Search found 58 matches

by yellowhousejake
Wed May 08, 2019 2:10 pm
Forum: Administrators
Topic: CVE-2019-9670 being actively exploited
Replies: 213
Views: 93278

Re: CVE-2019-9670 being actively exploited

Currently I have tripwire running to alert me of any changes. I can spin up my last nightly Veeam backup and copy any compromised files over quickly if needed. Just watching now.

DAve
by yellowhousejake
Fri May 03, 2019 5:50 pm
Forum: Administrators
Topic: CVE-2019-9670 being actively exploited
Replies: 213
Views: 93278

Re: CVE-2019-9670 being actively exploited

I have installed tripwire and configured it to check the /opt/zimbra directories pretty thoroughly. I will need to pull it back once I see what happens inside the jetty directories. Obviously not checking directories like data and log. I am curious after reading the simple idea of creating your own ...
by yellowhousejake
Thu May 02, 2019 8:01 pm
Forum: Administrators
Topic: CVE-2019-9670 being actively exploited
Replies: 213
Views: 93278

Re: CVE-2019-9670 being actively exploited

I agree the firewall will not make this a non-issue, but what ways are there to determine if a server request is valid? I am looking at tripwire now for at least an early warning system. Thinking of Zimbra as a web server is exactly the correct way to look at the product. We have always done so sinc...
by yellowhousejake
Thu May 02, 2019 5:54 pm
Forum: Administrators
Topic: Autocomplete fails after upgrade from 8.0.7 to 8.8.9
Replies: 4
Views: 505

Re: Autocomplete fails after upgrade from 8.0.7 to 8.8.9

Thank you for the response but that is a different issue. Auto complete works in the sense that it finds the address you are searching for in the GAL, personal contacts, and emailed contacts. The issue lies in the contents of the address field within that contact. If there is only an email address, ...
by yellowhousejake
Thu May 02, 2019 3:22 pm
Forum: Administrators
Topic: CVE-2019-9670 being actively exploited
Replies: 213
Views: 93278

Re: CVE-2019-9670 being actively exploited

I still thought it best to see if I should patch for this exploit but I am unable to determine if it is needed. When I go the security page it does not list this CVE number under any patches for 8.8.9. for current zimbra supported version, namely 8.8 .x , you must update to the latest version. Than...
by yellowhousejake
Thu May 02, 2019 2:26 pm
Forum: Administrators
Topic: CVE-2019-9670 being actively exploited
Replies: 213
Views: 93278

Re: CVE-2019-9670 being actively exploited

An great thread with lots of clear instruction, thank you to everyone who has contributed. We recently did a migration from 8.0.7 NE to 8.8.9 NE so I was very interested in this thread. We had no issues with 8.0.7 and in fact only upgraded because our paid support no longer covered version 8.0.7. So...
by yellowhousejake
Thu May 02, 2019 12:23 pm
Forum: Administrators
Topic: Autocomplete fails after upgrade from 8.0.7 to 8.8.9
Replies: 4
Views: 505

Re: Autocomplete fails after upgrade from 8.0.7 to 8.8.9

Digging deeper, it looks like the problem is caused when someone copies an email address from a message and pastes it into a contact rather than right clicking and selecting "Add to Contacts".

So, no one else is seeing this in their Zimbra?

DAve
by yellowhousejake
Tue Apr 30, 2019 6:02 pm
Forum: Administrators
Topic: Autocomplete fails after upgrade from 8.0.7 to 8.8.9
Replies: 4
Views: 505

Re: Autocomplete fails after upgrade from 8.0.7 to 8.8.9

I confirmed that I can edit the offending email field in contacts and change it only the email address and auto complete now works as it should populating the To: field in the message. It certainly looks like Zimbra 8.8.9 is not working with the email field populated as it could be in 8.0.7. I am go...
by yellowhousejake
Tue Apr 30, 2019 4:01 pm
Forum: Administrators
Topic: Autocomplete fails after upgrade from 8.0.7 to 8.8.9
Replies: 4
Views: 505

Autocomplete fails after upgrade from 8.0.7 to 8.8.9

Recent upgrade from 8.0.7 NE to 8.8.9 NE on Ubuntu. Migration was through ZMig to backupNG. No real problems. Today I have had users complain that some of their contacts do not work. They can see them with auto complete, but after selecting the contact it does not go into the To: field. Where the co...
by yellowhousejake
Thu Apr 25, 2019 5:25 pm
Forum: Administrators
Topic: Change helo name and banner
Replies: 4
Views: 442

[SOLVED] Re: Change helo name and banner

Worked perfectly, thank you.

DAve

Go to advanced search