Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 12 of 12
  1. #1
    Member
    Join Date
    Aug 2001
    Posts
    110

    Default Abusive FTP users

    At least once a day, someone tries to connect via FTP to all the IPs on our servers. Since a lot of the servers have over 200 IPs, the server load skyrockets with all the processes.

    What is the best way to stop this without effecting legitimate users? Would this directive do the job?
    MaxClientsPerHost 1

    Also, does anyone set a MaxClients directive as a global directive since the MaxClientsPerHost will only catch them if they come from the same IP.

  2. #2
    Member
    Join Date
    Jan 2002
    Posts
    148

    Default

    if the connection is coming from a cable subscriber, your best bet would to be edit the host.deny file to include his IP, I don't know how cable internet is else where, but my IP rarely changes./

  3. #3
    Member
    Join Date
    Aug 2001
    Posts
    110

    Default

    Thanks, but each time they hit our IP blocks, they are coming from a different IP. It isn't a single person doing it... It is coming from scanning software that people run to find open FTP servers that will allow then anonymous FTP upload and download so they can distribute pirated software.

    I wouldn’t have even noticed it since it only lasts a few minutes, but we have some new monitoring software that pages me when the load gets too high.

  4. #4
    Member rpmws's Avatar
    Join Date
    Aug 2001
    Location
    back woods of NC, USA
    Posts
    1,858

    Default

    [quote:cd0fcc3db7][i:cd0fcc3db7]Originally posted by jumpdomain[/i:cd0fcc3db7]

    Thanks, but each time they hit our IP blocks, they are coming from a different IP. It isn't a single person doing it... It is coming from scanning software that people run to find open FTP servers that will allow then anonymous FTP upload and download so they can distribute pirated software.

    I wouldn’t have even noticed it since it only lasts a few minutes, but we have some new monitoring software that pages me when the load gets too high.
    [/quote:cd0fcc3db7]

    Just curious .. I get these all the time and if I remember correctly it is from some weird domain like wanadoo.fr
    ..or something like that ... does that ring a bell ?
    Just keeping my "eye" on things....
    R. Paul Mathews
    RPMWS - diehard cPanel Nutcase

  5. #5
    Member
    Join Date
    Aug 2001
    Posts
    110

    Default

    rpmws,

    Yes, that is the usual domain they come from... I suspect it is a large ISP in France. I am tempted to block their entire IP block but I am not 100% sure that we do not have any legitimate customers who also use them.

  6. #6
    Member
    Join Date
    Aug 2001
    Posts
    210

    Default

    I get LOADS of hack attempts from wandaloo.fr - and I have emailed them many, many times about it - each time they don't reply.

    I believe wandaloo.fr is a HUGE ISP in France that owns Freeserve in the UK (from memory).

    Also, I get a lot of people trying to ftp into my server using ftp/anonymous - but both of them are blocked, so they get denied.

    --James

  7. #7
    Member
    Join Date
    Aug 2001
    Posts
    110

    Default

    Unless I am mistaken, anonymous FTP access to each IP based site is turned on by default when you create the account.

    Anyone know an easy way to disable it so the user has to turn it on?

  8. #8
    Member
    Join Date
    Aug 2001
    Posts
    89

    Default

    i think that blocking the percentage of (possibly non existant) legitimate users is worth the risk with wandaloo.fr.

  9. #9
    Member
    Join Date
    Aug 2001
    Posts
    421
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    For some reason ProFTP does not block IP addresses in the hosts.deny file. Anyone know why?

  10. #10
    Member
    Join Date
    Aug 2001
    Posts
    130

    Default

    Im curious about this topic also...


    Zach

  11. #11
    Registered User
    Join Date
    Nov 2003
    Posts
    3

    Default

    hosts.deny only applies to the services listed in /etc/inetd.conf
    check that file to see what services are listed

  12. #12
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Wow! A two and a half year old thread - WTG
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

Similar Threads & Tags
Similar threads

  1. Should we all turn off the abusive Sender Callouts?
    By SuperBaby in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 01-23-2008, 10:06 PM
  2. Users' Anonymous FTP going to /var/ftp
    By Robotech_Master in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 03-08-2006, 05:17 PM
  3. Disallowing FTP to certain users (Pure FTP)
    By Scotty_B in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 02-22-2006, 11:42 AM
  4. FTP users
    By jaymc in forum New User Questions
    Replies: 2
    Last Post: 04-15-2005, 10:35 AM
  5. Can't login via FTP / Create new FTP users
    By davvve in forum cPanel and WHM Discussions
    Replies: 24
    Last Post: 05-11-2004, 10:24 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube