Author Topic: How Secure is RoundCube now?  (Read 4574 times)

Offline izrunas

  • Newbie
  • *
  • Posts: 2
How Secure is RoundCube now?
« on: May 13, 2009, 11:39:07 AM »
I had been previously required to remove RoundCube from my server due to security holes.  How secure is RoundCube now?  Is it safe to install again?  

I understand that there were targeted brute-force attacks based on default URLs, but that's easy enough to circumvent by using an atypical directory name.  

I love this product, but cannot afford any security breaches.

Thank you.

Offline izrunas

  • Newbie
  • *
  • Posts: 2
Why is there no response?
« Reply #1 on: June 05, 2009, 05:43:21 PM »
I would have thought that questions about security would be promptly handled and answered.  If I have been mis-informed about problems, I'd like to know.  I want to reinstall the software as soon as I can be sure it is ok.

Thank you...

Offline JohnDoh

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 2,856
How Secure is RoundCube now?
« Reply #2 on: June 09, 2009, 08:14:16 AM »
Well I think the issue you are talking about was fixed a while ago (SourceForge.net: News: Security update for 0.2-beta). AFAIK there are no issues which have been reported but not yet fixed but I am not a developer, you might be better off asking on the dev mailing list.
Roundcube Plugins: Contextmenu, SpamAssassin Prefs, and more…