CVE-2011-2523 refers to a maliciously backdoored distribution of vsftpd 2.3.4 that was available for download during a limited window in late June and early July 2011. The issue is not a conventional implementation flaw in the upstream daemon logic, but a supply-chain compromise in which additional code was inserted into the distributed package. The implanted logic inspects the FTP USER command for the string ":)". When that sequence is present in the supplied username, the backdoor invokes a hidden routine that creates a TCP listener on port 6200, accepts an inbound connection, redirects standard input, output, and error to the socket, and executes /bin/sh. Successful triggering therefore exposes an unauthenticated remote shell on the affected host.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
17 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (45 hidden).
This seven-file Portuguese-language repository is a documented isolated KVM/libvirt penetration-testing lab, not a packaged exploit tool. It contains a README, Nmap and Nikto scan outputs, a libvirt network XML definition, and evidence logs for two manual Netcat-based root-shell demonstrations. No standalone source-code exploit or executable entry point is present. The primary demonstrated exploit is CVE-2011-2523: an FTP USER value ending in `:)` is sent to the Metasploitable2 target's vsFTPd 2.3.4 service on TCP/21, after which the compromised service exposes a root shell on TCP/6200. A second evidence file shows direct unauthenticated root-shell access to the intentionally exposed Metasploitable bindshell on TCP/1524. The repository additionally records unexploited or unconfirmed exposure of UnrealIRCd, distccd, Java RMI, legacy web components, and other services. It explicitly states that testing occurred only against a personal intentionally vulnerable VM on isolated subnet 192.168.100.0/24.
This three-file repository contains a standalone Python proof-of-exploitation script for CVE-2011-2523, the trojanized vsFTPd 2.3.4 distribution. main.py uses only Python's socket library. It connects to a manually configured target on FTP TCP/21, reads the banner, and proceeds only when the parsed parenthesized version exactly matches "vsFTPd 2.3.4". It sends USER and PASS values containing ':)' to trigger the known backdoor, then connects to TCP/6200 and provides a basic interactive command loop for the resulting root bind shell. The implementation includes handling for refused connections, DNS errors, and timeouts, but has no command-line arguments, authentication, logging, or payload customization beyond editing the hardcoded target variable. README.md documents the historical supply-chain compromise, intended Metasploitable2 lab use, expected root-shell behavior, and references; .gitignore excludes standard Python, IDE, capture, and sensitive configuration artifacts.
This is a small standalone Python/pwntools exploit proof of concept for CVE-2011-2523, the maliciously backdoored vsFTPd 2.3.4 source distribution. The repository contains one executable code file (Exploit.py), a README describing setup and lab use, and a standard Python .gitignore. Exploit.py accepts a target IP address and optional FTP port, connects to the FTP service, parses the banner text following `vsFTPd ` through the closing `)`, and proceeds only if the reported version exactly equals `2.3.4`. It then sends `USER hello:)` and a password, which invokes the implanted backdoor behavior, waits one second, and connects to the expected TCP/6200 bind shell with an interactive session. It is a functional exploitation tool rather than merely a detection script. A minor implementation caveat is that custom ports are passed from argv without explicit integer conversion, and the script references `sys.argv` without an explicit `import sys` (though pwntools wildcard imports may make this work depending on its exported namespace).
The repository contains one README.md file, but that file embeds a complete Python 3 exploit rather than only documentation. It targets CVE-2011-2523, the backdoored vsftpd 2.3.4 FTP distribution, reportedly tested on Debian. The script accepts a target host as a positional argument, connects to TCP/21 through Python's telnetlib, waits for the '(vsFTPd 2.3.4)' banner, and sends 'USER nergal:)' followed by a dummy password. This username is the known trigger for the vsftpd backdoor. It then opens a second Telnet connection to target TCP/6200 and exposes an interactive shell to the operator. The code includes basic SIGINT handling and configurable-in-source FTP port/banner checks. No scanning, version-range handling, persistence, credential theft, or post-exploitation automation is included.
The repository contains one standalone POSIX C++ exploit program, exploit_vsftpd_2_3_4.cpp, targeting the malicious/backdoored vsftpd 2.3.4 release tracked as CVE-2011-2523. It accepts a target IPv4 address as its sole command-line argument, connects to FTP on TCP/21, reads the server banner without validating it, and sends the backdoor trigger `USER user:)` followed by a password command. It closes the FTP session, waits five seconds for the backdoor listener to initialize, then attempts a TCP connection to port 6200 on the same target. If successful, its select()-based interactive_shell routine multiplexes local standard input and the remote socket, providing an interactive bind-shell terminal. There are no hardcoded external IP addresses, domains, download URLs, persistence mechanisms, or post-exploitation commands; the only target-specific network values are the caller-provided IP and hardcoded ports 21 and 6200.
This repository is a small write-up style exploit/CTF repository rather than a standalone exploit tool. It contains 4 files: a README with the full attack narrative and embedded Python proof-of-concept, a loot file recording the recovered flag, an Nmap scan output file, and a .gitignore excluding cracked/hash artifacts. The core exploit capability is a manual network exploit for CVE-2011-2523, the backdoored vsftpd 2.3.4 release. The embedded Python snippet connects to the target FTP service on 10.150.150.12:21, sends a USER value containing ':)' to trigger the malicious code path, sends any password, waits briefly, and then connects to the resulting root bind shell on 10.150.150.12:6200. Once connected, it can execute arbitrary commands as root; the example runs 'id' and the write-up shows post-exploitation access to /root/FLAG1.txt. The repository does not include a reusable exploit script file; the exploit exists only as code embedded in README.md, so maturity is best classified as POC. Additional repository context includes enumeration artifacts showing anonymous FTP access, SSH on port 22, and host details for an Ubuntu 20.04.1 target named 'portal'. Overall purpose: document reconnaissance, exploitation, and flag capture for a vulnerable host running the vsftpd 2.3.4 backdoor.
This repository is a small standalone Python 3 exploit for the vsftpd 2.3.4 backdoor (CVE-2011-2523). It contains three files: an MIT LICENSE, a README describing usage and operational caveats, and a single code file, v2b_exploit.py. The script is dependency-free and uses only the Python standard library (argparse, select, socket, sys, time). The exploit workflow is straightforward: it optionally connects to the target FTP service and reads the banner to check for 'vsftpd 2.3.4'; it then connects again and sends an FTP USER command with a username containing ':)' ('smile:)') followed by a PASS command, which triggers the malicious backdoor; after a short delay it repeatedly attempts to connect to the spawned shell listener on TCP/6200; once connected, it provides an interactive raw shell interface and immediately runs 'id; uname -a' to verify privilege and host details. On exit, it sends 'exit' and cleanly shuts down the socket so the one-shot backdoor listener is released. Main exploit capabilities: remote network exploitation of a backdoored FTP daemon, banner verification, backdoor triggering, retry logic for shell connection, and interactive arbitrary command execution as root. The README also documents an important operational constraint: port 6200 behaves as a single-client mutex, so only one shell session can exist at a time and stale listeners may require cleanup or reboot. There are no hardcoded external IPs or URLs. The primary fingerprintable targets are the user-supplied target IP, FTP port 21 by default, and the backdoor shell port 6200 by default.
Small standalone Python proof-of-concept exploit for CVE-2011-2523, the malicious backdoor present in compromised vsFTPd 2.3.4 distributions. The repository contains only three files: a GPL license, a short README with usage/installation notes, and the main exploit script `poc.py`. The script uses `pwntools` and `argparse`, accepts a target IP and optional FTP port, connects to the FTP service, and sends the classic backdoor trigger sequence `USER pwn:)` and `PASS pwn:)`. After a short delay it attempts a second TCP connection to port 6200, which is the shell listener exposed by the backdoored daemon. If successful, it verifies shell access by echoing a hardcoded delimiter string, then enters an interactive loop that sends arbitrary commands and reads output until the delimiter is seen. Functionally, this is a real exploit rather than a detector: it provides interactive remote command execution/root shell access on vulnerable targets. The code is simple and operational, but not heavily weaponized or modular.
This repository is a lab-oriented operational proof-of-concept for a complete SOC investigation scenario built around CVE-2011-2523, the vsftpd 2.3.4 backdoor. It is not just a detector or write-up: the main attack logic is in src/run_attack_chain.sh, which orchestrates a four-phase intrusion against an isolated Metasploitable2 target at 172.23.0.200. Phase 1 performs aggressive Nmap reconnaissance across multiple ports and writes scan artifacts. Phase 2 exploits the vulnerable FTP service either through Metasploit's exploit/unix/ftp/vsftpd_234_backdoor module or manually by sending a USER value containing ':)' to TCP/21, then connecting to the spawned root shell on TCP/6200. Phase 3 provides post-exploitation persistence instructions: create a local user named sysbackup, grant passwordless sudo via /etc/sudoers, and install a cron-based reverse shell callback to the attacker on port 9999. Phase 4 demonstrates exfiltration by sending a sample sensitive file from /tmp/sensitive_data.txt to a netcat listener on attacker port 5555. The repository structure supports both offense and investigation. src/build_timeline.py is a Python utility that parses Metasploit logs, auth logs, and tshark CSV exports, classifies events into RECON/EXPLOIT/PERSIST/EXFIL phases using regex rules, extracts IOCs, and emits JSON and Markdown reports. configs/splunk_detection_rules.spl contains Splunk SPL queries for detecting each phase, including the notable port-6200 backdoor connection and non-standard exfiltration port 5555. docker/docker-compose.yml defines the isolated Metasploitable2 lab environment on subnet 172.23.0.0/24. samples/sample_timeline.json shows expected output from the timeline builder. Overall purpose: demonstrate an end-to-end attacker workflow and the corresponding defender telemetry correlation for a historically significant backdoored service. The exploit capability is real but constrained to a deliberately vulnerable lab target. The code is best characterized as OPERATIONAL because it includes actionable exploitation and post-exploitation steps, but payloads and workflow are largely hardcoded for the lab scenario rather than broadly weaponized.
This repository is a small standalone proof-of-concept exploit for CVE-2011-2523, the backdoored vsFTPd 2.3.4 release. It contains two files: a Python exploit script (CVE-2011-2523.py) and a README describing the vulnerability, requirements, and usage. The Python script uses pwntools to connect over the network to a target FTP service, read the banner until it finds 'vsFTPd ' and the version string, and abort unless the banner reports version 2.3.4. If the version matches, it sends the known trigger sequence using a username containing ':)' ('USER hello:)') and a password ('PASS hello123'), then closes the FTP connection. After a short delay, it connects to TCP port 6200 on the same target and drops the operator into an interactive shell via pwntools' interactive mode. The exploit is therefore a real remote code execution exploit, not merely a detector. Its capability is limited to exploiting the built-in backdoor and attaching to the resulting shell; it does not include post-exploitation automation, scanning, payload customization, or persistence features. The repository structure is minimal and purpose-built for demonstrating exploitation of vulnerable vsFTPd instances, such as lab targets or intentionally vulnerable VMs.
This repository is a small standalone Python proof-of-concept exploit for the vsftpd 2.3.4 backdoor vulnerability (CVE-2011-2523). It contains three files: an MIT LICENSE, a README with basic installation and execution instructions, and a single Python exploit script, `vsftpd_234_backdoor.py`. The script is the only code file and the clear entry point. The exploit works in two stages. First, it enumerates local IPv4 interfaces using `psutil.net_if_addrs()`, skips loopback and link-local addresses, and tests which local source IP can reach the victim's FTP service on TCP/21. It then binds a socket to that local interface and connects to the target FTP server. After receiving the banner, it sends a crafted FTP username `USER test:)` followed by `PASS test`, which is the classic trigger for the maliciously backdoored vsftpd 2.3.4 build. Second, after a short delay, it opens a new TCP connection to the same target on port 6200, which is the backdoor listener created by the vulnerable service. If successful, the script enters an interactive loop, sending user-supplied commands and printing returned output, effectively giving the operator a remote root shell. The exploit is operational rather than a mere detector: it does not just check for vulnerability, it actively triggers the backdoor and provides command execution. There is no advanced payload customization or framework integration; the payload is hardcoded to the known backdoor trigger and a simple interactive shell. No external URLs, domains, or hardcoded IPs are present. The main fingerprintable network targets are TCP/21 for FTP and TCP/6200 for the spawned shell. The script also includes helper functions for safe socket reads and collecting all available shell output. Overall, the repository's purpose is straightforward: exploit a backdoored vsftpd 2.3.4 instance to obtain an interactive root shell over the network.
Repository purpose: proof-of-concept exploit for vsftpd 2.3.4 backdoor command execution (CVE-2011-2523), demonstrating manual steps and an automated Python script. Structure: - README.md: Explains the vulnerability and provides manual exploitation steps (scan port 21, trigger backdoor with username containing ':)', then connect to port 6200 with netcat). Also includes the same Python PoC code. - script.py: The actual automated exploit. Takes two CLI args: target IP and a command string. - LICENSE: Apache 2.0. - .gitignore: Standard Python ignores. Exploit flow (script.py): 1) Uses Python ftplib to connect to the target FTP service (default port 21) with a short timeout. 2) Logs in using username 'user:)' (the ':)' sequence is the trigger) and any password; exceptions are ignored. 3) Sleeps 1 second to allow the service to open the backdoor listener. 4) Opens a raw TCP socket to the target on port 6200 (the backdoor shell), sends the provided command plus newline, receives up to 4096 bytes, prints output, and closes. Notable limitations: no robust error handling (exceptions mostly ignored), assumes the backdoor binds on 6200 and returns output in a single recv, and executes only one command per run.
This repository contains a Bash script (vsftpd_exploit.sh) designed to automate the exploitation of the vsftpd 2.3.4 backdoor vulnerability (CVE-2011-2523). The script first checks if the target's FTP port (21) is open and if the service is running the vulnerable version. If so, it attempts to trigger the backdoor by logging in with a username ending in ':)', then connects to the shell opened by the backdoor on TCP port 6200. The script provides colored terminal output and a help panel for ease of use. The README.md provides usage instructions and describes the exploit's purpose. The exploit is operational and provides a shell if successful, but is not weaponized or part of a larger framework.
This repository contains a Python exploit for CVE-2011-2523, targeting the maliciously backdoored version of vsFTPd 2.3.4. The exploit works by connecting to the target's FTP service on port 21 and sending a specially crafted username (ending with ':)'), which activates the backdoor if present. After a short delay, the exploit attempts to connect to port 6200, where the backdoored vsFTPd spawns a root shell. The user is then provided with an interactive shell interface. The exploit is only effective against the compromised vsFTPd 2.3.4 binary and will not work against legitimate versions. The repository is structured simply, with a single Python exploit script (exploit.py), a README with usage instructions and background, a license file, and a bonus note for CTF players. No hardcoded IPs or domains are present; the target IP is supplied by the user at runtime.
This repository contains a Python exploit (main.py) for the vsftpd 2.3.4 backdoor vulnerability (CVE-2011-2523). The exploit connects to a target FTP server on port 21 and sends a specially crafted USER command containing ':)', which triggers the backdoor in vulnerable versions of vsftpd. After a short delay, the exploit attempts to connect to port 6200 on the same host, where the backdoor opens a shell. The script then provides an interactive prompt, allowing the attacker to execute arbitrary commands on the compromised server. The repository consists of a README.md describing the vulnerability and the main exploit script. The exploit is operational and provides a working shell if the target is vulnerable.
This repository contains a Python exploit script (exploit.py) targeting the backdoored vsftpd 2.3.4 FTP server (CVE-2011-2523). The exploit works by connecting to the target's FTP service (default port 21) and sending a specially crafted username containing ':)', which triggers the backdoor to open a shell on TCP port 6200. The script then connects to this shell, providing the attacker with an interactive command shell on the target system. The exploit is operational and provides remote code execution capabilities. The repository is simple, containing only a license, a README with usage instructions and background, and the exploit script itself. No framework is used; the exploit is standalone and written in Python.
This repository contains a single Python script, 'vsftpd234-exploit.py', which exploits the backdoor present in vsftpd version 2.3.4 (CVE-2011-2523). The script connects to the target's FTP service, triggers the backdoor by sending a specially crafted username, and then attempts to open a shell on the target's port 6200. It delivers a base64-encoded reverse shell payload that, when executed, causes the target to connect back to the attacker's machine on a specified port, providing an interactive shell. The script is operational and requires the attacker to specify the target's address and port, as well as their own address and port for the reverse shell connection. The exploit is network-based, targeting the FTP service on port 21 and the backdoor shell on port 6200. The payload is a Python one-liner that spawns a bash shell and connects it to the attacker's listener. The repository is focused, containing only the exploit script, and is intended for use against vulnerable vsftpd 2.3.4 instances.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A supply-chain backdoor in the maliciously distributed vsftpd 2.3.4 package that opens a root shell on port 6200/TCP when triggered during login.
A malicious backdoor in the vsftpd 2.3.4 package that is triggered when a username containing ':)' is supplied during FTP login, causing the server to open a shell listener on TCP port 6200 and enabling remote shell access.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.