Page 1 of 1

CSF not blocking

Posted: 29 Jul 2019, 23:16
by RhuanGonzaga
Hi, I make a block of /24 IP address on my server but this block still acessing my sites, I already try restart csf, apache and the problem persists, I runn csftest.pl too!

Code: Select all

[root@server csf]# ./csftest.pl
Testing ip_tables/iptable_filter...OK
Testing ipt_LOG...OK
Testing ipt_multiport/xt_multiport...OK
Testing ipt_REJECT...OK
Testing ipt_state/xt_state...OK
Testing ipt_limit/xt_limit...OK
Testing ipt_recent...OK
Testing xt_connlimit...OK
Testing ipt_owner/xt_owner...OK
Testing iptable_nat/ipt_REDIRECT...OK
Testing iptable_nat/ipt_DNAT...OK

RESULT: csf should function on this server
Csf grep:

Code: Select all

[root@server csf]# csf -g 46.229.168.0/24

Table  Chain            num   pkts bytes target     prot opt in     out     source               destination

filter DENYIN           2       21  1260 DROP       all  --  !lo    *       46.229.168.0/24      0.0.0.0/0

filter DENYOUT          2        0     0 LOGDROPOUT  all  --  *      !lo     0.0.0.0/0            46.229.168.0/24

csf.deny: 46.229.168.0/24 # Manually denied: 46.229.168.0/24 (US/United States/-) - Mon Jul 29 18:39:30 2019

Code: Select all

[root@server apache2]# grep '46.229.168.133' access_log
46.229.168.133 - - [29/Jul/2019:19:11:53 -0300] "GET /dresses-c-1_19_20_29/baby-girls-champagne-embroidered-bead-cap-sleeve-flower-girl-dress-6m-p-443.htm?action=add_product HTTP/1.1" 404 10297 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
46.229.168.133 - - [29/Jul/2019:19:12:05 -0300] "GET /other-mens-clothing-c-1_136_253/better-triple-goose-leather-jacket-black-with-real-fur-collar-by-prince-bernado-p-1538.htm HTTP/1.1" 404 10303 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
46.229.168.133 - - [29/Jul/2019:19:12:46 -0300] "GET /tops-c-1_124_129/nfl-team-apparel-vneck-top-women039s-m-medium-green-bay-packers-fitted-p-11274.htm HTTP/1.1" 404 10263 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
46.229.168.133 - - [29/Jul/2019:19:12:50 -0300] "GET /index.php?action=wishlist_add_product&main_page=wishlist&products_id=6318 HTTP/1.1" 404 10221 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
46.229.168.133 - - [29/Jul/2019:19:12:53 -0300] "GET /pants-c-1_106_607/women039s-gap-gray-0341969034-corduroy-legging-jeans-pants-size-27r-p-14845.htm HTTP/1.1" 404 10253 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
46.229.168.133 - - [29/Jul/2019:19:12:54 -0300] "GET /coats-jackets-c-1_124_147/men039s-sperry-blue-rain-coat-boat-packable-jacket-zip-up-windbreaker-xs-x-small-p-874.htm HTTP/1.1" 404 10291 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
46.229.168.133 - - [29/Jul/2019:19:12:55 -0300] "GET /coats-jackets-c-1_117_142/nfl-49039ers-faux-leather-jacket-fan-apparel-logo-sz-xl-black-red-metallic-gold-p-1128.htm HTTP/1.1" 404 10297 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
46.229.168.133 - - [29/Jul/2019:19:13:02 -0300] "GET /womens-clothing-c-1_107_199_201_202_203/ HTTP/1.1" 404 10145 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
46.229.168.133 - - [29/Jul/2019:19:13:07 -0300] "GET /coats-jackets-vests-c-1_107_149/tek-gear-women039s-jacket-size-m-bluenavy-white-active-cotton-nylon-p-8483.htm?action=add_product HTTP/1.1" 404 10317 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
46.229.168.133 - - [29/Jul/2019:19:13:25 -0300] "GET /sleepwear-c-1_34_174_188/geelong-cats-afl-boys-cotton-flannel-pyjama-set-size-5-new-p-1326.html HTTP/1.1" 404 10249 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
46.229.168.133 - - [29/Jul/2019:19:13:26 -0300] "GET /index.php?action=wishlist_add_product&main_page=wishlist&products_id=336 HTTP/1.1" 404 10225 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
46.229.168.133 - - [29/Jul/2019:19:13:33 -0300] "GET /sweaters-c-1_130_279/patagonia-mens-fleece-14-half-zip-olive-green-pullover-sweater-size-xl-p-6881.html HTTP/1.1" 404 10268 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
46.229.168.133 - - [29/Jul/2019:19:13:37 -0300] "GET /index.php?action=wishlist_add_product&main_page=wishlist&products_id=2516 HTTP/1.1" 404 10221 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
46.229.168.133 - - [29/Jul/2019:19:13:42 -0300] "GET /per-una-ladies-dark-denim-straight-leg-stretch-jeans-uk-size-18-p-4380.html HTTP/1.1" 404 10215 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
46.229.168.133 - - [29/Jul/2019:19:13:48 -0300] "GET /bags-c-1_2_5/hot-unisex-canvas-waterproof-backpack-rucksack-casual-travel-shoulders-bag-new-p-5767.html HTTP/1.1" 404 10268 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
46.229.168.133 - - [29/Jul/2019:19:13:50 -0300] "GET /wallets-c-1_2_6/metal-credit-card-wallet-front-pocket-minimalist-business-card-holder-amp-mone-p-5564.html HTTP/1.1" 404 10271 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
46.229.168.133 - - [29/Jul/2019:19:14:01 -0300] "GET /nike-hooded-vest-mens-xs-extra-small-fitness-or-running-top-therma-fit-cotton-p-7336.htm HTTP/1.1" 404 10241 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
46.229.168.133 - - [29/Jul/2019:19:14:02 -0300] "GET /outerwear-c-1_9_17_52/kids-r-us-gray-toggle-winter-jacket-size-4t-p-325.htm?action=add_product HTTP/1.1" 404 10247 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
46.229.168.133 - - [29/Jul/2019:19:14:15 -0300] "GET /index.php?action=wishlist_add_product&main_page=wishlist&products_id=4421 HTTP/1.1" 404 10227 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
46.229.168.133 - - [29/Jul/2019:19:14:17 -0300] "GET /vtg-boston-red-sox-navy-jacket-men-m-70s80s-patch-logo-quilt-padded-lining-mlb-p-956.html HTTP/1.1" 404 10243 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
46.229.168.133 - - [29/Jul/2019:19:14:24 -0300] "GET /kids-clothing-shoes-accs-c-1_40/ HTTP/1.1" 404 10123 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
46.229.168.133 - - [29/Jul/2019:19:14:35 -0300] "GET /tops-c-1_65_66/autumn-women-shirt-long-lantern-sleeve-tops-turndown-collar-bowknot-blouse-kz-p-8882.html HTTP/1.1" 404 10270 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
46.229.168.133 - - [29/Jul/2019:19:14:37 -0300] "GET /tops-c-1_105_136/women039s-lace-floral-unpadded-bra-triangle-bralette-bralet-bra-bustier-crop-top-p-8252.htm HTTP/1.1" 404 10281 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
46.229.168.133 - - [29/Jul/2019:19:14:46 -0300] "GET /index.php?action=wishlist_add_product&main_page=wishlist&products_id=13051 HTTP/1.1" 404 10229 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
46.229.168.133 - - [29/Jul/2019:19:14:49 -0300] "GET /tshirts-c-1_124_125_126/gstar-raw-men039s-tach-trunk-ao-short-milkballpen-blue-ao-9442-p-6939.html?action=add_product HTTP/1.1" 404 10293 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
46.229.168.133 - - [29/Jul/2019:19:14:51 -0300] "GET /coats-jackets-vests-c-1_76_512/young-dimensions-girls-parker-in-my-pocket-rain-coatage-34-p-10562.htm HTTP/1.1" 404 10267 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
46.229.168.133 - - [29/Jul/2019:19:15:07 -0300] "GET /casual-buttondown-shirts-c-1_115_467_468/ HTTP/1.1" 404 10144 "-" "Mozilla/5.0 (compatible; SemrushBot/3~bl; +http://www.semrush.com/bot.html)"
How to fix this ?
Ps: Csf is not on testing mode:

Code: Select all

[root@server nginx]# grep TESTING /etc/csf/csf.conf
TESTING = "0"
TESTING_INTERVAL = "5"
# unless TESTING is enabled above. The check is done every 300 seconds