The new cPanel WebDisk facility occasionally throws up suspicious process emails when people use it. It may be worth adding its process to the ignore processes list if you let customers use it.
This is whats needed inside the process ignore list:
It would be nice if I could move certain logon failures to a timed list so that they would clear in a specified time.
We never remove SSH failures but FTP, SMTP are often legit users that for whatever reason get themselves locked out.
If we could set this list to clear at certain intervals, it would make life a bit easier and at the same time, anyone trying hack in is going to be long gone...
CSF already does a nice job watching the exim_mainlog file. Many of us have also setup WHM to not allow any domain to send over x amount of emails per hour. When a spammer gets on the server and attempts to do so it is logged in exim_mainlog. It would be a great help if CSF could also check for multiple failures of this limit by checking for excessive sending attempts as well. I think that this...
I noticed that filtering based on UID or GID of source packet in csf.allow works only if d=port is specified.
I think it would be nice to make s/d=port setting optional (unless you had a good reason to design it like that)
Is there any way to have an email sent to either the server administrator or maybe even a field setup within CSF admin page, so that when your upgrade button appears in WHM it would email telling you an update is available.
Not sure if others would benifit from this but hey worth asking.
Is it possible to add a new feature to CSF so that if an IP address is blocked due to exceeding the CT_LIMIT (Connection Tracking Limit) the email produced actually contains details of the connections in progress.
For example, instead of just:
From: root
To: root
Subject: lfd: 12.34.56.78 blocked with too many connections
It would be nice if you could set which BLOCKS you would like to be PERM and which TEMP. The items requested with this option would be:
LF_SSHD; LF_FTPD; LF_POP3D; LF_IMAPD; LF_HTACCESS; LF_MODSEC; LF_CPANEL; LT_POP3D; and LT_IMAPD.
Currently you please a postive number in the option for these. What if CSF looks at the number and if it is positive then it is a PERM BLOCK and if negitive it is...
Firstly, thank you so much for this script! It is excellent!
Personally I have shut off the cPanel mod_security plugin and installed mod_security myself. This way I don't get cPanel scrubbing the audit_log every hour. Your script does a far better job of displaying more information about each potential attack!
I wonder though for someone that has little to no idea about these things,...
Hello,
i have dedicated server and install csf and lfd
will time i upload one shell c99 on server and run them,and in part :: Command execute :: and enter cat /var/cpanel/accounting.log, i can see all user and all site in my server
and if i enter command ls /home/ /public_html i can enter to any user that want
Do you have away ?
i close them,until hacker can`t see all site and see all files...
Maybe adding a feature on setup to enable/disable CSF frontend on WHM be helpfull for those dummies that get managed Dedicated or VPS, so we can disable frontend for those that do not know how to deal with it.
would it be possible to add the IP address for SU alerts. I though if I just added the shortcut in the email alert it may put the IP in there, but it doesn't. IE:
lfd: SU login alert - Successful login from admin to root
Time: Thu Dec 21 09:09:28 2006
From: admin
To: root
Status: Successful login
IP:
as we now disabling direct root logins and it would be handy, when an alert...
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum