The ProFTPD 1.3.3c Source Tarball Backdoor

Updated 5 Oct 2026 · Incident date 28 Nov 2010 · source tarball

PackageProFTPD 1.3.3b -> 1.3.3c (tarball served from ftp.proftpd.org and mirrors 2010-11-28 to 2010-12-02)
Filesrc/help.c

The ProFTPD 1.3.3c source tarball contained a backdoor between 28 November and 2 December 2010. The tracking ids are CVE-2010-20103 and GHSA-xm7r-423x-5463. The backdoor gave an unauthenticated remote user a shell on the server.

The poisoned archive was the official download for about five days.

What happened

Someone added a hidden FTP command to the ProFTPD download archive. The GitHub advisory says the hidden command causes the server to run arbitrary shell commands with root privileges. It needs no authentication and no user interaction, and it works over the network. The advisory gives a CVSS v4 score of 9.3.

The Rapid7 Metasploit module page confirms that the backdoor was added to the ProFTPD download archive and that the archive carried it from 28 November to 2 December 2010. The module targets Linux and Unix.

The change sits in src/help.c. When the server receives the hidden HELP ACIDBITCHEZ command, the code switches to root and starts /bin/sh. The same tarball also changed configure and added tests/tests.c, according to the aldeid analysis of the backdoored archive.

Affected versions

Only the tarball of ProFTPD 1.3.3c downloaded in the window is affected.

Anyone who compiled the tarball from the official site or a mirror in the window has the backdoor in the built server.

Indicators of compromise

The sources I fetched give no file hashes. Compare your source tree with a clean tarball from the project.

How to check

Check the server version.

proftpd -v

If it reports 1.3.3c, check when you downloaded the source. Search the source tree for the shell call that the record names.

grep -n "/bin/sh" src/help.c

A clean help.c has no shell spawn in it. Run this on the source tree you used to build, not on a live server.

What to do now

  1. Stop the ProFTPD service if the source came from the bad archive.
  2. Rebuild from a clean tarball of a later release.
  3. Treat the server as compromised. The backdoor gave root access, so review it from the start.
  4. Rotate credentials and keys on that server.
  5. Check tarball integrity against signed checksums before you build.

Vigilance compares the version you trust with a new one and reports the file that gained a new capability. Here a help source file gained a shell spawn. See all attacks.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old ProFTPD-1.3.3b --new ProFTPD-1.3.3c
files scanned: 28

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    configure
           It now downloads from the internet and reads saved passwords and access keys. It did not before.

Frequently asked questions

Which ProFTPD version had the backdoor?

The ProFTPD 1.3.3c source tarball, served from 28 November to 2 December 2010. The id is CVE-2010-20103.

How do I check if my ProFTPD has the backdoor?

Run proftpd -v. If it reports 1.3.3c, check when you downloaded the source and rebuild from a clean tarball of a later release.

Sources

  1. github.com/advisories/GHSA-xm7r-423x-5463
  2. rapid7.com/db/modules/exploit/unix/ftp/proftpd_133c_backdoor/
  3. aldeid.com/wiki/Exploits/proftpd-1.3.3c-backdoor

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free