Posts Tagged ‘CSF

Greetings,
I wonder if Kaspersky Total Space security applyable on linux wb hosting servers (virtual or dedicated) I mean, we don’t have the GUI can it be configured with shell? Would you recommend it to be used for web hosting servers? Anybody had any expirience with it? Is it truth that if I install it [...]

Hello to everybody. I’ve just upgraded to VB4.0.2 PL1 from VB3.8.4 and I’ve some problems with mod_security.
My server has cPanel 11.25.0-S43473 – WHM 11.25.0 – X 3.9 on CENTOS 5.4 x86_64 standard.
Every now and then mod_sec ban permanently the IP of some VB4 users.
I don’t really know WHM but I know that if someone gets [...]

My servers sometimes become completely inaccessible in any service by all users (not only me). Then my system administrators from web hosting company enter with KVM in the remote machine, they disable this firewall and i can normally enter again and re-eneble CSF/LFD and all go back to normal.
I am constantly up to date regarding [...]

Hello everybody,
i am running shared hosting service and i once had one of my IPs blocked by the major email providers like hotmail,yahoo and gmail cos one of my customers was sending out spam in large amounts which ended up with my server IP being blocked.
since then i decided to be strict but am not [...]

I have installed CSF firewall in openvz hardware / main node . When i start the csf the vps inside the node not accessable ( even not pinging ) . how to enable this so that when csf is started in main node the vps are also accessable

For more information click here.

Hello everybody,
i have web hosting server with cPenal installed and i installed csf + lfd so today i got an email address from LFD
PID: 5947
Account: xyxyxyx
Uptime: 37777 seconds

Executable:
/usr/bin/perl

Command Line (often faked in exploits):
spamd child

Network connections by the process (if any):
tcp: 127.0.0.1:783 -> 0.0.0.0:0
tcp: 127.0.0.1:783 -> 127.0.0.1:56935
udp: x.x.x.x:21804 -> y.y.y.y:53
Files [...]

Hello,
In past 2 days i am having my server hit with HTTP FLOOD.
LFD + CSF is automatically blocking floods, but, even with CSF they make Apache inaccessible for couple of minutes or so.
What i found out that, this floods are coming usually from Thailand, ADSL (Dynamic IP provider).
How could i block only this provider (fully) [...]

hello we are under huge boot ddos attack .
csf and lfd cant block the ip because there are many range ip send connection on port 80.
its my server status :
9-0 17539 0/6/6 _ 0.10 0 0 0.0 0.01 0.01 88.227.96.2 localhost GET /topsite/button.php?u=dasd5a5ds4a HTTP/1.1
10-0 17541 1/8/8 C 0.00 1 0 0.4 0.00 0.00 85.103.210.28 localhost GET /topsite/button.php?u=das5d4a54 HTTP/1.1
11-0 17542 0/6/6 _ 0.02 0 0 0.0 0.00 0.00 85.108.112.76 localhost GET /topsite/button.php?u=g1 HTTP/1.1
12-0 18210 1/4/6 C 0.00 1 0 0.4 0.00 0.02 195.174.158.120 localhost GET /topsite/button.php?u=kmzk HTTP/1.1
13-0 17745 0/6/6 _ 0.12 0 0 0.0 0.01 0.01 88.227.96.2 localhost GET /topsite/button.php?u=dsad54a5d4a HTTP/1.1
14-0 19583 1/3/4 C 0.00 0 0 0.4 0.00 0.00 81.214.163.134 localhost GET /topsite/button.php?u=dsad54a5d4a HTTP/1.1
15-0 19584 1/3/3 C 0.00 0 0 0.4 0.00 0.00 [...]

Hi,
There’s a spammer on my server who’s sending spam from the localhost. My CSF firewall gives me the LOCALHOSTRELAY emails such as:

Quote:

Time: Wed Feb 24 11:42:45 2010 +0000
Type: LOCALHOSTRELAY, localhost – 127.0.0.1
Count: 51 emails relayed
Blocked: No
Sample of the first 10 emails:
2010-02-24 11:41:43 1NkFcV-0005Xm-Ro <= titolocric2@excite.it H=localhost [127.0.0.1] P=smtp S=580 id=01cab545.301d6e3b@localhost T="Hi" for robert.skogevall@ziehl-abegg.se
2010-02-24 [...]

Hi all!
I came here because I am out of ideas! Let me start by saying I run an image host. Now, I allow hotlinking on my site because that’s what an image host is for, after all. But there is one pesky chinese web-site that is seriously stealing my bandwidth…. hundreds of gigabytes.
Now, I have [...]