I just got 14 messages all stating that my account logged onto root. But that wasn't me. I quickly logged on and checked and see no evidence of any root logins.
Suspecting that these might be older messages just now coming in (from previous days) I checked the email headers and they show that they came in just a minute ago. The /var/log/exim_mainlog also shows that the messages were just sent....
In a VPS with Ubuntu 16 & CSF that uses /etc/apache2/sites-enable (etc) and the vhosts......
There is a lot of webpages with user and password fields to use services like:
roundcube
phpmyadmin
and webpages that has login for users to post documents etc....
How is possible to have CSF monitoring those login pages and block ips after X tries?
Best Regards
I just notice i have an error when try to start CSF.
Here output.
ACCEPT all opt -- in eth1 out * 0.0.0.0/0 -> 0.0.0.0/0
ACCEPT all opt -- in * out eth1 0.0.0.0/0 -> 0.0.0.0/0
ACCEPT all opt in eth1 out * ::/0 -> ::/0
ACCEPT all opt in * out eth1 ::/0 -> ::/0
*ERROR* line:
Command:
Error:
You should check through the main output carefully
I have a Debian 9 server with all the latest patches and CSF/LFD the latest version. Just a standard configuration with one IP number, no crazy things.
I want to automatically block IPs when they try to break in. I thought CSF/LFD did out of the box, but still I wake up with 600 of the below alert mails:
Feb 6 05:32:48 mail02 postfix/submission/smtpd : warning:...
My home network works within 192.168.178.0/24 .
My plan was to only (mainly) allow internal connections to and from the server on which CSF has been installed.
Therefore I started with adding 102.168.178.0/24 to csf.allow:
###############################################################################
# Copyright 2006-2017, Way to the Web Limited
# URL:
# Email:...
Hi,
I have some client with about 20 stations
one of the sation try to connect to the smtp with incorrect login details
on CSF, I got the next message:
1.1.1.1 # lfd: (smtpauth) Failed SMTP AUTH login from 1.1.1.1 (US/Usa/-): 5 in the last 3600 secs - Sat Nov 03 02:32:40 2013
there is any possible to add the username to this message?
for example, 1.1.1.1 # lfd: (smtpauth) Failed SMTP AUTH login...
I've read through quite a few posts on this forum and no one else seems to have the issue I'm having. I can't even get csf to register the postfix sasl attacks.
I have enabled login failure protection but it is letting a lot of attempts through:
# Enable login failure detection of sshd connections
#
# SECURITY NOTE: This option is affected by the RESTRICT_SYSLOG option. Read
# this file about RESTRICT_SYSLOG before enabling this option:
LF_SSHD = 5
LF_SSHD_PERM = 1
We are currently testing messenger with reCAPTCHA activated to allow our customer to unblock their IP when blocked.
So far, the HTML service is running and we are able to get the web page.
The reCAPTCHA is able to validate if the visitor is a bot or not but for some reason, once reCAPTCHA has been validated, the IP still remains blocked even tho we are seeing the following message:
In WHM when the CSF Firewall is enabled and Backups are triggered, there is a huge amount of softIRQs triggered (see screenshot at the bottom). When disabling the CSF Firewall: those softIRQs are a lot lower.
We have other servers elsewhere (VPS, not dedicated) and while there are some softIRQs, it is not as much as the screenshot attached.
I'm trying to setup a custom regex for nextcloud login failure detection. It is not working (triggering when I try to login >5 times with incorrect credentials):
I have setup /var/www/nextcloud/data/nextcloud.log as CUSTOM1_LOG. lfd says it is watching the file, and entries look like this:
Hi all,
It might be that Christmas is coming and my brain is more focus on Santa stuff instead of being able to read and understand the instructions, or that I am just TAU (tired as usual).
My problem is that I can't figure out if LF_INTERVAL is doing one or 2 things:
1) limiting the number of triggers accepted during the LF_INTERVAL number of seconds
2) setting the time between checks
Hello guys,
WGET seems to not work (and another error see below)
# wget 100mb . test
--2013-11-24 18:15:15-- 100mb . test
Resolving cachefly.test . net... 205.234.175.175
Connecting to cachefly.test . net|205.234.175.175|:80... ^C
It times out if I do not cancel.
Log:
Nov 24 17:54:00 master lfd : CCL Error: Unable to retrieve GeoLite Country database - Unable to download: 599 - Could not...
How can i get CSF to work whit proxy? I have add the IP-address that the python script that i use connect whit but i end up whit time out error. But when i disable CSF everything is working and i have add the ip address to the csf.ignore and csf.allow file but it dont help.
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum