LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Closed Thread
  Search this Thread
Old 12-05-2010, 07:46 AM   #1
tronayne
Senior Member
 
Registered: Oct 2003
Location: Northeastern Michigan, where Carhartt is a Designer Label
Distribution: Slackware 32- & 64-bit Stable
Posts: 3,541

Rep: Reputation: 1065Reputation: 1065Reputation: 1065Reputation: 1065Reputation: 1065Reputation: 1065Reputation: 1065Reputation: 1065
ProFTPD Main File Server Hacked, Possible Backdoor Inserted


This was reported in http://indiepropub.com/new-backdoor-...erable/312889/:
Quote:
One of the most popular open-source projects was compromised between Nov. 28 and Dec. 2.

ProFTPD, a file transfer protocol (FTP) server, had its main file server hacked and a version that contained a backdoor trojan was uploaded. Anyone who downloaded version 1.3.3c of the software in that timeframe are vulnerable.

The trojan allows full access to the system by attackers. The ProFTPD project team advised anyone who may be vulnerable to check for compromises and immediately update to a non-compromised version that is available on the website. The team also provided a link that can check the security signatures on their site here.

Analysts have speculated that an unpatched vulnerability in the FTP server daemon running on the ProFTPD site allowed the hackers access to the server. From there it was easy for them to simply replace the legitimate source code with the new version containing the backdoor. The breach was discovered on Dec. 1, and fixed, but due to time lags in servers mirroring the master download site, the warning was issued for anyone downloading the software between Nov. 28 and Dec. 2.
Checking my system,
Code:
ls -l /var/log/packages/proftp*
-rw-r--r-- 1 root root 7835 2010-11-02 07:24 /var/log/packages/proftpd-1.3.3c-x86_64-1_slack13.1
Nope, not between the dates, but if somebody did download from the project server between those dates...

Hope this helps some.

Last edited by tronayne; 12-05-2010 at 07:48 AM.
 
Old 12-05-2010, 08:08 AM   #2
allend
LQ 5k Club
 
Registered: Oct 2003
Location: Melbourne
Distribution: Slackware64-15.0
Posts: 6,375

Rep: Reputation: 2754Reputation: 2754Reputation: 2754Reputation: 2754Reputation: 2754Reputation: 2754Reputation: 2754Reputation: 2754Reputation: 2754Reputation: 2754Reputation: 2754
Also reported here on LQ. http://www.linuxquestions.org/questi...ibuted-847916/
 
Old 12-05-2010, 09:04 AM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Indeed. FUPs (if any) to http://www.linuxquestions.org/questi...ibuted-847916/, TIA.
 
  


Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
ProFTPD.org Compromised, Backdoor Distributed win32sux Linux - Security 1 12-02-2010 01:07 PM
Backdoor to server? Joe of Loath Linux - Server 16 11-29-2010 06:36 AM
Weirdness with ProFTPd and Logwatch: hacked? pdeman2 Linux - Security 3 06-19-2006 08:59 PM
Displaying a html file when CD is inserted ... how to do it? tuxfood Linux - General 4 03-17-2006 02:04 PM
IS there any antivirus soft for my Slackware Proftpd file server ! RINO2004 Linux - Software 3 06-22-2004 03:17 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 04:23 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration