Permanently Block IP or CIDR

bst11
Junior Member
Posts: 3
Joined: 15 Nov 2008, 15:12

Permanently Block IP or CIDR

Post by bst11 »

How about a feature to permanently block IP by putting them in something like csf.pdeny
Right now if the deny_ip_limit is set at 100 and then if all the 100 IPs are filled up and CSF starts removing from the oldest IP blocked order the ones at the top get removed. But there are certain IPs which I would like to keep permanently blocked even if the limit has been reached and csf removes the oldest banned IPs, I wouldn't mind if 1 IP is permanently blocked and now I got only 99 remaining within which csf rotates the other blocked IPs.
ckh
Junior Member
Posts: 147
Joined: 10 Dec 2006, 15:35

Post by ckh »

I think the global_deny file would be a good solution.
bst11
Junior Member
Posts: 3
Joined: 15 Nov 2008, 15:12

Post by bst11 »

Hi Chris
Thanks for the solution. I am aware of Global_deny but my concern is the security of having a list web accessible. Since the URL is accessible through the browser, if someone manages to access the domain www folders (through FTP for example) and modify the list it can create some problems. That's why I would like to have a csf.pdeny file which is in /etc/csf that is outside of the public_html and not accessible by any browser or visitor to see what ranges or IP are blocked or be capable of editing it under any circumstance.
ckh
Junior Member
Posts: 147
Joined: 10 Dec 2006, 15:35

Post by ckh »

I don't know how a list of IP's would be insecure but if you are that concerned about it, just name the file something really obscure that couldn't be guessed.

If someone gets your ftp information or otherwise gets access to the file, you are going to have worse problems to worry about than a list of IPs.
docenta
Junior Member
Posts: 23
Joined: 10 Apr 2007, 11:16
Contact:

Post by docenta »

Amazing, just like to offer the same - permanent deny. Mean .pdeny where the IPs will not be wiped when the limit is reached. A very good addon I think.


Thanks,
chirpy
Moderator
Posts: 3537
Joined: 09 Dec 2006, 18:13

Post by chirpy »

There'll be a feature in the next release to stop DENY_IP_LIMIT from removing specified entries in csf.deny
robm
Junior Member
Posts: 33
Joined: 20 Jan 2007, 20:44

Post by robm »

Was this feature ever added? Not sure if the csf.gdeny file is the solution? Thanks.

Rob
chirpy
Moderator
Posts: 3537
Joined: 09 Dec 2006, 18:13

Post by chirpy »

robm
Junior Member
Posts: 33
Joined: 20 Jan 2007, 20:44

Post by robm »

chirpy wrote:It was added ages ago:
http://configserver.com/blog/index.php?itemid=370
Doh! Completely missed that. Thanks for pointing it out. :)

Rob
halimzhz
Junior Member
Posts: 4
Joined: 05 Sep 2014, 12:17

Re: Permanently Block IP or CIDR

Post by halimzhz »

Dear CSF,

I understand this is the old thread, i try to refer to the link above but theres nothing about where i can get the tip to permanent block the IP instead of csf.deny

Please help. TQ
Post Reply