alternatively the assembler, linker, or loader. As this requires subverting the compiler, this in turn can be fixed by recompiling the compiler, removing the backdoor insertion code. This defense can in turn be subverted by putting a source meta-backdoor in the compiler, so that when it detects that it is compiling itself it then inserts this meta-backdoor generator, together with the original backdoor generator for the original program under attack. After this is done, the source meta-backdoor can be removed, and the compiler recompiled from original source with the compromised compiler executable: the backdoor has been bootstrapped. This attack dates to a 1974 paper by Karger and Schell,<sup id="cite_ref-Karger-Schell-1974_25-0" class="reference"><a href="#cite_note-Karger-Schell-1974-25"><span class="cite-bracket">[</span>24<span class="cite-bracket">]</span></a></sup> and was popularized in Thompson's 1984 article, entitled "Reflections on Trusting Trust";<sup id="cite_ref-Thompson-1984_26-0" class="reference"><a href="#cite_note-Thompson-1984-26"><span class="cite-bracket">[</span>25<span class="cite-bracket">]</span></a></sup> it is hence colloquially known as the "Trusting Trust" attack <span role="note" class="hatnote navigation-not-searchable crossreference">(see: <a href="#Compiler_backdoors">§ Compiler backdoors</a>, below, for details)</span>. Analogous attacks can target lower levels of the system,
such as the operating system, and can be inserted during the system <a href="Booting" title="Booting">booting</a> process; these are also mentioned by Karger and Schell in 1974, and now exist in the form of <a href="Boot_sector_virus" class="mw-redirect" title="Boot sector virus">boot sector viruses</a>.<sup id="cite_ref-Karger-Schell-1974_25-1" class="reference"><a href="#cite_note-Karger-Schell-1974-25"><span class="cite-bracket">[</span>24<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Karger-Schell-2002_27-0" class="reference"><a href="#cite_note-Karger-Schell-2002-27"><span class="cite-bracket">[</span>26<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Asymmetric_backdoors">Asymmetric backdoors</h3></div>
<p>A traditional backdoor is a symmetric backdoor: anyone that finds the backdoor can in turn use it. The notion of an asymmetric backdoor was introduced by Adam Young and <a href="Moti_Yung" title="Moti Yung">Moti Yung</a> in the <i>Proceedings of Advances in Cryptology – Crypto '96</i>. An asymmetric backdoor can only be used by the attacker who plants it, even if the full implementation of the backdoor becomes public (e.g. via publishing, being discovered and disclosed by <a href="Reverse_engineering" title="Reverse engineering">reverse engineering</a>, etc.). Also, it is computationally intractable to detect the presence of an asymmetric backdoor under black-box queries. This class of attacks have been termed <a href="Kleptography" title="Kleptography">kleptography</a>; they can be carried out in software, hardware (for example, <a href="Smartcard" class="mw-redirect" title="Smartcard">smartcards</a>), or a combination of the two. The theory of asymmetric backdoors is part of a larger field now called <a href="Cryptovirology" title="Cryptovirology">cryptovirology</a>. Notably, <a href="NSA" class="mw-redirect" title="NSA">NSA</a> inserted a kleptographic backdoor into the <a href="Dual_EC_DRBG" title="Dual EC DRBG">Dual EC DRBG</a> standard.<sup id="cite_ref-Zetter-2013_8-1" class="reference"><a href="#cite_note-Zetter-2013-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Akkad-2014_28-0" class="reference"><a href="#cite_note-Akkad-2014-28"><span class="cite-bracket">[</span>27<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Perlroth-2013_29-0" class="reference"><a href="#cite_note-Perlroth-2013-29"><span class="cite-bracket">[</span>28<span class="cite-bracket">]</span></a></sup>
</p><p>There exists an experimental asymmetric backdoor in <a href="RSA_(cryptosystem)" class="mw-redirect" title="RSA (cryptosystem)">RSA</a> <a href="Key_(cryptography)" title="Key (cryptography)">key</a> generation. This OpenSSL RSA backdoor, designed by Young and Yung, utilizes a twisted pair of elliptic curves, and has been made available.<sup id="cite_ref-Malicious-Cryptography_30-0" class="reference"><a href="#cite_note-Malicious-Cryptography-30"><span class="cite-bracket">[</span>29<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Compiler_backdoors">Compiler backdoors</h2></div>
<p>A sophisticated form of <a href="Black_box" title="Black box">black box</a> backdoor is a <b>compiler backdoor</b>, where not only is a compiler subverted—to insert a backdoor in some other program, such as a login program—but it is further modified to detect when it is compiling itself and then inserts both the backdoor insertion code (targeting the other program) and the code-modifying self-compilation, like the mechanism through which <a href="Retrovirus" title="Retrovirus">retroviruses</a> infect their host. This can be done by modifying the source code, and the resulting compromised compiler (object code) can compile the original (unmodified) source code and insert itself: the exploit has been boot-strapped.
</p><p>This attack was originally presented in Karger & Schell (1974),<sup id="cite_ref-31" class="reference"><a href="#cite_note-31"><span class="cite-bracket">[</span>note 2<span class="cite-bracket">]</span></a></sup> which was a <a href="United_States_Air_Force" title="United States Air Force">United States Air Force</a> security analysis of <a href="Multics" title="Multics">Multics</a>, where they described such an attack on a <a href="PL/I" title="PL/I">PL/I</a> compiler, and call it a "compiler trap door". They also mention a variant where the system initialization code is modified to insert a backdoor during <a href="Booting" title="Booting">booting</a>, as this is complex and poorly understood, and call it an "initialization trapdoor"; this is now known as a <a href="Boot_sector_virus" class="mw-redirect" title="Boot sector virus">boot sector virus</a>.<sup id="cite_ref-Karger-Schell-2002_27-1" class="reference"><a href="#cite_note-Karger-Schell-2002-27"><span class="cite-bracket">[</span>26<span class="cite-bracket">]</span></a></sup>
</p><p>This attack was then actually implemented by <a href="Ken_Thompson" title="Ken Thompson">Ken Thompson</a>, and popularized in his <a href="Turing_Award" title="Turing Award">Turing Award</a> acceptance speech in 1983, "Reflections on Trusting Trust",<sup id="cite_ref-Thompson-1984_26-1" class="reference"><a href="#cite_note-Thompson-1984-26"><span class="cite-bracket">[</span>25<span class="cite-bracket">]</span></a></sup> which points out that trust is relative, and the only software one can truly trust is code where every step of the bootstrapping has been inspected. This backdoor mechanism is based on the fact that people only review source (human-written) code, and not compiled <a href="Machine_code" title="Machine code">machine code</a> (<a href="Object_code" title="Object code">object code</a>). A <a href="Software" title="Software">program</a> called a <a href="Compiler" title="Compiler">compiler</a> is used to create the second from the first, and the compiler is usually trusted to do an honest job.
</p><p>Thompson's paper<sup id="cite_ref-Thompson-1984_26-2" class="reference"><a href="#cite_note-Thompson-1984-26"><span class="cite-bracket">[</span>25<span class="cite-bracket">]</span></a></sup> describes a modified version of the <a href="Unix" title="Unix">Unix</a> <a href="C_(programming_language)" title="C (programming language)">C</a> compiler that would put an invisible backdoor in the Unix <a href="Logging_(computer_security)" class="mw-redirect" title="Logging (computer security)">login</a> command when it noticed that the login program was being compiled, and would also add this feature undetectably to future compiler versions upon their compilation as well. As the compiler itself was a compiled program, users would be extremely unlikely to notice the machine code instructions that performed these tasks. (Because of the second task, the compiler's source code would appear "clean".) What's worse, in Thompson's <a href="Proof_of_concept" title="Proof of concept">proof of concept</a> implementation, the subverted compiler also subverted the analysis program (the <a href="Disassembler" title="Disassembler">disassembler</a>), so that anyone who examined the binaries in the usual way would not actually see the real code that was running, but something else instead.
</p><p>Karger and Schell gave an updated analysis of the original exploit in 2002, and, in 2009, Wheeler wrote a historical overview and survey of the literature.<sup id="cite_ref-33" class="reference"><a href="#cite_note-33"><span class="cite-bracket">[</span>note 3<span class="cite-bracket">]</span></a></sup> In 2023, Cox published an annotated version of Thompson's backdoor source code.<sup id="cite_ref-34" class="reference"><a href="#cite_note-34"><span class="cite-bracket">[</span>31<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Occurrences">Occurrences</h3></div>
<p>Thompson's version was, officially, never released into the wild. However, it is believed that a version was distributed to <a href="BBN_Technologies" class="mw-redirect" title="BBN Technologies">BBN</a> and at least one use of the backdoor was recorded.<sup id="cite_ref-36" class="reference"><a href="#cite_note-36"><span class="cite-bracket">[</span>note 4<span class="cite-bracket">]</span></a></sup> There are scattered anecdotal reports of such backdoors in subsequent years.
</p><p>In August 2009, an attack of this kind was discovered by Sophos labs. The W32/Induc-A virus infected the program compiler for <a href="Delphi_(programming_language)" class="mw-redirect" title="Delphi (programming language)">Delphi</a>, a Windows programming language. The virus introduced its own code to the compilation of new Delphi programs, allowing it to infect and propagate to many systems, without the knowledge of the software programmer. The virus looks for a Delphi installation, modifies the SysConst.pas file, which is the source code of a part of the standard library and compiles it. After that, every program compiled by that Delphi installation will contain the virus. An attack that propagates by building its own <a href="Trojan_horse_(computing)" title="Trojan horse (computing)">Trojan horse</a> can be especially hard to discover. It resulted in many software vendors releasing infected executables without realizing it, sometimes claiming false positives. After all, the executable was not tampered with, the compiler was. It is believed that the Induc-A virus had been propagating for at least a year before it was discovered.<sup id="cite_ref-38" class="reference"><a href="#cite_note-38"><span class="cite-bracket">[</span>note 5<span class="cite-bracket">]</span></a></sup>
</p><p>In 2015, a malicious copy of Xcode, <a href="XcodeGhost" title="XcodeGhost">XcodeGhost</a>, also performed a similar attack and infected iOS apps from a dozen of software companies in China. Globally, 4,000 apps were found to be affected. It was not a true Thompson Trojan, as it does not infect development tools themselves, but it did prove that toolchain poisoning can cause substantial damages.<sup id="cite_ref-XcodeGhost_39-0" class="reference"><a href="#cite_note-XcodeGhost-39"><span class="cite-bracket">[</span>34<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Countermeasures">Countermeasures</h3></div>
<p>Once a system has been compromised with a backdoor or Trojan horse, such as the <i>Trusting Trust</i> compiler, it is very hard for the "rightful" user to regain control of the system – typically one should rebuild a clean system and transfer data (but not executables) over. However, several practical weaknesses in the <i>Trusting Trust</i> scheme have been suggested. For example, a sufficiently motivated user could painstakingly review the machine code of the untrusted compiler before using it. As mentioned above, there are ways to hide the Trojan horse, such as subverting the disassembler; but there are ways to counter that defense, too, such as writing a disassembler from scratch.
</p><p>A generic method to counter trusting trust attacks is called <b>diverse double-compiling</b>. The method requires a different compiler and the source code of the compiler-under-test. That source, compiled with both compilers, results in two different stage-1 compilers, which however should have the same behavior. Thus the same source compiled with both stage-1 compilers must then result in two identical stage-2 compilers. A formal proof is given that the latter comparison guarantees that the purported source code and executable of the compiler-under-test correspond, under some assumptions. This method was applied by its author to verify that the C compiler of the <a href="GNU_Compiler_Collection" title="GNU Compiler Collection">GCC suite</a> (v. 3.0.4) contained no trojan, using <a href="Intel_C%2B%2B_Compiler" title="Intel C++ Compiler">icc</a> (v. 11.0) as the different compiler.<sup id="cite_ref-Wheeler-2009_32-1" class="reference"><a href="#cite_note-Wheeler-2009-32"><span class="cite-bracket">[</span>30<span class="cite-bracket">]</span></a></sup>
</p><p>In practice such verifications are not done by end users, except in extreme circumstances of intrusion detection and analysis, due to the rarity of such sophisticated attacks, and because programs are typically distributed in binary form. Removing backdoors (including compiler backdoors) is typically done by simply rebuilding a clean system. However, the sophisticated verifications are of interest to operating system vendors, to ensure that they are not distributing a compromised system, and in high-security settings, where such attacks are a realistic concern.
</p>
<div class="mw-heading mw-heading2"><h2 id="List_of_known_backdoors">List of known backdoors</h2></div>
<ul><li><a href="Back_Orifice" title="Back Orifice">Back Orifice</a> was created in 1998 by <a href="Hacker_(computer_security)" class="mw-redirect" title="Hacker (computer security)">hackers</a> from <a href="Cult_of_the_Dead_Cow" title="Cult of the Dead Cow">Cult of the Dead Cow</a> group as a remote administration tool. It allowed <a href="Windows" class="mw-redirect" title="Windows">Windows</a> computers to be remotely controlled over a network and parodied the name of Microsoft's <a href="BackOffice" class="mw-redirect" title="BackOffice">BackOffice</a>.</li>
<li>The <a href="Dual_EC_DRBG" title="Dual EC DRBG">Dual EC DRBG</a> <a href="Cryptographically_secure_pseudorandom_number_generator" title="Cryptographically secure pseudorandom number generator">cryptographically secure pseudorandom number generator</a> was revealed in 2013 to possibly have a <a href="Kleptography" title="Kleptography">kleptographic</a> backdoor deliberately inserted by NSA, who also had the private key to the backdoor.<sup id="cite_ref-Zetter-2013_8-2" class="reference"><a href="#cite_note-Zetter-2013-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Perlroth-2013_29-1" class="reference"><a href="#cite_note-Perlroth-2013-29"><span class="cite-bracket">[</span>28<span class="cite-bracket">]</span></a></sup></li>
<li>Several backdoors in the <a href="Copyright_infringement" title="Copyright infringement">unlicensed</a> copies of <a href="WordPress" title="WordPress">WordPress</a> <a href="Plug-in_(computing)" title="Plug-in (computing)">plug-ins</a> were discovered in March 2014.<sup id="cite_ref-WordPress_40-0" class="reference"><a href="#cite_note-WordPress-40"><span class="cite-bracket">[</span>35<span class="cite-bracket">]</span></a></sup> They were inserted as <a href="Obfuscation_(software)" title="Obfuscation (software)">obfuscated</a> <a href="JavaScript" title="JavaScript">JavaScript</a> code and silently created, for example, an <a href="System_administrator" title="System administrator">admin</a> account in the website database. A similar scheme was later exposed in a <a href="Joomla" title="Joomla">Joomla</a> plugin.<sup id="cite_ref-Sinegubko-2014_41-0" class="reference"><a href="#cite_note-Sinegubko-2014-41"><span class="cite-bracket">[</span>36<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Borland" title="Borland">Borland</a> <a href="Interbase" class="mw-redirect" title="Interbase">Interbase</a> versions 4.0 through 6.0 had a hard-coded backdoor, put there by the developers. The server code contains a compiled-in backdoor account (username: <i>politically</i>, password: <i>correct</i>), which could be accessed over a network connection; a user logging in with this backdoor account could take full control over all Interbase databases. The backdoor was detected in 2001 and a <a href="Patch_(computing)" title="Patch (computing)">patch</a> was released.<sup id="cite_ref-Vulnerability_42-0" class="reference"><a href="#cite_note-Vulnerability-42"><span class="cite-bracket">[</span>37<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Interbase-Server_43-0" class="reference"><a href="#cite_note-Interbase-Server-43"><span class="cite-bracket">[</span>38<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Juniper_Networks" title="Juniper Networks">Juniper Networks</a> backdoor inserted in the year 2008 into the versions of firmware <a href="ScreenOS" title="ScreenOS">ScreenOS</a> from 6.2.0r15 to 6.2.0r18 and from 6.3.0r12 to 6.3.0r20<sup id="cite_ref-Juniper-firewall_44-0" class="reference"><a href="#cite_note-Juniper-firewall-44"><span class="cite-bracket">[</span>39<span class="cite-bracket">]</span></a></sup> that gives any user administrative access when using a special master password.<sup id="cite_ref-Zagrozenia_45-0" class="reference"><a href="#cite_note-Zagrozenia-45"><span class="cite-bracket">[</span>40<span class="cite-bracket">]</span></a></sup></li>
<li>Several backdoors were discovered in C-DATA Optical Line Termination (OLT) devices.<sup id="cite_ref-CDATA-OLTs_46-0" class="reference"><a href="#cite_note-CDATA-OLTs-46"><span class="cite-bracket">[</span>41<span class="cite-bracket">]</span></a></sup> Researchers released the findings without notifying C-DATA because they believe the backdoors were intentionally placed by the vendor.<sup id="cite_ref-FTTH-devices_47-0" class="reference"><a href="#cite_note-FTTH-devices-47"><span class="cite-bracket">[</span>42<span class="cite-bracket">]</span></a></sup></li>
<li>A backdoor in versions 5.6.0 and 5.6.1 of the popular Linux utility <a href="XZ_Utils" title="XZ Utils">XZ Utils</a> was <a href="XZ_Utils_backdoor" title="XZ Utils backdoor">discovered in March 2024</a> by software developer Andres Freund.<sup id="cite_ref-register_48-0" class="reference"><a href="#cite_note-register-48"><span class="cite-bracket">[</span>43<span class="cite-bracket">]</span></a></sup> The backdoor gives an attacker who possesses a specific <a href="Ed448" class="mw-redirect" title="Ed448">Ed448</a> private key <a href="Remote_code_execution" class="mw-redirect" title="Remote code execution">remote code execution</a> capabilities on the affected Linux systems. The issue has been assigned a <a href="Common_Vulnerability_Scoring_System" title="Common Vulnerability Scoring System">CVSS</a> score of 10.0, the highest possible score.<sup id="cite_ref-49" class="reference"><a href="#cite_note-49"><span class="cite-bracket">[</span>44<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-50" class="reference"><a href="#cite_note-50"><span class="cite-bracket">[</span>45<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-SamJames_51-0" class="reference"><a href="#cite_note-SamJames-51"><span class="cite-bracket">[</span>46<span class="cite-bracket">]</span></a></sup></li></ul>
<div class="mw-heading mw-heading2"><h2 id="See_also">See also</h2></div>
<ul><li><a href="Backdoor%3AWin32.Hupigon" class="mw-redirect" title="Backdoor:Win32.Hupigon">Backdoor:Win32.Hupigon</a></li>
<li><a href="Hardware_backdoor" title="Hardware backdoor">Hardware backdoor</a></li>
<li><a href="Titanium_(malware)" title="Titanium (malware)">Titanium (malware)</a></li></ul>
<div class="mw-heading mw-heading2"><h2 id="Notes">Notes</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */
.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}
/* end https://en.wikipedia.org/ */
</style><div class="reflist">
<div class="mw-references-wrap"><ol class="references">
<li id="cite_note-20"><span class="mw-cite-backlink"><b><a href="#cite_ref-20">^</a></b></span> <span class="reference-text">This hypothetical scenario is essentially a silicon version of the undetectable <a href="#compiler_backdoors">#compiler backdoors</a></span>
</li>
<li id="cite_note-31"><span class="mw-cite-backlink"><b><a href="#cite_ref-31">^</a></b></span> <span class="reference-text">Specifically Section 3.4.5 "Trap Door Insertion"<sup id="cite_ref-Karger-Schell-1974_25-2" class="reference"><a href="#cite_note-Karger-Schell-1974-25"><span class="cite-bracket">[</span>24<span class="cite-bracket">]</span></a></sup><sup class="reference nowrap"><span title="Page: 52">: 52 </span></sup></span>
</li>
<li id="cite_note-33"><span class="mw-cite-backlink"><b><a href="#cite_ref-33">^</a></b></span> <span class="reference-text">Karger & Schell (2002): Section 3.2.4: Compiler trap doors<sup id="cite_ref-Karger-Schell-2002_27-2" class="reference"><a href="#cite_note-Karger-Schell-2002-27"><span class="cite-bracket">[</span>26<span class="cite-bracket">]</span></a></sup><sup class="reference nowrap"><span title="Page: 52">: 52 </span></sup><br>Wheeler (2009): <a rel="nofollow" class="external text" href="http://www.dwheeler.com/trusting-trust/dissertation/html/wheeler-trusting-trust-ddc.html#2.Background%20and%20related%20work">Section 2: Background and related work</a><sup id="cite_ref-Wheeler-2009_32-0" class="reference"><a href="#cite_note-Wheeler-2009-32"><span class="cite-bracket">[</span>30<span class="cite-bracket">]</span></a></sup></span>
</li>
<li id="cite_note-36"><span class="mw-cite-backlink"><b><a href="#cite_ref-36">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="http://www.catb.org/jargon/html/B/back-door.html">Jargon File entry for "backdoor"</a> describes Thompson compiler hack<sup id="cite_ref-Jargon_35-0" class="reference"><a href="#cite_note-Jargon-35"><span class="cite-bracket">[</span>32<span class="cite-bracket">]</span></a></sup></span>
</li>
<li id="cite_note-38"><span class="mw-cite-backlink"><b><a href="#cite_ref-38">^</a></b></span> <span class="reference-text">Sophos labs on the discovery of the Induc-A virus<sup id="cite_ref-Compileavirus_37-0" class="reference"><a href="#cite_note-Compileavirus-37"><span class="cite-bracket">[</span>33<span class="cite-bracket">]</span></a></sup></span>
</li>
</ol></div></div>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<div class="reflist reflist-columns references-column-width" style="column-width: 30em;">
<ol class="references">
<li id="cite_note-Eckersley-2017-1"><span class="mw-cite-backlink"><b><a href="#cite_ref-Eckersley-2017_1-0">^</a></b></span> <span class="reference-text"><style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */
.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}
/* end https://en.wikipedia.org/ */
</style><cite id="CITEREFEckersleyPortnoy2017" class="citation web cs1">Eckersley, Peter; Portnoy, Erica (8 May 2017). <a rel="nofollow" class="external text" href="https://www.eff.org/deeplinks/2017/05/intels-management-engine-security-hazard-and-users-need-way-disable-it">"Intel's Management Engine is a security hazard, and users need a way to disable it"</a>. <i>www.eff.org</i>. <a href="Electronic_Frontier_Foundation" title="Electronic Frontier Foundation">EFF</a><span class="reference-accessdate">. Retrieved <span class="nowrap">15 May</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-Hoffman-2017-2"><span class="mw-cite-backlink"><b><a href="#cite_ref-Hoffman-2017_2-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFHoffman2017" class="citation web cs1">Hoffman, Chris (22 November 2017). <a rel="nofollow" class="external text" href="https://www.howtogeek.com/334013/intel-management-engine-explained-the-tiny-computer-inside-your-cpu/">"Intel Management Engine, Explained: The Tiny Computer Inside Your CPU"</a>. How-To Geek<span class="reference-accessdate">. Retrieved <span class="nowrap">July 13,</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-3"><span class="mw-cite-backlink"><b><a href="#cite_ref-3">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://techcrunch.com/2024/10/07/the-30-year-old-internet-backdoor-law-that-came-back-to-bite/">"The 30-year-old internet backdoor law that came back to bite"</a>. 7 October 2024.</cite></span>
</li>
<li id="cite_note-4"><span class="mw-cite-backlink"><b><a href="#cite_ref-4">^</a></b></span> <span class="reference-text"><cite id="CITEREFMichael_Kan2024" class="citation news cs1">Michael Kan (7 October 2024). <a rel="nofollow" class="external text" href="https://www.pcmag.com/news/chinese-hackers-reportedly-breached-isps-including-att-verizon">"Chinese Hackers Reportedly Breached ISPs Including AT&T, Verizon"</a>. <i><a href="PC_Magazine" class="mw-redirect" title="PC Magazine">PC Magazine</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">8 October</span> 2024</span>. <q>privacy researchers to call out the US government for maintaining a confidential "backdoor" to enable internet-based wiretapping. "Case in point: there's no way to build a backdoor that only the 'good guys' can use," tweeted Meredith Whittaker, president of the encrypted chat app Signal</q></cite></span>
</li>
<li id="cite_note-5"><span class="mw-cite-backlink"><b><a href="#cite_ref-5">^</a></b></span> <span class="reference-text"><cite id="CITEREFSarah_KrouseDustin_VolzAruna_ViswanathaRobert_McMillan2024" class="citation news cs1">Sarah Krouse; Dustin Volz; Aruna Viswanatha; Robert McMillan (5 October 2024). <a rel="nofollow" class="external text" href="https://www.wsj.com/tech/cybersecurity/u-s-wiretap-systems-targeted-in-china-linked-hack-327fc63b">"U.S. Wiretap Systems Targeted in China-Linked Hack"</a>. <i><a href="Wall_Street_Journal" class="mw-redirect" title="Wall Street Journal">Wall Street Journal</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">8 October</span> 2024</span>. <q>For months or longer, the hackers might have held access to network infrastructure used to cooperate with lawful U.S. requests for communications data</q></cite></span>
</li>
<li id="cite_note-6"><span class="mw-cite-backlink"><b><a href="#cite_ref-6">^</a></b></span> <span class="reference-text"><cite id="CITEREFDustin_Volz2024" class="citation news cs1">Dustin Volz (2 November 2024). <a rel="nofollow" class="external text" href="https://www.wsj.com/livecoverage/harris-trump-election-11-01-24/card/chinese-hackers-stole-phone-audio-from-both-harris-and-trump-campaigns-Sfa6s0vIBEmEWOjeaZ8e">"Chinese Hackers Stole Phone Audio From Both Harris and Trump Campaigns"</a>. <i><a href="Wall_Street_Journal" class="mw-redirect" title="Wall Street Journal">Wall Street Journal</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">3 November</span> 2024</span>. <q>targeted the phones of former President Donald Trump, his running mate, JD Vance, and people affiliated with Vice President Kamala Harris's presidential campaign</q></cite></span>
</li>
<li id="cite_note-Wysopal-Eng-7"><span class="mw-cite-backlink"><b><a href="#cite_ref-Wysopal-Eng_7-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFChris_Wysopal,_Chris_Eng" class="citation web cs1">Chris Wysopal, Chris Eng. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20140801093904/http://www.veracode.com/sites/default/files/Resources/Whitepapers/static-detection-of-backdoors-1.0.pdf">"Static Detection of Application Backdoors"</a> <span class="cs1-format">(PDF)</span>. Veracode. Archived from <a rel="nofollow" class="external text" href="http://www.veracode.com/sites/default/files/Resources/Whitepapers/static-detection-of-backdoors-1.0.pdf">the original</a> <span class="cs1-format">(PDF)</span> on 2014-08-01<span class="reference-accessdate">. Retrieved <span class="nowrap">2015-03-14</span></span>.</cite></span>
</li>
<li id="cite_note-Zetter-2013-8"><span class="mw-cite-backlink">^ <a href="#cite_ref-Zetter-2013_8-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-Zetter-2013_8-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-Zetter-2013_8-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFZetter2013" class="citation magazine cs1">Zetter, Kim (2013-09-24). <a rel="nofollow" class="external text" href="https://www.wired.com/threatlevel/2013/09/nsa-backdoor/">"How a Crypto 'Backdoor' Pitted the Tech World Against the NSA"</a>. <i>Wired</i><span class="reference-accessdate">. Retrieved <span class="nowrap">5 April</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-Ashok-2017-9"><span class="mw-cite-backlink"><b><a href="#cite_ref-Ashok-2017_9-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFAshok2017" class="citation web cs1">Ashok, India (21 June 2017). <a rel="nofollow" class="external text" href="http://www.ibtimes.co.uk/hackers-using-nsa-malware-doublepulsar-infect-windows-pcs-monero-mining-trojan-1627220">"Hackers using NSA malware DoublePulsar to infect Windows PCs with Monero mining Trojan"</a>. International Business Times UK<span class="reference-accessdate">. Retrieved <span class="nowrap">1 July</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-Microsoft-Back-Doors-10"><span class="mw-cite-backlink"><b><a href="#cite_ref-Microsoft-Back-Doors_10-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.gnu.org/proprietary/malware-microsoft.en.html">"Microsoft Back Doors"</a>. <i>GNU Operating System</i><span class="reference-accessdate">. Retrieved <span class="nowrap">1 July</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-Ars-Technica-2017-11"><span class="mw-cite-backlink"><b><a href="#cite_ref-Ars-Technica-2017_11-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://arstechnica.com/security/2017/04/nsa-backdoor-detected-on-55000-windows-boxes-can-now-be-remotely-removed/">"NSA backdoor detected on >55,000 Windows boxes can now be remotely removed"</a>. Ars Technica. 2017-04-25<span class="reference-accessdate">. Retrieved <span class="nowrap">1 July</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-Backdoors-and-Trojan-Horses-12"><span class="mw-cite-backlink"><b><a href="#cite_ref-Backdoors-and-Trojan-Horses_12-0">^</a></b></span> <span class="reference-text"><cite class="citation journal cs1">"Backdoors and Trojan Horses: By the Internet Security Systems' X-Force". <i>Information Security Technical Report</i>. <b>6</b> (4): <span class="nowrap">31–</span>57. 2001-12-01. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1016%2FS1363-4127%2801%2900405-8">10.1016/S1363-4127(01)00405-8</a>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a> <a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/1363-4127">1363-4127</a>.</cite></span>
</li>
<li id="cite_note-Linthicum-13"><span class="mw-cite-backlink"><b><a href="#cite_ref-Linthicum_13-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFLinthicum" class="citation news cs1">Linthicum, David. <a rel="nofollow" class="external text" href="https://www.infoworld.com/article/3167908/cloud-computing/caution-the-clouds-back-door-is-your-data-center.html">"Caution! The cloud's backdoor is your datacenter"</a>. <i>InfoWorld</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2018-11-29</span></span>.</cite></span>
</li>
<li id="cite_note-Bogus-story-14"><span class="mw-cite-backlink"><b><a href="#cite_ref-Bogus-story_14-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20140626134118/http://blog.erratasec.com/2012/05/bogus-story-no-chinese-backdoor-in.html">"Bogus story: no Chinese backdoor in military chip"</a>. <i>blog.erratasec.com</i>. Archived from <a rel="nofollow" class="external text" href="http://blog.erratasec.com/2012/05/bogus-story-no-chinese-backdoor-in.html">the original</a> on 26 June 2014<span class="reference-accessdate">. Retrieved <span class="nowrap">5 April</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-Clipper-a-failure-15"><span class="mw-cite-backlink"><b><a href="#cite_ref-Clipper-a-failure_15-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.eff.org/deeplinks/2015/04/clipper-chips-birthday-looking-back-22-years-key-escrow-failures">"Clipper a failure"</a>. 16 April 2015.</cite></span>
</li>
<li id="cite_note-Menisov-2022-16"><span class="mw-cite-backlink"><b><a href="#cite_ref-Menisov-2022_16-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFMenisovLomakoDudkin2022" class="citation journal cs1 cs1-prop-foreign-lang-source">Menisov, Artem B.; Lomako, Aleksandr G.; Dudkin, Andrey S. (2022-08-22). <a rel="nofollow" class="external text" href="https://ntv.ifmo.ru/file/article/21359.pdf">"Метод защиты нейронных сетей от компьютерных бэкдор-атак на основе идентификации триггеров закладок"</a> [A method for protecting neural networks from computer backdoor attacks based on the trigger identification] <span class="cs1-format">(PDF)</span>. <i>Journal Scientific and Technical of Information Technologies, Mechanics and Optics</i> (in Russian). <b>140</b> (4): 742. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.17586%2F2226-1494-2022-22-4-742-750">10.17586/2226-1494-2022-22-4-742-750</a>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a> <a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/2226-1494">2226-1494</a>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:251940761">251940761</a>.</cite></span>
</li>
<li id="cite_note-Petersen-1967-17"><span class="mw-cite-backlink"><b><a href="#cite_ref-Petersen-1967_17-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFPetersenTurn1967" class="citation cs2">Petersen, H.E.; Turn, R. (1967), "System Implications of Information Privacy", <i>Proceedings of the AFIPS Spring Joint Computer Conference</i>, <b>30</b>, AFIPS Press: <span class="nowrap">291–</span>300</cite></span>
</li>
<li id="cite_note-Security-Controls-18"><span class="mw-cite-backlink"><b><a href="#cite_ref-Security-Controls_18-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFWH_Ware1970" class="citation report cs1">WH Ware, ed. (February 1970). Security Controls for Computer Systems. <i>Technical Report R-609</i> (Report). <a href="RAND_Corporation" title="RAND Corporation">RAND Corp</a>.</cite></span>
</li>
<li id="cite_note-19"><span class="mw-cite-backlink"><b><a href="#cite_ref-19">^</a></b></span> <span class="reference-text"><cite id="CITEREFGaoDoanZhangMa2020" class="citation arxiv cs1">Gao, Yansong; Doan, Bao Gia; Zhang, Zhi; Ma, Siqi; Zhang, Jiliang; Fu, Anmin; Nepal, Surya; Kim, Hyoungshick (2020-08-02). "Backdoor Attacks and Countermeasures on Deep Learning: A Comprehensive Review". <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/2007.10760">2007.10760</a></span> [<a rel="nofollow" class="external text" href="https://arxiv.org/archive/cs.CR">cs.CR</a>].</cite></span>
</li>
<li id="cite_note-McVoy-21"><span class="mw-cite-backlink"><b><a href="#cite_ref-McVoy_21-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFMcVoy" class="citation web cs1">McVoy, Larry. <a rel="nofollow" class="external text" href="https://lore.kernel.org/lkml/20031105230350.GB12992@work.bitmover.com/">"Re: BK2CVS problem"</a>. <i>linux-kernel mailing list</i><span class="reference-accessdate">. Retrieved <span class="nowrap">18 September</span> 2020</span>.</cite></span>
</li>
<li id="cite_note-An-attempt-to-backdoor-22"><span class="mw-cite-backlink"><b><a href="#cite_ref-An-attempt-to-backdoor_22-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://lwn.net/Articles/57135/">"An attempt to backdoor the kernel"</a>. <i>lwn.net</i>. 2003-11-06. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20040216120134/http://lwn.net:80/Articles/57135/">Archived</a> from the original on 2004-02-16<span class="reference-accessdate">. Retrieved <span class="nowrap">2021-02-08</span></span>.</cite></span>
</li>
<li id="cite_note-Poulsen-2003-23"><span class="mw-cite-backlink"><b><a href="#cite_ref-Poulsen-2003_23-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFPoulsen2003" class="citation web cs1">Poulsen, Kevin (6 November 2003). <a rel="nofollow" class="external text" href="http://www.securityfocus.com/news/7388">"Thwarted Linux backdoor hints at smarter hacks"</a>. <i>SecurityFocus</i>.</cite></span>
</li>
<li id="cite_note-SamsungGalaxyBackdoor-24"><span class="mw-cite-backlink"><b><a href="#cite_ref-SamsungGalaxyBackdoor_24-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://redmine.replicant.us/projects/replicant/wiki/SamsungGalaxyBackdoor">"SamsungGalaxyBackdoor - Replicant"</a>. <i>redmine.replicant.us</i><span class="reference-accessdate">. Retrieved <span class="nowrap">5 April</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-Karger-Schell-1974-25"><span class="mw-cite-backlink">^ <a href="#cite_ref-Karger-Schell-1974_25-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-Karger-Schell-1974_25-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-Karger-Schell-1974_25-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFKargerSchell1974" class="citation book cs1">Karger, Paul A.; Schell, Roger R. (June 1974). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20110709024412/http://csrc.nist.gov/publications/history/karg74.pdf"><i>Multics Security Evaluation: Vulnerability Analysis</i></a> <span class="cs1-format">(PDF)</span>. Vol. II. Archived from <a rel="nofollow" class="external text" href="http://csrc.nist.gov/publications/history/karg74.pdf">the original</a> <span class="cs1-format">(PDF)</span> on 2011-07-09<span class="reference-accessdate">. Retrieved <span class="nowrap">2014-11-09</span></span>.</cite></span>
</li>
<li id="cite_note-Thompson-1984-26"><span class="mw-cite-backlink">^ <a href="#cite_ref-Thompson-1984_26-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-Thompson-1984_26-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-Thompson-1984_26-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFThompson1984" class="citation journal cs1"><a href="Ken_Thompson" title="Ken Thompson">Thompson, Ken</a> (August 1984). <a rel="nofollow" class="external text" href="http://www.ece.cmu.edu/~ganger/712.fall02/papers/p761-thompson.pdf">"Reflections on Trusting Trust"</a> <span class="cs1-format">(PDF)</span>. <i><a href="Communications_of_the_ACM" title="Communications of the ACM">Communications of the ACM</a></i>. <b>27</b> (8): <span class="nowrap">761–</span>763. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.1145%2F358198.358210">10.1145/358198.358210</a></span>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:34854438">34854438</a>.</cite></span>
</li>
<li id="cite_note-Karger-Schell-2002-27"><span class="mw-cite-backlink">^ <a href="#cite_ref-Karger-Schell-2002_27-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-Karger-Schell-2002_27-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-Karger-Schell-2002_27-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFKargerSchell2002" class="citation book cs1">Karger, Paul A.; Schell, Roger R. (September 18, 2002). "Thirty years later: Lessons from the Multics security evaluation". <a rel="nofollow" class="external text" href="http://www.acsac.org/2002/papers/classic-multics.pdf"><i>18th Annual Computer Security Applications Conference, 2002. Proceedings</i></a> <span class="cs1-format">(PDF)</span>. IEEE. pp. <span class="nowrap">119–</span>126. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2FCSAC.2002.1176285">10.1109/CSAC.2002.1176285</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>0-7695-1828-1</bdi><span class="reference-accessdate">. Retrieved <span class="nowrap">2014-11-08</span></span>.</cite></span>
</li>
<li id="cite_note-Akkad-2014-28"><span class="mw-cite-backlink"><b><a href="#cite_ref-Akkad-2014_28-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFAkkad2014" class="citation news cs1">Akkad, Omar El (20 January 2014). <a rel="nofollow" class="external text" href="https://www.theglobeandmail.com/technology/business-technology/the-strange-connection-between-the-nsa-and-an-ontario-tech-firm/article16402341/">"The strange connection between the NSA and an Ontario tech firm"</a>. <i>The Globe and Mail</i><span class="reference-accessdate">. Retrieved <span class="nowrap">5 April</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-Perlroth-2013-29"><span class="mw-cite-backlink">^ <a href="#cite_ref-Perlroth-2013_29-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-Perlroth-2013_29-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFPerlrothLarsonShane2013" class="citation news cs1">Perlroth, Nicole; Larson, Jeff; Shane, Scott (5 September 2013). <a rel="nofollow" class="external text" href="https://www.nytimes.com/2013/09/06/us/nsa-foils-much-internet-encryption.html">"N.S.A. Able to Foil Basic Safeguards of Privacy on Web"</a>. <i>The New York Times</i><span class="reference-accessdate">. Retrieved <span class="nowrap">5 April</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-Malicious-Cryptography-30"><span class="mw-cite-backlink"><b><a href="#cite_ref-Malicious-Cryptography_30-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20150221133432/http://www.cryptovirology.com/cryptovfiles/newbook.html">"Malicious Cryptography: Cryptovirology and Kleptography"</a>. <i>www.cryptovirology.com</i>. Archived from <a rel="nofollow" class="external text" href="http://www.cryptovirology.com/cryptovfiles/newbook.html">the original</a> on 21 February 2015<span class="reference-accessdate">. Retrieved <span class="nowrap">5 April</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-Wheeler-2009-32"><span class="mw-cite-backlink">^ <a href="#cite_ref-Wheeler-2009_32-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-Wheeler-2009_32-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFWheeler2009" class="citation thesis cs1">Wheeler, David A. (7 December 2009). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20141008195228/http://www.dwheeler.com/trusting-trust/dissertation/html/wheeler-trusting-trust-ddc.html"><i>Fully Countering Trusting Trust through Diverse Double-Compiling</i></a> (Ph.D.). Fairfax, VA: <a href="George_Mason_University" title="George Mason University">George Mason University</a>. Archived from <a rel="nofollow" class="external text" href="http://www.dwheeler.com/trusting-trust/dissertation/html/wheeler-trusting-trust-ddc.html">the original</a> on 2014-10-08<span class="reference-accessdate">. Retrieved <span class="nowrap">2014-11-09</span></span>.</cite></span>
</li>
<li id="cite_note-34"><span class="mw-cite-backlink"><b><a href="#cite_ref-34">^</a></b></span> <span class="reference-text"><cite id="CITEREFCox2023" class="citation web cs1">Cox, Russ (October 25, 2023). <a rel="nofollow" class="external text" href="https://research.swtch.com/nih">"Running the "Reflections on Trusting Trust" Compiler"</a>.</cite></span>
</li>
<li id="cite_note-Jargon-35"><span class="mw-cite-backlink"><b><a href="#cite_ref-Jargon_35-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.catb.org/jargon/html/B/back-door.html">"Jargon File entry for "backdoor""</a> – via catb.org.</cite></span>
</li>
<li id="cite_note-Compileavirus-37"><span class="mw-cite-backlink"><b><a href="#cite_ref-Compileavirus_37-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20110109102302/https://nakedsecurity.sophos.com/2009/08/18/compileavirus">"Compile-a-virus — W32/Induc-A"</a>. Archived from <a rel="nofollow" class="external text" href="https://nakedsecurity.sophos.com/2009/08/18/compileavirus">the original</a> on 2011-01-09.</cite></span>
</li>
<li id="cite_note-XcodeGhost-39"><span class="mw-cite-backlink"><b><a href="#cite_ref-XcodeGhost_39-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://arstechnica.com/information-technology/2015/09/apple-scrambles-after-40-malicious-xcodeghost-apps-haunt-app-store/">"Apple scrambles after 40 malicious "XcodeGhost" apps haunt App Store"</a>. 21 September 2015.</cite></span>
</li>
<li id="cite_note-WordPress-40"><span class="mw-cite-backlink"><b><a href="#cite_ref-WordPress_40-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://blog.sucuri.net/2014/03/unmasking-free-premium-wordpress-plugins.html">"Unmasking "Free" Premium WordPress Plugins"</a>. <i>Sucuri Blog</i>. 2014-03-26<span class="reference-accessdate">. Retrieved <span class="nowrap">3 March</span> 2015</span>.</cite></span>
</li>
<li id="cite_note-Sinegubko-2014-41"><span class="mw-cite-backlink"><b><a href="#cite_ref-Sinegubko-2014_41-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFSinegubko2014" class="citation web cs1">Sinegubko, Denis (2014-04-23). <a rel="nofollow" class="external text" href="http://blog.sucuri.net/2014/04/joomla-plugin-constructor-backdoor.html">"Joomla Plugin Constructor Backdoor"</a>. <i>Sucuri</i><span class="reference-accessdate">. Retrieved <span class="nowrap">13 March</span> 2015</span>.</cite></span>
</li>
<li id="cite_note-Vulnerability-42"><span class="mw-cite-backlink"><b><a href="#cite_ref-Vulnerability_42-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.kb.cert.org/vuls/id/247371">"Vulnerability Note VU#247371"</a>. <i>Vulnerability Note Database</i><span class="reference-accessdate">. Retrieved <span class="nowrap">13 March</span> 2015</span>.</cite></span>
</li>
<li id="cite_note-Interbase-Server-43"><span class="mw-cite-backlink"><b><a href="#cite_ref-Interbase-Server_43-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.cert.org/historical/advisories/CA-2001-01.cfm">"Interbase Server Contains Compiled-in Back Door Account"</a>. <i><a href="CERT_Coordination_Center" title="CERT Coordination Center">CERT</a></i>. 31 December 2001<span class="reference-accessdate">. Retrieved <span class="nowrap">13 March</span> 2015</span>.</cite></span>
</li>
<li id="cite_note-Juniper-firewall-44"><span class="mw-cite-backlink"><b><a href="#cite_ref-Juniper-firewall_44-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://arstechnica.com/security/2015/12/researchers-confirm-backdoor-password-in-juniper-firewall-code/">"Researchers confirm backdoor password in Juniper firewall code"</a>. <i>Ars Technica</i>. 2015-12-21<span class="reference-accessdate">. Retrieved <span class="nowrap">2016-01-16</span></span>.</cite></span>
</li>
<li id="cite_note-Zagrozenia-45"><span class="mw-cite-backlink"><b><a href="#cite_ref-Zagrozenia_45-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1 cs1-prop-foreign-lang-source"><a rel="nofollow" class="external text" href="https://spece.it/bezpieczenstwo/zagrozenia-tygodnia-2015-w52">"Zagrożenia tygodnia 2015-W52 - Spece.IT"</a>. <i>Spece.IT</i> (in Polish). 2015-12-23<span class="reference-accessdate">. Retrieved <span class="nowrap">2016-01-16</span></span>.</cite></span>
</li>
<li id="cite_note-CDATA-OLTs-46"><span class="mw-cite-backlink"><b><a href="#cite_ref-CDATA-OLTs_46-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://pierrekim.github.io/blog/2020-07-07-cdata-olt-0day-vulnerabilities.html">"Multiple vulnerabilities found in CDATA OLTs - IT Security Research by Pierre"</a>.</cite></span>
</li>
<li id="cite_note-FTTH-devices-47"><span class="mw-cite-backlink"><b><a href="#cite_ref-FTTH-devices_47-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.zdnet.com/article/backdoor-accounts-discovered-in-29-ftth-devices-from-chinese-vendor-c-data/">"Backdoor accounts discovered in 29 FTTH devices from Chinese vendor C-Data"</a>. <i><a href="ZDNet" class="mw-redirect" title="ZDNet">ZDNet</a></i>.</cite></span>
</li>
<li id="cite_note-register-48"><span class="mw-cite-backlink"><b><a href="#cite_ref-register_48-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFClaburn" class="citation web cs1">Claburn, Thomas. <a rel="nofollow" class="external text" href="https://www.theregister.com/2024/03/29/malicious_backdoor_xz/">"Malicious backdoor spotted in Linux compression library xz"</a>. <i>The Register</i>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20240401022057/https://www.theregister.com/2024/03/29/malicious_backdoor_xz/">Archived</a> from the original on 1 April 2024<span class="reference-accessdate">. Retrieved <span class="nowrap">1 April</span> 2024</span>.</cite></span>
</li>
<li id="cite_note-49"><span class="mw-cite-backlink"><b><a href="#cite_ref-49">^</a></b></span> <span class="reference-text"><cite id="CITEREFGatlan" class="citation web cs1">Gatlan, Sergiu. <a rel="nofollow" class="external text" href="https://www.bleepingcomputer.com/news/security/red-hat-warns-of-backdoor-in-xz-tools-used-by-most-linux-distros/">"Red Hat warns of backdoor in XZ tools used by most Linux distros"</a>. <i>BleepingComputer</i>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20240329192759/https://www.bleepingcomputer.com/news/security/red-hat-warns-of-backdoor-in-xz-tools-used-by-most-linux-distros/">Archived</a> from the original on 29 March 2024<span class="reference-accessdate">. Retrieved <span class="nowrap">29 March</span> 2024</span>.</cite></span>
</li>
<li id="cite_note-50"><span class="mw-cite-backlink"><b><a href="#cite_ref-50">^</a></b></span> <span class="reference-text"><cite id="CITEREFAkamai_Security_Intelligence_Group2024" class="citation web cs1">Akamai Security Intelligence Group (1 April 2024). <a rel="nofollow" class="external text" href="https://www.akamai.com/blog/security-research/critical-linux-backdoor-xz-utils-discovered-what-to-know">"XZ Utils Backdoor – Everything You Need to Know, and What You Can Do"</a>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20240402014912/https://www.akamai.com/blog/security-research/critical-linux-backdoor-xz-utils-discovered-what-to-know">Archived</a> from the original on 2 April 2024<span class="reference-accessdate">. Retrieved <span class="nowrap">2 April</span> 2024</span>.</cite></span>
</li>
<li id="cite_note-SamJames-51"><span class="mw-cite-backlink"><b><a href="#cite_ref-SamJames_51-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFJames" class="citation web cs1">James, Sam. <a rel="nofollow" class="external text" href="https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27">"xz-utils backdoor situation (CVE-2024-3094)"</a>. <i>GitHub</i>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20240402010500/https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27">Archived</a> from the original on 2 April 2024<span class="reference-accessdate">. Retrieved <span class="nowrap">2 April</span> 2024</span>.</cite></span>
</li>
</ol></div>
<p><br>
</p>
<div class="mw-heading mw-heading2"><h2 id="External_links">External links</h2></div>
<ul><li><a rel="nofollow" class="external text" href="https://www.wordfence.com/learn/finding-removing-backdoors/">Finding and Removing Backdoors</a></li>
<li><a rel="nofollow" class="external text" href="http://learn-networking.com/network-security/three-archaic-backdoor-trojan-programs-that-still-serve-great-pranks">Three Archaic Backdoor Trojan Programs That Still Serve Great Pranks</a> <a rel="nofollow" class="external text" href="https://web.archive.org/web/20150527204633/http://learn-networking.com/network-security/three-archaic-backdoor-trojan-programs-that-still-serve-great-pranks">Archived</a> 2015-05-27 at the <a href="Wayback_Machine" title="Wayback Machine">Wayback Machine</a></li>
<li><a rel="nofollow" class="external text" href="http://www.2-spyware.com/backdoors-removal">Backdoors removal</a> — List of backdoors and their removal instructions.</li>
<li>FAQ Farm's <a rel="nofollow" class="external text" href="https://web.archive.org/web/20051015042726/http://www.faqfarm.com/Q/FAQ/1772">Backdoors FAQ</a>: wiki question and answer forum</li>
<li><a rel="nofollow" class="external text" href="https://www.owasp.org/images/a/ae/OWASP_10_Most_Common_Backdoors.pdf">List of backdoors and Removal</a></li></ul>
<div class="navbox-styles"><style data-mw-deduplicate="TemplateStyles:r1129693374">
/* start https://en.wikipedia.org/ */
.mw-parser-output .hlist dl,.mw-parser-output .hlist ol,.mw-parser-output .hlist ul{margin:0;padding:0}.mw-parser-output .hlist dd,.mw-parser-output .hlist dt,.mw-parser-output .hlist li{margin:0;display:inline}.mw-parser-output .hlist.inline,.mw-parser-output .hlist.inline dl,.mw-parser-output .hlist.inline ol,.mw-parser-output .hlist.inline ul,.mw-parser-output .hlist dl dl,.mw-parser-output .hlist dl ol,.mw-parser-output .hlist dl ul,.mw-parser-output .hlist ol dl,.mw-parser-output .hlist ol ol,.mw-parser-output .hlist ol ul,.mw-parser-output .hlist ul dl,.mw-parser-output .hlist ul ol,.mw-parser-output .hlist ul ul{display:inline}.mw-parser-output .hlist .mw-empty-li{display:none}.mw-parser-output .hlist dt::after{content:": "}.mw-parser-output .hlist dd::after,.mw-parser-output .hlist li::after{content:" · ";font-weight:bold}.mw-parser-output .hlist dd:last-child::after,.mw-parser-output .hlist dt:last-child::after,.mw-parser-output .hlist li:last-child::after{content:none}.mw-parser-output .hlist dd dd:first-child::before,.mw-parser-output .hlist dd dt:first-child::before,.mw-parser-output .hlist dd li:first-child::before,.mw-parser-output .hlist dt dd:first-child::before,.mw-parser-output .hlist dt dt:first-child::before,.mw-parser-output .hlist dt li:first-child::before,.mw-parser-output .hlist li dd:first-child::before,.mw-parser-output .hlist li dt:first-child::before,.mw-parser-output .hlist li li:first-child::before{content:" (";font-weight:normal}.mw-parser-output .hlist dd dd:last-child::after,.mw-parser-output .hlist dd dt:last-child::after,.mw-parser-output .hlist dd li:last-child::after,.mw-parser-output .hlist dt dd:last-child::after,.mw-parser-output .hlist dt dt:last-child::after,.mw-parser-output .hlist dt li:last-child::after,.mw-parser-output .hlist li dd:last-child::after,.mw-parser-output .hlist li dt:last-child::after,.mw-parser-output .hlist li li:last-child::after{content:")";font-weight:normal}.mw-parser-output .hlist ol{counter-reset:listitem}.mw-parser-output .hlist ol>li{counter-increment:listitem}.mw-parser-output .hlist ol>li::before{content:" "counter(listitem)"\a0 "}.mw-parser-output .hlist dd ol>li:first-child::before,.mw-parser-output .hlist dt ol>li:first-child::before,.mw-parser-output .hlist li ol>li:first-child::before{content:" ("counter(listitem)"\a0 "}
/* end https://en.wikipedia.org/ */
</style><style data-mw-deduplicate="TemplateStyles:r1236075235">
/* start https://en.wikipedia.org/ */
.mw-parser-output .navbox{box-sizing:border-box;border:1px solid #a2a9b1;width:100%;clear:both;font-size:88%;text-align:center;padding:1px;margin:1em auto 0}.mw-parser-output .navbox .navbox{margin-top:0}.mw-parser-output .navbox+.navbox,.mw-parser-output .navbox+.navbox-styles+.navbox{margin-top:-1px}.mw-parser-output .navbox-inner,.mw-parser-output .navbox-subgroup{width:100%}.mw-parser-output .navbox-group,.mw-parser-output .navbox-title,.mw-parser-output .navbox-abovebelow{padding:0.25em 1em;line-height:1.5em;text-align:center}.mw-parser-output .navbox-group{white-space:nowrap;text-align:right}.mw-parser-output .navbox,.mw-parser-output .navbox-subgroup{background-color:#fdfdfd}.mw-parser-output .navbox-list{line-height:1.5em;border-color:#fdfdfd}.mw-parser-output .navbox-list-with-group{text-align:left;border-left-width:2px;border-left-style:solid}.mw-parser-output tr+tr>.navbox-abovebelow,.mw-parser-output tr+tr>.navbox-group,.mw-parser-output tr+tr>.navbox-image,.mw-parser-output tr+tr>.navbox-list{border-top:2px solid #fdfdfd}.mw-parser-output .navbox-title{background-color:#ccf}.mw-parser-output .navbox-abovebelow,.mw-parser-output .navbox-group,.mw-parser-output .navbox-subgroup .navbox-title{background-color:#ddf}.mw-parser-output .navbox-subgroup .navbox-group,.mw-parser-output .navbox-subgroup .navbox-abovebelow{background-color:#e6e6ff}.mw-parser-output .navbox-even{background-color:#f7f7f7}.mw-parser-output .navbox-odd{background-color:transparent}.mw-parser-output .navbox .hlist td dl,.mw-parser-output .navbox .hlist td ol,.mw-parser-output .navbox .hlist td ul,.mw-parser-output .navbox td.hlist dl,.mw-parser-output .navbox td.hlist ol,.mw-parser-output .navbox td.hlist ul{padding:0.125em 0}.mw-parser-output .navbox .navbar{display:block;font-size:100%}.mw-parser-output .navbox-title .navbar{float:left;text-align:left;margin-right:0.5em}body.skin--responsive .mw-parser-output .navbox-image img{max-width:none!important}@media print{body.ns-0 .mw-parser-output .navbox{display:none!important}}
/* end https://en.wikipedia.org/ */
</style></div><div role="navigation" class="navbox" aria-labelledby="Information_security92" style="padding:3px"><table class="nowraplinks mw-collapsible autocollapse navbox-inner" style="border-spacing:0;background:transparent;color:inherit"><tbody><tr><th scope="col" class="navbox-title" colspan="3"><style data-mw-deduplicate="TemplateStyles:r1239400231">
/* start https://en.wikipedia.org/ */
.mw-parser-output .navbar{display:inline;font-size:88%;font-weight:normal}.mw-parser-output .navbar-collapse{float:left;text-align:left}.mw-parser-output .navbar-boxtext{word-spacing:0}.mw-parser-output .navbar ul{display:inline-block;white-space:nowrap;line-height:inherit}.mw-parser-output .navbar-brackets::before{margin-right:-0.125em;content:"[ "}.mw-parser-output .navbar-brackets::after{margin-left:-0.125em;content:" ]"}.mw-parser-output .navbar li{word-spacing:-0.125em}.mw-parser-output .navbar a>span,.mw-parser-output .navbar a>abbr{text-decoration:inherit}.mw-parser-output .navbar-mini abbr{font-variant:small-caps;border-bottom:none;text-decoration:none;cursor:inherit}.mw-parser-output .navbar-ct-full{font-size:114%;margin:0 7em}.mw-parser-output .navbar-ct-mini{font-size:114%;margin:0 4em}html.skin-theme-clientpref-night .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}@media(prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}}@media print{.mw-parser-output .navbar{display:none!important}}
/* end https://en.wikipedia.org/ */
</style><div id="Information_security92" style="font-size:114%;margin:0 4em"><a href="Information_security" title="Information security">Information security</a></div></th></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Threat_(computer)" class="mw-redirect" title="Threat (computer)">Threats</a></th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Adware" title="Adware">Adware</a></li>
<li><a href="Advanced_persistent_threat" title="Advanced persistent threat">Advanced persistent threat</a></li>
<li><a href="Arbitrary_code_execution" title="Arbitrary code execution">Arbitrary code execution</a></li>
<li>Bombs
<ul><li><a href="Fork_bomb" title="Fork bomb">Fork</a></li>
<li><a href="Logic_bomb" title="Logic bomb">Logic</a></li>
<li><a href="Time_bomb_(software)" title="Time bomb (software)">Time</a></li>
<li><a href="Zip_bomb" title="Zip bomb">Zip</a></li></ul></li>
<li><a href="Hardware_backdoor" title="Hardware backdoor">Hardware backdoors</a></li>
<li><a href="Code_injection" title="Code injection">Code injection</a></li>
<li><a href="Crimeware" title="Crimeware">Crimeware</a></li>
<li><a href="Cross-site_scripting" title="Cross-site scripting">Cross-site scripting</a></li>
<li><a href="Cross-site_leaks" title="Cross-site leaks">Cross-site leaks</a></li>
<li><a href="DOM_clobbering" title="DOM clobbering">DOM clobbering</a></li>
<li><a href="History_sniffing" title="History sniffing">History sniffing</a></li>
<li><a href="Cryptojacking" title="Cryptojacking">Cryptojacking</a></li>
<li><a href="Botnet" title="Botnet">Botnets</a></li>
<li><a href="Data_breach" title="Data breach">Data breach</a></li>
<li><a href="Drive-by_download" title="Drive-by download">Drive-by download</a></li>
<li><a href="Browser_Helper_Object" title="Browser Helper Object">Browser Helper Objects</a></li>
<li><a href="Computer_virus" title="Computer virus">Viruses</a></li>
<li><a href="Data_scraping" title="Data scraping">Data scraping</a></li>
<li><a href="Denial-of-service_attack" title="Denial-of-service attack">Denial-of-service attack</a></li>
<li><a href="Eavesdropping" title="Eavesdropping">Eavesdropping</a></li>
<li><a href="Email_fraud" title="Email fraud">Email fraud</a></li>
<li><a href="Email_spoofing" title="Email spoofing">Email spoofing</a></li>
<li><a href="Exploit_(computer_security)" title="Exploit (computer security)">Exploits</a></li>
<li><a href="Dialer#Fraudulent_dialer" title="Dialer">Fraudulent dialers</a></li>
<li><a href="Hacktivism" title="Hacktivism">Hacktivism</a></li>
<li><a href="Infostealer" title="Infostealer">Infostealer</a></li>
<li><a href="Insecure_direct_object_reference" title="Insecure direct object reference">Insecure direct object reference</a></li>
<li><a href="Keystroke_logging" title="Keystroke logging">Keystroke loggers</a></li>
<li><a href="Malware" title="Malware">Malware</a></li>
<li><a href="Payload_(computing)" title="Payload (computing)">Payload</a></li>
<li><a href="Phishing" title="Phishing">Phishing</a>
<ul><li><a href="Voice_phishing" title="Voice phishing">Voice</a></li></ul></li>
<li><a href="Polymorphic_engine" title="Polymorphic engine">Polymorphic engine</a></li>
<li><a href="Privilege_escalation" title="Privilege escalation">Privilege escalation</a></li>
<li><a href="Ransomware" title="Ransomware">Ransomware</a></li>
<li><a href="Rootkit" title="Rootkit">Rootkits</a></li>
<li><a href="Scareware" title="Scareware">Scareware</a></li>
<li><a href="Shellcode" title="Shellcode">Shellcode</a></li>
<li><a href="Spamming" title="Spamming">Spamming</a></li>
<li><a href="Social_engineering_(security)" title="Social engineering (security)">Social engineering</a></li>
<li><a href="Spyware" title="Spyware">Spyware</a></li>
<li><a href="Software_bug" title="Software bug">Software bugs</a></li>
<li><a href="Trojan_horse_(computing)" title="Trojan horse (computing)">Trojan horses</a></li>
<li><a href="Hardware_Trojan" title="Hardware Trojan">Hardware Trojans</a></li>
<li><a href="Remote_access_trojan" class="mw-redirect" title="Remote access trojan">Remote access trojans</a></li>
<li><a href="Vulnerability_(computer_security)" title="Vulnerability (computer security)">Vulnerability</a></li>
<li><a href="Web_shell" title="Web shell">Web shells</a></li>
<li><a href="Wiper_(malware)" title="Wiper (malware)">Wiper</a></li>
<li><a href="Computer_worm" title="Computer worm">Worms</a></li>
<li><a href="SQL_injection" title="SQL injection">SQL injection</a></li>
<li><a href="Rogue_security_software" title="Rogue security software">Rogue security software</a></li>
<li><a href="Zombie_(computing)" title="Zombie (computing)">Zombie</a></li></ul>
</div></td><td class="noviewer navbox-image" rowspan="3" style="width:1px;padding:0 0 0 2px"><div></div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Defenses</th><td class="navbox-list-with-group navbox-list navbox-even hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Application_security" title="Application security">Application security</a>
<ul><li><a href="Secure_coding" title="Secure coding">Secure coding</a></li>
<li>Secure by default</li>
<li><a href="Secure_by_design" title="Secure by design">Secure by design</a>
<ul><li><a href="Misuse_case" title="Misuse case">Misuse case</a></li></ul></li></ul></li>
<li><a href="Computer_access_control" title="Computer access control">Computer access control</a>
<ul><li><a href="Authentication" title="Authentication">Authentication</a>
<ul><li><a href="Multi-factor_authentication" title="Multi-factor authentication">Multi-factor authentication</a></li></ul></li>
<li><a href="Authorization" title="Authorization">Authorization</a></li></ul></li>
<li><a href="Computer_security_software" title="Computer security software">Computer security software</a>
<ul><li><a href="Antivirus_software" title="Antivirus software">Antivirus software</a></li>
<li><a href="Security-focused_operating_system" title="Security-focused operating system">Security-focused operating system</a></li></ul></li>
<li><a href="Data-centric_security" title="Data-centric security">Data-centric security</a></li>
<li><a href="Obfuscation_(software)" title="Obfuscation (software)">Software obfuscation</a></li>
<li><a href="Data_masking" title="Data masking">Data masking</a></li>
<li><a href="Encryption" title="Encryption">Encryption</a></li>
<li><a href="Firewall_(computing)" title="Firewall (computing)">Firewall</a></li>
<li><a href="Intrusion_detection_system" title="Intrusion detection system">Intrusion detection system</a>
<ul><li><a href="Host-based_intrusion_detection_system" title="Host-based intrusion detection system">Host-based intrusion detection system</a> (HIDS)</li>
<li><a href="Anomaly_detection" title="Anomaly detection">Anomaly detection</a></li></ul></li>
<li><a href="Information_security_management" title="Information security management">Information security management</a>
<ul><li><a href="Information_risk_management" class="mw-redirect" title="Information risk management">Information risk management</a></li>
<li><a href="Security_information_and_event_management" title="Security information and event management">Security information and event management</a> (SIEM)</li></ul></li>
<li><a href="Runtime_application_self-protection" title="Runtime application self-protection">Runtime application self-protection</a></li>
<li><a href="Site_isolation" title="Site isolation">Site isolation</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Related<br>security<br>topics</th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Computer_security" title="Computer security">Computer security</a></li>
<li><a href="Automotive_security" title="Automotive security">Automotive security</a></li>
<li><a href="Cybercrime" title="Cybercrime">Cybercrime</a>
<ul><li><a href="Cybersex_trafficking" title="Cybersex trafficking">Cybersex trafficking</a></li>
<li><a href="Computer_fraud" title="Computer fraud">Computer fraud</a></li></ul></li>
<li><a href="Cybergeddon" title="Cybergeddon">Cybergeddon</a></li>
<li><a href="Cyberterrorism" title="Cyberterrorism">Cyberterrorism</a></li>
<li><a href="Cyberwarfare" title="Cyberwarfare">Cyberwarfare</a></li>
<li><a href="Electronic_warfare" title="Electronic warfare">Electronic warfare</a></li>
<li><a href="Information_warfare" title="Information warfare">Information warfare</a></li>
<li><a href="Internet_security" title="Internet security">Internet security</a></li>
<li><a href="Mobile_security" title="Mobile security">Mobile security</a></li>
<li><a href="Network_security" title="Network security">Network security</a></li>
<li><a href="Copy_protection" title="Copy protection">Copy protection</a></li>
<li><a href="Digital_rights_management" title="Digital rights management">Digital rights management</a></li></ul>
</div></td></tr></tbody></table></div>
<div class="navbox-styles"></div><div role="navigation" class="navbox" aria-labelledby="Malware_topics109" style="padding:3px"><table class="nowraplinks mw-collapsible autocollapse navbox-inner" style="border-spacing:0;background:transparent;color:inherit"><tbody><tr><th scope="col" class="navbox-title" colspan="2"><div id="Malware_topics109" style="font-size:114%;margin:0 4em"><a href="Malware" title="Malware">Malware</a> topics</div></th></tr><tr><th scope="row" class="navbox-group" style="width:1%">Infectious malware</th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Comparison_of_computer_viruses" title="Comparison of computer viruses">Comparison of computer viruses</a></li>
<li><a href="Computer_virus" title="Computer virus">Computer virus</a></li>
<li><a href="Computer_worm" title="Computer worm">Computer worm</a></li>
<li><a href="List_of_computer_worms" title="List of computer worms">List of computer worms</a></li>
<li><a href="Timeline_of_computer_viruses_and_worms" title="Timeline of computer viruses and worms">Timeline of computer viruses and worms</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Concealment</th><td class="navbox-list-with-group navbox-list navbox-even hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul>
<li><a href="Clickjacking" title="Clickjacking">Clickjacking</a></li>
<li><a href="Man-in-the-browser" title="Man-in-the-browser">Man-in-the-browser</a></li>
<li><a href="Man-in-the-middle_attack" title="Man-in-the-middle attack">Man-in-the-middle</a></li>
<li><a href="Rootkit" title="Rootkit">Rootkit</a></li>
<li><a href="Trojan_horse_(computing)" title="Trojan horse (computing)">Trojan horse</a></li>
<li><a href="Zombie_(computing)" title="Zombie (computing)">Zombie computer</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Malware for profit</th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Adware" title="Adware">Adware</a></li>
<li><a href="Botnet" title="Botnet">Botnet</a></li>
<li><a href="Crimeware" title="Crimeware">Crimeware</a></li>
<li><a href="Fleeceware" title="Fleeceware">Fleeceware</a></li>
<li><a href="Form_grabbing" title="Form grabbing">Form grabbing</a></li>
<li><a href="Dialer#Fraudulent_dialer" title="Dialer">Fraudulent dialer</a></li>
<li><a href="Infostealer" title="Infostealer">Infostealer</a></li>
<li><a href="Keystroke_logging" title="Keystroke logging">Keystroke logging</a></li>
<li><a href="Internet_bot#Malicious_purposes" title="Internet bot">Malbot</a></li>
<li><a href="Privacy-invasive_software" class="mw-redirect" title="Privacy-invasive software">Privacy-invasive software</a></li>
<li><a href="Ransomware" title="Ransomware">Ransomware</a></li>
<li><a href="Rogue_security_software" title="Rogue security software">Rogue security software</a></li>
<li><a href="Scareware" title="Scareware">Scareware</a></li>
<li><a href="Spyware" title="Spyware">Spyware</a></li>
<li><a href="Web_threat" title="Web threat">Web threats</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">By operating system</th><td class="navbox-list-with-group navbox-list navbox-even hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li>Android malware</li>
<li>Classic Mac OS viruses</li>
<li>iOS malware</li>
<li><a href="Linux_malware" title="Linux malware">Linux malware</a></li>
<li>MacOS malware</li>
<li><a href="Macro_virus" title="Macro virus">Macro virus</a></li>
<li><a href="Mobile_malware" title="Mobile malware">Mobile malware</a></li>
<li><a href="Palm_OS_viruses" title="Palm OS viruses">Palm OS viruses</a></li>
<li><a href="HyperCard_viruses" class="mw-redirect" title="HyperCard viruses">HyperCard viruses</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Protection</th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Anti-keylogger" title="Anti-keylogger">Anti-keylogger</a></li>
<li><a href="Antivirus_software" title="Antivirus software">Antivirus software</a></li>
<li><a href="Browser_security" title="Browser security">Browser security</a></li>
<li><a href="Data_loss_prevention_software" title="Data loss prevention software">Data loss prevention software</a></li>
<li><a href="Defensive_computing" title="Defensive computing">Defensive computing</a></li>
<li><a href="Firewall_(computing)" title="Firewall (computing)">Firewall</a></li>
<li><a href="Internet_security" title="Internet security">Internet security</a></li>
<li><a href="Intrusion_detection_system" title="Intrusion detection system">Intrusion detection system</a></li>
<li><a href="Mobile_security" title="Mobile security">Mobile security</a></li>
<li><a href="Network_security" title="Network security">Network security</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Countermeasures</th><td class="navbox-list-with-group navbox-list navbox-even hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Computer_and_network_surveillance" title="Computer and network surveillance">Computer and network surveillance</a></li>
<li><a href="Honeypot_(computing)" title="Honeypot (computing)">Honeypot</a></li>
<li><a href="Operation%3A_Bot_Roast" title="Operation: Bot Roast">Operation: Bot Roast</a></li></ul>
</div></td></tr></tbody></table></div>
<div class="navbox-styles"></div><div role="navigation" class="navbox authority-control" aria-label="Navbox390" style="padding:3px"><table class="nowraplinks hlist navbox-inner" style="border-spacing:0;background:transparent;color:inherit"><tbody><tr><th scope="row" class="navbox-group" style="width:1%">Authority control databases: National </th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em"><ul><li><span class="uid"><a rel="nofollow" class="external text" href="https://d-nb.info/gnd/4704524-3">Germany</a></span></li></ul></div></td></tr></tbody></table></div>
<style data-mw-deduplicate="TemplateStyles:r1130092004">
/* start https://en.wikipedia.org/ */
.mw-parser-output .portal-bar{font-size:88%;font-weight:bold;display:flex;justify-content:center;align-items:baseline}.mw-parser-output .portal-bar-bordered{padding:0 2em;background-color:#fdfdfd;border:1px solid #a2a9b1;clear:both;margin:1em auto 0}.mw-parser-output .portal-bar-related{font-size:100%;justify-content:flex-start}.mw-parser-output .portal-bar-unbordered{padding:0 1.7em;margin-left:0}.mw-parser-output .portal-bar-header{margin:0 1em 0 0.5em;flex:0 0 auto;min-height:24px}.mw-parser-output .portal-bar-content{display:flex;flex-flow:row wrap;flex:0 1 auto;padding:0.15em 0;column-gap:1em;align-items:baseline;margin:0;list-style:none}.mw-parser-output .portal-bar-content-related{margin:0;list-style:none}.mw-parser-output .portal-bar-item{display:inline-block;margin:0.15em 0.2em;min-height:24px;line-height:24px}@media screen and (max-width:768px){.mw-parser-output .portal-bar{font-size:88%;font-weight:bold;display:flex;flex-flow:column wrap;align-items:baseline}.mw-parser-output .portal-bar-header{text-align:center;flex:0;padding-left:0.5em;margin:0 auto}.mw-parser-output .portal-bar-related{font-size:100%;align-items:flex-start}.mw-parser-output .portal-bar-content{display:flex;flex-flow:row wrap;align-items:center;flex:0;column-gap:1em;border-top:1px solid #a2a9b1;margin:0 auto;list-style:none}.mw-parser-output .portal-bar-content-related{border-top:none;margin:0;list-style:none}}.mw-parser-output .navbox+link+.portal-bar,.mw-parser-output .navbox+style+.portal-bar,.mw-parser-output .navbox+link+.portal-bar-bordered,.mw-parser-output .navbox+style+.portal-bar-bordered,.mw-parser-output .sister-bar+link+.portal-bar,.mw-parser-output .sister-bar+style+.portal-bar,.mw-parser-output .portal-bar+.navbox-styles+.navbox,.mw-parser-output .portal-bar+.navbox-styles+.sister-bar{margin-top:-1px}
/* end https://en.wikipedia.org/ */
</style></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-07-30" href="https://en.wikipedia.org/wiki/?title=Backdoor_(computing)&oldid=1303265713">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
</body></html>