FYI…

ProFTPD server hacked…
- http://www.darkreading.com/taxonomy/index/…le/id/228500217
Dec 02, 2010 - "The main FTP server that serves up the open-source ProFTPD FTP software was hacked and booby-trapped with a backdoor Trojan - meaning anyone who downloaded the code during the past few days from the server or its mirror servers could be running a compromised copy of the software that would allow the attacker full access to his systems. The ProFTPD Project team yesterday reported* that these servers were hosting the compromised version of the ProFTPD 1.3.3c source code, which runs on Unix and Unix-like systems. "All users who run versions of ProFTPD which have been downloaded and compiled in this time window are strongly advised to check their systems for security compromises and install unmodified versions of ProFTPD," the team posted on its site*. They also provided a link** for users to check the integrity of their ProFTPD code.
According to an analysis of the breach***, the likely entry point for the attackers was an unpatched security hole in the FTP server daemon, which gave them access to the server, where the attackers then swapped out the legitimate code with their backdoored version. The breach was discovered and fixed…"
* http://www.proftpd.org/index.html

** http://www.proftpd.org/md5_pgp.html

*** http://sourceforge.net/mailarchive/message…r.castaglia.org
___

- http://www.theregister.co.uk/2010/12/21/pr…oor_upload_bug/
21st December 2010
- http://www.proftpd.org/docs/NEWS-1.3.3d
1.3.3d - Released 17-Dec-2010

- http://www.proftpd.org/docs/RELEASE_NOTES-1.3.3d

:ph34r: <_<