Skip to content


Damn Roundcube Exploit

Tempted by it’s snazzy interface, I installed Roundcube Webmail. Little did I know there was a known exploit for the version I installed from the Ubuntu repos. On Friday, Bytemark pulled the plug on my VPS after some spotty little oik used the exploit to gain shell access to my VPS and proceeded to launch SSH attacks on other servers, whose admins then complained.

I identified the exploit, removed Roundcube, emailed the details to Bytemark and they promptly re-instated my network connectivity. Fair play to Bytemark for responding quickly - and on a Saturday too.

Posted in Techy.

One Response

Stay in touch with the conversation, subscribe to the RSS feed for comments on this post.

  1. Thank you for this post, I found it really useful, having experienced similar problems myself

Some HTML is OK

(required)

(required, but never shared)

or, reply to this post via trackback.