Since DirectAdmin maintains its own CSF ‘fork’ and quite a lot of DirectAdmin servers are still running CSF, is DA aware of these vulnerabilities and are there plans to release fixes for the DirectAdmin version?
Who's forked version of CSF is affected by this? Is it cPanel's fork of CSF only?
If you fork CSF, call it something else - I don't care what, but just call it something else. Rename DirectAdmin's CSF fork to daCSF. Do something to distinguish all of the CSF forks from each other. Keep calling the binary csf if you want to, but make csf -v print something distinctive.
While I agree: I was asking more generally.. if DirectAdmin is aware of this and if there are plans on their side to pick up the security patches for the version it now ships with.
I know for a fact that the vulnerable code is present in the DA version, or ‘daCSF’ fork if you will . So mainly i’m trying to find out what DA’s plans are going forward and if it’s on their radar at all. It’s all not very public (yet).
@DanielP, the default DA installation is not affected. There is a vulnerability in the CSF captcha/messenger feature. Users who manually enabled it are effected. We are planing to release new CSF build with captcha/messenger feature completely removed.