After migration to AlmaLinux 9 from CentOS 7 I suddenly met the problem with loading files by ftp (example from shell)
curl -u user:password ' -o /var/www/html/df/file1.zip
Result
curl: (7) Failed to connect to example.com port 21: Connection refused
When I stop only CSF service (lfd and iptables leave running as i s) - everything is OK, file will be downloaded by...
I have a server that will be used for development tasks. So i want this server only accessible from Finland (for some ports only, all other ports will be blocked for anywhere). I tried lots of settings and couldn't make it working.
Hi - we're needing some assistance to get these type of attacks blocked automatically with a custom regex- say 10 login attempts in 12 hours to mitigate slow logins and permanently banned and added to block list where we can remove them if needed in case of customer false attempts. We've tried a few things including fail2ban although it would be great if LFD can scan the logs and ban them...
I've seen some posts about using BLOCK_REPORT to customize when an IP is blocked. I'm looking for something that will allow me to execute a custom script whenever CSF identifies accounts exceeding processes, mem, time limits. I want to be able to kill certain accounts (based on their web hosting plan) via a custom script that will allow me to do further reporting/stats at the same time.
There are a lot of questions on this forum regarding this, and I have read most of them. As is usually the case, I am receiving a huge amount of notifications from CSF, from a cron.php that the user of this server has placed and wants to run every 5 minutes. This process is legit, and we want to keep it running. The output is this:
I'm facing a strange issue where CSF is not blocking nor allowing IPs in Almalinux/CL 9.
If I add a temporarly allow like this, it creates an IPTABLES entry and it doesn't work (port 22 is not in TCP_OUT):
# csf -ta 12.34.12.34
ACCEPT all opt -- in !lo out * 12.34.12.34 -> 0.0.0.0/0
ACCEPT all opt -- in * out...
Hello,
After upgrading from Ubuntu 22.04 to 24.04, and while CSF+ProFTP server was working fine, now it doesn't allow to retrieve directory listing.
Any suggestions ?
Once an hour the load on one of our servers spikes big time. Normal load is barely above zero, but it spikes to loads over 100.0 for a minute or two then comes back down to normal.
When it spikes I always see these: processes, with the first one causing the load:
lfd - retrieving global lists
lfd - retrieving blocklists (waiting for list lock)
lfd - retrieving countrycode lists (waiting for...
Hello ,
I created a custom modsec rule that returns a 403 status code if there is a sql injection attempt, i want csf to block the ip that is triggering this rule by monitoring the log that modsec is logging in it , but it isnt blocking it at all
the log came up as either
/usr/local/apache/error_log or
/var/log/apache2/error_log
so in csf.conf i specified the MODSEC_LOG to be...
It seems LFD outputs its blocked messages (eg. Firewall: *UDP_IN Blocked* IN=eth0... ) to the system journal with priority 4 (warning), even when it's just blocking incoming traffic based on port number. This makes them gold-coloured in my TTY, but more annoyingly it gets spammed out to my VPS's emergency console standard output, putting out lines every few seconds. Is there a way to get LFD to...
Temporary blocks that triggered the permanent block:
Tue Sep 10 07:14:01 2024 (CT) IP :: (Unknown) found to have 32 connections
Tue Sep 10 07:44:01 2024 (CT) IP ::...
Hi there,
After the latest cpanel update to version 122.0.5 we have all of sudden been getting lfd email every hour as such:
Time: Mon Aug 26 16:07:26 2024 +0100
File: /tmp/.spamassassin3950SumxCatmp
Reason: Suspicious directory
Owner: nobody:nobody (99:99)
Action: No action taken
CSF having an IP detection error. It is actually from Colombia, but it detects it as Romania
Query:
A) What database does CSF work with to query IP and country of origin?
B) How can you update the CSF IP database?
C) Is there a way to report this type of IP location errors?
I get this email from my server:
Subject: Cron /usr/sbin/csf -u
Message: csf and lfd have been disabled, use 'csf -e' to enable
I logged in to WHM to enable again all connection become blocked, if I disable via SSH everything works fine.
I can't image what I have to do to work again, should I reinstall csf or how can I find the problem?
I did not changed anything for weeks, csf updated 5...
When CSF blocks an IP, it shows all the information of where and why including the country code. I'm not sure where CSF gets the country code information but why can't you simply block by the country code instead of huge lists of CIDR's? I am able to do this in Modesecurity but I would rather block for the entire server instead of just http.
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum