CC_IGNORE not working after upgrade to csf: v12.02
Posted: 09 Apr 2018, 17:11
After the upgrade to CSF 12.02 the login failure daemon is blocking IP addresses from countries that are listed in CC_IGNORE!
Peer support forums for ConfigServer Scripts
https://mail.forum.configserver.com/
Code: Select all
CC_LOOKUPS = "1"
Code: Select all
# ls -la /var/lib/csf/Geo/
total 5888
drw------- 2 root root 4096 Apr 9 15:26 .
drw------- 9 root root 4096 Apr 9 10:26 ..
-rw------- 1 root root 4345880 Apr 9 15:26 GeoLite2-ASN-CSV.zip
-rw------- 1 root root 1651128 Apr 9 15:26 GeoLite2-Country-CSV.zip
Code: Select all
# ls -la /var/lib/csf/Geo/
total 35040
drw------- 2 root root 4096 Apr 9 09:47 .
drw------- 9 root root 4096 Apr 9 14:55 ..
-rw-r--r-- 1 root root 55 Apr 9 09:47 COPYRIGHT.txt
-rw-r--r-- 1 root root 19244527 Apr 9 08:47 GeoLite2-ASN-Blocks-IPv4.csv
-rw-r--r-- 1 root root 2629108 Apr 9 08:47 GeoLite2-ASN-Blocks-IPv6.csv
-rw-r--r-- 1 root root 10743419 Apr 9 09:47 GeoLite2-Country-Blocks-IPv4.csv
-rw-r--r-- 1 root root 3224646 Apr 9 09:47 GeoLite2-Country-Blocks-IPv6.csv
-rw-r--r-- 1 root root 9928 Apr 9 09:47 GeoLite2-Country-Locations-en.csv
-rw-r--r-- 1 root root 433 Apr 9 09:47 LICENSE.txt
-rw-r--r-- 1 root root 116 Apr 9 09:47 README.txt
Code: Select all
Apr 9 09:43:47 web4 lfd[21909]: (imapd) Failed IMAP login from 69.172.158.167 (69-172-158-167.cable.teksavvy.com): 3 in the last 3600 secs - *Blocked in csf* [LF_IMAPD]
Code: Select all
Apr 9 09:36:25 web4 dovecot: imap-login: Aborted login (auth failed, 1 attempts in 2 secs): user=<education@removed.com>, method=PLAIN, rip=69.172.158.167, lip=216.138.192.180, TLS, session=<sBoOK2xpGcxFrJ6n>
Apr 9 09:36:38 web4 dovecot: imap-login: Aborted login (auth failed, 1 attempts in 6 secs): user=<education@removed.com>, method=PLAIN, rip=69.172.158.167, lip=216.138.192.180, TLS: Disconnected, session=<D0qZK2xpH8xFrJ6n>
Apr 9 09:43:42 web4 dovecot: imap-login: Disconnected: Inactivity (auth failed, 1 attempts in 179 secs): user=<education@removed.com>, method=PLAIN, rip=69.172.158.167, lip=216.138.192.180, TLS, session=<MGyUOmxpf8xFrJ6n>
Apr 9 09:43:42 web4 dovecot: imap-login: Disconnected: Inactivity (no auth attempts in 180 secs): user=<>, rip=69.172.158.167, lip=216.138.192.180, TLS, session=<XlJARWxpgMxFrJ6n>
Code: Select all
Apr 9 08:47:26 web4 lfd[13105]: CC Error: Unable to retrieve GeoLite2 CSV Country database [http://geolite.maxmind.com/download/geoip/database/GeoLite2-Country-CSV.zip] - Unable to rename /var/lib/csf/Geo/GeoLite2-Country-CSV.zip.tmp to /var/lib/csf/Geo/GeoLite2-Country-CSV.zip: No such file or directory
Code: Select all
Apr 9 08:48:09 web3 lfd[26765]: CCL: Retrieving GeoLite2 Country database [http://geolite.maxmind.com/download/geoip/database/GeoLite2-Country-CSV.zip]
Apr 9 08:48:09 web3 lfd[25962]: Country Code Ignores...
Apr 9 08:48:12 web3 lfd[26765]: CCL Error: /var/lib/csf/Geo/GeoLite2-Country-Blocks-IPv4.csv empty or missing
Apr 9 08:48:19 web3 lfd[26764]: CC: Retrieving GeoLite2 CSV Country database [http://geolite.maxmind.com/download/geoip/database/GeoLite2-Country-CSV.zip]
Apr 9 08:48:21 web3 lfd[26764]: CC Error: GeoLite2-Country-Blocks-IPv4.csv empty or missing
Apr 9 08:48:21 web3 lfd[26764]: CC: Retrieving GeoLite2 CSV ASN database [http://geolite.maxmind.com/download/geoip/database/GeoLite2-ASN-CSV.zip]
Apr 9 08:48:27 web3 lfd[26764]: CC Error: GeoLite2-ASN-Blocks-IPv4.csv empty or missing
Apr 9 08:48:27 web3 lfd[26764]: CC: Processing GeoLite2 CSV Country/ASN database
Apr 9 08:48:27 web3 lfd[26764]: CC: Extracting zone from GeoLite2 CSV Country/ASN database for [BR]
Apr 9 08:48:27 web3 lfd[26764]: CC: No entries found for [BR] in /var/lib/csf/Geo/GeoLite2-Country-Blocks-IPv4.csv
Apr 9 08:48:27 web3 lfd[26764]: CC: Extracting zone from GeoLite2 CSV Country/ASN database for [CN]
Apr 9 08:48:27 web3 lfd[26764]: CC: No entries found for [CN] in /var/lib/csf/Geo/GeoLite2-Country-Blocks-IPv4.csv
Apr 9 08:48:27 web3 lfd[26764]: CC: Extracting zone from GeoLite2 CSV Country/ASN database for [CA]
Apr 9 08:48:27 web3 lfd[26764]: CC: No entries found for [CA] in /var/lib/csf/Geo/GeoLite2-Country-Blocks-IPv4.csv
Apr 9 08:48:27 web3 lfd[26764]: CC: Repopulating CC_ALLOWP with IP addresses from [CA]
Apr 9 08:48:29 web3 lfd[26764]: CC: Finished repopulating CC_ALLOWP with IP addresses from [CA]
Apr 9 08:48:30 web3 lfd[26764]: CC: Repopulating CC_DENYP with IP addresses from [BR]
Apr 9 08:48:31 web3 lfd[26764]: CC: Finished repopulating CC_DENYP with IP addresses from [BR]
Apr 9 08:48:31 web3 lfd[26764]: CC: Repopulating CC_DENYP with IP addresses from [CN]
Apr 9 08:48:32 web3 lfd[26764]: CC: Finished repopulating CC_DENYP with IP addresses from [CN]