1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

TO - All Hosts - IMPORTANT - SECURITY ALERT - URGENT !!

Discussion in 'Security' started by ishan, Mar 7, 2008.

  1. #1
    SECURITY ALERT: Horde arbitrary file inclusion vulnerability


    We at LaceHost have already updated cPanel to the latest version.
    I would recommend all of you to do so too.

    Thank you
    Ishan
     
    ishan, Mar 7, 2008 IP
  2. mycoolworld

    mycoolworld Peon

    Messages:
    577
    Likes Received:
    9
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Thanks a lot Ishan.
    Regards
     
    mycoolworld, Mar 7, 2008 IP
  3. prilep

    prilep Well-Known Member

    Messages:
    3,852
    Likes Received:
    228
    Best Answers:
    0
    Trophy Points:
    185
    #3
    Umm this was out 2 days ago and I already updated everything :). This will probably warn others.

    - Prilep :D
     
    prilep, Mar 7, 2008 IP
  4. ishan

    ishan Prominent Member

    Messages:
    2,212
    Likes Received:
    88
    Best Answers:
    0
    Trophy Points:
    325
    #4
    ????????????
    The update was released on 6th March , & its still 6th March in some parts of the world :)

    http://changelog.cpanel.net/

    :p
     
    ishan, Mar 7, 2008 IP
  5. prilep

    prilep Well-Known Member

    Messages:
    3,852
    Likes Received:
    228
    Best Answers:
    0
    Trophy Points:
    185
    #5
    I was saying the problem with horde was released a couple of days ago :) and I disabled it right away :).

    - Prilep :D
     
    prilep, Mar 7, 2008 IP
  6. IwhiC

    IwhiC Peon

    Messages:
    2,594
    Likes Received:
    61
    Best Answers:
    0
    Trophy Points:
    0
    #6
    HI, yes, I got a IM from the head server tech at my data center telling me to update as well, so all of you on our servers, we will be updating this soon..

    Thanks for the heads up..
     
    IwhiC, Mar 7, 2008 IP
  7. Lime-Designs

    Lime-Designs Active Member

    Messages:
    357
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    60
    #7
    Hi thanks yes our techs have updated thank you.
     
    Lime-Designs, Mar 7, 2008 IP
  8. 55host.net

    55host.net Peon

    Messages:
    480
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #8
    we just updated our systems too, thank you for the update.
     
    55host.net, Mar 7, 2008 IP
  9. Hostable

    Hostable Guest

    Messages:
    76
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #9
    It's so great when all hosts come together and and tell each other important stuff :D
     
    Hostable, Mar 7, 2008 IP
  10. Hostable

    Hostable Guest

    Messages:
    76
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #10
    It's so great when all hosts come together and and tell each other important stuff :D
     
    Hostable, Mar 7, 2008 IP
  11. IwhiC

    IwhiC Peon

    Messages:
    2,594
    Likes Received:
    61
    Best Answers:
    0
    Trophy Points:
    0
    #11
    All of our updates have been completed..
     
    IwhiC, Mar 7, 2008 IP
  12. st_jimi

    st_jimi Peon

    Messages:
    632
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    0
    #12
    we just updated our servers too,

    i was reading some stuff on this at wht and there saying you should update cpanel but still disable horde untill horde release a patch
     
    st_jimi, Mar 7, 2008 IP
  13. IwhiC

    IwhiC Peon

    Messages:
    2,594
    Likes Received:
    61
    Best Answers:
    0
    Trophy Points:
    0
    #13
    I was reading that as well, we still have our horde disabled for now, untill I here back from either cpanel or the data center, to confirm.
     
    IwhiC, Mar 7, 2008 IP
  14. prilep

    prilep Well-Known Member

    Messages:
    3,852
    Likes Received:
    228
    Best Answers:
    0
    Trophy Points:
    185
    #14
    I disabled horde 3 or 4 days ago and updated cPanel now :).

    - Prilep :D
     
    prilep, Mar 7, 2008 IP
  15. InFloW

    InFloW Peon

    Messages:
    1,488
    Likes Received:
    39
    Best Answers:
    0
    Trophy Points:
    0
    #15
    Patched in builds later than 21594

    Or if you go by version then you're looking at:

    For 11.19.x Everything 11.19.2 or newer is patched
    For 11.18.x Everything 11.18.2 or newer is patched


    You can check by running:

    /scripts/autorepair check_horde_patch


    cPanel patched it and sent it to the Horde Project for inclusion in their code base.
     
    InFloW, Mar 7, 2008 IP
  16. ishan

    ishan Prominent Member

    Messages:
    2,212
    Likes Received:
    88
    Best Answers:
    0
    Trophy Points:
    325
    #16
    Exactly..
    There is no need to disable Horde & force users to use other Mail programs.
     
    ishan, Mar 7, 2008 IP
  17. IwhiC

    IwhiC Peon

    Messages:
    2,594
    Likes Received:
    61
    Best Answers:
    0
    Trophy Points:
    0
    #17
    Yup I just got the confirmation back that the patch fixed the problem, and there is no need to disable the horde mail.

     
    IwhiC, Mar 7, 2008 IP
  18. ishan

    ishan Prominent Member

    Messages:
    2,212
    Likes Received:
    88
    Best Answers:
    0
    Trophy Points:
    325
    #18
    Hey,
    I cannot reply to your PM right now, as whenever I go into PMs, my browser shows Stopped :(

    Anyway, whatever you did was right :)

    Ishan
     
    ishan, Mar 7, 2008 IP
  19. prilep

    prilep Well-Known Member

    Messages:
    3,852
    Likes Received:
    228
    Best Answers:
    0
    Trophy Points:
    185
    #19
    Haha i thought there was some other way. Thanks.

    - Prilep :D
     
    prilep, Mar 7, 2008 IP
  20. IwhiC

    IwhiC Peon

    Messages:
    2,594
    Likes Received:
    61
    Best Answers:
    0
    Trophy Points:
    0
    #20
    Hey with this update, is any one else missing the icons in the cpanel, x3 skin..
     
    IwhiC, Mar 7, 2008 IP