Search found 1042 matches

by Sergio
16 Dec 2023, 23:01
Forum: General Discussion (cxs)
Topic: First time ever CXS rule is not working, why?
Replies: 2
Views: 2080

Re: First time ever CXS rule is not working, why?

Ohhh, that is why.

Thought I was doing something wrong, thanks for telling, appreciated.

Best Regards,
Sergio
by Sergio
16 Dec 2023, 12:39
Forum: General Discussion (cxs)
Topic: First time ever CXS rule is not working, why?
Replies: 2
Views: 2080

First time ever CXS rule is not working, why?

Hi, Sarah. Would you be kind to tell me what I am doing wrong on the following rule that I have created on CXS? InmunifyAV+ is detecting the following code as malicious, so, I have added the rule in cxs.xtra to quarantine the file but is not working. This is the code that I want to block: <?php eval...
by Sergio
14 Dec 2023, 02:26
Forum: General Discussion (csf)
Topic: Trying to ignore a Perl script, but still getting alerts
Replies: 3
Views: 3091

Re: Trying to ignore a Perl script, but still getting alerts

Great to know it worked for you, your welcome.
by Sergio
13 Dec 2023, 03:36
Forum: General Discussion (csf)
Topic: Trying to ignore a Perl script, but still getting alerts
Replies: 3
Views: 3091

Re: Trying to ignore a Perl script, but still getting alerts

Try this instead:

Code: Select all

 cmd:/usr/bin/perl /home/example/public_html/cgi-bin/cart.cgi
Sergio
by Sergio
09 Dec 2023, 02:39
Forum: General Discussion (csf)
Topic: Custom REGEX rules for CSF.
Replies: 93
Views: 2016341

REGEX Rule to block census.shodan.io

This rule blocks any connection from census.shodan.io. (I really don't like attacks from these servers) # BLOCKING CENSUS SHODAN if (($lgfile eq $config{CUSTOM2_LOG}) and ($line =~ /^\S+\s\S+\sSMTP\s\D+from\s\S+(?>\.census\.shodan\.io|\.censys\-scanner\.com)\s\[(\S+)\]/i)) { return ("",$1,...
by Sergio
06 Dec 2023, 02:56
Forum: Suggestions (csf)
Topic: Please add instructions on how to migrate to a new server
Replies: 4
Views: 10837

Re: Please add instructions on how to migrate to a new server

Do you have CXS installed or MailScanner?
by Sergio
23 Nov 2023, 20:38
Forum: General Discussion (csf)
Topic: Suspicious process running
Replies: 1
Views: 3988

Re: Suspicious process running

First of all, you don't need to copy all the log lines, just a few ones are needed. I recommend you to add one of the following lines in csf.pignore: REGEX for any version of ea-php: pexe:/opt/cpanel/ea\-php\d+/root/usr/sbin/php\-fpm Rule just for ea-php81: exe:/opt/cpanel/ea-php81/root/usr/sbin/php...
by Sergio
17 Nov 2023, 03:50
Forum: General Discussion (csf)
Topic: csf CC_DENY country blocking delayed filling of IPSETs
Replies: 1
Views: 2618

Re: csf CC_DENY country blocking delayed filling of IPSETs

One easy way to block Countries is using cPhulk.
Enable it on your server, then go to the BLACK LIST by Country and you can block all the ones that you don't want.

Also, you can add range of IPs that you don't want them to access your server.
by Sergio
15 Nov 2023, 16:43
Forum: MailScanner Front-End
Topic: Please add the SUBJECT COUNT into MSFE statistics, please.
Replies: 1
Views: 3714

Please add the SUBJECT COUNT into MSFE statistics, please.

Sarah, Would you be kind to check the possibility to add a "SUBJECT COUNT" into MSFE Statistics, please? It will be great if it could send a warning mail when more that 100 emails (or threshold defined by admin) with the same subject are sent, this will help to track any email account that...