Nation State Hackers Exploiting Zero-Day in Roundcube Webmail Software
-
- Senior user
- Posts: 827
- Joined: 2016-12-08 02:21
Re: Nation State Hackers Exploiting Zero-Day in Roundcube Webmail Software
Is there a patch yet?
-
- Senior user
- Posts: 827
- Joined: 2016-12-08 02:21
Re: Nation State Hackers Exploiting Zero-Day in Roundcube Webmail Software
https://github.com/roundcube/roundcubem ... /tag/1.6.5
Roundcube Webmail 1.6.5
For Roundcube Webmail 1.5.6 version, see:
https://github.com/roundcube/roundcubemail/releases
Roundcube Webmail 1.6.5
Code: Select all
This is a security update to the stable version 1.6 of Roundcube Webmail. It provides a fix to a recently reported XSS vulnerability:
Fix cross-site scripting (XSS) vulnerability in setting Content-Type/Content-Disposition for attachment preview/download reported by Rene Rehme (rehme.infosec).
This version is considered stable and we recommend to update all productive installations of Roundcube 1.6.x with it. Please do backup your data before updating!
https://github.com/roundcube/roundcubemail/releases
CIDR to RegEx: d-fault.nl/cidrtoregex
DNS Lookup: d-fault.nl/dnstools
DKIM Generator: d-fault.nl/dkimgenerator
DNSBL Lookup: d-fault.nl/dnsbllookup
GEOIP Lookup: d-fault.nl/geoiplookup
DNS Lookup: d-fault.nl/dnstools
DKIM Generator: d-fault.nl/dkimgenerator
DNSBL Lookup: d-fault.nl/dnsbllookup
GEOIP Lookup: d-fault.nl/geoiplookup
-
- New user
- Posts: 7
- Joined: 2017-08-31 14:39
Re: Nation State Hackers Exploiting Zero-Day in Roundcube Webmail Software
Anyone knows if the latest version of HMailServer ( 5.6.8 ) is compatible with the latest version of RoundCube ( 1.6.5 )?
Thanks
Thanks
Re: Nation State Hackers Exploiting Zero-Day in Roundcube Webmail Software
It has nothing to do with the roundcube version with hmailserver version since roundcube is just a mail client.
you can use any roundcube version with any version of hamilserver
Regards
you can use any roundcube version with any version of hamilserver
Regards
-
- New user
- Posts: 7
- Joined: 2017-08-31 14:39
Re: Nation State Hackers Exploiting Zero-Day in Roundcube Webmail Software
https://nextcloud.com/blog/open-source- ... nextcloud/
Can't they pickup hMailServer development as well?
Can't they pickup hMailServer development as well?

CIDR to RegEx: d-fault.nl/cidrtoregex
DNS Lookup: d-fault.nl/dnstools
DKIM Generator: d-fault.nl/dkimgenerator
DNSBL Lookup: d-fault.nl/dnsbllookup
GEOIP Lookup: d-fault.nl/geoiplookup
DNS Lookup: d-fault.nl/dnstools
DKIM Generator: d-fault.nl/dkimgenerator
DNSBL Lookup: d-fault.nl/dnsbllookup
GEOIP Lookup: d-fault.nl/geoiplookup
Re: Nation State Hackers Exploiting Zero-Day in Roundcube Webmail Software
Linux only!RvdH wrote: ↑2023-11-29 14:40https://nextcloud.com/blog/open-source- ... nextcloud/
Can't they pickup hMailServer development as well?![]()



Re: Nation State Hackers Exploiting Zero-Day in Roundcube Webmail Software
Don't think so.palinka wrote: ↑2023-11-29 15:11Linux only!RvdH wrote: ↑2023-11-29 14:40https://nextcloud.com/blog/open-source- ... nextcloud/
Can't they pickup hMailServer development as well?![]()
![]()
![]()
![]()
It is written in PHP.
I'm a long term user of Nextcloud - love it.
They already have a web mail client called Snappy Mail that is an app inclusion, but exciting to see them get a hold of roundcube too.
Nextcloud is an offshoot or OwnCloud
Just 'cause I link to a page and say little else doesn't mean I am not being nice.
https://www.hmailserver.com/documentation
https://www.hmailserver.com/documentation
Re: Nation State Hackers Exploiting Zero-Day in Roundcube Webmail Software
Its not just php. You need to install docker on windows to run it, and also reverse proxy it if you have a webserver already running. It used to be php only and ran on windows + xampp. I did try it out many years ago. But at some point they gave up development for windows.mattg wrote: ↑2023-11-30 01:45Don't think so.palinka wrote: ↑2023-11-29 15:11Linux only!RvdH wrote: ↑2023-11-29 14:40https://nextcloud.com/blog/open-source- ... nextcloud/
Can't they pickup hMailServer development as well?![]()
![]()
![]()
![]()
It is written in PHP.
I'm a long term user of Nextcloud - love it.
They already have a web mail client called Snappy Mail that is an app inclusion, but exciting to see them get a hold of roundcube too.
Nextcloud is an offshoot or OwnCloud
I've been using filerun, which is amazing. Very lightweight, fast, works well with webdav + nextcloud client. But they ended their free license so there will be no more updates unless you pay and the price is crazy - enterprise pricing. I would absolutely pay for 2 or 3 users if the price were reasonable. So I'm keeping my eye on nextcloud and owncloud.