Web Hosting Talk







View Full Version : Melange Security Server


SchultzNY
08-03-2003, 09:28 AM
Hey

Was just talking to my security guy and he said he was looking at the server and found something called Melange Chat Server. I assume this is what cpanel is using for the chat rooms, but i figured ill go check the melange website and found this:

Due to lack of time development on the melange chat system and support had to be abandon. You may go on now, but keep in mind that there was no update for a long time. THERE ARE KNOWN BUGS AND SECURITY CONCERNS, SO USING MELANGE IS ON YOUR OWN RISK! Also when you write an email, please be patient, you may have to wait quite a while for an answer. Sorry.

So thats it, its a buggy piece of trash. Does anyone know how to disable it or have any idea on securing it? I definately dont want a security hole open on my server.

Andrew

sprintserve
08-03-2003, 11:41 AM
Go to WHM. You can go to server setup, then service manager.

Untick Melange.

You are done.

Rclark
08-05-2003, 02:11 PM
Well the bug was a buffer overflow in the /NICK command. But this was only the case if it was compiled with a certain older version of GCC or less. If you do require its use then there is a way of checking to see if you're vulnerable.. if not just turn her off =>

Here is the link to the security advisory:
http://www.idefense.com/advisory/12.16.02b.txt


Here is a link to the POC Code:
http://www.securiteam.com/exploits/6W00L1F6AS.html

:D