lfd Dynamic DNS entries are generating remote access reports

This forum is only for reproducible bugs with csf and lfd (i.e. not iptables problems, lack of understanding how to use a feature, etc). Posts must be accompanied with full technical details of the problem and how it can be recreated. Any posts not adhering to this, or not considered bugs, will be moved to the General Discussion (csf) forum.
Post Reply
MindStar
Junior Member
Posts: 8
Joined: 27 May 2007, 23:48
Location: UK

lfd Dynamic DNS entries are generating remote access reports

Post by MindStar »

Hi,

A couple of versions ago, something changed with the way that CSF treats hostnames listed in the lfd Dynamic DNS.

I am now receiving email alerts of the form[INDENT] lfd: SSH login alert for user XXXXX from AAA.BBB.CCC.DDD (Unknown)
[/INDENT]each time I login to the server from this IP addresss, which one of the hostnames listed in the lfd Dynamic DNS list resolves to.

I've double-checked the IP addresses and that I can resolve the dynamic dns hostname on the server. Is there some other configuration option that I need to set?

Thanks.
chirpy
Moderator
Posts: 3537
Joined: 09 Dec 2006, 18:13

Post by chirpy »

That's perfectly normal. The DYNDNS feature allows the IP through iptables, it doesn't affect lfd at all.
MindStar
Junior Member
Posts: 8
Joined: 27 May 2007, 23:48
Location: UK

Post by MindStar »

Hmmm. The thing is that it wasn't generating access reports/alerts until recently :confused:

i.e. I could log in from a remote IP that was registered with a DynDNS hostname and CSF did not send an access report/alert.
chirpy
Moderator
Posts: 3537
Joined: 09 Dec 2006, 18:13

Post by chirpy »

That's because the regex's were recently improved to pick up SSH logins correctly.
MindStar
Junior Member
Posts: 8
Joined: 27 May 2007, 23:48
Location: UK

Post by MindStar »

OK. Would it be possible to whitelist some or all of the DynDNS hosts?

Thanks.
chirpy
Moderator
Posts: 3537
Joined: 09 Dec 2006, 18:13

Post by chirpy »

Not at present, because lfd doesn't support ignoring of DYNDNS entries - that only applies to csf and the building of the iptables rules. I'll look a adding an option to csf.conf to additionally ignore DYNDNS entries.
MindStar
Junior Member
Posts: 8
Joined: 27 May 2007, 23:48
Location: UK

Post by MindStar »

Thanks, I think it could be a popular feature :)
MindStar
Junior Member
Posts: 8
Joined: 27 May 2007, 23:48
Location: UK

Post by MindStar »

I see that you've incorporated this into the latest release, and it works a treat. Thanks! :):):)
Post Reply