It seems there are some recent Roundcube exploit, already fixed in latest version, so it is highly recommendable upgrading it.
You can read more here
http://trac.roundcube.net/ticket/1485618
http://forum.abestweb.com/showthread.php?t=114931
in my error_log I can identify different IPs trying it everyday
[Sat Jan 10 15:58:27 2009] [error] [client 67.223.236.213] File does not exist: /usr/local/apache/htdocs/roundcubemail-0.1
[Sat Jan 10 15:58:27 2009] [error] [client 67.223.236.213] File does not exist: /usr/local/apache/htdocs/roundcubemail-0.1
[Sat Jan 10 15:58:28 2009] [error] [client 67.223.236.213] File does not exist: /usr/local/apache/htdocs/roundcubemail
[Sat Jan 10 15:58:28 2009] [error] [client 67.223.236.213] File does not exist: /usr/local/apache/htdocs/roundcubemail
[Sat Jan 10 15:58:28 2009] [error] [client 67.223.236.213] File does not exist: /usr/local/apache/htdocs/roundcubemail-0.2
[Sat Jan 10 15:58:29 2009] [error] [client 67.223.236.213] File does not exist: /usr/local/apache/htdocs/roundcubemail-0.2
[Sat Jan 10 15:58:29 2009] [error] [client 67.223.236.213] File does not exist: /usr/local/apache/htdocs/roundcube-0.1
[Sat Jan 10 15:58:30 2009] [error] [client 67.223.236.213] File does not exist: /usr/local/apache/htdocs/roundcube-0.1
[Sat Jan 10 15:58:30 2009] [error] [client 67.223.236.213] File does not exist: /usr/local/apache/htdocs/webmail
[Sat Jan 10 15:58:30 2009] [error] [client 67.223.236.213] File does not exist: /usr/local/apache/htdocs/webmail
[Sat Jan 10 15:58:31 2009] [error] [client 67.223.236.213] File does not exist: /usr/local/apache/htdocs/mail
[Sat Jan 10 15:58:31 2009] [error] [client 67.223.236.213] File does not exist: /usr/local/apache/htdocs/mail
[Sat Jan 10 15:58:32 2009] [error] [client 67.223.236.213] File does not exist: /usr/local/apache/htdocs/bin
[Sat Jan 10 15:58:32 2009] [error] [client 67.223.236.213] File does not exist: /usr/local/apache/htdocs/bin
[Sat Jan 10 15:58:33 2009] [error] [client 67.223.236.213] File does not exist: /usr/local/apache/htdocs/roundcube
[Sat Jan 10 15:58:33 2009] [error] [client 67.223.236.213] File does not exist: /usr/local/apache/htdocs/roundcube
[Sat Jan 10 15:58:33 2009] [error] [client 67.223.236.213] File does not exist: /usr/local/apache/htdocs/rc
[Sat Jan 10 15:58:34 2009] [error] [client 67.223.236.213] File does not exist: /usr/local/apache/htdocs/rc
Roundcube exploit - upgrade to latest version
Started by
dimitre
, Jan 10 2009 01:19 PM
1 reply to this topic
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users
Sign In
Create Account









