Go Back   HostGator Peer Support Forums > HostGator Announcements > General Announcements

Notices

Reply
 
Thread Tools
  #1  
Old 03-05-2008, 04:07 AM
GatorMary
HostGator Guest
 
Posts: n/a
Exclamation Horde Webmail Disabled

Hello,

We are investigating a potentially previously unknown and undocumented security issue in Horde Webmail. During this investigation, the program will not be available for use on all of our shared and reseller servers. There is no estimated completion time for this investigation at the moment, but we will keep you informed in this thread. Please use the other webmail programs, squirrel mail and round cube are still available.

Thank you for your understanding,

Mary Wior
HostGator Network Security
Reply With Quote
  #2  
Old 03-05-2008, 08:29 AM
Heimdol Heimdol is offline
Hatchling Croc
 
Join Date: Aug 2007
Posts: 17
Default Re: Horde Webmail Disabled

Thanks for posting on this was curious what was up. Better to bring it down and fix it then leave the security hole there during the fixing process.
__________________
Scubalinks by LJIII: http://www.ljiii.com
Military Police Pictures: http://mpvet.ljiii.com
Reply With Quote
  #3  
Old 03-05-2008, 10:16 AM
ryzeeg ryzeeg is offline
Hatchling Croc
 
Join Date: Mar 2008
Posts: 1
Default Re: Horde Webmail Disabled

Try http://yourdomain.com:2095/roundcube/index.php to get to the login for Round Cube. Make sure to put your domain name in of course into the before link.
Reply With Quote
  #4  
Old 03-05-2008, 11:51 AM
jammer jammer is offline
Hatchling Croc
 
Join Date: Apr 2007
Posts: 4
Default Re: Horde Webmail Disabled

Is there any word on whether horde will be reinstated? If not, how do we recover sent emails, address book, etc?
Reply With Quote
  #5  
Old 03-05-2008, 11:56 AM
GatorBrent's Avatar
GatorBrent GatorBrent is offline
HostGator Staff
 
Join Date: Oct 2002
Location: houston, texas
Posts: 2,977
Default Re: Horde Webmail Disabled

There is no eta at this time.


Any cpanel server in the world running horde can currently be rooted with a local account. I'm sure you all would rather use another mail program then have site 0wned.

We'll let you know more information as we get it, but until then horde will remain disabled.
__________________
Gators love marshmallows.
Reply With Quote
  #6  
Old 03-05-2008, 11:57 AM
jammer jammer is offline
Hatchling Croc
 
Join Date: Apr 2007
Posts: 4
Default Re: Horde Webmail Disabled

Completely agree, but if it remains disabled can we recover the sent emails and address book content?
Reply With Quote
  #7  
Old 03-05-2008, 11:59 AM
newview's Avatar
newview newview is offline
Hatchling Croc
 
Join Date: Jul 2007
Posts: 37
Default Re: Horde Webmail Disabled

Quote:
Originally Posted by GatorBrent View Post
I'm sure you all would rather use another mail program then have site 0wned.
Thanks for taking proactive measures to protect my sites . . . I appreciate it.
Reply With Quote
  #8  
Old 03-05-2008, 12:09 PM
GatorBrent's Avatar
GatorBrent GatorBrent is offline
HostGator Staff
 
Join Date: Oct 2002
Location: houston, texas
Posts: 2,977
Default Re: Horde Webmail Disabled

I really don't see it being disabled more then a few days. Once we have a better idea of how were going to handle this exploit beyond disabling horde we'll figure out a way for everyone to import address book / messages.
__________________
Gators love marshmallows.
Reply With Quote
  #9  
Old 03-05-2008, 12:20 PM
jammer jammer is offline
Hatchling Croc
 
Join Date: Apr 2007
Posts: 4
Default Re: Horde Webmail Disabled

Thank you very much and thanks for being proactive, to echo the previous post.
Reply With Quote
  #10  
Old 03-05-2008, 01:21 PM
sutra
HostGator Guest
 
Posts: n/a
Default Re: Horde Webmail Disabled

I learned about this from my panic clients an hour ago who happened to be 'can't live without Horde' people. While it's good that you guys posted the message here, I couldn't help but think such is a very critical issue, it would be very nice for you to send out a notification to all hosting accounts, so that we can inform our clients, instead for them to call us in panic.
Reply With Quote
  #11  
Old 03-05-2008, 02:13 PM
windwebguy windwebguy is offline
Hatchling Croc
 
Join Date: Aug 2005
Posts: 22
Default Re: Horde Webmail Disabled

I agree with Sutra. While I very much appreciate Hostgator taking steps to fix this, it would be nice if I could be the one to inform my clients rather than the other way around. Even a few hours notice would be better than no notice.
Reply With Quote
  #12  
Old 03-05-2008, 02:48 PM
Chaz Chaz is offline
Hatchling Croc
 
Join Date: Mar 2008
Posts: 1
Default Re: Horde Webmail Disabled

All hostgators colleagues (clients and workers),
First at all, I congratulate all hostgator support team to avoid all security holes, vulnerabilities and collaborate with a full sites uptime. A+!
I'm from Argentina (sorry my elementary english! jeje) and here was a little fever with the horde! Anyone in my work use it every day because is easy and everybody be accustomed with it. Today, with this service suspension, we start feeling sick... jajajajaja
I don't know the version servers use, but I ask a question to support team:
Can test last stable or beta version on a testing server?... (please don't test in the server i am! jojojo) For ex, 2008-01-22 release a beta 4.2RC2...
Or the problem is in the Horde framework?

I know only a little about servers but If any of support maintain inform about fixing advances I appreciate.

Thanks to all!

Diego.
(I repeat, my write sucks... and speaking too!)

Last edited by Chaz; 03-05-2008 at 02:52 PM. Reason: bad writting
Reply With Quote
  #13  
Old 03-05-2008, 03:56 PM
GatorDaveC's Avatar
GatorDaveC GatorDaveC is offline
HostGator Staff
 
Join Date: Mar 2006
Location: Ontario, Canada
Posts: 2,147,483,721
Default Re: Horde Webmail Disabled

Quote:
Originally Posted by jammer View Post
Completely agree, but if it remains disabled can we recover the sent emails and address book content?
The horde database which contains your address books is still intact. As soon as we make a proof of concept for this security hole we can then either make a patch or see if a newer version of Horde has the hole. The default CPanel installation uses version 2.74, and 3.x is already marked as stable on the Horde website.

We'll have to do some testing, give us about a week or so to figure out what we are going to do with Horde.
Reply With Quote
  #14  
Old 03-05-2008, 05:01 PM
gtgeorge's Avatar
gtgeorge gtgeorge is offline
Emperor Croc
 
Join Date: Mar 2005
Posts: 2,258
Default Re: Horde Webmail Disabled

Quote:
Originally Posted by GatorDaveC View Post
The horde database which contains your address books is still intact. As soon as we make a proof of concept for this security hole we can then either make a patch or see if a newer version of Horde has the hole. The default CPanel installation uses version 2.74, and 3.x is already marked as stable on the Horde website.

We'll have to do some testing, give us about a week or so to figure out what we are going to do with Horde.
For those on dedicated servers I have two questions:

1: What steps should we take if we want to disable access to Horde and prevent the exploit?

2: Will we receive instructions to implement the same "fix" when HG has it sorted?

__________________
best regards,
George
Reply With Quote
  #15  
Old 03-05-2008, 05:14 PM
slapshotw's Avatar
slapshotw slapshotw is offline
Veteran Croc
 
Join Date: Jun 2006
Posts: 5,163
Default Re: Horde Webmail Disabled

Quote:
Originally Posted by gtgeorge View Post
1: What steps should we take if we want to disable access to Horde and prevent the exploit?
You can disable horde in tweak settings-->uncheck horde. I'm not sure if this will delete any saved address books though.
__________________
Follow me on Twitter! http://twitter.com/mrw
Reply With Quote
  #16  
Old 03-05-2008, 05:17 PM
gtgeorge's Avatar
gtgeorge gtgeorge is offline
Emperor Croc
 
Join Date: Mar 2005
Posts: 2,258
Default Re: Horde Webmail Disabled

Would that prevent the eploit though? Or does something else need to be done? Gators????
__________________
best regards,
George
Reply With Quote
  #17  
Old 03-05-2008, 05:41 PM
TheWebsiteTailor TheWebsiteTailor is offline
Hatchling Croc
 
Join Date: Apr 2006
Posts: 7
Default Re: Horde Webmail Disabled

Quote:
Originally Posted by sutra View Post
...it would be very nice for you to send out a notification to all hosting accounts, so that we can inform our clients, instead for them to call us in panic.
I 100% agree!
Reply With Quote
  #18  
Old 03-05-2008, 07:42 PM
skeetr's Avatar
skeetr skeetr is offline
Royal Croc
 
Join Date: Dec 2007
Location: Washington State
Posts: 432
Default Re: Horde Webmail Disabled

Quote:
Originally Posted by sutra View Post
...it would be very nice for you to send out a notification to all hosting accounts, so that we can inform our clients, instead for them to call us in panic.
I am not so sure that this would have been very effective. They posted it on the forums which is the fastest way for them to get the word out to everyone. It sorta seems like an emergency so I am glad that they disabled it, posted in the forums and then went about trying to figure out how to deal with and fix the problem.

Having to send an email to what 700,000 customers to let them know that they are going to be disabling a program that is susceptible to hackers and then disabling it....sounds like the wrong approach. They did what they did because they were concerned about their customers security. They didnt do this so that they were more secure (I highly doubt HG uses Horde for their email). They did this because there was a security risk and their CUSTOMERS (you) could be adversely affected.

As a reseller, I understand the whole thing about having to hear things from your customer, but sometimes thats the way things go.

On a dedicated server, you would have been notified (via forums) and then it would have been up to you to schedule when Horde went offline, but since you are in a shared environment, HG has to look after us all and unfortunately, they cant afford to take the time to notify everyone ahead of time.
Reply With Quote
  #19  
Old 03-05-2008, 08:54 PM
bdtprez bdtprez is offline
Hatchling Croc
 
Join Date: May 2005
Posts: 6
Default Re: Horde Webmail Disabled

Could someone please just put up a simple "horde has been disabled due to a security vulnerability" html page so I dont have to notify every one of my customers individually?

Thanks!
Reply With Quote
  #20  
Old 03-05-2008, 10:02 PM
GatorDaveC's Avatar
GatorDaveC GatorDaveC is offline
HostGator Staff
 
Join Date: Mar 2006
Location: Ontario, Canada
Posts: 2,147,483,721
Default Re: Horde Webmail Disabled

I've added a text for you. I would rather just remove the Horde icon, but this works too.
Reply With Quote
  #21  
Old 03-05-2008, 10:27 PM
bdtprez bdtprez is offline
Hatchling Croc
 
Join Date: May 2005
Posts: 6
Default Re: Horde Webmail Disabled

Thank you so much, you guys are wonderful!

I prefer this to removing the icon as many people use Horde and they would just start calling saying "Where's Horde!" At least this way they know we are looking out for them.

Thanks again!
Reply With Quote
  #22  
Old 03-05-2008, 11:48 PM
Korrigan Korrigan is offline
Hatchling Croc
 
Join Date: Mar 2008
Posts: 1
Default Re: Horde Webmail Disabled

Is it possible any incoming mail was lost?
Reply With Quote
  #23  
Old 03-05-2008, 11:49 PM
slapshotw's Avatar
slapshotw slapshotw is offline
Veteran Croc
 
Join Date: Jun 2006
Posts: 5,163
Default Re: Horde Webmail Disabled

No, this will only affect the webmail client, not incoming mail.
__________________
Follow me on Twitter! http://twitter.com/mrw
Reply With Quote
  #24  
Old 03-06-2008, 12:16 AM
GatorPatrick's Avatar
GatorPatrick GatorPatrick is offline
HostGator Staff
 
Join Date: Apr 2007
Location: Houston, TX
Posts: 31,353
Default Re: Horde Webmail Disabled

A quick update. We have isolated the vulnerability and we are currently working on producing a secure patch. We still have no ETA however and we will update this thread with new information as it becomes available.
__________________
Patrick Pelanne
Deputy Chief Technical Officer
HostGator LLC.
http://support.hostgator.com
Reply With Quote
  #25  
Old 03-06-2008, 03:43 AM
GatorPatrick's Avatar
GatorPatrick GatorPatrick is offline
HostGator Staff
 
Join Date: Apr 2007
Location: Houston, TX
Posts: 31,353
Default Re: Horde Webmail Disabled

Another update, at this time we are able to successfully produce proof of a working exploit for this vulnerability. Based on this we will be able to develop a patch quickly. More updates to follow.
__________________
Patrick Pelanne
Deputy Chief Technical Officer
HostGator LLC.
http://support.hostgator.com
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump

All times are GMT -6. The time now is 11:45 PM.

 
Forum SEO by Zoints