Receiving E-Mail Notifications - Even when EMAIL_ALERT disabled ??
Posted: 15 Nov 2020, 12:52
I get a huge amount of e-mail notifications such as the ones below on a daily basis:
I've already changed the /etc/csf/csf.conf to be:
LF_EMAIL_ALERT = "0"
LF_TEMP_EMAIL_ALERT = "0"
CT_EMAIL_ALERT = "0"
PS_EMAIL_ALERT = "1"
LF_SSH_EMAIL_ALERT = "1" - But it says 'Send an email alert if anyone logs in successfully using SSH
The comment on 'LF_SSH_EMAIL_ALERT' says that this e-mail is sent if someone logs into SSH successfully (which I would want), but the e-mail alerts are coming through when they have failed to login and therefore being blocked.
Any ideas on why I am getting these e-mails despite the settings I have above ?
Thanks in advance
Code: Select all
Time: Sun Nov 15 12:45:01 2020 +0000
IP: 191.239.XXX.XX (BR/Brazil/-)
Failures: 3 (sshd)
Interval: 3600 seconds
Blocked: Permanent Block [LF_SSHD]
Log entries:
Nov 15 12:30:49 server sshd[27350]: Invalid user git from 191.239.XXX.XX port 45826
Nov 15 12:30:51 server sshd[27350]: Failed password for invalid user git from 191.239.XXX.XX port 45826 ssh2
Nov 15 12:44:59 server sshd[30313]: Invalid user confluence from 191.239.XXX.XX port 48198
LF_EMAIL_ALERT = "0"
LF_TEMP_EMAIL_ALERT = "0"
CT_EMAIL_ALERT = "0"
PS_EMAIL_ALERT = "1"
LF_SSH_EMAIL_ALERT = "1" - But it says 'Send an email alert if anyone logs in successfully using SSH
The comment on 'LF_SSH_EMAIL_ALERT' says that this e-mail is sent if someone logs into SSH successfully (which I would want), but the e-mail alerts are coming through when they have failed to login and therefore being blocked.
Any ideas on why I am getting these e-mails despite the settings I have above ?
Thanks in advance