Every time I write about Windows security software, I get a predictable flood of responses from Linux advocates who claim that they don’t need any such protection. Today comes a shining example of why they’re wrong.
If you downloaded and installed the open-source Unreal IRC server in the last 8 months or so, you’ve been pwned. Here’s the official announcement:
Hi all,
This is very embarrassing…
We found out that the Unreal3.2.8.1.tar.gz file on our mirrors has been replaced quite a while ago with a version with a backdoor (trojan) in it.
This backdoor allows a person to execute ANY command with the privileges of the user running the ircd. The backdoor can be executed regardless of any user restrictions (so even if you have passworded server or hub that doesn’t allow any users in).
I have always advocated that Linux is not immune to malware, and to install from trusted sources, always, regardless of your platform. This is something that drives the point home to all Linux users. Granted, this software is for anyone running an IRC server on their box, and (at least on Ubuntu) would have to be manually installed, since it isn't in the trusted repos. But always keep your PC's security on the brain.