Search found 5 matches

by debug
17 Apr 2014, 02:05
Forum: General Discussion (csf)
Topic: lfd on server.xxxxxx: UID 25 (named) Tracking Hit
Replies: 3
Views: 5236

lfd on server.xxxxxx: UID 25 (named) Tracking Hit

Hello, I am getting the following email many times since a blocked hacking attempt by almost the same IP. What is the meaning of this message ? How to ride of the message ? 202.0.0.0/8 is blocked by CSF. Sample of port hits: Apr 16 20:08:03 server kernel: [11322599.068185] Firewall: *UDP_OUT Blocked...
by debug
05 Feb 2014, 01:47
Forum: General Discussion (csf)
Topic: 50 SMTP attacks by day from a botnet
Replies: 8
Views: 9373

Re: 50 SMTP attacks by day from a botnet

you can't block or disable port 25 just because of this. Hi Sergio, I am tired to receive 50 emails a day at my external & personal email address just because of this. I am alone on this server with 0 email account. What are the disadvantages to disable port 25? Will it prevent me from receivin...
by debug
04 Feb 2014, 23:41
Forum: General Discussion (csf)
Topic: 50 SMTP attacks by day from a botnet
Replies: 8
Views: 9373

50 SMTP attacks by day from a botnet

Hello, I have a server being attacked in the form of a botnet. I am getting 50 emails a day (since the last two days) like this: Time: Tue Feb 4 17:07:09 2014 -0500 IP: 213.186.183.252 (JO/Jordan/-) Failures: 5 (smtpauth) Interval: 3600 seconds Blocked: Permanent Block Log entries: 2014-02-04 17:06:...
by debug
30 Jan 2014, 14:59
Forum: General Discussion (csf)
Topic: Is it normal ?
Replies: 2
Views: 3207

Re: Is it normal ?

Here is the reply of my hoster. My VPS is managed. It looks like the newer version of CSF is now making additional security recommendations. One of these include changing your PHP handler from DSO to SuPHP. The handler can be changed to address the warning in CSF, but the decision will need to be ma...
by debug
30 Jan 2014, 14:15
Forum: General Discussion (csf)
Topic: Is it normal ?
Replies: 2
Views: 3207

Is it normal ?

Hello,

The screen (UI) after a CSF security check has changed since the last update. Is it normal?

I can't post a photobucket screenshot because I am not currently authorised to post url links. I don't understand why.

Regards