Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    Member
    Join Date
    Mar 2004
    Location
    Netherlands
    Posts
    40
    cPanel/Enkompass Access Level

    DataCenter Provider

    Default cPHulk and botnet

    For a few days now tons of IP's have been trying to gain access to our servers via ssh, so I suspect a botnet. every morning my mailbox is filled with hundreds of mails per server from cPHulk saying it banned IP's.

    What I'm wondering is if there is a way to stop or prevent this kind of botnet attacks.

  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Nov 2006
    Posts
    4

    Default

    You could use tcpwrappers to protect the SSHd service and only allow certain IPs access. This would prevent them from being able to even authenticate to the server and would just discard their connection.

    You could also change the SSH port to a different port.

    Other than that you would need some sort of network firewall to filter the connections out at the network level before it reaches the server.

  3. #3
    Member
    Join Date
    Nov 2006
    Posts
    81

    Default

    I am having this problem as well. I implemented ssh guard (Sshguard), which updates the firewall rules as brute force attacks are identified. It works quite well.

Similar Threads & Tags
Similar threads

  1. CPHulk locked me out
    By halyconprime in forum New User Questions
    Replies: 2
    Last Post: 04-12-2010, 01:43 PM
  2. My server is under SYN and/or botnet, how can I prevent this attack?
    By PHP Warner in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 04-05-2010, 04:15 AM
  3. Cphulk.
    By 2fast in forum cPanel and WHM Discussions
    Replies: 8
    Last Post: 09-05-2009, 01:37 PM
  4. cphulk
    By offline in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 03-13-2009, 01:52 PM
  5. cphulk configuration
    By erinspice in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 09-25-2008, 07:18 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube