Just a small note to say that it's great you've added support for dynamic hostnames, thanks! However, would it be possible to have more control over the firewall entries so that they have specific port access? As it stands right now they are given blanket ACCEPT permissions on all ports and protocols which is a little too excessive, imo.
Recently, a spammer guessed the email password of one of our users (he guessed it in 5 tries!) and then proceeded to use SMTP AUTH to send thousands of spams through my server.
I looked through my e-mail alerts, and did not find any alerts about this high volume of relayed mail. I only found out about the problem due to receiving an alert about the high queue size.
I just spotted an upload scanner on a competitors site that looks very nifty, but it is very expensive at least for us.
The scanner will monitor files that are uploaded via FTP or php scripts, and will block and alert if for example someone tries to upload one of those r57shell scripts.
There are some very neat elements within CSF that, for example looks for executable files in the /tmp...
I don`t know if this utterly possible, but what I`d like to see would be a feature to allow/deny useragents. Basically, I`ve had a nasty issue last days with Googlebot being blocked out, and the only thing I could see in the logs were a port scan ip blocked ...
After 4 days, I said what the heck, I`ll look in CSF - > Iptables last x log entries ... and guess what ... google bot blocked ...
So I`d...
I'm not sure if this is worth your time, but when running the 'csf -m' command on a Fedora 10 server, CSF inaccurately reports the OS as outdated. Since this is the latest version, you could add checks. That said, I'm not sure how many people run Fedora servers, and if it would be worth it to add checking for the current release version to accomplish this. Just a suggestion. The work you do...
first time i'm installed on my box, csf working well, i'm upgrading to v.4.64 just now and installing webmin modules, csf not want start up, when i look inside /var/log/lfd.log:
Hi,
Really love these programs! But I've needed to customize regex.pm to match my errors messages and also to cover a few other programs. It would be great if there was a method to add new regex patterns and protect them from being over-written during upgrades.
As another example, my smtpauth listens on 25 and 587, so I have to edit within lfd.pl to change this. This should be controlled in a...
Hello,
I would first like to thank the ConfigServer team for the scripts makes available to us. :D
and would like to request the possibility of adding a button to automatically clean the file csf.deny.
On many occasions I have to access the firewall through my blackberry, and it is uncomfortable to edit the file csf.deny using a mobile device, a button to automatically clean the file csf.deny and...
Block Reporting is a very nice feature. Current is possible to give these parameters:
ARG 1 = IP Address # The IP address or CIDR being blocked
ARG 2 = ports # Port, comma separated list or * for all ports
ARG 3 = permanent # 0=temporary block, 1=permanent block
ARG 4 = inout # Direction of block: in, out or inout
ARG 5 = timeout # If a temporary block, TTL in seconds, otherwise 0
ARG 6 =...
Can a warning be added in the interface regarding the FTP not working on a VPS until port changes are made' on a new install of CSF..
It seems this catches quite a few people out..
I had CSF installed on a new VPS server and this bit was not done, which caused me and my clients a couple of days of angst wondering why I could ftp in, and my clients could not (as I had my IP address in the exempt...
When the mysql slow queries log is enabled, it would be great to get a csf alert like dbuser has had more than XX slow queries recorded in the last XX minutes.
I have a suggestion for the existant LF_SCRIPT_ALERT function. Right now when it detects spam, it chmod's the directory and chattr's it.
It would be really good if it could also delete the emails associated with this script which are still in the mail queue. This would prevent spam from exiting the server. ;)
I'd like to know if this is possible for future releases...
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum