ProFTPD distribution servers compromised
It was announced that the source for ProFTPD was compromised and a back door was inserted. The attacker compromised the main ftp.proftpd.org site on November 28, 2010. This site is also the main rsync server, which means that anybody who has downloaded ProFTPD between then and December 1, 2010 is potentially running a version with the backdoor code. According to reports, this compromise was performed against an unpatched vulnerability within ProFTPD itself, so even if you did not install the backdoored version, you may be running vulnerable software.
More information is available at here
Kevin Johnson
×
Diary Archives
Comments
purdy@tecman.com
Cool
Dec 2nd 2010
1 decade ago
I just hope this was a hacker and not a cracker.
purdy@tecman.com
please hack my site ;)
Yellow
Dec 2nd 2010
1 decade ago