#1 (permalink)  
Old 12-18-2008, 10:31 AM
kjg kjg is offline
Registered User
 
Join Date: Mar 2004
Posts: 24
kjg
cphulk and host access control stopped working after upgrade?

Getting thousands of emails saying "Large Number of Failed Login Attempts from IP 64.185.237.173" since an hour back

The IP is added to brutes and blocked with expiration 2009-01-01, but after a while it starts all over again.

Also tried to stop the IP via host acces control (all deny) but it seems not to work either.

I don't understand this. A guess is that the db is flushed all the time making it possible for the attacker to continue.

We have the problem on the 3 servers that are upgraded to 11.24.4

cPanel 11.24.4-R32470 - WHM 11.24.2 - X 3.9
CENTOS 5.2

Any help would be very much appreciated.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 12-18-2008, 10:40 AM
Staff
 
Join Date: Jun 2007
Posts: 9
cPanelBrandonM is on a distinguished road
Hello,
Would it be possible to get you to submit a support ticket so that we may take a look at this server? Thanks in advance.
__________________
Brandon Mandevill
Technical Analyst II
cPanel Technical Support

Please remember that these forums are not an official means of support. To seek support, please visit http://tickets.cpanel.net/submit.

In addition, if you wish to submit an official feature request, please visit http://bugzilla.cPanel.net.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 12-18-2008, 06:43 PM
Registered User
 
Join Date: Dec 2008
Posts: 1
hlooman is on a distinguished road
Same problem with cPHulk

Hello, I have the exact same problem, 11K+ emails with login attempts in 2 days since the update.

Tried reconfiguring CPHulk to no avail.

Keep me informed on any progress on this.

Thanks, Hans.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 12-19-2008, 08:00 AM
Registered User
 
Join Date: Jan 2004
Posts: 48
Zazoos1
Yes, I am experiencing this SAME problem since the upgrade. Thousands upon thousands of emails... opened support ticket yesterday but so far no reply.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 12-19-2008, 10:21 AM
cpanelnick's Avatar
cPanel Staff
 
Join Date: Feb 2003
Location: Houston, TX
Posts: 4,348
cpanelnick is on a distinguished road
Quote:
Originally Posted by Zazoos1 View Post
Yes, I am experiencing this SAME problem since the upgrade. Thousands upon thousands of emails... opened support ticket yesterday but so far no reply.
Please post the ticket # so we can look into this.

Thanks
__________________
-Nick
cPanel Inc.

Need support? Submit a request here. These forums are not an official support channel.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 12-29-2008, 03:55 AM
Registered User
 
Join Date: Aug 2003
Posts: 70
headout
We have the same problem, after the update.
cPanel 11.24.4-R32603 - WHM 11.24.2 - X 3.9
FREEBSD 6.2 i386 on standard

Users don't get blocked. The expiration time just gets renewed.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 01-03-2009, 03:15 PM
kjg kjg is offline
Registered User
 
Join Date: Mar 2004
Posts: 24
kjg
Update:
We posted a ticket to support and they solved it after a while.
According to them, there will be a fix in the next release.

Seems that the protection works ok, but the system keeps sending emails also after the ip is blocked.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 01-05-2009, 02:30 PM
Registered User
 
Join Date: Jul 2004
Posts: 162
jack01 is on a distinguished road
The bugzilla is here:

http://bugzilla.cpanel.net/show_bug.cgi?id=8457

everyone affected please vote if you can.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9 (permalink)  
Old 01-06-2009, 11:05 AM
kjg kjg is offline
Registered User
 
Join Date: Mar 2004
Posts: 24
kjg
As I said in the post above, the cpanel tech people solved it and told me:

"The issue (multiple E-Mails for a brute force attack) has been patched and will be available in revision 32707+."

I got that answer dec 30 and some 14 hours later I got the following:
"The fix is being tested and should be out in all 11.24 Builds soon."

So I guess it is on its way
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 06:20 PM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
© cPanel Inc