The vsftpd 2.3.4 Backdoor Supply Chain Attack
Updated 5 Oct 2026 · Incident date 30 Jun 2011 · source tarball
vsftpd 2.3.2 -> vsftpd 2.3.4 tarball served on the master site 2011-06-30 to 2011-07-03sysdeputil.cIn June and July 2011, an attacker replaced the vsftpd 2.3.4 download tarball on the project's master site with a version that held a backdoor. A user who logged in with a name that contained the characters :) got a command shell on port 6200. The CVE is CVE-2011-2523.
The flaw was not in the original code. The attacker changed the file in the distribution channel.
What happened
An unknown attacker uploaded a different version of vsftpd 2.3.4 to the master download site. Wikipedia and The Register report that the archive was tampered with between 30 June and 1 July 2011 and that the author, Chris Evans, found it on Sunday 3 July 2011 and removed it that day. Evans moved the main download to a new site on Google App Engine afterward.
The xorl analysis explains the code. The change was in str.c. When the user name begins with the bytes 0x3a 0x29 (the characters :)) in the parsed string, a function named vsf_sysutil_extra() runs. That function opens a TCP socket on port 6200 and starts /bin/sh on it, with input and output tied to the connection. The analysis adds that a valid user name character must come before the smiley, for example X:).
The shell did not need a valid password. The backdoor worked for anyone who can reach both the FTP port and port 6200. The sources give no list of victims.
Vigilance compares the version you trust with the new one. A release that gained a function that opens a socket and starts a shell is the kind of change it reports. See the scan block below.
Affected versions
- vsftpd 2.3.4, from the tarball
vsftpd-2.3.4.tar.gzon the master site from 30 June to 3 July 2011.
Only that download was affected. Other versions of vsftpd and copies of 2.3.4 from other sources, such as distribution packages built from clean source, are not named in the sources.
Indicators of compromise
- A user name that contains
:)in FTP logs. - A listener on TCP port
6200on the FTP server. - The byte sequence
0x3a29and the function namevsf_sysutil_extrain the source filestr.c.
The sources fetched here give no file hash for the bad tarball, so this page lists none.
How to check
Check whether the source tree has the function name. If you built vsftpd from a 2.3.4 tarball, search the source:
grep -rn "vsf_sysutil_extra" vsftpd-2.3.4/
Any match means the tarball is the backdoored one. To check a running server, look for a listener on port 6200.
ss -ltnp | grep :6200
Also check the installed version with vsftpd -v.
What to do now
- Upgrade to a patched version of vsftpd later than 2.3.4, from a source that you trust.
- If a server ran the backdoored build, treat it as compromised. The shell ran with the rights of the server process, so rebuild the host.
- Block inbound traffic to port 6200 at the firewall.
- Check downloaded source against the author's GPG signature.
- Replace anonymous or open FTP with a service that you need.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 22 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED configure It now downloads from the internet and runs other programs. It did not before.
Frequently asked questions
Which vsftpd version contained the backdoor?
Version 2.3.4, from the tarball on the master site between 30 June and 3 July 2011, contained the backdoor.
How does the vsftpd 2.3.4 backdoor work?
A user name with a smiley face, the characters :), starts a function that opens port 6200 and runs a shell. The attacker then connects to that port.
Sources
More supply chain attacks
- XZ Utils backdoor 24 Feb 2024
- Webmin SourceForge build backdoor 1 Apr 2018
- phpMyAdmin 3.5.2.2 SourceForge mirror backdoor 22 Sept 2012
- ProFTPD 1.3.3c source tarball backdoor 28 Nov 2010
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.