One IP not fully blocked by csf
Posted: 10 Aug 2013, 22:03
I just had the cPanel Service Package + MailScanner work done to a dedicated LAMP server, and LOVE it! It was money very well spent indeed! :-)
There was just one IP so far that I had to manually enter in order to block. I don't know if this is a bug, something specific to my server, or what. I didn't see anything in the documentation or in this forum about this.
There were hundreds of lines like this (446 in just one email). After several notifications like this from lfd about this IP address, I finally manually blocked the IP below in the WHM plugin, and the notifications --and the entries in /var/log/secure-- immediately stopped.
/var/log/secure:
Aug 10 01:00:24 srv3 sshd[4427]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:00:33 srv3 sshd[4435]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:00:33 srv3 sshd[4436]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:00:33 srv3 sshd[4437]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:00:33 srv3 sshd[4438]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:00:33 srv3 sshd[4439]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:00:33 srv3 sshd[4440]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:00:33 srv3 sshd[4441]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:00:33 srv3 sshd[4442]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:01:37 srv3 sshd[4748]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:01:47 srv3 sshd[4750]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:01:47 srv3 sshd[4751]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:01:47 srv3 sshd[4752]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:01:47 srv3 sshd[4753]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:01:47 srv3 sshd[4754]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:01:47 srv3 sshd[4755]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:01:47 srv3 sshd[4756]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:01:47 srv3 sshd[4757]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:02:50 srv3 sshd[4792]: refused connect from 5.135.143.59 (5.135.143.59)
... [many more like this over an hour]
This only appeared in /var/log/secure, not in any other log such as /var/log/messages.
I even have the last line in /etc/hosts.allow "sshd : ALL : deny" (without the quotes). I don't know how or what this IP is up to or why an attack from only this IP happens. Anyone have any ideas? Should I even be concerned about this?
Thanks,
Mike
There was just one IP so far that I had to manually enter in order to block. I don't know if this is a bug, something specific to my server, or what. I didn't see anything in the documentation or in this forum about this.
There were hundreds of lines like this (446 in just one email). After several notifications like this from lfd about this IP address, I finally manually blocked the IP below in the WHM plugin, and the notifications --and the entries in /var/log/secure-- immediately stopped.
/var/log/secure:
Aug 10 01:00:24 srv3 sshd[4427]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:00:33 srv3 sshd[4435]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:00:33 srv3 sshd[4436]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:00:33 srv3 sshd[4437]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:00:33 srv3 sshd[4438]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:00:33 srv3 sshd[4439]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:00:33 srv3 sshd[4440]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:00:33 srv3 sshd[4441]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:00:33 srv3 sshd[4442]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:01:37 srv3 sshd[4748]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:01:47 srv3 sshd[4750]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:01:47 srv3 sshd[4751]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:01:47 srv3 sshd[4752]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:01:47 srv3 sshd[4753]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:01:47 srv3 sshd[4754]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:01:47 srv3 sshd[4755]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:01:47 srv3 sshd[4756]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:01:47 srv3 sshd[4757]: refused connect from 5.135.143.59 (5.135.143.59)
Aug 10 01:02:50 srv3 sshd[4792]: refused connect from 5.135.143.59 (5.135.143.59)
... [many more like this over an hour]
This only appeared in /var/log/secure, not in any other log such as /var/log/messages.
I even have the last line in /etc/hosts.allow "sshd : ALL : deny" (without the quotes). I don't know how or what this IP is up to or why an attack from only this IP happens. Anyone have any ideas? Should I even be concerned about this?
Thanks,
Mike