نمایش نتایج: از شماره 1 تا 5 , از مجموع 5

موضوع: Exim Security Update

  1. #1
    عضو انجمن RezaFH آواتار ها
    تاریخ عضویت
    Jul 2009
    محل سکونت
    تبریز
    نوشته ها
    699
    تشکر تشکر کرده 
    1,032
    تشکر تشکر شده 
    2,817
    تشکر شده در
    1,444 پست

    پیش فرض Exim Security Update

    کسانی که سرور هاستینگ cPanel دارن حتما exim رو آپدیت کنند.
    دستور آپدیت :
    کد:
    /scripts/eximup
    و توضیحات cPanel در این مورد :

    کد:
    Message: 1
    Date: Fri, 10 Dec 2010 00:42:57 -0600
    From: Kenneth Power <kenp@cpanel.net>
    To: news@cpanel.net
    Subject: [cPanel-News] Critical: exim security update
    Message-ID: <D092C409-8697-4D86-97F5-1DF4E7968328@cpanel.net>
    Content-Type: text/plain; charset=windows-1252
    
    =============
    Summary
    =============
    A privilege escalation vulnerability exists in Exim, the mail transfer agent used by cPanel & WHM.
    
    -----------------------
    Security Rating
    -----------------------
    This update has been rated as Critical by the cPanel Security team.
    
    Description
    -----------------------
    Research up to this point indicates the exploit is a buffer overflow vulnerability that takes advantage of the default Exim configuration settings related to altering Exim's runtime configuration file along with overriding the macro definitions in the configuration file. This buffer overflow may lead to arbitrary code execution with the privileges of the user executing the Exim daemon. However, the Exim user retains root privileges when running the -C and -D command line flags. Through the creation of a temporary exim configuration which is processed with the -C or -D flags, the Exim user is able to execute arbitrary commands as root.
    
    Solution
    -----------------------
    To resolve and work around the issue, for Linux-based systems cPanel has issued new Exim RPMs. The new version of Exim locks configuration file locations to the /etc/exim prefix as well as disabling use of the -D flag. Server Owners are strongly urged to upgrade to the following Exim RPM versions:
    
           ? Systems configured to use Maildir: Exim 4.69-25
           ? Systems configured to use mbox (deprecated): Exim 4.63-4
    
    Exim RPMs will be distributed through cPanel's package management system. All cPanel & WHM servers receiving updates automatically will receive the updated Exim RPM during normal update and maintenance operations (upcp).  If you prefer to install the update right now, please run the following in a root shell:
    
       /scripts/eximup
    
    On cPanel & WHM FreeBSD servers, Exim is an unmanaged install performed from the Ports system. To apply a like setup on FreeBSD systems, server administrators will need to perform the following manual configuration:
    
           ?  Remove WITHOUT_ALT_CONFIG_PREFIX=yes from /etc/make.conf
           ?  Add the following to /var/db/ports/exim/options
    
    WITH_ALT_CONFIG_PREFIX=true
    SEDLIST+= -e 's,^(ALT_CONFIG_PREFIX=).*,\1/etc/exim,'
    SEDLIST+= -e 's,^\# (DISABLE_D_OPTION=),\1,'
    
           ? Change directory to /usr/ports/mail/exim
           ? Execute 'make deinstall'
           ? Execute 'make install'
    
    Caution: the above changes have potential to be undone by /scripts/checkmakeconf, and updates to the Exim port. An upcoming version of cPanel & WHM 11.28 will resolve this for FreeBSD users.
    
    References
    -----------------------
    http://docs.cpanel.net/twiki/bin/view/AllDocumentation/SecurityLevels
    http://www.exim.org/lurker/message/20101207.215955.bb32d4f2.en.html
    لطفا اطلاع رسانی کنید ...

  2. تعداد تشکر ها ازRezaFH به دلیل پست مفید


  3. # ADS




     

  4. #2
    عضو دائم IFACO.Net آواتار ها
    تاریخ عضویت
    Mar 2009
    محل سکونت
    Root
    نوشته ها
    1,272
    تشکر تشکر کرده 
    242
    تشکر تشکر شده 
    1,314
    تشکر شده در
    804 پست

    پیش فرض پاسخ : Exim Security Update

    در تکمیل پست قبلی : از طریق فعال کردن آپدیت سی پنل در whm هم می توانید exim رو آپدیت کنید.
    شرکت هاستینگ ایفاکو
    سایت رسمی : IFACO.NET
    هاستینگی تخصصی و مطمئن برای ایرانیان عزیز
    ...: كسی كه ارزش خود را بشناسد، خويشتن را با امور فناپذير خوار نمی‌سازد :...

  5. تعداد تشکر ها از IFACO.Net به دلیل پست مفید


  6. #3
    کاربر اخراج شده
    تاریخ عضویت
    Jun 2010
    نوشته ها
    200
    تشکر تشکر کرده 
    53
    تشکر تشکر شده 
    413
    تشکر شده در
    285 پست

    Exclamation پاسخ : Exim Security Update

    نقل قول نوشته اصلی توسط RezaFH نمایش پست ها
    کسانی که سرور هاستینگ cPanel دارن حتما exim رو آپدیت کنند.
    دستور آپدیت :
    کد:
    /scripts/eximup
    و توضیحات cPanel در این مورد :

    کد:
    Message: 1
    Date: Fri, 10 Dec 2010 00:42:57 -0600
    From: Kenneth Power <kenp@cpanel.net>
    To: news@cpanel.net
    Subject: [cPanel-News] Critical: exim security update
    Message-ID: <D092C409-8697-4D86-97F5-1DF4E7968328@cpanel.net>
    Content-Type: text/plain; charset=windows-1252
     
    =============
    Summary
    =============
    A privilege escalation vulnerability exists in Exim, the mail transfer agent used by cPanel & WHM.
     
    -----------------------
    Security Rating
    -----------------------
    This update has been rated as Critical by the cPanel Security team.
     
    Description
    -----------------------
    Research up to this point indicates the exploit is a buffer overflow vulnerability that takes advantage of the default Exim configuration settings related to altering Exim's runtime configuration file along with overriding the macro definitions in the configuration file. This buffer overflow may lead to arbitrary code execution with the privileges of the user executing the Exim daemon. However, the Exim user retains root privileges when running the -C and -D command line flags. Through the creation of a temporary exim configuration which is processed with the -C or -D flags, the Exim user is able to execute arbitrary commands as root.
     
    Solution
    -----------------------
    To resolve and work around the issue, for Linux-based systems cPanel has issued new Exim RPMs. The new version of Exim locks configuration file locations to the /etc/exim prefix as well as disabling use of the -D flag. Server Owners are strongly urged to upgrade to the following Exim RPM versions:
     
           ? Systems configured to use Maildir: Exim 4.69-25
           ? Systems configured to use mbox (deprecated): Exim 4.63-4
     
    Exim RPMs will be distributed through cPanel's package management system. All cPanel & WHM servers receiving updates automatically will receive the updated Exim RPM during normal update and maintenance operations (upcp).  If you prefer to install the update right now, please run the following in a root shell:
     
       /scripts/eximup
     
    On cPanel & WHM FreeBSD servers, Exim is an unmanaged install performed from the Ports system. To apply a like setup on FreeBSD systems, server administrators will need to perform the following manual configuration:
     
           ?  Remove WITHOUT_ALT_CONFIG_PREFIX=yes from /etc/make.conf
           ?  Add the following to /var/db/ports/exim/options
     
    WITH_ALT_CONFIG_PREFIX=true
    SEDLIST+= -e 's,^(ALT_CONFIG_PREFIX=).*,\1/etc/exim,'
    SEDLIST+= -e 's,^\# (DISABLE_D_OPTION=),\1,'
     
           ? Change directory to /usr/ports/mail/exim
           ? Execute 'make deinstall'
           ? Execute 'make install'
     
    Caution: the above changes have potential to be undone by /scripts/checkmakeconf, and updates to the Exim port. An upcoming version of cPanel & WHM 11.28 will resolve this for FreeBSD users.
     
    References
    -----------------------
    http://docs.cpanel.net/twiki/bin/view/AllDocumentation/SecurityLevels
    http://www.exim.org/lurker/message/20101207.215955.bb32d4f2.en.html
    لطفا اطلاع رسانی کنید ...
    اين يك مشكل امنيتي هست ؟

  7. #4
    عضو دائم IFACO.Net آواتار ها
    تاریخ عضویت
    Mar 2009
    محل سکونت
    Root
    نوشته ها
    1,272
    تشکر تشکر کرده 
    242
    تشکر تشکر شده 
    1,314
    تشکر شده در
    804 پست

    پیش فرض پاسخ : Exim Security Update

    نقل قول نوشته اصلی توسط Ariya نمایش پست ها
    اين يك مشكل امنيتي هست ؟
    This update has been rated as Critical by the cPanel Security team.
    شرکت هاستینگ ایفاکو
    سایت رسمی : IFACO.NET
    هاستینگی تخصصی و مطمئن برای ایرانیان عزیز
    ...: كسی كه ارزش خود را بشناسد، خويشتن را با امور فناپذير خوار نمی‌سازد :...

  8. #5
    مدیر کل Vahid آواتار ها
    تاریخ عضویت
    Aug 2008
    نوشته ها
    2,724
    تشکر تشکر کرده 
    435
    تشکر تشکر شده 
    6,976
    تشکر شده در
    2,085 پست

    پیش فرض پاسخ : Exim Security Update

    من یه مشکلی داشتم که ایمیل ها به یاهو نمیرفت ...
    با این دستور حل شد ....

    ---------- Post added at 12:29 AM ---------- Previous post was at 12:25 AM ----------

    LOG: MAIN
    SMTP error from remote mail server after initial connection: host g.mx.mail.yahoo.com [98.137.54.238]: 421 4.7.1 [TS03] All messages from 66.197.185.85 will be permanently deferred; Retrying will NOT succeed. See http://postmaster.yahoo.com/421-ts03.html
    Connecting to b.mx.mail.yahoo.com [74.6.136.65]:25 ... connected
    SMTP<< 421 4.7.1 [TS03] All messages from 66.197.185.85 will be permanently deferred; Retrying will NOT succeed. See http://postmaster.yahoo.com/421-ts03.html
    SMTP>> QUIT
    LOG: MAIN
    SMTP error from remote mail server after initial connection: host b.mx.mail.yahoo.com [74.6.136.65]: 421 4.7.1 [TS03] All messages from 66.197.185.85 will be permanently deferred; Retrying will NOT succeed. See http://postmaster.yahoo.com/421-ts03.html
    Connecting to e.mx.mail.yahoo.com [67.195.168.230]:25 ... connected
    SMTP<< 421 4.7.1 [TS03] All messages from 66.197.185.85 will be permanently deferred; Retrying will NOT succeed. See http://postmaster.yahoo.com/421-ts03.html
    SMTP>> QUIT
    LOG: MAIN
    SMTP error from remote mail server after initial connection: host e.mx.mail.yahoo.com [67.195.168.230]: 421 4.7.1 [TS03] All messages from 66.197.185.85 will be permanently deferred; Retrying will NOT succeed. See http://postmaster.yahoo.com/421-ts03.html
    Connecting to f.mx.mail.yahoo.com [98.137.54.237]:25 ... connected
    SMTP<< 421 4.7.1 [TS03] All messages from 66.197.185.85 will be permanently deferred; Retrying will NOT succeed. See http://postmaster.yahoo.com/421-ts03.html
    SMTP>> QUIT
    LOG: MAIN
    SMTP error from remote mail server after initial connection: host f.mx.mail.yahoo.com [98.137.54.237]: 421 4.7.1 [TS03] All messages from 66.197.185.85 will be permanently deferred; Retrying will NOT succeed. See http://postmaster.yahoo.com/421-ts03.html
    Connecting to d.mx.mail.yahoo.com [209.191.88.254]:25 ... connected
    SMTP<< 421 4.7.1 [TS03] All messages from 66.197.185.85 will be permanently deferred; Retrying will NOT succeed. See http://postmaster.yahoo.com/421-ts03.html
    SMTP>> QUIT
    LOG: MAIN
    SMTP error from remote mail server after initial connection: host d.mx.mail.yahoo.com [209.191.88.254]: 421 4.7.1 [TS03] All messages from 66.197.185.85 will be permanently deferred; Retrying will NOT succeed. See http://postmaster.yahoo.com/421-ts03.html
    Connecting to j.mx.mail.yahoo.com [66.94.237.64]:25 ... connected
    SMTP<< 421 4.7.1 [TS03] All messages from 66.197.185.85 will be permanently deferred; Retrying will NOT succeed. See http://postmaster.yahoo.com/421-ts03.html
    SMTP>> QUIT
    LOG: MAIN
    SMTP error from remote mail server after initial connection: host j.mx.mail.yahoo.com [66.94.237.64]: 421 4.7.1 [TS03] All messages from 66.197.185.85 will be permanently deferred; Retrying will NOT succeed. See http://postmaster.yahoo.com/421-ts03.html
    LOG: MAIN
    == pineal_melatonin@yahoo.com R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host j.mx.mail.yahoo.com [66.94.237.64]: 421 4.7.1 [TS03] All messages from 66.197.185.85 will be permanently deferred; Retrying will NOT succeed. See http://postmaster.yahoo.com/421-ts03.html
    برای پیش رفت در علم آسانسوری وجود ندارد پله ها را باید پیاده رفت /./ همیشه این یادتان باشد که دست بالای دست بسیار است.
    يادمان باشد براي يك بار ايستادن صد ها بار افتاده ايم /./ بک آپ مهمترین رمز موفقیت هاستینگ /./ امنیت مطلق نیست.
    ارتباط مستقیم با من :
    Admin -{(@)}- WebHostingTalk . ir

اطلاعات موضوع

کاربرانی که در حال مشاهده این موضوع هستند

در حال حاضر 1 کاربر در حال مشاهده این موضوع است. (0 کاربران و 1 مهمان ها)

موضوعات مشابه

  1. فروش Eset Smart Security 8 با تخفیف 20 درصدی و یک Mobile Security رایگان
    توسط speednet در انجمن فروش انواع لایسنس
    پاسخ ها: 9
    آخرين نوشته: March 5th, 2015, 18:38
  2. Roundcube 0.8.6 - security update
    توسط nginxweb در انجمن دايرکت ادمين DirectAdmin
    پاسخ ها: 3
    آخرين نوشته: March 30th, 2013, 01:36
  3. exim-26 down
    توسط hostironi در انجمن سی پنل CPanel
    پاسخ ها: 0
    آخرين نوشته: June 25th, 2012, 00:28
  4. ارسال نکردن ایمیل و مشکل در exim و ریست نشدن exim
    توسط tanhasystem در انجمن سی پنل CPanel
    پاسخ ها: 1
    آخرين نوشته: January 8th, 2012, 22:23
  5. مشکل با exim
    توسط irantrack در انجمن سوالات و مشکلات
    پاسخ ها: 1
    آخرين نوشته: June 27th, 2010, 23:21

مجوز های ارسال و ویرایش

  • شما نمیتوانید موضوع جدیدی ارسال کنید
  • شما امکان ارسال پاسخ را ندارید
  • شما نمیتوانید فایل پیوست کنید.
  • شما نمیتوانید پست های خود را ویرایش کنید
  •