SIR DYSTIC

The Cult of the Dead Cow ran on jokes with a point, and in the summer of 1998 one of its newer members walked onstage at DEF CON 6 and handed the joke to the entire internet. Josh Buchbinder — "Sir Dystic" — had written a small Windows program that let anyone with a copy quietly take over a Windows 98 machine across a network. He called it Back Orifice, a pun on Microsoft's "BackOffice," and he said out loud that the point was to prove Windows had almost nothing underneath it. The antivirus industry filed it under "trojan horse" by lunchtime. He had named himself after a 1930s comic-book villain who keeps trying to do evil and keeps accidentally doing good — which is either the best joke in this whole file or a confession, depending on who you ask.

BO was supposed to be a statement about the fact that people feel secure and safe, although there are wide, gaping holes in both the operating system they're using and the means of defense they're using against hostile code.

Sir Dystic (Josh Buchbinder), on why he wrote Back Orifice — the remote-administration tool the antivirus industry immediately called a trojan

WHO
Josh Buchbinder — "Sir Dystic," member of Cult of the Dead Cow since May 1997 FACT
THE NAME
Taken from a 1930s bondage-comic character, "Sir Dystic D'Arcy," who — by his own telling — "tried to do evil things but always bungles it and ends up doing good inadvertently" FACT
THE DRAMA
Wrote Back Orifice and released it at DEF CON 6 on Aug 1, 1998 to embarrass Microsoft; cDc called it a security demonstration, the antivirus industry called it malware
ALSO BUILT
NBName (NetBIOS DoS, DEF CON 8, 2000), SMBRelay and SMBRelay2 (SMB man-in-the-middle, 2001), and NetE FACT
STATUS
ENSHRINED — the man who turned Windows 9x security into a punchline in front of a live audience

This file is not an accusation; Sir Dystic's most famous act — releasing Back Orifice — was a piece of theater with a stated security point, and the fight over what it "really" was is the drama. The through-line is a programmer who built a point-and-click remote-control tool for the most common consumer operating system on earth, said in plain language that the point was to prove the security wasn't there, and let the argument over whether that was research or a weapon run for the next twenty-five years. Both readings are true at once, which was always the joke.

the drama timeline

ACT I — THE VILLAIN WHO DOES GOOD BY ACCIDENT (1997)

A programmer joins the sassiest underground computer group in America and picks a handle that turns out to be a mission statement.

  1. MAY 1997

    Enter Sir Dystic

    Josh Buchbinder joins Cult of the Dead Cow under the handle "Sir Dystic," lifted from a 1930s bondage-comic character named Sir Dystic D'Arcy — a bungling would-be villain who, in Buchbinder's description, "always bungles it and ends up doing good inadvertently." He is, by cDc standards, a late arrival to a group that had been running its "t-file" ezine since 1984 (see Grandmaster Ratte').

ACT II — BACK ORIFICE AT DEF CON 6 (AUG 1998)

One member, one tool, one stage, one purpose: make Windows security a punchline in front of a conference hall.

  1. AUG 1, 1998

    The release

    At DEF CON 6 in Las Vegas, Sir Dystic releases Back Orifice — a Windows 9x remote-administration tool, default port 31337 ("elite"), whose name mocks Microsoft's "BackOffice" server line. His stated purpose: to demonstrate the lack of security in Windows 98. The antivirus industry immediately categorized it as malware, noting it could be installed without user interaction, hide from a casual look, and ship as the payload of a trojan horse. Both readings are true at once, which is the point.

    Cult of the Dead Cow, in the official DEF CON documentary's bonus footage: the theater that carried a serious point about the state of Windows security. (DEFCONConference, YouTube.)
  2. AUG 1998

    "A statement," in his own words

    Sir Dystic frames the release plainly: Back Orifice "was supposed to be a statement about the fact that people feel secure and safe, although there are wide, gaping holes" in both the operating system and the defenses running on it. The tool was the argument; the discomfort it caused was the argument landing.

ACT III — RESEARCH OR WEAPON (1998–1999)

The moment it shipped, everyone agreed on what Back Orifice did and split cleanly over what it was for.

  1. 1998

    The antivirus verdict

    Antivirus vendors and Microsoft treat Back Orifice as a straightforward attack tool: a remote-access trojan that a hostile installer could drop silently, giving an attacker point-and-click control of a victim's machine. Script kiddies used it exactly that way, which made the classification look correct on its own terms.

  2. JUL 10, 1999

    BO2k — the sequel he didn't write

    At DEF CON 7, cDc releases Back Orifice 2000 (BO2k) — a rebuilt, open-source version targeting Windows NT, authored not by Sir Dystic but by fellow cDc member DilDog. Sir Dystic wrote the original; the franchise carried the argument forward. Same point, bigger surface.

ACT IV — MORE TOOLS, SAME MESSAGE (2000–2001)

Back Orifice was the famous one, but it was a habit: find the gap, write the proof, hand it to the room.

  1. JUL 29, 2000

    NBName at DEF CON 8

    Sir Dystic releases NBName, a tool that can disable the NetBIOS name service on a network — a denial-of-service against Windows networking that, again, doubles as a demonstration that the protocol had no defense against it.

  2. MAR 21, 2001

    SMBRelay

    He releases SMBRelay and SMBRelay2, tools enabling man-in-the-middle attacks against the Windows SMB file-sharing protocol — a class of weakness that would still be haunting Windows networks many years later. The pattern is set: name the hole, ship the proof of concept, let the vendor argue about it afterward.

both sides, on the record

Back Orifice was an attack tool: whatever Sir Dystic called it, the program could be installed without the user's knowledge, hide from a casual inspection, and ship as the payload of a trojan horse — and it was, widely, by people with no interest in "security research." Microsoft and the antivirus industry filed it under malware on day one, and a wave of script-kiddie infections made that classification look accurate [2].

Shipping the capability is not neutral: releasing a point-and-click remote-control tool for the most common consumer OS on earth, from a stage, is an act with consequences. Sir Dystic supplied the capability; the internet decided what to do with it, and a lot of what it did was not research.

The point was real, and it landed: Windows 9x genuinely lacked the security model to stop a tool like Back Orifice, and Sir Dystic's stated purpose was to prove that in public rather than let it stay quietly true. Embarrassment is a legitimate patch-forcing mechanism, and Windows did get more defensible in the years that followed [1].

He said what it was for: the tool was released with an explicit argument — that users "feel secure and safe" while sitting on "wide, gaping holes." That is a research thesis stated out loud, not a crime concealed, and the handle he chose — the villain who does good by accident — telegraphed the whole stance [1].

It was one of a series of proofs: NBName and SMBRelay followed the same method — find the gap in Windows networking, write the demonstration, hand it to a conference — which reads as a consistent disclosure practice, not opportunistic malware authorship [1].

YOU DECIDE

Back Orifice really could be weaponized, and really was — and it really did expose that Windows 9x had almost nothing underneath it. Both facts are load-bearing; keep one and drop the other and you get either Microsoft's press release or the fan's poster. Strip the myth away and Sir Dystic is a programmer who built a working proof that the emperor had no security, gave it a filthy joke of a name, said in plain English what it was for, and let the world spend twenty-five years deciding whether that made him a researcher or a vandal.

The archive does not deify. The archive keeps the announcement text — and the antivirus signature.

evidence locker

PRIMARY / REFERENCE

  1. Wikipedia — Sir Dystic ATTRIBUTED — the May 1997 cDc membership, the comic-book origin of the handle, the authorship of Back Orifice and its DEF CON 6 debut, his first-party "wide, gaping holes" statement of purpose, and the later tools (NBName at DEF CON 8, SMBRelay/SMBRelay2, NetE). en.wikipedia.org/wiki/Sir_Dystic
  2. Wikipedia — Back Orifice ATTRIBUTED — the Aug 1, 1998 DEF CON 6 release, the "BackOffice" pun and port 31337, cDc's stated purpose ("demonstrate the lack of security in Microsoft's Windows"), and the antivirus industry's immediate malware/trojan classification. Both sides of the dispute. en.wikipedia.org/wiki/Back_Orifice
  3. DEF CON 6 media archive — cDc "Back Orifice Announcement" PRIMARY — the group's own announcement text for the tool, from the DEF CON 6 conference archive. media.defcon.org/…/Back Orifice Announcement.txt
  4. DEF CON documentary bonus footage — "CDC muxed" (DEFCONConference, YouTube) PRIMARY — cDc footage from the official DEF CON documentary, embedded above. youtube.com/watch?v=C9WjzBThpUg

CONTEXT & CROSS-LINKS

  1. Wikipedia — Back Orifice 2000 ATTRIBUTED — the 1999 DEF CON 7 sequel, written by cDc's DilDog rather than Sir Dystic; context for the franchise the original started. en.wikipedia.org/wiki/Back_Orifice_2000
  2. troll.fan — Cult of the Dead Cow CROSS-LINK — the group Sir Dystic joined in 1997 and released Back Orifice under. troll.fan/dossiers/cult-of-the-dead-cow.html
  3. troll.fan — Grandmaster Ratte' CROSS-LINK — the cDc founder whose slaughterhouse ezine Sir Dystic joined thirteen years in. troll.fan/dossiers/grandmaster-ratte.html
  4. troll.fan — DEF CON CROSS-LINK — the stage where Back Orifice (DEF CON 6, 1998) and NBName (DEF CON 8, 2000) debuted. troll.fan/dossiers/defcon.html
  5. troll.fan — Crew Rivalries & the scene timeline CROSS-LINK — cDc's place among the crews of the era, and the wider chronology. troll.fan/crew-rivalries.html · troll.fan/timeline.html
The standard. Josh Buchbinder is a public figure of twenty-five years' standing; his cDc membership, the authorship and DEF CON 6 release of Back Orifice, the "BackOffice" pun, his stated purpose, and the later tools are matters of record on the reference pages above. Back Orifice is presented as disputed — his stated intent and the antivirus/Microsoft view are both given at full strength, attributed. Back Orifice 2000 is noted as DilDog's work, not his. Nothing beyond the public record is asserted. If a line here couldn't survive scrutiny, it wouldn't be on the page.