The UnrealIRCd 3.2.8.1 Tarball Backdoor

Updated 5 Oct 2026 · Incident date 1 Nov 2009 · source tarball

PackageUnrealIRCd 3.2.8.1 (official, md5 7b741e94e867c0a7370553fd01506c66) -> backdoored Unreal3.2.8.1.tar.gz (md5 752e46f2d873c1679fa99de3f52a274d)
Fileinclude/struct.h

The UnrealIRCd 3.2.8.1 source tarball Unreal3.2.8.1.tar.gz held a backdoor that let anyone run commands on the server. Attackers replaced the tarball around 10 November 2009, and the project found it on 12 June 2010.

Rapid7 lists the issue as CVE-2010-2075.

What happened

Attackers broke into the official UnrealIRCd site and FTP mirrors and swapped the 3.2.8.1 tarball for a trojaned one. The project announcement, posted by Syzops on 12 June 2010, says the compromise started around November 2009. Rapid7 and LWN date the swap to about 10 November 2009, so the backdoor stayed in place for about seven months.

The backdoor was a disguised debug macro in include/struct.h. LWN explains that a command that starts with the letters AB went straight to system(). Commands ran with the rights of the user that ran the server. Access restrictions on the IRC server did not stop it. The project says that the code is in the core, so removing a module does not help. LWN reports that the code entered the Gentoo distribution.

A clean 3.2.8.1 tarball with a published MD5 sum existed. The bad tarball gained a macro that pipes attacker text into a shell call. A diff of include/struct.h between the two shows it at once.

Read the project announcement, LWN and the Rapid7 module page.

Affected versions

Indicators of compromise

How to check

Hash the tarball and search the header file. The project gave both checks in its announcement.

md5sum Unreal3.2.8.1.tar.gz
grep DEBUG3_DOLOG_SYSTEM include/struct.h

Run the second command in the source folder. Two lines of output mean the source is trojaned. A hash of 752e46f2... also means the bad tarball.

What to do now

  1. Stop any UnrealIRCd server built from a 3.2.8.1 tarball downloaded after 10 November 2009.
  2. Download the source again from the official site and check the MD5 sum against 7b741e94e867c0a7370553fd01506c66.
  3. Recompile and restart. Removing a module is not enough.
  4. Treat the host as compromised, because attackers could run any command. Check it for changes and rotate credentials stored on it.
  5. Verify signatures. The project started to sign releases with GPG after this incident.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old UnrealIRCd-prev --new UnrealIRCd-current
files scanned: 85

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    configure
           It now runs other programs. It did not before.

Frequently asked questions

What was the UnrealIRCd 3.2.8.1 backdoor?

A trojaned source tarball with a macro in include/struct.h that passed text starting with AB to system(), so attackers could run commands on the server.

How do I check if my UnrealIRCd is backdoored?

Run md5sum on the tarball and compare it with 7b741e94e867c0a7370553fd01506c66. Also run grep DEBUG3_DOLOG_SYSTEM include/struct.h. Two lines of output mean a trojaned copy.

How long was the UnrealIRCd backdoor in the tarball?

About seven months, from around 10 November 2009 to 12 June 2010.

Sources

  1. seclists.org/fulldisclosure/2010/Jun/277
  2. lwn.net/Articles/392201/
  3. rapid7.com/db/modules/exploit/unix/irc/unreal_ircd_3281_backdoor/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free