All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
ConfigServer is sending out lots of mails per day - is it possible to stop for a site?
We are using ConfigServer Firewall on our Cpanel server with around 200 sites.
Each day we get a huge amount of mails about mostly one site. The mails is about lfd (see under). Is it possible to stop this on only one site, or do we have to turn off the option?
Emne: lfd on cxxxxx.xxxxx.no: Suspicious process running under user stavexxxx Time: Fri Jan 12 10:10:07 2018 +0100 PID: 11089 (Parent PID:11089) Account: stavexxxxx Uptime: 79 seconds Executable: /usr/bin/perl Command Line (often faked in exploits): bash Network connections by the process (if any): tcp: 0.0.0.0:34790 -> 0.0.0.0:0 Files open by the process (if any): /dev/null /dev/null /dev/null Memory maps by the process (if any): 00400000-00402000 r-xp 00000000 fd:00 2625699 /usr/bin/perl 00601000-00602000 rw-p 00001000 fd:00 2625699 /usr/bin/perl 01ff1000-023d2000 rw-p 00000000 00:00 0 023d2000-023f3000 rw-p 00000000 00:00 0
Comments
How about ignoring perl in lfd?...
I see you didnt read, at least not reply to the other thread. Are you expecting the LET crew to be your SysAdmins? Maybe you should look at hiring someone to manage your servers?
Just RTM - section 8 for process tracking https://download.configserver.com/csf/readme.txt
Yea...it's not so simple, they guy that did the setup and managed the server is not with the company any more. The hosting part has only been an extra service for some of our customers. So not making much of a profit. It is not our main business at all, we deliver IT support and ASP solutions.
If people don't want to help me, just don't reply? If nobody is replying in any of my threads here, I just have to find another forum. For the owner of the company is not hiring anybody to manage a server we don't earn money from.
Ken, you are so far over your head that it's scary. It's not your fault, but one of these days you're going to badly bungle this. Tell the owner you need some training or assistance.
Definitely tell the owner you need some assistance there...
Why not reinstall?
Even if you turn off CSF notifications, the notifications for suspicious processes still get sent so just add a filter into your email client and trash them until they fix the bug
Its not a bug. Just add it to the ignore/trusted binaries list.
I feel you. Took me forever to figure out why it kept sending notifications despite every setting being defined for it to not. Don't even remember what I changed, just keep hammering at it until you hate yourself.
[Insert wife joke here]
Usually, you can add an entry for the binary to the /etc/csf/pignore file (there should already be examples of the format in the file). After that, do a csf -r to restart.