Backdoor found in UnrealIRCD 3.2.8.1

XoC--

Regular Member
Jr. VIP
Premium Member
Joined
Mar 5, 2009
Messages
271
Reaction score
120
We found out that the Unreal3.2.8.1.tar.gz file on our mirrors has been replaced quite a while ago with a version with a backdoor (trojan) in it.
This backdoor allows a person to execute ANY command with the privileges of the user running the ircd. The backdoor can be executed regardless of any user restrictions (so even if you have passworded server or hub that doesn't allow any users in).

http://forums.unrealircd.com/viewtopic.php?t=6562

I'm kind of surprised this doesn't happen more often or does it?
A lot of projects are being hosted off site in mirrors including FireFox, imagine the potential.
 
Back
Top