There's at least 20+ IPs scanning for Roundcube and my server isn't even that well-known. Do you think they're doing massive random scans or are they getting a list of IPs with the DA control panel somewhere?[Thu Jan 08 13:27:50 2009] [error] [client 94.23.11.210] ModSecurity: Access denied with code 400 (phase 2). Pattern match "^[\\d\\.]+$" at REQUEST_HEADERS:Host. [file "/etc/modsecurity2/protocol_anomalies.conf"] [line "60"] [id "960017"] [msg "Host header is a numeric IP address"] [severity "CRITICAL"] [tag "PROTOCOL_VIOLATION/IP_HOST"] [hostname "38.103.145.214"] [uri "/webmail/bin/msgimport"] [unique_id "SWZFpiZnkdIAAFWfHV4AAAAL"]
[Thu Jan 08 13:27:50 2009] [error] [client 94.23.11.210] ModSecurity: Access denied with code 400 (phase 2). Pattern match "^[\\d\\.]+$" at REQUEST_HEADERS:Host. [file "/etc/modsecurity2/protocol_anomalies.conf"] [line "60"] [id "960017"] [msg "Host header is a numeric IP address"] [severity "CRITICAL"] [tag "PROTOCOL_VIOLATION/IP_HOST"] [hostname "38.103.145.210"] [uri "/webmail/bin/msgimport"] [unique_id "SWZFpiZnkdIAAFT-FDsAAAAA"]
[Thu Jan 08 13:27:50 2009] [error] [client 94.23.11.210] ModSecurity: Access denied with code 400 (phase 2). Pattern match "^[\\d\\.]+$" at REQUEST_HEADERS:Host. [file "/etc/modsecurity2/protocol_anomalies.conf"] [line "60"] [id "960017"] [msg "Host header is a numeric IP address"] [severity "CRITICAL"] [tag "PROTOCOL_VIOLATION/IP_HOST"] [hostname "38.103.145.213"] [uri "/webmail/bin/msgimport"] [unique_id "SWZFpiZnkdIAAFUPFAkAAAAE"]
[Thu Jan 08 13:27:53 2009] [error] [client 94.23.11.210] ModSecurity: Access denied with code 400 (phase 2). Pattern match "^[\\d\\.]+$" at REQUEST_HEADERS:Host. [file "/etc/modsecurity2/protocol_anomalies.conf"] [line "60"] [id "960017"] [msg "Host header is a numeric IP address"] [severity "CRITICAL"] [tag "PROTOCOL_VIOLATION/IP_HOST"] [hostname "38.103.145.211"] [uri "/webmail/bin/msgimport"] [unique_id "SWZFqSZnkdIAAFWfHV8AAAAL"]
[Thu Jan 08 13:50:14 2009] [error] [client 69.62.203.26] ModSecurity: Access denied with code 400 (phase 2). Pattern match "^[\\d\\.]+$" at REQUEST_HEADERS:Host. [file "/etc/modsecurity2/protocol_anomalies.conf"] [line "60"] [id "960017"] [msg "Host header is a numeric IP address"] [severity "CRITICAL"] [tag "PROTOCOL_VIOLATION/IP_HOST"] [hostname "38.103.145.210"] [uri "/nonexisten****"] [unique_id "SWZK5iZnkdIAAFgNsEUAAAAH"]
[Thu Jan 08 13:50:15 2009] [error] [client 69.62.203.26] ModSecurity: Access denied with code 400 (phase 2). Pattern match "^[\\d\\.]+$" at REQUEST_HEADERS:Host. [file "/etc/modsecurity2/protocol_anomalies.conf"] [line "60"] [id "960017"] [msg "Host header is a numeric IP address"] [severity "CRITICAL"] [tag "PROTOCOL_VIOLATION/IP_HOST"] [hostname "38.103.145.214"] [uri "/nonexisten****"] [unique_id "SWZK5yZnkdIAAFd1nm0AAAAD"]
[Thu Jan 08 13:50:16 2009] [error] [client 69.62.203.26] ModSecurity: Access denied with code 400 (phase 2). Pattern match "^[\\d\\.]+$" at REQUEST_HEADERS:Host. [file "/etc/modsecurity2/protocol_anomalies.conf"] [line "60"] [id "960017"] [msg "Host header is a numeric IP address"] [severity "CRITICAL"] [tag "PROTOCOL_VIOLATION/IP_HOST"] [hostname "38.103.145.214"] [uri "/mail/bin/msgimport"] [unique_id "SWZK6CZnkdIAAFdonlIAAAAF"]
[Thu Jan 08 13:50:16 2009] [error] [client 69.62.203.26] ModSecurity: Access denied with code 400 (phase 2). Pattern match "^[\\d\\.]+$" at REQUEST_HEADERS:Host. [file "/etc/modsecurity2/protocol_anomalies.conf"] [line "60"] [id "960017"] [msg "Host header is a numeric IP address"] [severity "CRITICAL"] [tag "PROTOCOL_VIOLATION/IP_HOST"] [hostname "38.103.145.214"] [uri "/bin/msgimport"] [unique_id "SWZK6CZnkdIAAFbdflEAAAAI"]
[Thu Jan 08 13:50:16 2009] [error] [client 69.62.203.26] ModSecurity: Access denied with code 400 (phase 2). Pattern match "^[\\d\\.]+$" at REQUEST_HEADERS:Host. [file "/etc/modsecurity2/protocol_anomalies.conf"] [line "60"] [id "960017"] [msg "Host header is a numeric IP address"] [severity "CRITICAL"] [tag "PROTOCOL_VIOLATION/IP_HOST"] [hostname "38.103.145.214"] [uri "/rc/bin/msgimport"] [unique_id "SWZK6CZnkdIAAFdmm04AAAAC"]
[Thu Jan 08 13:50:18 2009] [error] [client 69.62.203.26] ModSecurity: Access denied with code 400 (phase 2). Pattern match "^[\\d\\.]+$" at REQUEST_HEADERS:Host. [file "/etc/modsecurity2/protocol_anomalies.conf"] [line "60"] [id "960017"] [msg "Host header is a numeric IP address"] [severity "CRITICAL"] [tag "PROTOCOL_VIOLATION/IP_HOST"] [hostname "38.103.145.210"] [uri "/mail/bin/msgimport"] [unique_id "SWZK6iZnkdIAAFgds0UAAAAB"]
[Thu Jan 08 13:50:20 2009] [error] [client 69.62.203.26] ModSecurity: Access denied with code 400 (phase 2). Pattern match "^[\\d\\.]+$" at REQUEST_HEADERS:Host. [file "/etc/modsecurity2/protocol_anomalies.conf"] [line "60"] [id "960017"] [msg "Host header is a numeric IP address"] [severity "CRITICAL"] [tag "PROTOCOL_VIOLATION/IP_HOST"] [hostname "38.103.145.214"] [uri "/roundcube/bin/msgimport"] [unique_id "SWZK7CZnkdIAAFgNsEYAAAAH"]
[Thu Jan 08 13:50:23 2009] [error] [client 69.62.203.26] ModSecurity: Access denied with code 400 (phase 2). Pattern match "^[\\d\\.]+$" at REQUEST_HEADERS:Host. [file "/etc/modsecurity2/protocol_anomalies.conf"] [line "60"] [id "960017"] [msg "Host header is a numeric IP address"] [severity "CRITICAL"] [tag "PROTOCOL_VIOLATION/IP_HOST"] [hostname "38.103.145.214"] [uri "/webmail/bin/msgimport"] [unique_id "SWZK7yZnkdIAAFbdflIAAAAI"]
[Thu Jan 08 14:25:01 2009] [error] [client 195.3.206.36] ModSecurity: Access denied with code 400 (phase 2). Pattern match "^[\\d\\.]+$" at REQUEST_HEADERS:Host. [file "/etc/modsecurity2/protocol_anomalies.conf"] [line "60"] [id "960017"] [msg "Host header is a numeric IP address"] [severity "CRITICAL"] [tag "PROTOCOL_VIOLATION/IP_HOST"] [hostname "38.103.145.210"] [uri "/nonexisten****"] [unique_id "SWZTDSZnkdIAAFyzlQYAAAAD"]
I guess they probe/scan for port 2222 to find out?In a thread on webhostingtalk someone wrote that they were specifically targeting DirectAdmin servers.
In a thread on webhostingtalk someone wrote that they were specifically targeting DirectAdmin servers.
Jeff
Are you concerned about the remote injection vulnerability in 0.2-1.alpha and 0.2-3.beta? http://www.heise-online.co.uk/securi...--/news/112330
If so, we do not use these versions. We use 0.1stable which is not affected by theses issues. We'll be updating to 0.2stable in the near future
After running this update, old custombuild we get a blank page at http://domain/roundcube. Now what? Got the same mysql error as everyone else but just a blank page now.
Also, we are not running php5
I just checked the cpanel forums as i find the information a bit more accurate.
This is what they said.
Which means i was running 0.1stable before i ran this update. Now the update has screwed up the entire installation and possibly doesnt even run on php4. Ill have to get it off another server thats still running it and re install it.
nothing wrong with 0.1stable according to cpanel so if your still running it, keep it.
[root@server custombuild]# ./build roundcube
ls: /var/www/html/roundcube: No such file or directory
cat: /var/www/html/roundcube/index.php: No such file or directory
This instance of RoundCube is not yet configured!
Open http://url-to-roundcube/installer/ in your browser and follow the instuctions.
ERROR 1146 (42S02) at line 4 in file: 'SQL/mysql.update.sql': Table 'da_roundcube.messages' doesn't exist
Editing roundcube configuration...
Roundcube 0.2 has been installed successfully.
The build script version currently on DA's servers 1.1.15 does not work! As other's have stated I also get this same issue. When is 1.1.16 going to be pushed to the files.directadmin.com server??
With the current build it broke roundcube on the server.
Code:[root@server custombuild]# ./build roundcube ls: /var/www/html/roundcube: No such file or directory cat: /var/www/html/roundcube/index.php: No such file or directory This instance of RoundCube is not yet configured! Open http://url-to-roundcube/installer/ in your browser and follow the instuctions. ERROR 1146 (42S02) at line 4 in file: 'SQL/mysql.update.sql': Table 'da_roundcube.messages' doesn't exist Editing roundcube configuration... Roundcube 0.2 has been installed successfully.
This update does not work and breaks roundcube.
webserver:/usr/local/directadmin/custombuild# perl -pi -e 's/clean_old_webapps=no/clean_old_webapps=yes/' options.conf
webserver:/usr/local/directadmin/custombuild# ./build roundcube
cp: cannot stat `/var/www/html/roundcube/logs/*': No such file or directory
cp: cannot stat `/var/www/html/roundcube/temp/*': No such file or directory
Parse error: syntax error, unexpected T_OBJECT_OPERATOR in /var/www/html/roundcubemail-0.2/program/include/main.inc on line 75
ERROR 1091 (42000) at line 6 in file: 'SQL/mysql.update.sql': Can't DROP 'idx'; check that column/key exists
Editing roundcube configuration...
Roundcube 0.2 has been installed successfully.
Parse error: syntax error, unexpected T_OBJECT_OPERATOR in /var/www/html/roundcubemail-0.2/program/include/main.inc on line 74
I believe that's because you're using php 4.
Roundcube 0.2 requires php 5.
John
http://trac.roundcube.net/browser/trunk/roundcubemail/program/lib/html2text.php?rev=2148