Backdoored vsftpd Source Code Served from Official Site
Unidentified attackers have managed to backdoor the official vsftpd source package prompting the project's administrator to issue an alert and switch hosting providers.
Vsftpd is a popular FTP daemon used by some important open source projects. It is developed and maintained by reputed vulnerability researcher Chris Evans. "Earlier today, I was alerted that a vsftpd download from the master site (vsftpd-2.3.4.tar.gz) appeared to contain a backdoor," Evans announced on his blog on Sunday.
According to the security engineer, the backdoor attempts to create a TCP callback shell when the rogue instance receives a ":)" (smiley face) request.