Can someone provide some context? A python script alone is kind of hard to decipher.
I don't quite understand the special handling. Looks like it takes a byte from the server's output, hashes a special string containing that byte, and passes that back to the server. This is the backdoor.
Edit: Maybe that "special handling" is just standard protocol and it's just sending a plaintext password. I dunno.
EDIT: 5.0.7, not 5.0.2