201k views
3 votes
What version of vsftpd contained the smiley face backdoor?

User Draculater
by
5.4k points

1 Answer

1 vote

Answer:

Chris Evans, author of vsftpd announced that the master site for vsftpd was compromised and that the latest version of vsftpd (vsftpd-2.3.4.tar.gz) was backdoored. The backdoor payload is interesting. In response to a smiley face in the FTP username, a TCP callback shell is attempted. There is no obfuscation.

Step-by-step explanation:

User Nabeela
by
5.9k points