Search found 83 matches

by keat63
11 Apr 2018, 08:20
Forum: General Discussion (csf)
Topic: Custom REGEX rules for CSF.
Replies: 60
Views: 77848

Re: Custom REGEX rules for CSF.

Using Host Access Control in WHM, its possible to restrict Cpanel login to specific IP or range of IP's. However, any unauthorised log in attempts will generate the following warning: "Dropping connection from xxx.xxx.xxx.xxx because of tcp_wrappers at cpsrvd.pl line ####" There are no restrictions ...
by keat63
04 Apr 2018, 11:15
Forum: General Discussion (csf)
Topic: really could do with some help on a custom filter
Replies: 1
Views: 915

Re: really could do with some help on a custom filter

I've scoured the custom regex thread and it doesn't matter how many times i read it, it makes absolutely no logical sense to me.
I think writing my own regex is out of the question.
by keat63
03 Apr 2018, 08:16
Forum: General Discussion (csf)
Topic: really could do with some help on a custom filter
Replies: 1
Views: 915

really could do with some help on a custom filter

Returning to work today, I see multip[le attempts over a number of days of someone trying to log in to cpanel.

Dropping connection from xxx.xxx.xxx.xxx because of tcp_wrappers at cpsrvd.pl line 3622

Is anyone able to help me write a custom rule which will block the offending IP.
by keat63
22 Jan 2018, 13:25
Forum: MailScanner Front-End
Topic: Change messages
Replies: 2
Views: 2081

Re: Change messages

thanks
by keat63
19 Jan 2018, 09:38
Forum: MailScanner Front-End
Topic: Change messages
Replies: 2
Views: 2081

Change messages

does anyone know where to change this message please. This is a message from the MailScanner E-Mail Virus Protection Service ---------------------------------------------------------------------- The original e-mail attachment "PO KCTCN1104863.jar" is on the list of unacceptable attachments for this...
by keat63
03 Jul 2017, 13:27
Forum: General Discussion (csf)
Topic: CSF blocking Google Image Proxy Server
Replies: 3
Views: 1918

Re: CSF blocking Google Image Proxy Server

Try clearing out the blocked IP's and stat with a fresh blocklist.
This may help identify google.
by keat63
03 Jul 2017, 13:19
Forum: General Discussion (csf)
Topic: Best practices hardening a Cpanel / WHM Setup?
Replies: 1
Views: 1227

Re: Best practices hardening a Cpanel / WHM Setup?

Whitelist your IP in CSF. Using host access control (cpanel) allow ssh access to your IP or IP's, then deny SSH to all. Then change the port number to something else. https://forums.cpanel.net/threads/change-ssh-port-via-whm.108197/ In csf, configure ssh logins to something really low like 3 strikes...
by keat63
30 Jun 2017, 15:25
Forum: MailScanner Front-End
Topic: can anyone suggest a custom SA rule
Replies: 5
Views: 2594

Re: can anyone suggest a custom SA rule

After a number of experiments and waiting for these emails to arrive, I may have figured it out.
Just in case anyone else needs this, this is what I came up with.

header FROM_YOURRULENAME ALL =~ /mydomain\.co\.uk@/i
score FROM_YOURRULENAME 0.1

Giving it a very low score for testing purposes.
by keat63
30 Jun 2017, 13:48
Forum: MailScanner Front-End
Topic: can anyone suggest a custom SA rule
Replies: 5
Views: 2594

Re: can anyone suggest a custom SA rule

I'm still struggling with this one if anyone can help at all. (envelope-from <bounce-mc.us4_8899577.1056541-sales=mydomain.co.uk@mail208.atl61.xxxx.net>) I'm looking to score this phrase "sales=mydomain.co.uk@" I see a rule in SA which may do the trick if I could get the rejex right. header LOCAL_DE...
by keat63
23 Jun 2017, 14:38
Forum: MailScanner Front-End
Topic: Not Spam - Too Large
Replies: 1
Views: 1308

Re: Not Spam - Too Large

Actually, I think I stumbled on the answer.

Max Spam Check Size =