Roundcube exploited, versions out to fix the issue

Hackers exploit Roundcube webmail flaw to steal email, credentials

Here’s the deal. No piece of software, including webmale software like Roundcube is immune to vulnerabilities. According to the article, there are versions that fix the vulnerability.

The thing is, these attacks talked about within the article were targeted outside the United States, but it can happen anywhere.

Email sent to targets

The image shows a screenshot of an email interface. It includes the sender’s information partially blacked out, a subject line in Russian, which translates to “Regarding the visit,” and a timestamp of August 6, 2024, at 12:24 AM. Below, there’s an attachment icon for a Word document titled “Road map.doc” with
The attackers sent blank emails, except they did have a word document and code within the email. Once opened, the exploit happened.

While this was sent to probably someone in Russia, emails with attachments and no explanation are bound for trouble if I should say so. I’ve seen links, and attachments where I couldn’t open them or I opened the link and it went somewhere where I didn’t know.

It uses a h r e f based 64 to download a payload. I spaced the letters out on purpose.

Then it will inject an unauthorized log in form which takes the username and password of the session taken being used.

Attempted data exfiltration

The image shows a code snippet written in JavaScript. It includes a constant `filename` assigned to “Road map.docx” and a function `saveFileFromBase64`. It appears to involve an email operation, with a variable `mail` containing a Base64 encoded string. A `fetch` call is made to send an HTTP POST request,
After they get the data, they exfiltrate it.

The article talks about what version of Roundcube you should be using if you use Webmail at all.

I don’t like using webmail, and I’ve used it off and on for 20 plus years starting with Hotmail. While providers themselves are not the reason for this discussion, I did get hotmail to work with a mail client.

Roundcube comes with Cpanel, a very popular web control panel that lots of hosts use to administer accounts and for you to administer your account.

I don’t know if these control panels automaticly update things like roundcube, as I can’t see a version number when I log in.

Cpanel used to have three different clients, but Roundcube seems to be the only one being used these days.

Hackers exploit Roundcube webmail flaw to steal email, credentials is the article you need to read.

We want people to read and learn about these things so they can be aware. Thanks so much for reading!


Discover more from The Technology blog and podcast

Subscribe to get the latest posts sent to your email.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.