Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

December 2nd, 2010, 11:59 GMT · By

ProFTPD Distribution Server Compromised and Sources Backdoored

SHARE:

Adjust text size:


Official ProFTPD source code rigged with backdoor
Enlarge picture
Unknown attackers managed to compromise the main distribution server of the ProFTPD Project and rigged the source code with a root shell backdoor.

ProFTPD is a very popular open source FTP daemon (server) capable of running on most UNIX-like systems including Linux, BSD, Mac OS X and Solaris.

The software is distributed as source code from ftp.proftpd.org and other secondary distribution servers that mirror its content.

According to an announcement on the project’s website, the intrusion on ftp.proftpd.org happened sometime on November 28, but it wasn't detected until today.

All users who run versions of ProFTPD which have been downloaded and compiled in this time window are strongly advised to check their systems for security compromises and install unmodified versions of ProFTPD,” the project’s administrators write.

In an email to the proftpd-user mailing list, TJ Saunders, the ProFTPD maintainer, notes that attackers most likely exploited an unpatched security flaw in the FTP software to get in.

This is an interesting theory given that the ftp.proftpd.org has since been restored, but no alert of a zero-day critical vulnerability was issued.

Notable public FTP servers that use the ProFTPD software include ftp.apple.com, ftp.openssl.org and ftp.rsa.com.

With the newly gained access, the hackers modified the source code of ProFTPD 1.3.3c to include a backdoor that would allow them to obtain root shells on systems running the compromised version.

According to French vulnerability research company VUPEN Security, the backdoor can be activated by sending a command called "HELP ACIDBITCHEZ" to the FTP server and authentication is not necessary.

The unauthorized modification of the source code was noticed by Daniel Austin and relayed to the ProFTPD project by Jeroen Geilman on Wednesday, December 1 and fixed shortly afterwards,” Saunders notes.

TELL US WHAT YOU THINK:

1,085 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Free Software Collaborative Development Platform Hacked

Critical Remote Code Execution Vulnerability Fixed in ProFTPD

Complex Attack Hits Apache.org Services

Linux Trojan Hid in Popular IRC Server Software for Months

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM