SOLVED Using cPHulk and CSF Together?

sahostking

Well-Known Member
May 15, 2012
367
9
68
Cape Town, South Africa
cPanel Access Level
Root Administrator
Twitter
Decided to turn on CpHulk today as we just used CSF mainly and found cpHulk blocking some brute force attacks that CSF is not finding.

Looks like it improved alot. Do you guys recommend we still stick with CSF and just find the cause or is using both better now? or just cphulk

Lastly here is an example of cphulk blocking something CSF did not pickup.

Code:
Nov 27 20:16:57 lin02 pure-ftpd: ([email protected]) [INFO] New connection from 51.254.148.189
Nov 27 20:17:03 lin02 pure-ftpd: ([email protected]) [WARNING] Authentication failed for user [alexalarms]
Nov 27 20:17:03 lin02 pure-ftpd: ([email protected]) [INFO] Logout.
Nov 27 20:42:26 lin02 pure-ftpd: ([email protected]) [INFO] New connection from 51.254.148.189
Nov 27 20:42:30 lin02 pure-ftpd: ([email protected]) [WARNING] Authentication failed for user [mlclaw]
Nov 27 20:42:30 lin02 pure-ftpd: ([email protected]) [INFO] Logout.
Nov 27 21:06:32 lin02 pure-ftpd: ([email protected]) [INFO] New connection from 51.254.148.189
Nov 27 21:06:37 lin02 pure-ftpd: ([email protected]) [WARNING] Authentication failed for user [anolhealthcare]
Nov 27 21:06:37 lin02 pure-ftpd: ([email protected]) [INFO] Logout.
Nov 27 21:21:53 lin02 pure-ftpd: ([email protected]) [INFO] New connection from 51.254.148.189
Nov 27 21:21:57 lin02 pure-ftpd: ([email protected]) [WARNING] Authentication failed for user [fahrenheitrestaurant]
Nov 27 21:21:57 lin02 pure-ftpd: ([email protected]) [INFO] Logout.
Nov 27 21:38:29 lin02 pure-ftpd: ([email protected]) [INFO] New connection from 51.254.148.189
Nov 27 21:38:33 lin02 pure-ftpd: ([email protected]) [WARNING] Authentication failed for user [kidsparadise]
Nov 27 21:38:34 lin02 pure-ftpd: ([email protected]) [INFO] Logout.
Nov 27 21:55:13 lin02 pure-ftpd: ([email protected]) [INFO] New connection from 51.254.148.189
Nov 27 21:55:19 lin02 pure-ftpd: ([email protected]) [WARNING] Authentication failed for user [loupezelectrical]
Nov 27 21:55:19 lin02 pure-ftpd: ([email protected]) [INFO] Logout.
Nov 27 21:59:48 lin02 pure-ftpd: ([email protected]) [INFO] New connection from 51.254.148.189
Nov 27 21:59:52 lin02 pure-ftpd: ([email protected]) [WARNING] Authentication failed for user [thebusinessoasisgroup]
Nov 27 21:59:52 lin02 pure-ftpd: ([email protected]) [INFO] Logout.
Nov 27 22:55:05 lin02 pure-ftpd: ([email protected]) [INFO] New connection from 51.254.148.189
Nov 27 22:55:10 lin02 pure-ftpd: ([email protected]) [WARNING] Authentication failed for user [refugeepastoralcare]
Nov 27 22:55:11 lin02 pure-ftpd: ([email protected]) [INFO] Logout.
 
Last edited by a moderator:

danielpmc

Well-Known Member
Nov 3, 2016
78
33
18
usa
cPanel Access Level
Reseller Owner
Hello sahostking,

Wow! Your cpHulk is working really well judging by your logs. I am curious about your settings. Do you have cpHulk set at default settings or have you altered them? If you altered them could you share your settings with us? I ask this because my cpHulk sits like a lump on a log. Nothing happens. But when i look at my CSF logs i nail the nefarious #$#$*. to the wall. My CSF blocks SSH, Exim and FTP abusers everyday, yet cpHulk does not hardly ever block anything.

Do you guys recommend we still stick with CSF and just find the cause or is using both better now?
In my opinion i would rely on both services, simply because two security guards are better than one. Besides i could not imagine running a server(s) without a Firewall.

danielpmc
 

sahostking

Well-Known Member
May 15, 2012
367
9
68
Cape Town, South Africa
cPanel Access Level
Root Administrator
Twitter
Naaa just started it. No changes whatsoever.

I'm thinking of adding this to command text "csf --tempdeny %remote_ip% 3600"

Then when bruteforce is picked up with Cphulk it does not block there but rather in CSF? Anyone know if this will work well.

Going to test it shortly though.
 

cPanelMichael

Administrator
Staff member
Apr 11, 2011
47,910
2,213
363
I'm thinking of adding this to command text "csf --tempdeny %remote_ip% 3600"

Then when bruteforce is picked up with Cphulk it does not block there but rather in CSF? Anyone know if this will work well.
Yes, this should work as expected. However, you may want to disable "Block IP addresses at the firewall level if they trigger brute force protection" in your cPHulk configuraiton to avoid duplicate blocks of the IP address at the firewall level.

Thank you.
 
  • Like
Reactions: danielpmc

Medical Websites

Registered
Oct 10, 2017
1
0
1
Australia
cPanel Access Level
Root Administrator
Glad I found this thread. Just had the support people at our hosting provider tell me to turn off cPhulk because I am already using csf and it therefore isn't needed. This came after I posed a question about why cPhulk was spawning lots of processes, adding to server load, which, to me suggested there were just a lot of brute force attacks that csf wasn't detecting (our servers are also supposedly protected by their hardware firewall).

Pleased I trusted my own instincts on this and did my own searches, and maybe time to look for another provider.