The vsftpd 2.3.4 Backdoor Supply Chain Attack

Updated 5 Oct 2026 · Incident date 30 Jun 2011 · source tarball

Packagevsftpd 2.3.2 -> vsftpd 2.3.4 tarball served on the master site 2011-06-30 to 2011-07-03
Filesysdeputil.c

In June and July 2011, an attacker replaced the vsftpd 2.3.4 download tarball on the project's master site with a version that held a backdoor. A user who logged in with a name that contained the characters :) got a command shell on port 6200. The CVE is CVE-2011-2523.

The flaw was not in the original code. The attacker changed the file in the distribution channel.

What happened

An unknown attacker uploaded a different version of vsftpd 2.3.4 to the master download site. Wikipedia and The Register report that the archive was tampered with between 30 June and 1 July 2011 and that the author, Chris Evans, found it on Sunday 3 July 2011 and removed it that day. Evans moved the main download to a new site on Google App Engine afterward.

The xorl analysis explains the code. The change was in str.c. When the user name begins with the bytes 0x3a 0x29 (the characters :)) in the parsed string, a function named vsf_sysutil_extra() runs. That function opens a TCP socket on port 6200 and starts /bin/sh on it, with input and output tied to the connection. The analysis adds that a valid user name character must come before the smiley, for example X:).

The shell did not need a valid password. The backdoor worked for anyone who can reach both the FTP port and port 6200. The sources give no list of victims.

Vigilance compares the version you trust with the new one. A release that gained a function that opens a socket and starts a shell is the kind of change it reports. See the scan block below.

Affected versions

Only that download was affected. Other versions of vsftpd and copies of 2.3.4 from other sources, such as distribution packages built from clean source, are not named in the sources.

Indicators of compromise

The sources fetched here give no file hash for the bad tarball, so this page lists none.

How to check

Check whether the source tree has the function name. If you built vsftpd from a 2.3.4 tarball, search the source:

grep -rn "vsf_sysutil_extra" vsftpd-2.3.4/

Any match means the tarball is the backdoored one. To check a running server, look for a listener on port 6200.

ss -ltnp | grep :6200

Also check the installed version with vsftpd -v.

What to do now

  1. Upgrade to a patched version of vsftpd later than 2.3.4, from a source that you trust.
  2. If a server ran the backdoored build, treat it as compromised. The shell ran with the rights of the server process, so rebuild the host.
  3. Block inbound traffic to port 6200 at the firewall.
  4. Check downloaded source against the author's GPG signature.
  5. Replace anonymous or open FTP with a service that you need.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old vsftpd-prev --new vsftpd-current
files scanned: 22

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    configure
           It now downloads from the internet and runs other programs. It did not before.

Frequently asked questions

Which vsftpd version contained the backdoor?

Version 2.3.4, from the tarball on the master site between 30 June and 3 July 2011, contained the backdoor.

How does the vsftpd 2.3.4 backdoor work?

A user name with a smiley face, the characters :), starts a function that opens port 6200 and runs a shell. The attacker then connects to that port.

Sources

  1. xorl.wordpress.com/2011/07/05/vsftpd-2-3-4-backdoor/
  2. en.wikipedia.org/wiki/Vsftpd
  3. theregister.com/security/2011/07/05/popular-ftp-package-download-tarball-poisoned/1385024

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free