Dotable - the home of "No worries" hosting!  
 
Home About Products F.A.Q Network Status Affiliates Support Contact Search Terms
 
Dotable currently hosts more than 20,000 domains for clients from all parts of the planet. Dotable is an owner operated hosting company, with Dotable's owner's Bob and Steve having 15 years of combined hosting experience between them, going back to 2001.

Dotable offers a wide but focused range of hosting products. So if you're looking to purchase a domain, or host 1 domain, or need to host multiple domains, or need a reseller account, or a VPS account or a dedicated server, at Dotable we've got you covered.

Dotable mascot! Welcome to Dotable
Go Back   Dotable - Dot your Domains™ > Dotable Announcement Forum
Closed Thread
 
LinkBack Thread Tools Search this Thread Display Modes
Old 7th March 2008, 01:27 PM   #11 (permalink)
Current Location: Mars :)
 
Join Date: Jun 2006
Posts: 259
Default

Bob, I dont really care who found it first, its totally and utterly irrelevant.

Is the fix available like Cpanel says in their blog post yesterday?
If so please get it installed.
__________________
Cheers,
James
Reesy is offline  
Old 7th March 2008, 02:16 PM   #12 (permalink)
Member
 
Join Date: Jun 2006
Posts: 61
Default

It's not unknown for CPanel patches to be reissued once or twice to fix additional issues they missed the first time. With something as severe as a published root exploit I'd rather see Horde remain offline until the patch is 100% proven.

Thanks Steve and Bob for the quick action.
foobic is offline  
Old 7th March 2008, 02:21 PM   #13 (permalink)
Dotable Founder
 
Aussie Bob's Avatar
 
Join Date: Mar 2005
Location: Land down under
Posts: 3,687
Default

James,

That was posted today only a few hours ago on the cpanel security blog, and no, we won't be rushing to upgrade all cpanels accross our server fleet to EDGE release for the Horde fix. Steve will make a call on this shortly and make the appropriate announcement, but for now Horde will remain deactivated until we are 100% certian that the fix provided by cpanel works.

You are quite welcome to reactivate Horde in your VPS by upgrading Cpanel to their suggested EDGE release. I wouldn't rush this though, given this was a root breach but it's your call but we will accept no responsibility if your VPS is root breached.

Due to the severity of the breach (root breach) we acted quickly and let as many other hosts know too, yet at the same time being careful not to make public specific details about the actual exploit.
Aussie Bob is offline  
Old 7th March 2008, 02:24 PM   #14 (permalink)
Dotable Founder
 
Aussie Bob's Avatar
 
Join Date: Mar 2005
Location: Land down under
Posts: 3,687
Default

Quote:
Originally Posted by foobic View Post
It's not unknown for CPanel patches to be reissued once or twice to fix additional issues they missed the first time. With something as severe as a published root exploit I'd rather see Horde remain offline until the patch is 100% proven.

Thanks Steve and Bob for the quick action.
No worries. We will take the safe path given the severity of this root breach.
Aussie Bob is offline  
Old 7th March 2008, 05:13 PM   #15 (permalink)
Current Location: Mars :)
 
Join Date: Jun 2006
Posts: 259
Default

Quote:
Originally Posted by Aussie Bob View Post
James,

That was posted today only a few hours ago on the cpanel security blog, and no, we won't be rushing to upgrade all cpanels accross our server fleet to EDGE release for the Horde fix. Steve will make a call on this shortly and make the appropriate announcement, but for now Horde will remain deactivated until we are 100% certian that the fix provided by cpanel works.

You are quite welcome to reactivate Horde in your VPS by upgrading Cpanel to their suggested EDGE release. I wouldn't rush this though, given this was a root breach but it's your call but we will accept no responsibility if your VPS is root breached.

Due to the severity of the breach (root breach) we acted quickly and let as many other hosts know too, yet at the same time being careful not to make public specific details about the actual exploit.

Hello Bob,
Im not subscribed to all Cpanels bumpf so Im just commenting on what info I can find.
Most specifically in that blog post "The builds will be available to all other update servers within one hour of this posting." and "The patch will be available in builds 11.18.2 and greater "

Which was yesterday.
11.18 isnt the edge release?

What are we waiting for then exactly, im lost?
Are we waiting for the next secure upgrade of Cpanel... which could be what weeks/months away?
__________________
Cheers,
James
Reesy is offline  
Old 7th March 2008, 06:30 PM   #16 (permalink)
Dotable
 
Dotable Steve's Avatar
 
Join Date: Jun 2006
Location: Auckland
Posts: 1,402
Default

James,

If you want Horde re-activating on the your VPS, just drop a ticket into the helpdesk. Ranting here isn't doing anyone any good.

Horde will be turned back on, on our servers when we verify everything is fixed. If you want to opt out of us acting upon your behalf and disabling root exploits on your VPS, let us know that in the ticket as well.
__________________
Dotable - The home of "No Worries" hosting.
VPS ? Centos, Windows or Debian - Your choice
PHP5 ? Yes we do! ClientExec? No Worries!
Do We Ride the Rails? Yes we do!
Move your sites to Dotable ? Yes we will!
Dotable Steve is offline  
Old 7th March 2008, 08:26 PM   #17 (permalink)
Current Location: Mars :)
 
Join Date: Jun 2006
Posts: 259
Default

Hello Steve,
All im asking is that you should really give more information, it doesnt take 20 seconds to type a reason and to pull the plug and give nothing I think is unnaceptable.
I should not have to go searching the net for possible information and explanations as to your actions because you havent given basic information.
I have no problem with you shutting the whole server down for days on end as long as you tell us why, and when it will be back up.

Simple communication mate
__________________
Cheers,
James
Reesy is offline  
Old 7th March 2008, 09:09 PM   #18 (permalink)
Dotable
 
Dotable Steve's Avatar
 
Join Date: Jun 2006
Location: Auckland
Posts: 1,402
Default

Horde webmail is patched and now turned back on.
__________________
Dotable - The home of "No Worries" hosting.
VPS ? Centos, Windows or Debian - Your choice
PHP5 ? Yes we do! ClientExec? No Worries!
Do We Ride the Rails? Yes we do!
Move your sites to Dotable ? Yes we will!
Dotable Steve is offline  
Old 7th March 2008, 09:51 PM   #19 (permalink)
Dotable Founder
 
Aussie Bob's Avatar
 
Join Date: Mar 2005
Location: Land down under
Posts: 3,687
Default

Quote:
Originally Posted by Reesy View Post
Hello Steve,
All im asking is that you should really give more information, it doesnt take 20 seconds to type a reason and to pull the plug and give nothing I think is unnaceptable.
It's very sensitive, especially when this is a root breach. I'm not sure you're grasping the severity of this exploit. We're not talking about a small exploit here, but an exploit that gives full root access to the server. We can't say too much as this could put other hosts at risk who haven't disabled Horde.

Steve's not going to go into detail about the exploit, as this would be very careless and irresponsible, so there's good reasons for him saying as little as possible about the exploit as possible. I'm sure you can appreciate a certian amount of discretion in a situation such as this.

Anyhoooo, Steve's comfortable with their patch and Horde has now been reactivated across our server fleet so I'm closing this thread.
Aussie Bob is offline  
Closed Thread


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Go Back   Dotable - Dot your Domains™ > Dotable Announcement Forum


All times are GMT +10. The time now is 07:57 AM.


Home About Products F.A.Q Network Status Reasons Support Contact Search Terms

Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.1.0