Who is Chirpy? ConfigServer Services
cPanel Server Services from Way to The Web Ltd
 
Home Site Blog Services Support Terms & Conditions Privacy Policy Contact Us
cPanel Server Services
cPanel MailScanner Service
Server Recovery Service
Anti-Spammer/Exploit Service
General Server Management
Services FAQ
cPanel MailScanner Front-End
 
ConfigServer Scripts Forum
ConfigServer Firewall
ConfigServer Explorer
ConfigServer Mail Queues
ConfigServer Mail Manage
 
Why you should use :fail:
Searching for Spammers
Latest Vulns & Viruses
 
Free MailScanner Installer
Free Exim Dictionary Attack ACL
Free ClamAV install for MS
Upgrading MS and ClamAV
Rvskin MS integration
 
Way to the Web Limited

ConfigServer Blog

Please note that support is not provided through this blog - any support related comments will be removed

| 1 | 2 | 3 | ...| 36 | 37 | 38 | Next»

05 Jan 09: New csf v4.33

Category: General
Posted by: Chirpy
Changes:


  • Disable ST_LOOKUP by default on new installations

  • Modified lfd stats performance when ST_LOOKUP is enabled and added a warning for this setting to csf.conf for when DROP_IP_LOGGING is enabled


Category: MailScanner
Posted by: Chirpy
Changes:


  • New Mailscanner v4.74.13:
    http://www.mailscanner.info/ChangeLog


04 Jan 09: New csf v4.32

Category: General
Posted by: Chirpy
Changes:


  • Modified the su tracking regex to better trap RHE/CentOS v5 su login attempts

  • Added a Server Check for "FTP Logins with Root Password"

  • Added new WHM UI option to display Last X iptables Log Lines. Note that the report will only display log lines since this update. The new statistics will be expanded in future developments. Added new ST_* options to the cPanel csf.conf to control the recording of stats

  • Removed fwlogwatch from distro and will use self-produced reports


Category: General
Posted by: Chirpy
Rootkit Hunter announces release 1.3.4
The change log lists 4 additions, 8 changes and 9 bugfixes.
Naming a few:
- Added IntoXonia-NG rootkit check.
- Added Phalanx2 rootkit check.
- Added support for TCB shadow files.
- The '--propupd' option can now take an optional file, directory or package name after it.
- Revised file properties inode check.
- Tests against the SSH configuration file now accept the key/value pair.
- Improved the O/S name detection.
- The Linux 'os_specific' test has now been split into two separate tests.
- Improved ALLOWPROCDELFILE configuration option.
- Improved hidden files and directories check.
- The DBDIR directory can now be read-only, after installation.
- Improved debug file option.
- The system startup file and directory tests have now been merged.

24 Dec 08: New csf v4.31

Category: General
Posted by: Chirpy
Changes:


  • Added warning for those that enable PT_USERKILL in csf.conf - i.e. It is not a good idea to use that option

  • Modified PT_USERKILL to not kill (deleted) processes (these should be restarted manually after investigation) as per the documentation


Category: MailScanner
Posted by: Chirpy
Changes:


  • Fixed problem where the action for spam_action_deliver was being used by spamhigh_action_deliver instead of its own setting


20 Dec 08: New csf v4.30

Category: General
Posted by: Chirpy
Changes:


  • If you add the text "do not delete" to the comments of an entry in csf.deny then DENY_IP_LIMIT will ignore those entries and not remove them. Updated csf.deny information text for new installations

  • Made the (deleted) process text even more explicit for those that are not reading csf.conf or the FAQ for their explanation

  • Updated DSHIELD information URL in csf.conf

  • Added new feature - csf.rignore is an ignore file that lists domains and partial domains that lfd should ignore. Read /etc/csf/csf.rignore for more information. Note that .cpanel.net is always added on cPanel csf installations

  • Option GOOGLEBOT removed. This feature is now performed using csf.rignore. If GOOGLEBOT was previously enabled it will be added to csf.rignore


12 Dec 08: New csf v4.29

Category: General
Posted by: Chirpy
Changes:


  • Added Slackware support (tested on v12.2.0)

  • Added Fedora v10 support

  • Added new option GOOGLEBOT - Prevent *.googlebot.com from being blocked by lfd. See csf.conf for more information

  • Modified .cpanel.net check to use the same host lookup procedure as GOOGLEBOT to prevent domain spoofing

  • Added csf version from/to to output from csf --update when upgrading


11 Dec 08: New csf v4.28

Category: General
Posted by: Chirpy
Changes:


  • 4.28   - Fixed GENERIC csf problem with csf.pl perl modules


11 Dec 08: New csf v4.27

Category: General
Posted by: Chirpy
Changes:


  • New Feature - Port Flood Protection. This option configures iptables to offer protection from DOS attacks against specific ports. This option limits the number of connections per time interval that new connections can be made to specific ports. See csf.conf and readme.txt for more information. This option is only available on servers with the ipt_recent kernel module

  • cPanel DNSONLY compatibility added - Thanks to JJ for the assistance

  • Improved Cipher suite checking and advice for Apache and FTP in Server Check

  • Remove md5sum check from JS exploit check as it is covered by LF_INTEGRITY and causes confusion

  • Added new option LOGFLOOD_ALERT which will send an email alert based on logfloodalert.txt if lfd skips logs lines due to log file processing problems

  • Added new option PT_DELETED together with the FAQ explanation as to why lfd reports deleted processes. The option can be disabled to ignore such processes

  • Rearranged LOCALINPUT and LOCALOUTPUT rule positions to allow exceptions to SMTP_BLOCK


| 1 | 2 | 3 | ...| 36 | 37 | 38 | Next»
 

©1998-2005, Way to the Web Limited
ConfigServer, Way to the Web, WebUMake and WebUMake Hosting are trademarks of Way to the Web Limited