csf.pignore - use more than one criteria

Post Reply
Kiekeboe100
Junior Member
Posts: 1
Joined: 14 Feb 2010, 17:20

csf.pignore - use more than one criteria

Post by Kiekeboe100 »

Hi,

Would it be possible to change csf.pignore so that I can tell it to ignore the executable /bin/bash when it's from user stijn?

When i'm logged on with ssh I get these emails regularly, and the only possibility to stop them as far as I know is to add user:stijn or exe:/bin/bash to the list.

If i exclude /bin/bash I won't see notices for other people, and when I add my user, i won't receive any mails when my user account is compromised and someone is using it to run scanning tools.

Or maybe I'm just thinking a bit too paranoid :)

grtz,
Stijn
Sergio
Junior Member
Posts: 1712
Joined: 12 Dec 2006, 14:56

Post by Sergio »

This is the wrong forum to post your question, this forum is for Suggestions about improving CSF.

Any way, to answer your question, you don't need to psignore /bin/bash as it is already ignored because is part of the OS, but you can do a better way to ignore the process of your user doing the following:
exec: /home/stijn/public_html/exact_URL_of_the process_to_ignore.

Doing this, you will only be ignoring that particular process in one user.
Post Reply