Does csf/lfd check on number of ftp connects/disconnects
Posted: 13 Nov 2014, 05:10
Hello,
With LF_FTPD does csf/lfd check number of connects/disconnects on FTP port ?
I have 722 lines of connects disconnects inside a 10 min period that happened today (13-Nov-2014). csf/lfd was running when this attack took place. I might have left something out in csf/lfd config for this to be dealt with.
What settings do I need to tweak to deal with this ?
///////////////////////////////////////////////////////////////////////////
///////////////////////////////////////////////////////////////////////////
Nov 13 02:23:32 servername proftpd[16312]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:32 servername proftpd[16312]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:32 servername proftpd[16313]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:33 servername proftpd[16313]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:33 servername proftpd[16314]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:33 servername proftpd[16314]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:34 servername proftpd[16315]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:34 servername proftpd[16315]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:34 servername proftpd[16316]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:35 servername proftpd[16316]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:35 servername proftpd[16317]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:35 servername proftpd[16317]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:35 servername proftpd[16318]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:36 servername proftpd[16318]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:36 servername proftpd[16319]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:36 servername proftpd[16319]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:37 servername proftpd[16320]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:37 servername proftpd[16320]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:37 servername proftpd[16321]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:38 servername proftpd[16321]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:38 servername proftpd[16322]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:38 servername proftpd[16322]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:39 servername proftpd[16323]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:39 servername proftpd[16323]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:39 servername proftpd[16324]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:40 servername proftpd[16324]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:40 servername proftpd[16325]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:40 servername proftpd[16325]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:40 servername proftpd[16326]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:41 servername proftpd[16326]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
With LF_FTPD does csf/lfd check number of connects/disconnects on FTP port ?
I have 722 lines of connects disconnects inside a 10 min period that happened today (13-Nov-2014). csf/lfd was running when this attack took place. I might have left something out in csf/lfd config for this to be dealt with.
What settings do I need to tweak to deal with this ?
///////////////////////////////////////////////////////////////////////////
///////////////////////////////////////////////////////////////////////////
Nov 13 02:23:32 servername proftpd[16312]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:32 servername proftpd[16312]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:32 servername proftpd[16313]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:33 servername proftpd[16313]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:33 servername proftpd[16314]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:33 servername proftpd[16314]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:34 servername proftpd[16315]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:34 servername proftpd[16315]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:34 servername proftpd[16316]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:35 servername proftpd[16316]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:35 servername proftpd[16317]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:35 servername proftpd[16317]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:35 servername proftpd[16318]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:36 servername proftpd[16318]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:36 servername proftpd[16319]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:36 servername proftpd[16319]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:37 servername proftpd[16320]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:37 servername proftpd[16320]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:37 servername proftpd[16321]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:38 servername proftpd[16321]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:38 servername proftpd[16322]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:38 servername proftpd[16322]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:39 servername proftpd[16323]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:39 servername proftpd[16323]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:39 servername proftpd[16324]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:40 servername proftpd[16324]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:40 servername proftpd[16325]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:40 servername proftpd[16325]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.
Nov 13 02:23:40 servername proftpd[16326]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session opened.
Nov 13 02:23:41 servername proftpd[16326]: xx.xx.x.xxx (110.171.7.171[110.171.7.171]) - FTP session closed.