How to block IP at the first attack detected in CXS?

Community forum to discuss cxs.
If you believe that there is a problem with your cxs installation and want support then, as a paid product, you should use the helpdesk after having consulted the documentation.
Post Reply
Sergio
Junior Member
Posts: 1729
Joined: 12 Dec 2006, 14:56

How to block IP at the first attack detected in CXS?

Post by Sergio »

Hello Sarah,
Season greetings.

Sarah, is there a way to block on CSF Firewall an IP that trigers an MD5SUM at the first attempt?

If not, How may I can implement this?

Merry X'mas,
Sergio
Sarah
Moderator
Posts: 939
Joined: 09 Dec 2006, 22:49

Re: How to block IP at the first attack detected in CXS?

Post by Sarah »

It is only possible to block cxs modsecurity hits in csf because otherwise cxs does not have the IP address of the attacker. You can use LF_CXS to configure this.
Sergio
Junior Member
Posts: 1729
Joined: 12 Dec 2006, 14:56

Re: How to block IP at the first attack detected in CXS?

Post by Sergio »

Thank you, Sarah.

I was writing about MD5SUM generated by CXS.

ModSecurity rules, yes, I have that implemented on my servers and are working very well.

But I thought there might be a way to block IPs that triggers MD5SUMs that are already defined in CXS.XTRA, so, next time that the same file is uploaded and quarantined/deleted by CXS, the ofending IP could be blocked as well.

Best regards,
Sergio
Sarah
Moderator
Posts: 939
Joined: 09 Dec 2006, 22:49

Re: How to block IP at the first attack detected in CXS?

Post by Sarah »

Unless the file is detected via cxs modsecurity scanning, cxs has no information about the IP address of the attacker. I'm not sure what type of scan you are referring to.
Sergio
Junior Member
Posts: 1729
Joined: 12 Dec 2006, 14:56

Re: How to block IP at the first attack detected in CXS?

Post by Sergio »

Got it.

I thought that CXS when a file is blocked because the file matches an MD5SUM code defined on the CXS.XTRA it could got the IP that tried to upload the malicious file.

I managed to get the IP that tried to upload a bad file using the user's cPanel logs but it takes a long time to do it and thought that maybe CXS could have that info when an uploaded file matches an MD5SUM defined.
Sarah
Moderator
Posts: 939
Joined: 09 Dec 2006, 22:49

Re: How to block IP at the first attack detected in CXS?

Post by Sarah »

It makes no difference what type of match it is, MD5SUM or fingerprint or virus, unless it was detected via cxs modsecurity scanning, cxs cannot get the IP address.
Post Reply