Search found 7 matches

by WBA
16 Jul 2015, 13:57
Forum: General Discussion (csf)
Topic: fail to block port scans
Replies: 3
Views: 3114

Re: fail to block port scans

Ok, I have been able to get it working, I had to completely remove rsyslogd and reinstall.
/etc/init.d/rsyslog stop
apt-get remove --purge rsyslog
apt-get install rsyslog

Must have been a leftover from the upgrade.

Thanks again for pointing me in the right direction.
WBA
by WBA
16 Jul 2015, 13:32
Forum: General Discussion (csf)
Topic: fail to block port scans
Replies: 3
Views: 3114

Re: fail to block port scans

Is there any way to change this? I notice on the web others have the same problem. http://serverfault.com/questions/696628/where-does-vmunix-label-in-syslog-come-from-on-debian-linux-systems I upgraded from Squeeze as well and didn't change anything intentionally. Thank you for your very quick respo...
by WBA
15 Jul 2015, 19:22
Forum: General Discussion (csf)
Topic: fail to block port scans
Replies: 3
Views: 3114

fail to block port scans

Hello, I have a Debian 8 VM (Jessie) running on Xen, I can not get it to block port scans. I have set PS_INTERVAL = "100" PS_LIMIT = "10" All other functions seem to work fine. /etc/csf# /etc/csf/csftest.pl Testing ip_tables/iptable_filter...OK Testing ipt_LOG...OK Testing ipt_mu...
by WBA
01 Aug 2012, 22:16
Forum: Suggestions (csf)
Topic: Suggested change to Exim SMTP AUTH regex
Replies: 7
Views: 9969

Re: Suggested change to Exim SMTP AUTH regex

I think I have figured it out, you are correct, the reason for not blocking the IP was the time interval, after reviewing the log very closely there were less than 10 attempts in 5 minutes from each IP. I am going to increase the time spam to 30 minutes if I can figure out how. Thanks for the follow...
by WBA
26 Jul 2012, 16:54
Forum: Suggestions (csf)
Topic: Suggested change to Exim SMTP AUTH regex
Replies: 7
Views: 9969

Re: Suggested change to Exim SMTP AUTH regex

Hello, I seem to be having this same problem and it is not being picked up by CSF Currently using version 5.59 "csf is already at the latest version: v5.59" Here is what I see in /var/log/exim/mainlog 2012-07-26 10:51:04 plain authenticator failed for portal_peceofmind_com ([10.10.11.6]) [...
by WBA
22 Feb 2012, 18:08
Forum: Suggestions (csf)
Topic: pop3-login login failures not blocked after Dovecot upgrade
Replies: 4
Views: 10247

pop3-login login failures not blocked after Dovecot upgrade

LFD doesn't seem to recognise pop3-login failures after upgrading to Dovecot 2.1.0 We are running Direct Admin current with Dovecot 2.1.0 /var/log# csf --version csf: v5.46 (DirectAdmin) These are the log entries that don't work now Server1 Feb 22 11:21:39 bob1 dovecot: pop3-login: Disconnected: Ina...