Slashdot Mirror


ProFTPD.org Compromised, Backdoor Distributed

Orome1 writes "A warning has been issued by the developers of ProFTPD, the popular FTP server software, about a compromise of the main distribution server of the software project that resulted in attackers exchanging the offered source files for ProFTPD 1.3.3c with a version containing a backdoor. It is thought that the attackers took advantage of an unpatched security flaw in the FTP daemon in order to gain access to the server."

4 of 152 comments (clear)

  1. Should have used vsftpd by sparkz · · Score: 4, Funny

    Oh, the irony

    --
    Author, Shell Scripting : Expert Re
  2. Re:FTP by Rhaban · · Score: 4, Funny

    People still use Joomla?

  3. Wait, what was the hole again? by jonaskoelker · · Score: 4, Funny

    resulted in attackers exchanging the offered source files for ProFTPD 1.3.3c with a version containing a backdoor. It is thought that the attackers took advantage of an unpatched security flaw in the FTP daemon in order to gain access to the server.

    So instead of downloading an FTP server with a security hole, you could download one with... a security hole.

  4. Re:not on Debian stable by Anonymous Coward · · Score: 2, Funny

    thankfully that fancy new version will be available from official repository for Debian stable in about 100 years or so..

    That newfangled FTP protocol is still pretty new to the Debian Stable folks.