Jump to content

vsftpd

From Wikipedia, the free encyclopedia

This is an old revision of this page, as edited by Dan100 (talk | contribs) at 08:39, 1 July 2020 (See also). The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

vsftpd
Developer(s)Chris Evans
Stable release
3.0.3 / July 25, 2015 (2015-07-25)
Operating systemUnix-like systems
TypeFTP daemon
LicenseGPL
Websitesecurity.appspot.com/vsftpd.html

vsftpd, (or very secure FTP daemon),[1] is an FTP server for Unix-like systems, including Linux. It is licensed under the GNU General Public License. It supports IPv6, TLS and FTPS (explicit since 2.0.0 and implicit since 2.1.0). It is the default FTP server in the Ubuntu, CentOS, Fedora, NimbleX, Slackware and RHEL Linux distributions.

Compromised website

In July 2011, it was discovered that vsftpd version 2.3.4 downloadable from the master site had been compromised.[2][3] Users logging into a compromised vsftpd-2.3.4 server may issue a ":)" smileyface as the username and gain a command shell on port 6200.[3] This was not an issue of a security hole in vsftpd, instead, an unknown attacker had uploaded a different version of vsftpd which contained a backdoor. Since then, the site was moved to Google App Engine.

See also

References

  1. ^ "README file from source code".[dead link]
  2. ^ vsftpd Compromised Source Packages Backdoor Vulnerability at SecurityFocus
  3. ^ a b Evans, Chris (2011-06-03). "Alert: vsftpd download backdoored". Retrieved July 7, 2011.