vendor:
ProFTPD
by:
Daniel Austin and Jeroen Geilman
8,8
CVSS
HIGH
Backdoor vulnerability
264
CWE
Product Name: ProFTPD
Affected Version From: 1.3.3c
Affected Version To: 1.3.3c
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: All
2010
ProFTPD Compromise Report
The attackers most likely used an unpatched security issue in the FTP daemon to gain access to the server and used their privileges to replace the source files for ProFTPD 1.3.3c with a version which contained a backdoor.
Mitigation:
Users are strongly advised to check systems running the affected code for security compromises and compile/run a known good version of the code. To verify the integrity of the source files, use the GPG signatures available on the FTP servers as well on the ProFTPD homepage.