Hi all,
I'm hoping someone might have a clue for me as to what might be going on with a particular customer on one of my dedicated's. I use ConfigServer's CSF/LFD scripts, and this customer keeps getting "blocked with too many connections" when he FTP's in and tries to download his public_html folder to his computer.
Here's an example of an LFD alert I typically receive when he tries to FTP and gets blocked:
Time: Thu Aug 2 16:00:59 2007
IP: xx.xxx.xx.xxx (ppp-xx-xxx-xx-xxx.dsl.hstntx.swbell.net)
Connections: 878
Blocked: temporarily
When I check the lfd.log file all I see for it is this:
Thu Aug 2 16:00:59 2007 lfd: (CT) IP xx.xxx.xx.xxx found to have 878 connections - *Blocked in csf* for 1800 secs
At first I suspected that it might be his FTP client, so I had him try a different one. Same results.
This problem doesn't happen with any other customers.
Is it possible that his computer might be compromised and that maybe some form of malware on his system is creating extra connections when he logs in to FTP? (I have asked him to run some security scans on his system, waiting for results).
Are there other possibilities that anyone here can think of that might cause him to have "800 connections" simply by FTP'ing in to the server and downloading his web site?
Thanks for any opinions / advice, I appreciate it.
I'm hoping someone might have a clue for me as to what might be going on with a particular customer on one of my dedicated's. I use ConfigServer's CSF/LFD scripts, and this customer keeps getting "blocked with too many connections" when he FTP's in and tries to download his public_html folder to his computer.
Here's an example of an LFD alert I typically receive when he tries to FTP and gets blocked:
Time: Thu Aug 2 16:00:59 2007
IP: xx.xxx.xx.xxx (ppp-xx-xxx-xx-xxx.dsl.hstntx.swbell.net)
Connections: 878
Blocked: temporarily
When I check the lfd.log file all I see for it is this:
Thu Aug 2 16:00:59 2007 lfd: (CT) IP xx.xxx.xx.xxx found to have 878 connections - *Blocked in csf* for 1800 secs
At first I suspected that it might be his FTP client, so I had him try a different one. Same results.
This problem doesn't happen with any other customers.
Is it possible that his computer might be compromised and that maybe some form of malware on his system is creating extra connections when he logs in to FTP? (I have asked him to run some security scans on his system, waiting for results).
Are there other possibilities that anyone here can think of that might cause him to have "800 connections" simply by FTP'ing in to the server and downloading his web site?
Thanks for any opinions / advice, I appreciate it.