Ouch! Security Focus has a news piece titled, “Root kit surface after Jabber attack” which explains that the Jabber development servers have been owned for more then a year! These attacks, which have happened on other projects, are particularly nasty if they inject malicious code into a large software project. Not only did the developers have to discover that the box was owned, but now everyone working on the project needs to comb the source code looking for changes (and you can’t trust the revision control systems.) If the project’s source was modified, it’s amazing that it took this long for someone to notice — especially if it meant a backdoor went out to all servers running the Jabber engine!