#1 (permalink)  
Old 10-07-2005, 09:28 AM
Registered User
 
Join Date: Dec 2004
Posts: 388
abubin is on a distinguished road
uw-imapd vunerability question

I see this message on WHM with the uw-imapd vunerability problems.

Can I know what is this uw-imapd? What does it do? Do I wait for the problem to be fixed or upgrade to maildir?

What is maildir? which is better? Will upgrading to maildir cause any problems to my email system?

Thanks in advance.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 10-07-2005, 10:25 AM
chirpy's Avatar
Moderator
 
Join Date: Jun 2002
Location: Go on, have a guess
Posts: 13,495
chirpy will become famous soon enough
uw-imapd is the IMAP server that is used by cPanel for their cpimap daemon.

As to waiting, that's up to you. You should (be) subscribe(d) to the security mailing lists and reading the exploits to determine whether it is in your best interests to upgrade - that's only a decision that you can make as the sys admin.

Read up on the differences of mbox and maildir formats for mailboxes, there's plenty of information on the web.
__________________
Jonathan Michaelson
cPanel Forum Moderator

Need your cPanel servers secured and tuned?
cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
http://www.configserver.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 10-07-2005, 06:05 PM
Registered User
 
Join Date: Apr 2003
Posts: 131
astopy is on a distinguished road
Quote:
Originally Posted by chirpy
You should (be) subscribe(d) to the security mailing lists...
Are you referring to a cPanel security mailing list? Or individual ones for other applications? If there's a cPanel security list I'd be interested in knowing where I can subscribe.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 10-08-2005, 03:59 AM
chirpy's Avatar
Moderator
 
Join Date: Jun 2002
Location: Go on, have a guess
Posts: 13,495
chirpy will become famous soon enough
I'm referring to the likes of BugTraq and VulnWatch. BugTraq carried the uw-imap vulnerability issue several days ago.
__________________
Jonathan Michaelson
cPanel Forum Moderator

Need your cPanel servers secured and tuned?
cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
http://www.configserver.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 10-08-2005, 10:44 AM
Nic Nic is offline
Registered User
 
Join Date: Dec 2003
Posts: 13
Nic is an unknown quantity at this point
Quote:
Originally Posted by chirpy
I'm referring to the likes of BugTraq and VulnWatch. BugTraq carried the uw-imap vulnerability issue several days ago.
Probably stupid question, but.. can I just disable IMAP on the server (since nobody using it) until next cpanel release? Thanks
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 10-08-2005, 11:00 AM
trparky's Avatar
Registered User
 
Join Date: Apr 2003
Posts: 190
trparky is on a distinguished road
Yes, in the Service Control Panel in WHM.
__________________
Tom Parkison – Rochen Ltd. – tom@rochen.com
- Reseller Plans & Multiple Domain Solutions
- http://www.rochen.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 10-08-2005, 03:31 PM
chirpy's Avatar
Moderator
 
Join Date: Jun 2002
Location: Go on, have a guess
Posts: 13,495
chirpy will become famous soon enough
Remember that if you disable imap you disable the webmail apps. A simpler solution would probably be to block inbound TCP traffic to ports 143 and 993.
__________________
Jonathan Michaelson
cPanel Forum Moderator

Need your cPanel servers secured and tuned?
cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
http://www.configserver.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 10-08-2005, 06:56 PM
WeMasterz5's Avatar
Registered User
 
Join Date: Feb 2003
Location: Miami
Posts: 361
WeMasterz5
we done this conversion now we get errors every where

some like this

ERROR:
ERROR: Could not complete request.
Query: COPY 88:88 "BTRASH"
Reason Given: Error in IMAP command received by server.

Warning: session_start(): open(/tmp/sess_56938189dc5c6cdc026c8898f898c912, O_RDWR) failed: Permission denied (13) in /usr/local/cpanel/base/3rdparty/squirrelmail/functions/global.php on line 333

Warning: session_start(): Cannot send session cache limiter - headers already sent (output started at /usr/local/cpanel/base/3rdparty/squirrelmail/functions/global.php:333) in /usr/local/cpanel/base/3rdparty/squirrelmail/functions/global.php on line 333

Warning: Cannot modify header information - headers already sent by (output started at /usr/local/cpanel/base/3rdparty/squirrelmail/functions/global.php:333) in /usr/local/cpanel/base/3rdparty/squirrelmail/functions/i18n.php on line 211

Warning: Cannot modify header information - headers already sent by (output started at /usr/local/cpanel/base/3rdparty/squirrelmail/functions/global.php:333) in /usr/local/cpanel/base/3rdparty/squirrelmail/functions/global.php on line 305

Warning: Cannot modify header information - headers already sent by (output started at /usr/local/cpanel/base/3rdparty/squirrelmail/functions/global.php:333) in /usr/local/cpanel/base/3rdparty/squirrelmail/src/login.php on line 54

Warning: Cannot modify header information - headers already sent by (output started at /usr/local/cpanel/base/3rdparty/squirrelmail/functions/global.php:333) in /usr/local/cpanel/base/3rdparty/squirrelmail/plugins/cpanel_auth/setup.php on line 25
__________________
What is in a sig anywho é
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9 (permalink)  
Old 10-08-2005, 10:28 PM
Registered User
 
Join Date: Oct 2001
Posts: 154
Bruce
If you need help please use the following information:
Free Email Support for this conversion can be reached by emailing:

maildir@cpanel.net

Free Phone Support for this conversion can be reached by calling:

+1 302 757 7118
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old 10-08-2005, 10:34 PM
WeMasterz5's Avatar
Registered User
 
Join Date: Feb 2003
Location: Miami
Posts: 361
WeMasterz5
been there done all that, phone support M-F, and no reply on the email as of yet
__________________
What is in a sig anywho é
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #11 (permalink)  
Old 10-09-2005, 09:45 AM
chirpy's Avatar
Moderator
 
Join Date: Jun 2002
Location: Go on, have a guess
Posts: 13,495
chirpy will become famous soon enough
Quote:
Warning: session_start(): open(/tmp/sess_56938189dc5c6cdc026c8898f898c912, O_RDWR) failed: Permission denied (13) in
Sounds like a /tmp directory permissions or space issue:

1. Check that /tmp isn't full if it's a separate partition

2. Make sure that /tmp is chmod 1777

3. Try running:

/scripts/upcp --force
__________________
Jonathan Michaelson
cPanel Forum Moderator

Need your cPanel servers secured and tuned?
cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
http://www.configserver.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #12 (permalink)  
Old 10-09-2005, 09:48 AM
WeMasterz5's Avatar
Registered User
 
Join Date: Feb 2003
Location: Miami
Posts: 361
WeMasterz5
it was ( Query: COPY 88:88 "BTRASH" )

something to do with one of the folders we had in there, we ended up just downloading all the mail and making a new account
__________________
What is in a sig anywho é
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 07:58 AM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
© cPanel Inc