Search found 19 matches

by tvcnet
02 Oct 2011, 18:14
Forum: Suggestions (cxs)
Topic: New hack script format (cxs may need update)
Replies: 2
Views: 6284

New hack script format (cxs may need update)

Hi folks, I've just started observing a relatively new format for the gzinflate/base64 hacks, now starting with: <?php $D=strrev('edoced_46esab');$s=gzinflate Here is a picture snippet of a hack I observed this past week, which CXS does not pick up as a hack (when it should have). It's a pretty egre...
by tvcnet
23 Aug 2011, 01:45
Forum: Suggestions (csf)
Topic: readme CSF file examples missing.
Replies: 5
Views: 9939

Re: readme CSF file examples missing.

Hi, So are there general recommendations for these two settings? CONNLIMIT = PORTFLOOD = We have not used them in the past though are considering applying them on servers we've seen more aggressive connections recently. Safe settings that generally work well in a shared server environment recommende...
by tvcnet
27 May 2011, 19:59
Forum: Suggestions (cmm)
Topic: Empty Trash in email account and domain wide
Replies: 1
Views: 7513

Empty Trash in email account and domain wide

Wow, I'm amazed you folks haven't thought of this. With the increased used of mobile devices, clients are deleting or moving email to trash within accounts, then have no clue how to empty the trash (creating a lot of customer service time wastage). So... What do you think about adding these two opti...
by tvcnet
16 Dec 2010, 02:04
Forum: General Discussion (cxs)
Topic: STICKY rules for CXS.XTRA regs.
Replies: 71
Views: 200864

Re: Set a Sticky for CSF.XTRA regs.

Excellent! Thank you. -Jim
by tvcnet
28 Jun 2010, 01:31
Forum: Suggestions (cxs)
Topic: Email Reports - # in Subject Line, and Improved Summary
Replies: 5
Views: 8155

I'm really liking this latest subject format!
cxs Scan on username (Hits:1084) (Viruses:0) (Fingerprints:0)

Thanks,
Jim
by tvcnet
26 Apr 2010, 23:42
Forum: Suggestions (cxs)
Topic: Adding/Updating No execution text to htaccess in virus found directories
Replies: 1
Views: 5011

Adding/Updating No execution text to htaccess in virus found directories

Hi folks, Ok, we've found clients with the usual c99 shell scripts installed and the thought occurred to me below. Could CXS be set to either append this text to existing .htaccess files or add an .htaccess file to directories where obvious shell scripts have been located? Addhandler text/plain .pl ...
by tvcnet
21 Apr 2010, 20:44
Forum: General Discussion (cxs)
Topic: STICKY rules for CXS.XTRA regs.
Replies: 71
Views: 200864

Got it.
Wouldn't that chain of characters have to be:
Undefined index: pin
?

Which as far as I can tell would only be found in this specific error log file used for this specific type of phishing script.

Thanks,
Jim
by tvcnet
21 Apr 2010, 19:08
Forum: General Discussion (cxs)
Topic: STICKY rules for CXS.XTRA regs.
Replies: 71
Views: 200864

This actually worked:
regall:Undefined index: pin

with result:
# Regular expression match = [Undefined index: pin]:
'/home/webhost/public_html/images/ucon/error_log'
by tvcnet
21 Apr 2010, 18:27
Forum: General Discussion (cxs)
Topic: STICKY rules for CXS.XTRA regs.
Replies: 71
Views: 200864

One of the common phishing installer scripts creates a log file named: error_log (and FYI purposes other filenames in this phishing installer are login.php, regions.zip and index.htm) In this log file the one thing I believe could be ID's as a likely hack would be this line: [26-Feb-2010 16:12:02] ...
by tvcnet
21 Apr 2010, 18:22
Forum: General Discussion (cxs)
Topic: STICKY rules for CXS.XTRA regs.
Replies: 71
Views: 200864

One of the common phishing installer scripts creates a log file named: error_log (and FYI purposes other filenames in this phishing installer are login.php, regions.zip and index.htm) In this log file the one thing I believe could be ID's as a likely hack would be this line: [26-Feb-2010 16:12:02] P...