Community forum to discuss cxs.
If you believe that there is a problem with your cxs installation and want support then, as a paid product, you should use the helpdesk after having consulted the documentation.
Hi, I'm not sure what the CXS_ALL firewall rule (filter) is doing but it appears for blocked IP's in CSF/LFD and when I attempt to unblock, it unblocks the IP in LFD but the CXS_ALL filter remains.
The only way to override the rule is to white-list the IP.
1) What is this filter?
2) Is there any easy way unblock IP's in this list?
Each time I disable the Email configuration via your WHM command wizard UI (for watch and daily/weekly cron), the setting is saved but upon returning to the wizard the option is checked again which would result in the option being enabled when reconfiguring the command.
Generated command/config showing email is disabled:
Wizard, after returning to it when previously disabling the email...
I wanted to know if there is a way to not send CXS's results via mail. Even when I don't use --mail reports are sent anyways.
I am scanning lots of accounts and I don't need to receive an email for each one of them. I only need those report stored in a file, so I can read it when if I need to.
Hi
1-I purchased cxs scanner and every time i do manual scan to all of my whm account after the scan does finish i see that some of my whm account was deleted without my permission.what shoud i do to prevent delet my whm account?
next question is that i have phishing in my server but cxs doesn't detect and remove theme and i receive abuse from datacenter every day
thanks
I have a server where CXS is installed, but when I try to run a manual scan it doesn't actually scan any files. It goes through all folders and that's it.
Here's what's happening:
# /usr/sbin/cxs --baction high --bayes --breport medium --clamdsock /var/clamd --deep --defapache nobody --report /var/log/cxs.scan --logfile /var/log/cxs.log --doptions Mv --exploitscan --fallback...
I get inundated with hacker activity, mainly exploiting Wordpress to install files which CSXS deletes or quarantines but nothing stops the same hackers on the same IP addresses from attacking multiple WP installs.
I don't know of a way to deal with the issue other than to manually block all of the IP addresses. Maybe blocking the IP addresses does no good as it seems I am chasing my tail. No...
Actually we would like to extend the CXS to our 10 other servers , however we would like to have some clarifications please :
1 - We run only CXS watch deamon with CLAMAV , this will be enough to detect and protect against mass defacement perl scripts ?
2 - In CXS watch deamon logs i never see that CXS find something suspect ? should i mandatory create QUARANTINE or there is one by...
I find cxs very usefful on our Cpanel servers, and wish to use it on non-cpanel servers, to ensure their security.
I see that Cpanel is required, but i dont know if is viable use it (on limited way, or just only a few features) on non-cpanel server, or its not possible (and never be because...) use cxs on non Cpanel server.
Only i need is scan for files and daemon. Not need of interface or...
we're getting a lot of alerts for exploit P1410 but the affected files seem to be a simple archive script included in a lot of apps like coppermine, joomla extensions, CMS Made Simple and so on. The apparently bad file is even included in official sources of the named products. I don't know if maybe some malware used partially the same code as the legitimate script and now all are...
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum