I know that there is already a thread or two about the recent Roundcube exploit (and that it was apparently fixed in the latest 0.2 stable release), but I feel it is worth mentioning that you can be hit by this exploit even if you used Custombuild and chose not to install/manage Roundcube.
DirectAdmin apparently installs the Roundcube application (as well as the other webmail apps) even if you chose not to install/manage them in the Custombuild script. The script is a little ambiguous, because when I went through it just several days ago I was under the impression that if I disabled Roundcube in the Custombuild script that it would not be installed at all. Fast-forward to today and I got hit by the exploit, so I went in and immediately deleted the Roundcube folders. And yes, I used Custombuild from the start (no previous install of DirectAdmin on the server).
Is the current version of DirectAdmin still shipping with a vulnerable version of Roundcube? If so this should be updated immediately, and even better would be to actually not install the webmail applications unless specifically chosen in the Custombuild script.
DirectAdmin apparently installs the Roundcube application (as well as the other webmail apps) even if you chose not to install/manage them in the Custombuild script. The script is a little ambiguous, because when I went through it just several days ago I was under the impression that if I disabled Roundcube in the Custombuild script that it would not be installed at all. Fast-forward to today and I got hit by the exploit, so I went in and immediately deleted the Roundcube folders. And yes, I used Custombuild from the start (no previous install of DirectAdmin on the server).
Is the current version of DirectAdmin still shipping with a vulnerable version of Roundcube? If so this should be updated immediately, and even better would be to actually not install the webmail applications unless specifically chosen in the Custombuild script.
Last edited: