How about a feature to permanently block IP by putting them in something like csf.pdeny
Right now if the deny_ip_limit is set at 100 and then if all the 100 IPs are filled up and CSF starts removing from the oldest IP blocked order the ones at the top get removed. But there are certain IPs which I would like to keep permanently blocked even if the limit has been reached and csf removes the oldest banned IPs, I wouldn't mind if 1 IP is permanently blocked and now I got only 99 remaining within which csf rotates the other blocked IPs.
Permanently Block IP or CIDR
Hi Chris
Thanks for the solution. I am aware of Global_deny but my concern is the security of having a list web accessible. Since the URL is accessible through the browser, if someone manages to access the domain www folders (through FTP for example) and modify the list it can create some problems. That's why I would like to have a csf.pdeny file which is in /etc/csf that is outside of the public_html and not accessible by any browser or visitor to see what ranges or IP are blocked or be capable of editing it under any circumstance.
Thanks for the solution. I am aware of Global_deny but my concern is the security of having a list web accessible. Since the URL is accessible through the browser, if someone manages to access the domain www folders (through FTP for example) and modify the list it can create some problems. That's why I would like to have a csf.pdeny file which is in /etc/csf that is outside of the public_html and not accessible by any browser or visitor to see what ranges or IP are blocked or be capable of editing it under any circumstance.
I don't know how a list of IP's would be insecure but if you are that concerned about it, just name the file something really obscure that couldn't be guessed.
If someone gets your ftp information or otherwise gets access to the file, you are going to have worse problems to worry about than a list of IPs.
If someone gets your ftp information or otherwise gets access to the file, you are going to have worse problems to worry about than a list of IPs.
It was added ages ago:
http://configserver.com/blog/index.php?itemid=370
http://configserver.com/blog/index.php?itemid=370
Doh! Completely missed that. Thanks for pointing it out.chirpy wrote:It was added ages ago:
http://configserver.com/blog/index.php?itemid=370
Rob
Re: Permanently Block IP or CIDR
Dear CSF,
I understand this is the old thread, i try to refer to the link above but theres nothing about where i can get the tip to permanent block the IP instead of csf.deny
Please help. TQ
I understand this is the old thread, i try to refer to the link above but theres nothing about where i can get the tip to permanent block the IP instead of csf.deny
Please help. TQ