Skip to Content

Backdoor: a hidden access that bypasses security

A backdoor is a hidden access point that allows normal authentication mechanisms of a system to be bypassed. It may be installed by an attacker after an intrusion, or sometimes exist from the initial design of a piece of software.

Definition

A backdoor installed by an attacker guarantees them persistent access, even after an initial vulnerability has been fixed. This is precisely why a complete incident response goes beyond simply patching the entry vulnerability: it actively looks for any access that may have been left in place.

Some backdoors are not malicious in origin: maintenance or debugging functions forgotten in a product can, if discovered, be exploited as undocumented access. An audit of code or a penetration test can identify them.

Key points

Access that persists

A backdoor often survives the correction of the initial vulnerability, giving the attacker lasting access.

Sometimes not malicious in origin

Forgotten maintenance access can become, once discovered, an exploitable backdoor.

A systematic search after an incident

A serious incident response includes searching for persistent access left by the attacker.

How BCIT can support you

Our penetration tests and our incident response engagements include searching for undocumented or persistent access.

Frequently asked questions ❓

Can a backdoor survive a security patch?

Yes, that is precisely what makes it dangerous: fixing the entry vulnerability does not remove access already installed by the attacker.

How can you know whether a backdoor has been left in place?

A complete incident response, or a targeted penetration test, systematically includes an active search for undocumented access.

Not ready to talk yet? Discover our cybersecurity diagnostic →

Are you sure that no hidden access remains?

A penetration test or a targeted audit can remove any doubt.