SquirrelMail plugins compromised
[Posted July 31, 2009 by corbet]
SquirrelMail plugins compromised
[Security] Posted Jul 31, 2009 14:00 UTC (Fri) by corbet
The SquirrelMail team has sent out a notice saying that three plugins
(sasql, multilogin, and change_pass) were compromised on the project's
server. "Parts of these code changes attempts to send mail to an offsite
server containing passwords. We cannot establish a timeline of when
these plugins were compromised. If you are a user of these plugins,
it is strongly recommended you download a fresh copy from the
plugins repository." Changing passwords and looking for intrusions
might also be a good idea.
Full Story (comments: 6)