Re: Re: NeoMail-users digest, Vol 1 #958 - 1 msg
Ernie Miller <[email protected]> Fri, 21 Jan 2005 07:23:34 -0500
| Newsgroups | gmane.mail.neomail.general |
|---|---|
| Message-ID | <[email protected]> |
There has never been a published NeoMail explot. Never. Please refrain from this kind of scaremongering. With properly written code, suidperl != easily exploitable. There are thousands of web hosts (and quite a few mega-hosts and hosting resellers) that use NeoMail. These folks are experts at what they do. Do you honestly think they're installing NeoMail if it endangers their systems? -Ernie On Jan 20, 2005, at 11:40 PM, support wrote: > Hi, > > Warning suidperl is a highly easy and simple hackable exploit. > > You are endangering your server or hosting providers server by > installing this perl access. > > We are waiting for neomail to release a secure non hackable (easy > hack) version of neomail as we have many clients that like the > functions, but since this neomail is on the top of the easy hack to > root on a server we cannot use and will not recommend such to any > user. > > I hope neomail catches up with the times and patches the easy exploits. > > Richard ------------------------------------------------------- This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting Tool for open source databases. Create drag-&-drop reports. Save time by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc. Download a FREE copy at http://www.intelliview.com/go/osdn_nl