The UnrealIRCd 3.2.8.1 Tarball Backdoor
Updated 5 Oct 2026 · Incident date 1 Nov 2009 · source tarball
UnrealIRCd 3.2.8.1 (official, md5 7b741e94e867c0a7370553fd01506c66) -> backdoored Unreal3.2.8.1.tar.gz (md5 752e46f2d873c1679fa99de3f52a274d)include/struct.hThe UnrealIRCd 3.2.8.1 source tarball Unreal3.2.8.1.tar.gz held a backdoor that let anyone run commands on the server. Attackers replaced the tarball around 10 November 2009, and the project found it on 12 June 2010.
Rapid7 lists the issue as CVE-2010-2075.
What happened
Attackers broke into the official UnrealIRCd site and FTP mirrors and swapped the 3.2.8.1 tarball for a trojaned one. The project announcement, posted by Syzops on 12 June 2010, says the compromise started around November 2009. Rapid7 and LWN date the swap to about 10 November 2009, so the backdoor stayed in place for about seven months.
The backdoor was a disguised debug macro in include/struct.h. LWN explains that a command that starts with the letters AB went straight to system(). Commands ran with the rights of the user that ran the server. Access restrictions on the IRC server did not stop it. The project says that the code is in the core, so removing a module does not help. LWN reports that the code entered the Gentoo distribution.
A clean 3.2.8.1 tarball with a published MD5 sum existed. The bad tarball gained a macro that pipes attacker text into a shell call. A diff of include/struct.h between the two shows it at once.
Read the project announcement, LWN and the Rapid7 module page.
Affected versions
- Affected:
Unreal3.2.8.1.tar.gzdownloaded after 10 November 2009. - Not affected: the Windows builds, CVS, and version 3.2.8 and earlier.
Indicators of compromise
- MD5 of the backdoored tarball:
752e46f2d873c1679fa99de3f52a274d - MD5 of the official tarball:
7b741e94e867c0a7370553fd01506c66 - The string
DEBUG3_DOLOG_SYSTEMininclude/struct.h. A trojaned copy returns two lines. A clean copy returns none. - Official Windows installers, for comparison:
Unreal3.2.8.1.exe5a6941385cd04f19d9f4241e5c912d18andUnreal3.2.8.1-SSL.exea54eafa6861b6219f4f28451450cdbd3
How to check
Hash the tarball and search the header file. The project gave both checks in its announcement.
md5sum Unreal3.2.8.1.tar.gz
grep DEBUG3_DOLOG_SYSTEM include/struct.h
Run the second command in the source folder. Two lines of output mean the source is trojaned. A hash of 752e46f2... also means the bad tarball.
What to do now
- Stop any UnrealIRCd server built from a 3.2.8.1 tarball downloaded after 10 November 2009.
- Download the source again from the official site and check the MD5 sum against
7b741e94e867c0a7370553fd01506c66. - Recompile and restart. Removing a module is not enough.
- Treat the host as compromised, because attackers could run any command. Check it for changes and rotate credentials stored on it.
- Verify signatures. The project started to sign releases with GPG after this incident.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 85 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED configure It now runs other programs. It did not before.
Frequently asked questions
What was the UnrealIRCd 3.2.8.1 backdoor?
A trojaned source tarball with a macro in include/struct.h that passed text starting with AB to system(), so attackers could run commands on the server.
How do I check if my UnrealIRCd is backdoored?
Run md5sum on the tarball and compare it with 7b741e94e867c0a7370553fd01506c66. Also run grep DEBUG3_DOLOG_SYSTEM include/struct.h. Two lines of output mean a trojaned copy.
How long was the UnrealIRCd backdoor in the tarball?
About seven months, from around 10 November 2009 to 12 June 2010.
Sources
More supply chain attacks
- XZ Utils backdoor 24 Feb 2024
- Webmin SourceForge build backdoor 1 Apr 2018
- phpMyAdmin 3.5.2.2 SourceForge mirror backdoor 22 Sept 2012
- vsftpd 2.3.4 backdoor 30 Jun 2011
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.