Start Learning
Vulnerabilities · FTP

FTP Vulnerabilities on Metasploitable 2

Metasploitable 2 runs vsftpd 2.3.4, a version whose source was tampered with on a public mirror in 2011. It's kept here as a hands-on lesson in compromised software supply chains, not just an open port.

M2

Written by the M2 Lab Team · Cybersecurity writers focused on practical lab environments, network security, and penetration-testing education. Published Jan 22, 2026 · Updated Sep 13, 2026.

Quick Answer

Port 21 on Metasploitable 2 runs vsftpd 2.3.4, a version whose source was compromised in 2011 (CVE-2011-2523) to include a hidden command shell trigger. It's identified through a simple version banner grab — no exploitation needed to recognize it.

ServicePortNotes
vsftpd21/tcpVersion 2.3.4, backdoored build (CVE-2011-2523)

Why It Exists

Between June 30 and July 3, 2011, the vsftpd-2.3.4.tar.gz source archive on the project's official download server was replaced with a tampered copy. Rapid7 kept this exact version on Metasploitable 2 specifically to teach the concept: sometimes the vulnerability isn't a bug in otherwise-correct code, it's tampering somewhere in the distribution chain. This is tracked as CVE-2011-2523.

How the Backdoor Mechanism Works

The tampered source added a trigger condition to the login-handling code: if a client attempted to authenticate with a username containing the character sequence :) (a smiley face), the backdoored binary would skip normal authentication and instead bind a command shell to TCP port 6200. Anyone who noticed the trigger and connected to that port got an unauthenticated root shell — no password required. This is why, alongside port 21, a scan of Metasploitable 2 will sometimes also show port 6200 open if the backdoor has been triggered during a prior session.

How It's Identified

A standard service-enumeration scan grabs the FTP banner, which reports the version string directly:

nmap -sV -p 21 192.168.56.101

Returns a banner identifying "vsftpd 2.3.4." Recognizing that exact string as historically backdoored is a matter of knowing your software's incident history, not finding a subtle flaw through testing.

Metasploit's module database documents this under exploit/unix/ftp/vsftpd_234_backdoor, which is the standard reference point security tooling uses to flag the version — useful to know the module exists, even if your only goal on this page is recognizing the banner.

The Lesson

Version numbers matter beyond just "is this patched." Some versions carry a documented history of tampering entirely separate from ordinary bugs, and a security-aware read of a banner grab should account for that. This is also a clean, concrete example of a software supply-chain attack — the same category of risk behind incidents like SolarWinds and XZ Utils, just at a much smaller and easier-to-study scale.

How Defenders Mitigate It

Verify checksums and, where available, cryptographic signatures on any downloaded package before deploying it. Subscribe to vendor security advisories and CVE feeds for the software you run. Most importantly: if a specific release is ever confirmed tampered, treat every install of that exact version as compromised and replace it, rather than assuming a later patch alone resolves the exposure.

!

Only interact with this service inside your own isolated Metasploitable 2 lab. Testing it against a system you don't own or have written permission to test is illegal in most jurisdictions.

Related: the Nmap scanning tutorial to see how banner grabbing works in practice, and legacy services for a second backdoored-software example (UnrealIRCd) on the same machine.

FAQ

Is every version of vsftpd affected?

No. This issue was specific to a tampered download of version 2.3.4 during a narrow window in 2011. Current vsftpd releases are unaffected.

What does a banner grab actually show?

Just the text a service sends when a client connects, which conventionally includes the software name and version. It requires no special access to read.

What CVE covers the vsftpd 2.3.4 backdoor?

CVE-2011-2523. It tracks the specific tampered vsftpd 2.3.4 download that shipped with a hidden backdoor between June 30 and July 3, 2011.

How does the vsftpd backdoor actually work?

The tampered source added a trigger: attempting to log in with a username containing a smiley face sequence (:)) caused the backdoored binary to open a command shell on port 6200 instead of processing the login normally.

Is vsftpd itself an insecure FTP server?

No. vsftpd ("very secure FTP daemon") was designed with security as a primary goal. The 2011 incident was a one-time supply-chain compromise of a specific download, not a flaw in vsftpd's own code or design.