Go Back   HostGator Peer Support Forums > HostGator Announcements > General Announcements

Notices

Reply
 
Thread Tools
  #26  
Old 03-06-2008, 06:30 AM
dmolavi dmolavi is offline
Hatchling Croc
 
Join Date: May 2005
Posts: 28
Default Re: Horde Webmail Disabled

will the other clients offered still have our inbox/sent mail folders? basically, do all the clients you offer share the same mail directories?
__________________
Reply With Quote
  #27  
Old 03-06-2008, 07:25 AM
quietFinn's Avatar
quietFinn quietFinn is offline
Emperor Croc
 
Join Date: Feb 2005
Posts: 2,905
Default Re: Horde Webmail Disabled

Quote:
Originally Posted by gtgeorge View Post
For those on dedicated servers I have two questions:

1: What steps should we take if we want to disable access to Horde and prevent the exploit?
http://forums.hostgator.com/showthread.php?t=28936


Quote:
Originally Posted by gtgeorge View Post
2: Will we receive instructions to implement the same "fix" when HG has it sorted?

I can't give an official answer, but I am 100% sure we get the instructions.
__________________
quietFinn - netFinn Finland
"Be who you are and say what you feel because those who mind don't matter and those who matter don't mind." - Dr. Seuss
Reply With Quote
  #28  
Old 03-06-2008, 08:40 AM
tek2dev tek2dev is offline
Hatchling Croc
 
Join Date: Jul 2007
Location: Florida, USA
Posts: 10
Default Re: Horde Webmail Disabled

If it is going to be down for an undetermined amount of time then it would be very helpful if you could export the address books over to squirrel or round cube. That way our clients won't be as mad at us at they are getting right now.
Reply With Quote
  #29  
Old 03-06-2008, 09:35 AM
dashaver dashaver is offline
Hatchling Croc
 
Join Date: Feb 2007
Posts: 7
Default Re: Horde Webmail Disabled

I would like to repeat and second the question by tek2dev Any ideas on what we can do about the address book?
Reply With Quote
  #30  
Old 03-06-2008, 11:11 AM
snailguy snailguy is offline
Hatchling Croc
 
Join Date: Dec 2006
Posts: 6
Default Re: Horde Webmail Disabled

I'd would like to second the idea of getting address books over to squirrelmail/roundcube, as my users are adrift without them until this is fixed.

Thanks for being on the ball HG!
Reply With Quote
  #31  
Old 03-06-2008, 01:10 PM
tek2dev tek2dev is offline
Hatchling Croc
 
Join Date: Jul 2007
Location: Florida, USA
Posts: 10
Default Re: Horde Webmail Disabled

My clients would be happy to just get there address book switched over.

Of course they would like to have their old email but for right now can you get the address books over to the others??????????
Reply With Quote
  #32  
Old 03-06-2008, 01:16 PM
kmaw's Avatar
kmaw kmaw is offline
Emperor Croc
 
Join Date: Mar 2005
Location: Ontario, Canada
Posts: 1,886
Default Re: Horde Webmail Disabled

Quote:
Originally Posted by tek2dev View Post
Of course they would like to have their old email but for right now can you get the address books over to the others??????????
Email is the same in any of the webmail programs. Only address books and Horde settings are missing.
Reply With Quote
  #33  
Old 03-06-2008, 01:40 PM
tek2dev tek2dev is offline
Hatchling Croc
 
Join Date: Jul 2007
Location: Florida, USA
Posts: 10
Default Re: Horde Webmail Disabled

And that is what my clients want back the most is their address book. Plus according to the plan HG is suppose to be running backups, if so they can get the address books.
Reply With Quote
  #34  
Old 03-06-2008, 01:51 PM
DarkSorrow's Avatar
DarkSorrow DarkSorrow is offline
Swamp Croc
 
Join Date: Nov 2005
Location: Reeds Springs, Missouri
Posts: 250
Default Re: Horde Webmail Disabled

Quote:
Originally Posted by GatorMary View Post
Hello,

We are investigating a potentially previously unknown and undocumented security issue in Horde Webmail. During this investigation, the program will not be available for use on all of our shared and reseller servers. There is no estimated completion time for this investigation at the moment, but we will keep you informed in this thread. Please use the other webmail programs, squirrel mail and round cube are still available.

Thank you for your understanding,

Mary Wior
HostGator Network Security
How does one disable it on a Dedicated server?
__________________
sudo rm -rf /mnt/win32 ; sync ; dd if=/dev/random of=/mnt/win32/ooops bs=16384 ; sync
"Knowledge is Power, power corrupts, corruption is illegal. STOP LEARNING BEFORE YOU END UP IN JAIL!"
Reply With Quote
  #35  
Old 03-06-2008, 02:04 PM
Sam Sam is offline
Emperor Croc
 
Join Date: Jan 2007
Location: /bin/false
Posts: 3,057
Default Re: Horde Webmail Disabled

Quote:
Originally Posted by Defiance View Post
How does one disable it on a Dedicated server?
http://forums.hostgator.com/showthread.php?t=28936
Reply With Quote
  #36  
Old 03-06-2008, 02:06 PM
GvilleRick's Avatar
GvilleRick GvilleRick is offline
Emperor Croc
 
Join Date: Jan 2007
Location: Greenville, SC
Posts: 2,665
Default Re: Horde Webmail Disabled

There is a post in the dedicated linux server section of the forums that gives a shell command to disable Horde. You can find the post here.
Reply With Quote
  #37  
Old 03-06-2008, 04:34 PM
GatorBrent's Avatar
GatorBrent GatorBrent is offline
HostGator Staff
 
Join Date: Oct 2002
Location: houston, texas
Posts: 2,977
Default Re: Horde Webmail Disabled

The rest of the world is now starting to disable horde on their servers due to us contacting cpanel and a bunch of the major hosts we know. I just got off the phone with cpanel and they are releasing a patch for everyone this very moment.

Once we review the patch and are 100% sure this root exploit has been stopped we will then enable horde. This isn't actually a cpanel problem so much as an issue with horde. It affects any server running horde, but it's cpanel's problem because the majority of their licenses have horde enabled.
__________________
Gators love marshmallows.
Reply With Quote
  #38  
Old 03-06-2008, 04:57 PM
mpantoja mpantoja is offline
Hatchling Croc
 
Join Date: Mar 2008
Posts: 1
Default Re: Horde Webmail Disabled

Proactive. Great.

But couldn't you have included a link back to the webmail main page? All of my clients are using Horde (at my recommendation) and now they seem to think that they can't get webmail *at all*. So I have to personally consult with each of them to tell them to go to theirdomain.com/webmail.

As a shortcut (and for simplicity), I've set up all of my clients with a redirect to jump to Horde rather than the webmail main page (cuts out a step or two).

Please, please just add a link or a redirect.
Reply With Quote
  #39  
Old 03-06-2008, 06:44 PM
jaenosjelantru jaenosjelantru is offline
Hatchling Croc
 
Join Date: Jul 2007
Location: Tulsa, OK
Posts: 10
Default Re: Horde Webmail Disabled

I just thought I would post some verbiage here I sent to my clients. Some of you may need to use it in case you want to inform yours:


Dear Client-

There was a security vulnerability detected with the Horde webmail service which is very severe. Nothing harmful was done because corrective action was taken in time and this does not affect your computer in any way. The horde webmail application was disabled and will remain disabled until the problem can be resolved, which should be within days. A patch that fixes the exploit has already been developed. If you do not use webmail or email on your server at all, please disregard this notice.


I wanted to update those of you who may or may not know how to get to your email using another email application. Most of you probably don’t even use webmail but for those who do, you may still retrieve and send mails in the meantime using another program. If you currently use Horde, login to your webmail using the same credentials as normal except navigate here:

http://yourdomainname.com/webmail

Obviously, you will want to replace yourdomainname.com with your actual domain name. You will notice that horde is disabled but you can use Squirrel mail or round cube. I like horde the best, followed by round cube. With round cube, you must manually retrieve your mail, much like hitting the refresh, by using the little green arrow over the envelope, then select your inbox from the folder list on the left.

I apologize for any inconvenience this has caused. Please feel free to call me if you have any questions or concerns.


love and kisses... steven
Reply With Quote
  #40  
Old 03-06-2008, 06:46 PM
jaenosjelantru jaenosjelantru is offline
Hatchling Croc
 
Join Date: Jul 2007
Location: Tulsa, OK
Posts: 10
Default Re: Horde Webmail Disabled

By the way, thanks for being proactive on this and for letting us know right away. I just started getting emails and calls from my "hair is on fire cause I can't get to my email" clients.

I appreciate the speedy work as usual HG!
Reply With Quote
  #41  
Old 03-06-2008, 07:01 PM
GatorBrent's Avatar
GatorBrent GatorBrent is offline
HostGator Staff
 
Join Date: Oct 2002
Location: houston, texas
Posts: 2,977
Default Re: Horde Webmail Disabled

Cpanel has sent this out jut now....


"An arbitrary file inclusion vulnerability has been discovered in the Horde
webmail application. At present, we can confirm that this security
vulnerability in question affects Horde 3.1.6 and earlier. Based on
incomplete information at this time, we also believe this affects Horde
Groupware 1.0.4 and earlier as well (cPanel does not use Horde Groupware
at this time).

cPanel customers should update their cPanel and WHM servers immediately to
prevent any chance of compromise. The patch will be available in builds
11.18.2 and greater (or 11.19.2 and greater for EDGE systems). The updated
builds will be available immediately to all fast update servers. The
builds will be available to all other update servers within one hour of
this posting.


To check which version of cPanel and WHM is on your server, simply log
into WebHost Manager (WHM) and look in the top right corner, or execute
the following command from the command line as root:

/usr/local/cpanel/cpanel -V

You can upgrade your server by navigating to 'cPanel' -> 'Upgrade to
Latest Version' in WebHost Manager or by executing the following from the
command line as root:

/scripts/upcp


It is recommended that all use of Horde 3.1.6 and earlier be stopped (on
cPanel and non-cPanel systems alike) until Horde updates can be applied.
You can disable Horde on your cPanel system by unchecking the box next to
'Server Configuration' -> 'Tweak Settings' -> 'Mail' -> 'Horde Webmail'
within WHM, and saving the page with the new settings.


We would like to thank HostGator for providing the initial details in
their report of this vulnerability.
"
__________________
Gators love marshmallows.
Reply With Quote
  #42  
Old 03-06-2008, 07:08 PM
Rockoids's Avatar
Rockoids Rockoids is offline
Royal Croc
 
Join Date: Feb 2008
Location: Scottsdale, AZ
Posts: 415
Default Re: Horde Webmail Disabled

Way to go gang
__________________
Rock On,
Gene Steinberg
Co-Author, Attack of the Rockoids
Reply With Quote
  #43  
Old 03-06-2008, 07:22 PM
DarkSorrow's Avatar
DarkSorrow DarkSorrow is offline
Swamp Croc
 
Join Date: Nov 2005
Location: Reeds Springs, Missouri
Posts: 250
Default Re: Horde Webmail Disabled

So looks like they patched it and all is good now I just got that email also in my inbox.
__________________
sudo rm -rf /mnt/win32 ; sync ; dd if=/dev/random of=/mnt/win32/ooops bs=16384 ; sync
"Knowledge is Power, power corrupts, corruption is illegal. STOP LEARNING BEFORE YOU END UP IN JAIL!"
Reply With Quote
  #44  
Old 03-06-2008, 10:06 PM
GatorDaveC's Avatar
GatorDaveC GatorDaveC is offline
HostGator Staff
 
Join Date: Mar 2006
Location: Ontario, Canada
Posts: 2,147,483,765
Default Re: Horde Webmail Disabled

Everything is patched now. We have made our own patch for Horde, CPanel has done the same to strip out the malicious code from being injected.

If you would you like to get the update right a way on your dedicated servers, please go to http://forums.hostgator.com/showthre...d=1#post106772
Reply With Quote
  #45  
Old 03-06-2008, 10:12 PM
ethical ethical is offline
Hatchling Croc
 
Join Date: May 2006
Posts: 32
Default Re: Horde Webmail Disabled

still not working for me, will it take some time to take effect?

thanks
Reply With Quote
  #46  
Old 03-06-2008, 10:46 PM
GatorDaveC's Avatar
GatorDaveC GatorDaveC is offline
HostGator Staff
 
Join Date: Mar 2006
Location: Ontario, Canada
Posts: 2,147,483,765
Default Re: Horde Webmail Disabled

Quote:
Originally Posted by ethical View Post
still not working for me, will it take some time to take effect?

thanks
The shared/reseller servers are still updating to the newest CPanel release at this time. I meant the newest version of CPanel has been patched. Give us about an hour or so for finish updating all of the servers.
Reply With Quote
  #47  
Old 03-06-2008, 10:57 PM
Koni Koni is offline
Hatchling Croc
 
Join Date: Nov 2007
Posts: 37
Default Re: Horde Webmail Disabled

My WHM is now showing:

WHM 11.15.0 cPanel 11.18.2-S21594

Horde mail is back working again

Great job HG!!!!
Reply With Quote
  #48  
Old 03-07-2008, 06:13 AM
photografico's Avatar
photografico photografico is offline
Hatchling Croc
 
Join Date: Mar 2008
Posts: 1
Default Re: Horde Webmail Disabled

Hello,
i'm a new custumer and i have a reseller aluminum account, i have take a look in whm and the updat done, but after access to hord i have try to take a look to the adressbook and i have this error msg :

Some of Turba's configuration files are missing or unreadable
mime_drivers.php
This file controls local MIME drivers for Turba, specifically what kinds of files are viewable and/or downloadable.

Create these files from their .dist versions in /usr/local/cpanel/base/horde/turba/config and change them according to your needs.

i hope you can fixe this asap

thanks,
fico.
Reply With Quote
  #49  
Old 03-07-2008, 06:25 AM
aqw aqw is offline
Hatchling Croc
 
Join Date: Jul 2006
Posts: 4
Default Re: Horde Webmail Disabled

I'm experiencing the same Horde message as photografico above. It looks like a config file needs to be set??

AQW
Reply With Quote
  #50  
Old 03-07-2008, 10:06 AM
MikeC MikeC is offline
Baby Croc
 
Join Date: Dec 2003
Location: Fort Worth, Texas
Posts: 71
Default Re: Horde Webmail Disabled

Quote:
Originally Posted by photografico View Post
Hello,
....
Some of Turba's configuration files are missing or unreadable
mime_drivers.php
This file controls local MIME drivers for Turba, specifically what kinds of files are viewable and/or downloadable.

Create these files from their .dist versions in /usr/local/cpanel/base/horde/turba/config and change them according to your needs.
....
We're getting this on hummer as well. I'm opening a support ticket and recommend others do the same until we see a response from HG here, or it's fixed....
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

All times are GMT -6. The time now is 03:04 AM.