....appears that a lot of servers running older versions of Roundcube have been exploited today.
There is an vulnerability in one of the files - so if you use Roundcube update it immediately to the latest stable version.
If you don't use it and its just been installed as part of an install (especially relevant if you are a Directadmin user as Roundcube is installed with it), delete it or chmod the directory / files to 000
A quick check to see if you have been exploited is to check the /tmp directory.
If there are any files called wcube then you have been done over, as the expression goes.
Delete the files and you should be okay as long as you delete / upgrade Roundcube.
I found out the hard way on my DA VPS!
There is an vulnerability in one of the files - so if you use Roundcube update it immediately to the latest stable version.
If you don't use it and its just been installed as part of an install (especially relevant if you are a Directadmin user as Roundcube is installed with it), delete it or chmod the directory / files to 000
A quick check to see if you have been exploited is to check the /tmp directory.
If there are any files called wcube then you have been done over, as the expression goes.
Delete the files and you should be okay as long as you delete / upgrade Roundcube.
I found out the hard way on my DA VPS!