Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Member
    Join Date
    Nov 2008
    Posts
    174

    Default CPHulk - Appears not to work!

    OK, I have CPHulk enabled, with only myself in the trusted hosts list (already managed to lock myself out once, so I know it's working)...

    Now, I wake up this morning to find a pile of this in my /var/log/messages

    Feb 22 08:46:44 vps pure-ftpd: (?@58.246.161.120) [ERROR] Too many authentication failures
    Feb 22 08:46:44 vps pure-ftpd: (?@58.246.161.120) [INFO] New connection from 58.246.161.120
    Feb 22 08:46:45 vps pure-ftpd: (?@58.246.161.120) [WARNING] Authentication failed for user [tsinternetuser]
    Feb 22 08:47:24 vps last message repeated 4 times
    [repeat above about a thousand times at least]

    Now, why isn't CPHulk locking this dude out? the CPHulk screen in WHM shows no lockouts, no errors, nada... zip... nothing - it all looks fine and dandy. What gives?

    I'm running the latest release R33609

    Steve

  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Oct 2008
    Posts
    49

    Default

    Hi;

    Make sure that the CpHulk is enabled and properly configured.

    Enabling cPHulk is pretty easy. Simply log into your WHM control panel as root. From the main menu on the left, click on Security Center from the Security section.

    Click on the cPHulk Brute Force Detection link at the top of the page. Now you may want to configure cPHulk before you enable it. The configuration parameters are pretty much self-explanatory so I won’t go into details about this. Basically you set the number of failed attempts before an IP or an account is blocked and you set how long you want it to be blocked. Make sure you have configured the options properly here.

    When you’re done, simply click on the Enable button at the top.
    JaguarPC
    jaguarpc.com

  3. #3
    Member
    Join Date
    Nov 2008
    Posts
    174

    Default

    Thanks Shaun, but CPHulk is definitely enabled (as far as the WHM control panel pages are concerned)... It's also managed to lock me out in the past, so I am confident the service is running.

    IP Based Brute Force Protection Period in minutes:15
    Brute Force Protection Period in minutes:10
    Maximum Failures By Account:15
    Maximum Failures Per IP:5
    Maximum Failures Per IP:30
    Extend account lockout time upon additional authentication failures:no
    Send notification when brute force user is detected:yes

    I'm concerned that the log was so full of these messages, despite CPHulk was running, and that CPHulk has not recorded any failed login attempts.

    Has CPHulk ignores the logins because they were aimed at user "tsinternetuser", which obviously doesn't exist on a linux box?

  4. #4
    cPanel Staff cpanelnick's Avatar
    Join Date
    Feb 2003
    Location
    Houston, TX
    Posts
    4,597

    Default

    Please open a ticket @ https://tickets.cpanel.net/submit/
    -Nick
    cPanel Inc.

    Need support? Submit a request here. Complimentary support is available to all license holders regardless of where you purchased your license.
    Need a complimentary support account? Create one here.

Similar Threads & Tags
Similar threads

  1. DNS Zones does not appears in all clusters
    By jackg164 in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 06-01-2011, 10:07 AM
  2. cPHulk Doesn't work?
    By jazz57 in forum cPanel and WHM Discussions
    Replies: 35
    Last Post: 12-24-2007, 09:11 AM
  3. Â icon appears in Cpanel
    By jckno9 in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 05-25-2006, 03:16 AM
  4. cppop appears slow
    By avara in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 08-25-2002, 11:12 AM
  5. Connecting via FTP appears slow
    By avara in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 06-17-2002, 11:01 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube