Roundcube Community Forum

 

How Secure is RoundCube now?

Started by izrunas, May 13, 2009, 11:39:07 AM

Previous topic - Next topic

izrunas

I had been previously required to remove RoundCube from my server due to security holes.  How secure is RoundCube now?  Is it safe to install again?  

I understand that there were targeted brute-force attacks based on default URLs, but that's easy enough to circumvent by using an atypical directory name.  

I love this product, but cannot afford any security breaches.

Thank you.

izrunas

I would have thought that questions about security would be promptly handled and answered.  If I have been mis-informed about problems, I'd like to know.  I want to reinstall the software as soon as I can be sure it is ok.

Thank you...

JohnDoh

Well I think the issue you are talking about was fixed a while ago (SourceForge.net: News: Security update for 0.2-beta). AFAIK there are no issues which have been reported but not yet fixed but I am not a developer, you might be better off asking on the dev mailing list.
Roundcube Plugins: Contextmenu, SpamAssassin Prefs, and more...