Search found 20 matches

by curriertech
23 Mar 2017, 17:45
Forum: General Discussion (cmc)
Topic: Issue with whitelisting Mod_security rule in cPanel
Replies: 4
Views: 9944

Re: Issue with whitelisting Mod_security rule in cPanel

I may have found the issue on my server...sharing in case it helps. My modsec2.conf includes user.conf, (which includes whitelist.conf) and cpanel.conf. So whitelist.conf was being parsed before cpanel.conf. I've added a line to modsec2.conf to include whitelist.conf after user.conf and cpanel.conf ...
by curriertech
23 Mar 2017, 16:54
Forum: General Discussion (cmc)
Topic: Issue with whitelisting Mod_security rule in cPanel
Replies: 4
Views: 9944

Re: Issue with whitelisting Mod_security rule in cPanel

I'm seeing this behavior recently as well, lots of IPs getting blocked in CSF for rules that are whitelisted in CMC.
by curriertech
30 Mar 2014, 02:41
Forum: Suggestions (csf)
Topic: LFD email alerts for XX,XX countries only
Replies: 2
Views: 4049

Re: LFD email alerts for XX,XX countries only

I'm in the same boat, I'm only interested in failures from US/CA.
by curriertech
23 Mar 2014, 12:48
Forum: General Discussion (csf)
Topic: Block IP based on "ylmf-pc" text in logs
Replies: 19
Views: 19879

Re: Block IP based on "ylmf-pc" text in logs

Yeah I shouldn't post when I've been drinking. :) Thanks for the new regex, this should help with a lot of attacks.
by curriertech
22 Mar 2014, 02:20
Forum: General Discussion (csf)
Topic: too many distributed email notifications
Replies: 4
Views: 4922

Re: too many distributed email notifications

I was recently looking for a way to do this as well, but I couldn't find a way to do it. I ended up disabling alerts altogether.
by curriertech
22 Mar 2014, 02:10
Forum: General Discussion (csf)
Topic: Block IP based on "ylmf-pc" text in logs
Replies: 19
Views: 19879

Re: Block IP based on "ylmf-pc" text in logs

I had some conversations with Sergio about this stuff because I was actually looking for a way to block IPs that were attempting to authenticate as IDs that don't actually exist. I didn't want to have to maintain a list. Unfortunately because CSF is just watching the log for the errors, it has no id...
by curriertech
22 Mar 2014, 02:03
Forum: General Discussion (csf)
Topic: Block IP based on "ylmf-pc" text in logs
Replies: 19
Views: 19879

Re: Block IP based on "ylmf-pc" text in logs

Yes but you have to actually specify the IDs you consider bad, so if you just specify ylmf-pc it should block these for you. if (($lgfile eq $config{CUSTOM2_LOG}) and ($line =~ /\S+\s+\S+\s+dovecot_login authenticator failed for \(\[?\S+\]?\) \[(\S+)\]:\d+: \d+ Incorrect authentication data \(set_id...
by curriertech
22 Mar 2014, 01:56
Forum: General Discussion (csf)
Topic: Block IP based on "ylmf-pc" text in logs
Replies: 19
Views: 19879

Re: Block IP based on "ylmf-pc" text in logs

Check out the second post in this thread, I think if you cut the list of IDs down to just ylmf-pc and any others you're having trouble with, it will do what you need. viewtopic.php?f=6&t=7517
by curriertech
21 Mar 2014, 14:10
Forum: General Discussion (csf)
Topic: email alerts for root and cpanel logins
Replies: 5
Views: 5073

Re: email alerts for root and cpanel logins

The only things in csf.ignore are the ranges for my host's monitoring systems and 127.0.0.1.
by curriertech
20 Mar 2014, 12:51
Forum: General Discussion (csf)
Topic: email alerts for root and cpanel logins
Replies: 5
Views: 5073

Re: email alerts for root and cpanel logins

Also, I'm still getting all of the other email alerts from CSF/LFD, just not these specific alerts.