The ProFTPD 1.3.3c Source Tarball Backdoor
Updated 5 Oct 2026 · Incident date 28 Nov 2010 · source tarball
ProFTPD 1.3.3b -> 1.3.3c (tarball served from ftp.proftpd.org and mirrors 2010-11-28 to 2010-12-02)src/help.cThe ProFTPD 1.3.3c source tarball contained a backdoor between 28 November and 2 December 2010. The tracking ids are CVE-2010-20103 and GHSA-xm7r-423x-5463. The backdoor gave an unauthenticated remote user a shell on the server.
The poisoned archive was the official download for about five days.
What happened
Someone added a hidden FTP command to the ProFTPD download archive. The GitHub advisory says the hidden command causes the server to run arbitrary shell commands with root privileges. It needs no authentication and no user interaction, and it works over the network. The advisory gives a CVSS v4 score of 9.3.
The Rapid7 Metasploit module page confirms that the backdoor was added to the ProFTPD download archive and that the archive carried it from 28 November to 2 December 2010. The module targets Linux and Unix.
The change sits in src/help.c. When the server receives the hidden HELP ACIDBITCHEZ command, the code switches to root and starts /bin/sh. The same tarball also changed configure and added tests/tests.c, according to the aldeid analysis of the backdoored archive.
Affected versions
Only the tarball of ProFTPD 1.3.3c downloaded in the window is affected.
- Window: 28 November 2010 to 2 December 2010
- Version: 1.3.3c source tarball
- Not affected: a 1.3.3c installed from a distribution package that did not use the poisoned archive
Anyone who compiled the tarball from the official site or a mirror in the window has the backdoor in the built server.
Indicators of compromise
- A ProFTPD 1.3.3c server built from a tarball downloaded between 28 November and 2 December 2010
- A
proftpdprocess that starts a shell - Unexpected root shells that start from the FTP service
The sources I fetched give no file hashes. Compare your source tree with a clean tarball from the project.
How to check
Check the server version.
proftpd -v
If it reports 1.3.3c, check when you downloaded the source. Search the source tree for the shell call that the record names.
grep -n "/bin/sh" src/help.c
A clean help.c has no shell spawn in it. Run this on the source tree you used to build, not on a live server.
What to do now
- Stop the ProFTPD service if the source came from the bad archive.
- Rebuild from a clean tarball of a later release.
- Treat the server as compromised. The backdoor gave root access, so review it from the start.
- Rotate credentials and keys on that server.
- Check tarball integrity against signed checksums before you build.
Vigilance compares the version you trust with a new one and reports the file that gained a new capability. Here a help source file gained a shell spawn. See all attacks.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 28 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED configure It now downloads from the internet and reads saved passwords and access keys. It did not before.
Frequently asked questions
Which ProFTPD version had the backdoor?
The ProFTPD 1.3.3c source tarball, served from 28 November to 2 December 2010. The id is CVE-2010-20103.
How do I check if my ProFTPD has the backdoor?
Run proftpd -v. If it reports 1.3.3c, check when you downloaded the source and rebuild from a clean tarball of a later release.
Sources
More supply chain attacks
- XZ Utils backdoor 24 Feb 2024
- Webmin SourceForge build backdoor 1 Apr 2018
- phpMyAdmin 3.5.2.2 SourceForge mirror backdoor 22 Sept 2012
- vsftpd 2.3.4 backdoor 30 Jun 2011
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.