Ok, I have been able to get it working, I had to completely remove rsyslogd and reinstall.
/etc/init.d/rsyslog stop
apt-get remove --purge rsyslog
apt-get install rsyslog
Must have been a leftover from the upgrade.
Thanks again for pointing me in the right direction.
WBA
Search found 7 matches
- 16 Jul 2015, 13:57
- Forum: General Discussion (csf)
- Topic: fail to block port scans
- Replies: 3
- Views: 3114
- 16 Jul 2015, 13:32
- Forum: General Discussion (csf)
- Topic: fail to block port scans
- Replies: 3
- Views: 3114
Re: fail to block port scans
Is there any way to change this? I notice on the web others have the same problem. http://serverfault.com/questions/696628/where-does-vmunix-label-in-syslog-come-from-on-debian-linux-systems I upgraded from Squeeze as well and didn't change anything intentionally. Thank you for your very quick respo...
- 15 Jul 2015, 19:22
- Forum: General Discussion (csf)
- Topic: fail to block port scans
- Replies: 3
- Views: 3114
fail to block port scans
Hello, I have a Debian 8 VM (Jessie) running on Xen, I can not get it to block port scans. I have set PS_INTERVAL = "100" PS_LIMIT = "10" All other functions seem to work fine. /etc/csf# /etc/csf/csftest.pl Testing ip_tables/iptable_filter...OK Testing ipt_LOG...OK Testing ipt_mu...
- 01 Aug 2012, 22:16
- Forum: Suggestions (csf)
- Topic: Suggested change to Exim SMTP AUTH regex
- Replies: 7
- Views: 9969
Re: Suggested change to Exim SMTP AUTH regex
I think I have figured it out, you are correct, the reason for not blocking the IP was the time interval, after reviewing the log very closely there were less than 10 attempts in 5 minutes from each IP. I am going to increase the time spam to 30 minutes if I can figure out how. Thanks for the follow...
- 26 Jul 2012, 16:54
- Forum: Suggestions (csf)
- Topic: Suggested change to Exim SMTP AUTH regex
- Replies: 7
- Views: 9969
Re: Suggested change to Exim SMTP AUTH regex
Hello, I seem to be having this same problem and it is not being picked up by CSF Currently using version 5.59 "csf is already at the latest version: v5.59" Here is what I see in /var/log/exim/mainlog 2012-07-26 10:51:04 plain authenticator failed for portal_peceofmind_com ([10.10.11.6]) [...
- 27 Feb 2012, 15:26
- Forum: Suggestions (csf)
- Topic: pop3-login login failures not blocked after Dovecot upgrade
- Replies: 4
- Views: 10247
Re: pop3-login login failures not blocked after Dovecot upgr
Thank you, works perfect now.
- 22 Feb 2012, 18:08
- Forum: Suggestions (csf)
- Topic: pop3-login login failures not blocked after Dovecot upgrade
- Replies: 4
- Views: 10247
pop3-login login failures not blocked after Dovecot upgrade
LFD doesn't seem to recognise pop3-login failures after upgrading to Dovecot 2.1.0 We are running Direct Admin current with Dovecot 2.1.0 /var/log# csf --version csf: v5.46 (DirectAdmin) These are the log entries that don't work now Server1 Feb 22 11:21:39 bob1 dovecot: pop3-login: Disconnected: Ina...