[mimp] Phishing

robert@abilina.org robert at abilina.org
Mon Jul 10 06:23:43 PDT 2006


A couple of months ago, I setup a horde/mimp site for reading several imap 
accounts on my pocket-pc phone.  The system worked great, once I got it 
properly configured.

Eventually I had to take it down because it was hacked and a paypal 
phishing page had been installed somehow.  In speaking to a friend of 
mine, who does a better job of monitoring incoming hack attempts than I 
do, it is quite common for the hackers to be looking for horde installs, 
making him think that horde has a security hole.

Perhaps I did a poor job configuring my installation, or perhaps there are 
flaws in the code that make it hackable.  Is there any history on this, 
has anyone else experienced this?  I still have the complete setup 
including the uploaded page, I just took down apache.  The OS I am using 
is FC4.


-- 
Best Regards,
Robert

Fighting SPAM with Active Spam Filter, see:
http://a-s-k.sourceforge.net/


More information about the mimp mailing list