Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

July 4th, 2011, 09:33 GMT · By

Backdoored vsftpd Source Code Served from Official Site

SHARE:

Adjust text size:


vsftpd sources backdoored
Enlarge picture
Unidentified attackers have managed to backdoor the official vsftpd source package prompting the project's administrator to issue an alert and switch hosting providers.

Vsftpd is a popular FTP daemon used by some important open source projects. It is developed and maintained by reputed vulnerability researcher Chris Evans.

"Earlier today, I was alerted that a vsftpd download from the master site (vsftpd-2.3.4.tar.gz) appeared to contain a backdoor," Evans announced on his blog on Sunday.

According to the security engineer, the backdoor attempts to create a TCP callback shell when the rogue instance receives a ":)" (smiley face) request.

The attacker did not include a method of being notified of vulnerable installations, so they probably didn't care about mass compromise.

It's likely they were interested in a certain party deploying the backdoored version, or, as Evans says, they were just having some lulz.

Since vsftpd packages are redistributed by various Linux distros, it is highly probable that the backdoor would have been detected in before reaching users.

Some of the high-profile FTP servers based on vsftpd include ftp.redhat.com, ftp.suse.com, ftp.debian.com, ftp.freebsd.com, ftp.gnu.org, ftp.gnome.org, ftp.kde.org, ftp.kernel.org, ftp.gimp.org, and ftp.isc.org.

The backdoored package did not match the signature published on the official website for vsftpd-2.3.4, outlining the importance of checking download signatures.

To prevent similar compromises in the future Evans moved the vsftpd site and downloads to a hosting platform which he considers more secure: Google's App Engine.

It's worth noting that vsftpd is not the only project that had to deal with such a compromise. Last December, the maintainers of the ProFTPD project discovered that their distribution server was compromised and sources backdoored.

TELL US WHAT YOU THINK:

1,457 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


ProFTPD Distribution Server Compromised and Sources Backdoored

Linux Trojan Hid in Popular IRC Server Software for Months

PHP.net Wiki Server Hacked

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM