Squirrelmail

paul-w

Verified User
Joined
Jan 25, 2006
Messages
51
Location
Berkshire, UK
I updated DA today to the latest 1.48.3 and Apache to 2.4.16 using custombuild.

What prompted this was some spam sucking scum pushed 23,500 messages through one of my user's Squirrelmail account. They don't use Squirrelmail.

Yes, my fault. Should have patched more regularly.

Not sure if the attacker just obtained the user's credentials, exploited a vulnerability in something other than Squirrelmail or - and this is the point of this post - exploited a vulnerability in Squirrelmail itself.

I can't find any high vulnerabilities listed for Squirrelmail and I was running the latest, 1.4.22. The latest is from July 2011 I notice.

I've now uninstalled it. None of my users used it.
 
Hello,

What made you think that spam was sent through Squirrelmail? Did they have the account login details?
 
I could see from the maillog it was squirrelmail. Yes, the attacker could have guessed the credentials. However, the fact that this package hasn't been updated for 4 years concerns me.

No matter now since none of my customers had a need for it and it has been removed.

I removed roundcube and phpmyadmin while I was at it.
 
Back
Top