Search found 8 matches

by Buccleuch
29 Jan 2009, 16:35
Forum: Report Bugs (csf)
Topic: Auto update removes csf.tempint?
Replies: 2
Views: 5746

chirpy, Thanks for that. I got the auto update again this morning. Subject: lfd on toshiro: System Integrity checking detected a +modified system file Time: Thu Jan 29 09:40:08 2009 -0600 The following list of files have FAILED the md5sum comparision test. This means +that the file has been changed ...
by Buccleuch
29 Jan 2009, 16:25
Forum: Suggestions (csf)
Topic: alert mail
Replies: 5
Views: 7888

The email address is within the alert files.
by Buccleuch
21 Jan 2009, 15:52
Forum: Report Bugs (csf)
Topic: Auto update removes csf.tempint?
Replies: 2
Views: 5746

Auto update removes csf.tempint?

chirpy, My system auto-updated from 4.36 to 4.38 this morning, and in the process sent me the integrityalert email as follows: Time: Wed Jan 21 09:40:07 2009 -0600 The following list of files have FAILED the md5sum comparision test. This means +that the file has been changed in some way. This could ...
by Buccleuch
21 Jan 2009, 15:47
Forum: General Discussion (csf)
Topic: Strange blocks, "Port Scan" on INVALID state packets from legitimate users
Replies: 6
Views: 11045

Brilliant. Figured that out shortly after my reply, sorry I neglected to update the post to mention that. Thanks for taking the time to explain. :)
by Buccleuch
19 Jan 2009, 16:51
Forum: General Discussion (csf)
Topic: Strange blocks, "Port Scan" on INVALID state packets from legitimate users
Replies: 6
Views: 11045

chirpy, I guess I didn't catch the "repeated attempts to one port" as part of the port scanning. I certainly don't want to disable PF, and I've read elsewhere about disabling DROP_PF_LOGGING, but does that end up stopping the port scanning feature? Is there some way I can (without violatin...
by Buccleuch
16 Jan 2009, 19:34
Forum: General Discussion (csf)
Topic: Strange blocks, "Port Scan" on INVALID state packets from legitimate users
Replies: 6
Views: 11045

Here's what the email notices are looking like. Note, I only changed my IPs in this list because I have to believe A) the IRS has good security controls on their ingress traffic, and B) the IRS has good security controls on their egress traffic and workstation security. This guy is a confirmed legit...
by Buccleuch
16 Jan 2009, 19:33
Forum: General Discussion (csf)
Topic: Strange blocks, "Port Scan" on INVALID state packets from legitimate users
Replies: 6
Views: 11045

Strange blocks, "Port Scan" on INVALID state packets from legitimate users

Guys, I have a peculiar issue that's popped up since installing and configuring csf/lfd. I do believe I've followed the instructions and config file directives properly, but maybe I've overlooked something obvious to you. :cool: A little background. CentOS 5.2-64. Opteron 1216. Physical host (not VP...
by Buccleuch
15 Jan 2009, 20:51
Forum: Report Bugs (csf)
Topic: csf bogon bug
Replies: 3
Views: 6709

Sorry, but it's not a bug per se... From the config file: # Do NOT use this option if your server uses IP's on the bogon list (e.g. this # is often the case with servers behind a NAT firewall using ip routing) The only way bogons work along with using something like a 10.0.0.0/8 private network is i...