Skip to main content

Backdoored vsftpd Source Code Served from Official Site

posted onJuly 4, 2011
by l33tdawg

Unidentified attackers have managed to backdoor the official vsftpd source package prompting the project's administrator to issue an alert and switch hosting providers.

Vsftpd is a popular FTP daemon used by some important open source projects. It is developed and maintained by reputed vulnerability researcher Chris Evans. "Earlier today, I was alerted that a vsftpd download from the master site (vsftpd-2.3.4.tar.gz) appeared to contain a backdoor," Evans announced on his blog on Sunday.

According to the security engineer, the backdoor attempts to create a TCP callback shell when the rogue instance receives a ":)" (smiley face) request.

Source

Tags

Security Software-Programming

You May Also Like

Recent News

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th