ConfigServer Services Blog

Announcement

Way to the Web Ltd and Configserver.com will be closing down permanently on 31 August 2025.

This closure affects all of our commercial software including ConfigServer Exploit Scanner (cxs), MailScanner Front-End (MSFE), and Outgoing Spam Monitor (osm). It also affects our free software including ConfigServer Security and Firewall (csf), ConfigServer Mail Queues (cmq), ConfigServer Mail Manage (cmm), ConfigServer Modsecurity Control (cmc), and ConfigServer Explorer (cse).

After 31st August, there will be no further support, downloads, or license IP changes available.

In order to continue using any of our commercial software after the 31st of August, you must update the software to the latest version. If not updated, any of our commercial software products will cease to function and cannot be reactivated once the download and license servers are shut down.

We have prepared a list of FAQs to assist you with any questions you may have. If your question is not answered here, feel free to email us or log a ticket on the helpdesk between now and 31st August.

Future of csf

To allay some fears, we are seriously considering releasing csf (ConfigServer Security & Firewall) under the GPLv3 license. If we do this, it will be before we close for business and the software will be made available via our GitHub repository.

New cxs v14.02

Changes:

  • Product End of Life: Required for continued use after Way to the Web closure

New osm v3.00

Changes:

  • Product End of Life: Required for continued use after Way to the Web closure

Temporary Closure

We are taking a short break and will close the store, helpdesk and email from 17:00 BST on Tuesday, 29th April to 09:00 BST Thursday, 8th May 2025.

If you purchase a license or Service Package before the closing date and require installation, please be sure to leave at least 24-48 hours before then for the work to be done. Otherwise, any work will be scheduled for after this period. We will reopen on Thursday, 8th May 2025.

New csf v14.23

Changes:

  • Modified Apache regexes to detect “remote” or “client” as the IP trigger
  • Modified UI HTTP header checks to be case agnostic
  • Sanitise CC list strings