I was wondering if it would be possible to send lfd notifications like: login notification, suspicious process,... to an REST API endpoint/server, instead of sending them by email? In case of an email system failure, emails are not sent, but sending them to another (monitoring) system over eg. Https (to an API) would be a good alternative.
There seems to be an option to execute a script,...
This topic has been mentioned already. I have read all the relative posts, I think and cannot find an answer.
We are running centos 7.9, mod_security 3, CSF rules and mod_lsapi. We do see that mod_security is correctly identifying attacks in the cPanel tools. When we look in our CSF logs, we see only about a third of the IP's are being blocked.
I have problem with coding in file /etc/csf/csf.deny.
When I'm editing this file in Python I'm getting error: UnicodeDecodeError: 'utf-8' codec can't decode byte 0xce in position 2882: invalid continuation byte .
Hello Forum,
I want to block an IP Adresse in the range of 91.241.72.0 to 91.241.72.254. Due to spam and multiple IP Adresse in that range.
So i added 91.241.72.0/24 #do not delete to /etc/csf/csf.deny.
And yes i restarted the firewall.
Then i tried to ping 91.241.72.1 from my host... no ping.. Great I thought it works.
The next day I got spam from that IP range agian. WTF!
Hi, i have two servers that every hour the settings are reseting, and removes on special cofig on TCP_IN, TCP_OUT and SMTP_ALLOWUSER,
i tryed to fix this reinstalling, searching for a cronjob but i already not found what is happening, on the logs there is no not about the resetting
Unless I have an IP address/port entry in the csf.allow (tcp|in|d=5061|s=my_ip_address/32), incoming SIP signaling with TLS transport (not UDP) on port 5061 is blocked.
I suspect SPI is rejecting this traffic.
Is it possible to turn off SPI on specific ports?
port 5061 is being opened with port knocking. I can see incoming traffic on tcp 5061 port with tcpdump, so I guess port has been...
Any idea how to make CSF Firewall only logging to file not the console ?
Using CloudLinux 8.5 with cPanel, last time i check the server it was correctly logging into the log file, but now it's shows the log too in the console.
I recently installed ConfigServer Security & Firewall - csf v14.15 on my VPS and there is an apparently easy problem to solve. A single client has access to the webmail blocked by the Firewall. The internet provider that serves you very often changes the internet IP. There are customers that the provider is another and changes with 30 days or more the IP address, but this provider is messing...
I have six clustered CSF 14.15 servers, all with UDPFLOOD_ALLOWUSER = bind set, but I am receiving UID xxx (bind) Tracking Hit reports from all servers. This seemed to start happening after I enabled IPv6.
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum