Hello All,
I have enabled and configured CPHulk Brute Force Protection but it doesn't blacklist the offending IP's quickly or at all like the configuration I have put in.
In order I have the options filled out:
1440
30
4
4
30
All Check box's are checked.
I am expecting that after 4 failures the IP will be blacklisted, however I get email notification showing:
/24: https://myserver.net:2087/cgi/bl.cgi?ip=218.244.245.0/24
the email also shows other IP's with 16, 20, 30 failures and if I look at the blacklist on WHM it didn't add that IP to the blacklist.
I do see some IP's it blacklisted, but many are not listed.
I also see literally 100's of the below line from lastb:
root ssh:notty 218.244.245.251 Fri Mar 30 07:08 - 07:08 (00:00)
If I don't click on the link from the email to add it to the blacklist it's not happening.
I am running WHM 11.32.2 (build 8) CENTOS 5.8 i686.
Any suggestions appreciated.
I have enabled and configured CPHulk Brute Force Protection but it doesn't blacklist the offending IP's quickly or at all like the configuration I have put in.
In order I have the options filled out:
1440
30
4
4
30
All Check box's are checked.
I am expecting that after 4 failures the IP will be blacklisted, however I get email notification showing:
/24: https://myserver.net:2087/cgi/bl.cgi?ip=218.244.245.0/24
the email also shows other IP's with 16, 20, 30 failures and if I look at the blacklist on WHM it didn't add that IP to the blacklist.
I do see some IP's it blacklisted, but many are not listed.
I also see literally 100's of the below line from lastb:
root ssh:notty 218.244.245.251 Fri Mar 30 07:08 - 07:08 (00:00)
If I don't click on the link from the email to add it to the blacklist it's not happening.
I am running WHM 11.32.2 (build 8) CENTOS 5.8 i686.
Any suggestions appreciated.