Re: Re: NeoMail-users digest, Vol 1 #958 - 1 msg

Ernie Miller <[email protected]> Fri, 21 Jan 2005 07:23:34 -0500
Newsgroups gmane.mail.neomail.general
Message-ID <[email protected]>
There has never been a published NeoMail explot. Never. Please refrain 
from this kind of scaremongering. With properly written code, suidperl 
!= easily exploitable.  There are thousands of web hosts (and quite a 
few mega-hosts and hosting resellers) that use NeoMail. These folks are 
experts at what they do. Do you honestly think they're installing 
NeoMail if it endangers their systems?

-Ernie

On Jan 20, 2005, at 11:40 PM, support wrote:

> Hi,
>
> Warning suidperl is a highly easy and simple hackable exploit.
>
> You are endangering your server or hosting providers server by 
> installing this perl access.
>
> We are waiting for neomail to release a secure non hackable (easy 
> hack) version of neomail as we have many clients that like the 
> functions, but since this neomail is on the top of the easy hack to 
> root on a server we cannot use and will not recommend such to any 
> user.
>
> I hope neomail catches up with the times and patches the easy exploits.
>
> Richard



-------------------------------------------------------
This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting
Tool for open source databases. Create drag-&-drop reports. Save time
by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc.
Download a FREE copy at http://www.intelliview.com/go/osdn_nl