SECURITY: SquirrelMail Web Server Status, and Plugins Update

View: New views
8 Messages — Rating Filter:   Alert me  

SECURITY: SquirrelMail Web Server Status, and Plugins Update

by Jon Angliss :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

All,

We apologies for the extended downtime for the SquirrelMail plugins
repository, and some of the SquirrelMail site documentation.
Unfortunately due to conflicting time schedules, and some
miss-communications amongst the team (mostly my fault), the server
was unavailable for an extended length of time.

Server Status
- -------------
This evening, after an extended downtime, we finally rolled to using
the new server.  XS4All.nl were gracious in loaning us an additional
server whilst we migrated our data, to the new server.  All
documentation should now be online again, and active.  If you notice
any issues with the site, please feel free to email me directly,
I'll get onto it as soon as I can.

Plugins Compromise
- ------------------
During the initial announcement, we'd mentioned that we did not
believe that any of the plugins had been compromised.  Further
investigation has shown that the following plugins were indeed
compromised:

  - sasql-3.2.0
  - multilogin-2.4-1.2.9
  - change_pass-3.0-1.4.0

Parts of these code changes attempts to send mail to an offsite
server containing passwords.  We cannot establish a timeline of when
these plugins were compromised.  If you are a user of these plugins,
it is strongly recommended you download a fresh copy from the
plugins repository.  MD5s for the good versions are below:

a492922e5b0d2245d4e9bc255a7c5755  sasql-3.2.0.tar.gz
b143f2dc82f9e98dd43c632855255075  multilogin-2.4-1.2.9.tar.gz
2cff7c5d4f6f5d8455683bb5d96bb9fe  change_pass-3.0-1.4.0.tar.gz


Plugins Availability
- --------------------
As of now, the plugins are available to download again.  I
personally apologies for the extended outage of this, as I know some
of you have been eager to get these back up and running again.  Once
again, if you notice any issues with the site, feel free to email.


- --
Jon Angliss
<jon@...>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAkpydjMACgkQK4PoFPj9H3PXcQCgjKcpMMV4Whra4iRANBkr2Heg
6rcAoJ4CDtSwI9/E1lTtcsxaUf9QS9BK
=qs+a
-----END PGP SIGNATURE-----

------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
trial. Simplify your report design, integration and deployment - and focus on
what you do best, core application coding. Discover what's new with
Crystal Reports now.  http://p.sf.net/sfu/bobj-july
-----
squirrelmail-plugins mailing list
Posting guidelines: http://squirrelmail.org/postingguidelines
List address: squirrelmail-plugins@...
List archives: http://news.gmane.org/gmane.mail.squirrelmail.plugins
List info (subscribe/unsubscribe/change options): https://lists.sourceforge.net/lists/listinfo/squirrelmail-plugins

Re: SECURITY: SquirrelMail Web Server Status, and Plugins Update

by Derek Piazza :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Yey! Thank you!

Jon Angliss wrote:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> All,
>
> We apologies for the extended downtime for the SquirrelMail plugins
> repository, and some of the SquirrelMail site documentation.
> Unfortunately due to conflicting time schedules, and some
> miss-communications amongst the team (mostly my fault), the server
> was unavailable for an extended length of time.
>
> Server Status
> - -------------
> This evening, after an extended downtime, we finally rolled to using
> the new server.  XS4All.nl were gracious in loaning us an additional
> server whilst we migrated our data, to the new server.  All
> documentation should now be online again, and active.  If you notice
> any issues with the site, please feel free to email me directly,
> I'll get onto it as soon as I can.
>
> Plugins Compromise
> - ------------------
> During the initial announcement, we'd mentioned that we did not
> believe that any of the plugins had been compromised.  Further
> investigation has shown that the following plugins were indeed
> compromised:
>
>   - sasql-3.2.0
>   - multilogin-2.4-1.2.9
>   - change_pass-3.0-1.4.0
>
> Parts of these code changes attempts to send mail to an offsite
> server containing passwords.  We cannot establish a timeline of when
> these plugins were compromised.  If you are a user of these plugins,
> it is strongly recommended you download a fresh copy from the
> plugins repository.  MD5s for the good versions are below:
>
> a492922e5b0d2245d4e9bc255a7c5755  sasql-3.2.0.tar.gz
> b143f2dc82f9e98dd43c632855255075  multilogin-2.4-1.2.9.tar.gz
> 2cff7c5d4f6f5d8455683bb5d96bb9fe  change_pass-3.0-1.4.0.tar.gz
>
>
> Plugins Availability
> - --------------------
> As of now, the plugins are available to download again.  I
> personally apologies for the extended outage of this, as I know some
> of you have been eager to get these back up and running again.  Once
> again, if you notice any issues with the site, feel free to email.
>
>
> - --
> Jon Angliss
> <jon@...>
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.9 (MingW32)
> Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
>
> iEYEARECAAYFAkpydjMACgkQK4PoFPj9H3PXcQCgjKcpMMV4Whra4iRANBkr2Heg
> 6rcAoJ4CDtSwI9/E1lTtcsxaUf9QS9BK
> =qs+a
> -----END PGP SIGNATURE-----
>
> ------------------------------------------------------------------------------
> Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
> trial. Simplify your report design, integration and deployment - and focus on
> what you do best, core application coding. Discover what's new with
> Crystal Reports now.  http://p.sf.net/sfu/bobj-july
> -----
> squirrelmail-plugins mailing list
> Posting guidelines: http://squirrelmail.org/postingguidelines
> List address: squirrelmail-plugins@...
> List archives: http://news.gmane.org/gmane.mail.squirrelmail.plugins
> List info (subscribe/unsubscribe/change options): https://lists.sourceforge.net/lists/listinfo/squirrelmail-plugins
>  

------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
trial. Simplify your report design, integration and deployment - and focus on
what you do best, core application coding. Discover what's new with
Crystal Reports now.  http://p.sf.net/sfu/bobj-july
-----
squirrelmail-plugins mailing list
Posting guidelines: http://squirrelmail.org/postingguidelines
List address: squirrelmail-plugins@...
List archives: http://news.gmane.org/gmane.mail.squirrelmail.plugins
List info (subscribe/unsubscribe/change options): https://lists.sourceforge.net/lists/listinfo/squirrelmail-plugins

Re: SECURITY: SquirrelMail Web Server Status, and Plugins Update

by casfre@gmail.com :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

HI

>> We apologies for the extended downtime for the SquirrelMail plugins
>> repository, and some of the SquirrelMail site documentation.
>> Unfortunately due to conflicting time schedules, and some
>> miss-communications amongst the team (mostly my fault), the server
>> was unavailable for an extended length of time.

I know my e-mail is just 'one more', but I really want to say thank
you (and the whole team, including plugins developers) for
Squirrelmail and for your professional job.

Best regards,

Cássio

------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
trial. Simplify your report design, integration and deployment - and focus on
what you do best, core application coding. Discover what's new with
Crystal Reports now.  http://p.sf.net/sfu/bobj-july
-----
squirrelmail-plugins mailing list
Posting guidelines: http://squirrelmail.org/postingguidelines
List address: squirrelmail-plugins@...
List archives: http://news.gmane.org/gmane.mail.squirrelmail.plugins
List info (subscribe/unsubscribe/change options): https://lists.sourceforge.net/lists/listinfo/squirrelmail-plugins

Re: [SM-USERS] [SM-ANNOUNCE] SECURITY: SquirrelMail Web Server Status, and Plugins Update

by SquirrelMail Email List :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message


Jon,

Thanks for your hard work. Is there a way to check our code that is on our
servers so we can check to see if we do have "Compromised" code. If it is
compromised we need to have our users change passwords.

Thanks again,

Ken


On Thu, 30 Jul 2009, Jon Angliss wrote:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> All,
>
> We apologies for the extended downtime for the SquirrelMail plugins
> repository, and some of the SquirrelMail site documentation.
> Unfortunately due to conflicting time schedules, and some
> miss-communications amongst the team (mostly my fault), the server
> was unavailable for an extended length of time.
>
> Server Status
> - -------------
> This evening, after an extended downtime, we finally rolled to using
> the new server.  XS4All.nl were gracious in loaning us an additional
> server whilst we migrated our data, to the new server.  All
> documentation should now be online again, and active.  If you notice
> any issues with the site, please feel free to email me directly,
> I'll get onto it as soon as I can.
>
> Plugins Compromise
> - ------------------
> During the initial announcement, we'd mentioned that we did not
> believe that any of the plugins had been compromised.  Further
> investigation has shown that the following plugins were indeed
> compromised:
>
>  - sasql-3.2.0
>  - multilogin-2.4-1.2.9
>  - change_pass-3.0-1.4.0
>
> Parts of these code changes attempts to send mail to an offsite
> server containing passwords.  We cannot establish a timeline of when
> these plugins were compromised.  If you are a user of these plugins,
> it is strongly recommended you download a fresh copy from the
> plugins repository.  MD5s for the good versions are below:
>
> a492922e5b0d2245d4e9bc255a7c5755  sasql-3.2.0.tar.gz
> b143f2dc82f9e98dd43c632855255075  multilogin-2.4-1.2.9.tar.gz
> 2cff7c5d4f6f5d8455683bb5d96bb9fe  change_pass-3.0-1.4.0.tar.gz
>
>
> Plugins Availability
> - --------------------
> As of now, the plugins are available to download again.  I
> personally apologies for the extended outage of this, as I know some
> of you have been eager to get these back up and running again.  Once
> again, if you notice any issues with the site, feel free to email.
>
>
> - --
> Jon Angliss
> <jon@...>
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.9 (MingW32)
> Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
>
> iEYEARECAAYFAkpydjMACgkQK4PoFPj9H3PXcQCgjKcpMMV4Whra4iRANBkr2Heg
> 6rcAoJ4CDtSwI9/E1lTtcsxaUf9QS9BK
> =qs+a
> -----END PGP SIGNATURE-----
>
> ------------------------------------------------------------------------------
> Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
> trial. Simplify your report design, integration and deployment - and focus on
> what you do best, core application coding. Discover what's new with
> Crystal Reports now.  http://p.sf.net/sfu/bobj-july
> --
> squirrelmail-announce mailing list
> List Address: squirrelmail-announce@...
> List Info: https://lists.sourceforge.net/lists/listinfo/squirrelmail-announce
>
>
> ------------------------------------------------------------------------------
> Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
> trial. Simplify your report design, integration and deployment - and focus on
> what you do best, core application coding. Discover what's new with
> Crystal Reports now.  http://p.sf.net/sfu/bobj-july
> -----
> squirrelmail-users mailing list
> Posting guidelines: http://squirrelmail.org/postingguidelines
> List address: squirrelmail-users@...
> List archives: http://news.gmane.org/gmane.mail.squirrelmail.user
> List info (subscribe/unsubscribe/change options): https://lists.sourceforge.net/lists/listinfo/squirrelmail-users
>

------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
trial. Simplify your report design, integration and deployment - and focus on
what you do best, core application coding. Discover what's new with
Crystal Reports now.  http://p.sf.net/sfu/bobj-july
-----
squirrelmail-plugins mailing list
Posting guidelines: http://squirrelmail.org/postingguidelines
List address: squirrelmail-plugins@...
List archives: http://news.gmane.org/gmane.mail.squirrelmail.plugins
List info (subscribe/unsubscribe/change options): https://lists.sourceforge.net/lists/listinfo/squirrelmail-plugins

Re: [SM-ADMIN] [SM-USERS] [SM-ANNOUNCE] SECURITY: SquirrelMail Web Server Status, and Plugins Update

by Jon Angliss :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

SquirrelMail Email List wrote:
> Jon,
>
> Thanks for your hard work. Is there a way to check our code that is on our
> servers so we can check to see if we do have "Compromised" code. If it is
> compromised we need to have our users change passwords.

Absolutely.  If you check the setup.php file of the mentioned
plugins, you will see something like:

  eval(base64_decode(

This is followed by a base64 encoded string, which contains several
PHP commands to disable error handling, then send an email.

--
Jon Angliss
<jon@...>

------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
trial. Simplify your report design, integration and deployment - and focus on
what you do best, core application coding. Discover what's new with
Crystal Reports now.  http://p.sf.net/sfu/bobj-july
-----
squirrelmail-plugins mailing list
Posting guidelines: http://squirrelmail.org/postingguidelines
List address: squirrelmail-plugins@...
List archives: http://news.gmane.org/gmane.mail.squirrelmail.plugins
List info (subscribe/unsubscribe/change options): https://lists.sourceforge.net/lists/listinfo/squirrelmail-plugins

Re: [SM-USERS] [SM-ANNOUNCE] SECURITY: SquirrelMail Web Server Status, and Plugins Update

by Paul Lesniewski :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

On 7/31/09, SquirrelMail Email List <sm@...> wrote:
>
> Jon,
>
> Thanks for your hard work. Is there a way to check our code that is on our
> servers so we can check to see if we do have "Compromised" code. If it is
> compromised we need to have our users change passwords.

Download the plugin now (the one on our site is the original,
unmodified version.  Then run a diff between it and what you already
have.  You'll also want to use the checksums that Jon provided against
the tarball that you downloaded (both of these achieve the same
thing).

> Thanks again,
>
> Ken
>
>
> On Thu, 30 Jul 2009, Jon Angliss wrote:
>
>> -----BEGIN PGP SIGNED MESSAGE-----
>> Hash: SHA1
>>
>> All,
>>
>> We apologies for the extended downtime for the SquirrelMail plugins
>> repository, and some of the SquirrelMail site documentation.
>> Unfortunately due to conflicting time schedules, and some
>> miss-communications amongst the team (mostly my fault), the server
>> was unavailable for an extended length of time.
>>
>> Server Status
>> - -------------
>> This evening, after an extended downtime, we finally rolled to using
>> the new server.  XS4All.nl were gracious in loaning us an additional
>> server whilst we migrated our data, to the new server.  All
>> documentation should now be online again, and active.  If you notice
>> any issues with the site, please feel free to email me directly,
>> I'll get onto it as soon as I can.
>>
>> Plugins Compromise
>> - ------------------
>> During the initial announcement, we'd mentioned that we did not
>> believe that any of the plugins had been compromised.  Further
>> investigation has shown that the following plugins were indeed
>> compromised:
>>
>>  - sasql-3.2.0
>>  - multilogin-2.4-1.2.9
>>  - change_pass-3.0-1.4.0
>>
>> Parts of these code changes attempts to send mail to an offsite
>> server containing passwords.  We cannot establish a timeline of when
>> these plugins were compromised.  If you are a user of these plugins,
>> it is strongly recommended you download a fresh copy from the
>> plugins repository.  MD5s for the good versions are below:
>>
>> a492922e5b0d2245d4e9bc255a7c5755  sasql-3.2.0.tar.gz
>> b143f2dc82f9e98dd43c632855255075  multilogin-2.4-1.2.9.tar.gz
>> 2cff7c5d4f6f5d8455683bb5d96bb9fe  change_pass-3.0-1.4.0.tar.gz
>>
>>
>> Plugins Availability
>> - --------------------
>> As of now, the plugins are available to download again.  I
>> personally apologies for the extended outage of this, as I know some
>> of you have been eager to get these back up and running again.  Once
>> again, if you notice any issues with the site, feel free to email.

--
Paul Lesniewski
SquirrelMail Team
Please support Open Source Software by donating to SquirrelMail!
http://squirrelmail.org/donate_paul_lesniewski.php

------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
trial. Simplify your report design, integration and deployment - and focus on
what you do best, core application coding. Discover what's new with
Crystal Reports now.  http://p.sf.net/sfu/bobj-july
-----
squirrelmail-plugins mailing list
Posting guidelines: http://squirrelmail.org/postingguidelines
List address: squirrelmail-plugins@...
List archives: http://news.gmane.org/gmane.mail.squirrelmail.plugins
List info (subscribe/unsubscribe/change options): https://lists.sourceforge.net/lists/listinfo/squirrelmail-plugins

Re: [SM-USERS] [SM-ANNOUNCE] SECURITY: SquirrelMail Web Server Status, and Plugins Update

by Alexandros Vellis :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

On Sat, 1 Aug 2009 11:45:02 -0700
Paul Lesniewski <paul@...> wrote:

> On 7/31/09, SquirrelMail Email List <sm@...> wrote:

> > Thanks for your hard work. Is there a way to check our code that is
> > on our servers so we can check to see if we do have "Compromised"
> > code. If it is compromised we need to have our users change
> > passwords.
>
> Download the plugin now (the one on our site is the original,
> unmodified version.  Then run a diff between it and what you already
> have.

Let me mention in addition to this, that together with "diff" for the
command line, meld [1] is an excellent tool to compare two directories
or files (or even three).

You just untar the plugin you downloaded, and tell meld to compare that
folder with the folder where you have already installed a plugin.
Different files appear in red color.

I also use this tool extensively when upgrading php apps and plugins,
and I have to check for new configuration options in a config.sample.php
file. "meld" between config.php and config.sample.php, a couple of
clicks here and there to bring my current version up to speed, and I'm
set in less than a minute. :)

Alexandros

[1] http://meld.sourceforge.net/


------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
trial. Simplify your report design, integration and deployment - and focus on
what you do best, core application coding. Discover what's new with
Crystal Reports now.  http://p.sf.net/sfu/bobj-july
-----
squirrelmail-plugins mailing list
Posting guidelines: http://squirrelmail.org/postingguidelines
List address: squirrelmail-plugins@...
List archives: http://news.gmane.org/gmane.mail.squirrelmail.plugins
List info (subscribe/unsubscribe/change options): https://lists.sourceforge.net/lists/listinfo/squirrelmail-plugins

signature.asc (204 bytes) Download Attachment

Re: [SM-ADMIN] [SM-USERS] [SM-ANNOUNCE] SECURITY: SquirrelMail Web Server Status, and Plugins Update

by SquirrelMail Email List :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message



Jon,

Thanks! I did a grep on each plugin directory for "base64_decode" and
found nothing. Good news.

Thanks again,

Ken


On Sat, 1 Aug 2009, Jon Angliss wrote:

> SquirrelMail Email List wrote:
>> Jon,
>>
>> Thanks for your hard work. Is there a way to check our code that is on our
>> servers so we can check to see if we do have "Compromised" code. If it is
>> compromised we need to have our users change passwords.
>
> Absolutely.  If you check the setup.php file of the mentioned
> plugins, you will see something like:
>
>  eval(base64_decode(
>
> This is followed by a base64 encoded string, which contains several
> PHP commands to disable error handling, then send an email.
>
> --
> Jon Angliss
> <jon@...>
>
> ------------------------------------------------------------------------------
> Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
> trial. Simplify your report design, integration and deployment - and focus on
> what you do best, core application coding. Discover what's new with
> Crystal Reports now.  http://p.sf.net/sfu/bobj-july
> -----
> squirrelmail-plugins mailing list
> Posting guidelines: http://squirrelmail.org/postingguidelines
> List address: squirrelmail-plugins@...
> List archives: http://news.gmane.org/gmane.mail.squirrelmail.plugins
> List info (subscribe/unsubscribe/change options): https://lists.sourceforge.net/lists/listinfo/squirrelmail-plugins
>

------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
trial. Simplify your report design, integration and deployment - and focus on
what you do best, core application coding. Discover what's new with
Crystal Reports now.  http://p.sf.net/sfu/bobj-july
-----
squirrelmail-plugins mailing list
Posting guidelines: http://squirrelmail.org/postingguidelines
List address: squirrelmail-plugins@...
List archives: http://news.gmane.org/gmane.mail.squirrelmail.plugins
List info (subscribe/unsubscribe/change options): https://lists.sourceforge.net/lists/listinfo/squirrelmail-plugins