UnrealIRCd 3.2.8.1, as distributed from certain mirror sites between November 2009 and June 2010, was compromised with a Trojan Horse. The malicious modification was introduced in the DEBUG3_DOLOG_SYSTEM macro, enabling remote attackers to execute arbitrary system commands on affected servers. This was not a vulnerability in the original UnrealIRCd codebase, but rather a result of a supply chain compromise where the distributed source code was maliciously altered.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
6 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (6 hidden).
This three-file repository contains a standalone Python 3 exploit for the maliciously backdoored UnrealIRCd 3.2.8.1 distribution tracked as CVE-2010-2075. `main.py` uses only Python's `socket` module. It connects to the configured IRC target on TCP/6667, sends a minimal NICK/USER exchange, collects up to five banner reads, and proceeds only when the response contains `Unreal3.2.8.1`. It then listens on all local interfaces at TCP/4444, opens a second IRC connection, and sends the `AB;` command-execution trigger followed by a netcat/bash reverse-shell command. After receiving the callback, it relays interactive operator input to the shell. The README documents the historical supply-chain compromise, target lab assumptions, usage, and limitations. The code has basic timeout and connection-refusal handling, but a refused initial connection does not terminate execution and callback acceptance has no timeout.
This seven-file Portuguese-language repository is a documented isolated KVM/libvirt penetration-testing lab, not a packaged exploit tool. It contains a README, Nmap and Nikto scan outputs, a libvirt network XML definition, and evidence logs for two manual Netcat-based root-shell demonstrations. No standalone source-code exploit or executable entry point is present. The primary demonstrated exploit is CVE-2011-2523: an FTP USER value ending in `:)` is sent to the Metasploitable2 target's vsFTPd 2.3.4 service on TCP/21, after which the compromised service exposes a root shell on TCP/6200. A second evidence file shows direct unauthenticated root-shell access to the intentionally exposed Metasploitable bindshell on TCP/1524. The repository additionally records unexploited or unconfirmed exposure of UnrealIRCd, distccd, Java RMI, legacy web components, and other services. It explicitly states that testing occurred only against a personal intentionally vulnerable VM on isolated subnet 192.168.100.0/24.
Small standalone Bash exploit repository for CVE-2010-2075, the UnrealIRCd 3.2.8.1 backdoored tarball incident. The repo contains one executable script (exploit.sh), a README with usage and context, and a license file. The exploit is straightforward: it accepts RHOST, RPORT, LHOST, and LPORT as arguments, builds an AB;-prefixed command string understood by the trojanized UnrealIRCd service, and pipes it to the target using netcat. The embedded command launches /bin/bash on the victim and uses bash's /dev/tcp feature to create a reverse shell back to the attacker listener. This is a real exploit rather than a detector, with basic operational capability but no advanced features such as target validation, error handling, payload customization beyond CLI parameters, or persistence.
This repository contains a simple Ruby exploit script (exploit.rb) and a README.md with usage instructions. The exploit targets a network service (default port 6667) on a specified IP address, attempting to exploit a command injection vulnerability. The script connects to the target, sends a payload that injects the 'whoami' command, and attempts to redirect the output to the attacker's machine (192.168.56.102) on port 1111, where a netcat listener should be running. The README provides clear instructions for both attacker and victim setups. The exploit demonstrates basic command injection and exfiltration of command output over the network. No specific product or CVE is referenced, and the exploit is operational but not weaponized or part of a framework.
This repository contains a single Metasploit module: 'unreal_ircd_3281_backdoor.rb', which exploits a backdoor present in UnrealIRCD version 3.2.8.1. The backdoor was introduced in a compromised source archive distributed between November 2009 and June 12th, 2010. The exploit connects to the IRC server (default port 6667/TCP), sends a specially crafted command ('AB;' followed by the attacker's payload), and achieves remote command execution on the server. The module is fully integrated into the Metasploit framework, allowing the attacker to specify arbitrary shell commands as payloads. The exploit targets systems running the affected version of UnrealIRCD on Unix platforms and is associated with CVE-2010-2075. The code is mature and weaponized, providing reliable exploitation capabilities for the specified vulnerability.
This repository contains a Python exploit script (CVE-2010-2075.py) and a README for CVE-2010-2075, a backdoor vulnerability in UnrealIRCd 3.2.8.1. The exploit connects to a specified target IP and port (typically 6667 for IRC) and sends a specially crafted payload prefixed with 'AB;', which triggers the backdoor to execute arbitrary system commands. The script allows the attacker to specify any command, including reverse shell payloads, enabling full remote command execution on the vulnerable server. The README provides usage instructions and a demonstration of obtaining a reverse shell. The exploit is operational and requires the target to be running the specific vulnerable version of UnrealIRCd. No hardcoded IPs or domains are present; the attacker supplies the target and payload at runtime.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.