Getting thousands of these a day from hundreds of IPs mostly from China Telecom and a few other countries. I've just been manually denying IPs and various CiDRs.
Anyone ever come up with an automatic CSF solution to detect and block these.
Search found 12 matches
- 28 Mar 2018, 15:54
- Forum: General Discussion (csf)
- Topic: Can't block connections
- Replies: 2
- Views: 3992
- 01 Oct 2014, 15:27
- Forum: Report Bugs (csf)
- Topic: After upgrading to 7.51 - bug with csf.allow
- Replies: 5
- Views: 8003
Re: After upgrading to 7.51 - bug with csf.allow
Thanks. That got rid of the error.
- 01 Oct 2014, 14:57
- Forum: Report Bugs (csf)
- Topic: After upgrading to 7.51 - bug with csf.allow
- Replies: 5
- Views: 8003
Re: After upgrading to 7.51 - bug with csf.allow
I'm seeing the same error since my resolv.conf is also immutable. What issue are you having with the csf.allow entries? Just wondering if I'm having a problem there as well.
- 04 Oct 2013, 05:41
- Forum: Suggestions (csf)
- Topic: csf.deny List IP Address In Order
- Replies: 1
- Views: 3052
Re: csf.deny List IP Address In Order
But that list gets pruned from the top when the limit for the deny list is reached, which prunes the oldest. If they're no longer in chronological order, that would really mess things up.
- 14 Jul 2013, 00:54
- Forum: General Discussion (csf)
- Topic: csf.pignore is not working
- Replies: 4
- Views: 5730
Re: csf.pignore is not working
Weird. Have you tried restarting apache as well to see if it makes a difference?
- 13 Jul 2013, 18:20
- Forum: General Discussion (csf)
- Topic: csf.pignore is not working
- Replies: 4
- Views: 5730
Re: csf.pignore is not working
Try revising your exe line to include the first slash, so:
exe:/usr/sbin/httpd
exe:/usr/sbin/httpd
- 13 Jul 2013, 16:02
- Forum: General Discussion (csf)
- Topic: TOR Blocklist
- Replies: 14
- Views: 18575
Re: TOR Blocklist
Also, I read the changelog for the new releases and it should mention you need to manually edit the URL if that's going to be the case rather than just:
"Modified TOR URL in /etc/csf/csf.blocklists to use:" which to me says it's modifying my url as I was expecting.
"Modified TOR URL in /etc/csf/csf.blocklists to use:" which to me says it's modifying my url as I was expecting.
- 13 Jul 2013, 15:59
- Forum: General Discussion (csf)
- Topic: TOR Blocklist
- Replies: 14
- Views: 18575
Re: TOR Blocklist
Seems a little lacking in forethought not to update existing urls. The urls come with csf, so one would think they should be maintained by csf so when people like myself to decide to activate some more blocklists and have them immediately not work.
- 13 Jul 2013, 15:56
- Forum: General Discussion (csf)
- Topic: CSF & Blocklists setup
- Replies: 2
- Views: 6379
Re: CSF & Blocklists setup
Revise your TOR line to read: (remove the space after torproject and TorBulkExitList - forum won't let me post links) TOR|86400|0|http://check.torproject .org/cgi-bin/TorBulkExitList .py?ip=1.1.1.1 The recent csf update was supposed to change this but it hasn't for some. See the other thread about i...
- 13 Jul 2013, 15:47
- Forum: General Discussion (csf)
- Topic: TOR Blocklist
- Replies: 14
- Views: 18575
Re: TOR Blocklist
To also clarify, mine is CentOS 6.4 cPanel 11.38.1.6 dedicated server with many previous versions of the firewall installed.