Dev {Tricks}

  • Home
  • WordPress
  • OJS
  • Oxwall
  • Server and Hosting
You are here: Home / Archives for CSF

April 16, 2020 by dev Leave a Comment

Change DirectAdmin port from 2222 to your choice where CSF installed.

Here I will show you how to change port from 2222 to 9999 in two steps.

Step One: DirectAdmin

To change port of my choice (e.g., 9999), I have to open directadmin.conf as follows

vi /usr/local/directadmin/conf/directadmin.conf

Change port from 2222 to 9999

port=9999

Save and exit vi

:wq

Step Two: CSF

Find and change ports in CSF (ConfigServer Security & Firewall). Open csf.conf

vi /etc/csf/csf.conf

Change as follows:

TCP_IN = "9999"
TCP_OUT = "9999"

Save and exit vi

:wq

Restart the CSF firewall

csf -r

Then restart the DirectAdmin

service directadmin restart

You can do above task in login to DirectAdmin too.

Filed Under: DirectAdmin, Find & fix, Server and Hosting Tagged With: 2222, CSF, csf port, DirectAdmin, DirectAdmin 2222, DirectAdmin port, DirectAdmin port change

April 1, 2020 by dev Leave a Comment

How to install CSF with Brute Force Monitor (BFM) on DirectAdmin

CSF with Brute Force Monitor (BFM) will provide extra benefit of BFM to find some extra cases which triggers the blocks using CSF.

It will use the iptables configuration, and all features of CSF, plus the added benefit of the BFM

wget http://files.directadmin.com/services/all/csf/csf_install.sh
/bin/sh ./csf_install.sh

 

Filed Under: DirectAdmin, How to, Security, Server and Hosting Tagged With: BFM, Brute Force Monitor, configserver, ConfigServer Security & Firewall, ConfigServer Security & Firewall (csf), CSF, csf with BFM, DirectAdmin

November 27, 2019 by dev Leave a Comment

ConfigServer Security & Firewall, CSF basic commands, advanced configurations and settings

Basic CSF commands

  • Enable CSF
    csf -e
  • Disable CSF
    csf -x
  • Start CSF
    csf -s
  • Flush/Stop CSF
    csf -f
  • Reload CSF
    csf -r
  • Allow an IP and add it to csf.allow – /etc/csf/csf.allow
    csf -a 162.162.1.219
  • Remove and delete an IP from csf.allow – /etc/csf/csf.allow
    csf -ar 162.162.1.209
  • Place an IP on temporary deny list in /var/lib/csf/csf.tempban
    csf -td
  • Remove an IP from the temporary IP ban or allow list
    csf -tr 162.162.1.209
  • Flush all IPs from the temporary IP entries
    csf -tf
  • Deny an IP and add to csf.deny
    csf -d 162.162.1.209
  • Remove and Unblock an IP from csf.deny
    csf -dr 162.162.1.209
  • Remove and Unblock all entries from csf.deny
    csf -df
  • Search for a pattern match on iptables e.g : IP, CIDR, Port Number
    csf -g 152.167.1.118

Advanced Configuration to csf.conf at /etc/csf/csf.conf

  • Add root and admin notification email addresses at /etc/aliases.
    root: root@domain.com
    admin: admin@domain.com
    
  • Add email address to get all notifications – /etc/csf
    (csf > firewall configuration > Reporting Settings > LF_ALERT_TO = alert@domain.com)

    LF_ALERT_TO = "alert@domain.com"
  • Stop or disable “excessive resource usage” change PT_USERTIME = 0
    PT_USERTIME = "0"

    Under Process Tracking at /etc/csf

  • Don’t Block IP addresses that are in the csf.allow files
    IGNORE_ALLOW = "1"
  • Allow Incoming and Outgoing ICMP
    ICMP_IN = "1"
    ICMP_OUT = "1"
  • Block Certain Countres
    CC_DENY = "CA,CN,US"
    CC_ALLOW = "IN,ME,DE"
  • Send the Su and SSH Login log by Email
    LF_SSH_EMAIL_ALERT = "1"
    LF_SU_EMAIL_ALERT = "1"
  •  Get alert or notification
    LF_ALERT_TO = "email@domain.tld"

Warning in CSF

  • SYSLOG_CHECK option check
    (This option helps prevent brute force attacks on your server services)

    • Open /etc/csf/csf.conf
    • Search for “SYSLOG_CHECK”
    • Put value between 300 and 3600 seconds
      SYSLOG_CHECK = "600"
    • Restart CSF firewall
      #csf -r
  • Check for DNS recursion restrictions
    (You have a local DNS server running but do not appear to have any recursion restrictions set. This is a security and performance risk and you should look at restricting recursive lookups to the local IP addresses only)
    • Add following options to /etc/named.conf
      options {        
         allow-recursion {
         localhost;
      };
    • Restart named
      service named restart
  • Check for cxs
    (You should consider using cxs to scan web script uploads and user accounts for exploits uploaded to the server)

    ConfigServer eXploit Scanner (cxs) - from $60/server

    https://configserver.com/cp/cxs.html

  • Check for osm
    (You should consider using osm to provide protection from spammers exploiting the server)

    Outgoing Spam Monitor (osm) - $40/server

    https://www.configserver.com/cp/osm.html

  • Check for swap file
    (The server appears to have no swap file. This is usually considered a stability and performance risk. You should either add a swap partition, or create one via a normal file on an existing partition)
  • SSH/Telnet Check
    • Check SSH PasswordAuthentication
      (You should disable PasswordAuthentication and only allow access using PubkeyAuthentication to improve brute-force SSH security)
    • Check SSH UseDNS
      (You should disable UseDNS by editing /etc/ssh/sshd_config. Otherwise, lfd will be unable to track SSHD login failures successfully as the log files will not report IP addresses)

      UseDNS no

 

Filed Under: Digitalocean, DirectAdmin, Security, Server and Hosting, VPS Management Tagged With: CSF, csf.conf

  • Upwork
  • Freelancer
  • Fiverr
  • Guru

www.ojsexpert.com
www.ojsdev247.com

Recent Posts

  • To get your email for castamodel.com going to the right place, you need to update your DNS settings.
  • Security and WordPress
  • ROR
  • How do we copy google form to google workspace?
  • Install ImageMagick – Almalinux
  • How to remove /public/ from URL in Laravel
  • How to install Maldet alert?
  • How to Install Maldet and Run a Scan | Maldetect
  • Where is Roundcube location on CWP control panel?
  • How To Add Node.js Projects In aaPanel?
  • SPF/DKIM/DMARC Tools
  • Associative arrays – How to loop over Associative arrays
  • Indexed Arrays. How to loop over Indexed Arrays.
  • PHP Break | Continue
  • For Loop | While Loop | Do…While Loop | Foreach Loop
  • Strict mode in PHP
  • PHP Function Return Types
  • PHP Anonymous Functions (or Closures)
  • PHP Variadic Functions
  • PHP nullable type hints

Categories

  • Affiliate Marketing (1)
  • Customization (4)
    • CSS (2)
  • Email Solutions (23)
    • FrontApp (2)
    • Google Spreadsheet (2)
    • Microsoft Outlook (1)
    • PHP Email Form (3)
    • PolyMail (2)
    • Recaptcha (1)
    • Roundcube (4)
    • Thunderbird (3)
    • WebMail (5)
  • Games (1)
  • How to (87)
  • Joomla (6)
    • Akeeba (1)
    • Fix & Tricks (3)
  • jQuery (4)
  • jQuery Plugins (4)
    • BX Slider (1)
    • Slick (1)
  • Laravel (5)
  • Marketplace (5)
  • Miscellaneous (31)
  • MultiSaaS (1)
  • OJS (56)
    • Crossref (1)
    • Help (37)
    • Installation (10)
      • Issues (5)
    • Plugins (8)
    • Scholar Indexing (2)
    • Theme (7)
      • Templates (7)
        • Frontend (6)
        • legacy (1)
    • Theme Customization (10)
    • Theme Development (14)
    • TPL CSS JS (2)
    • Upgrade (11)
  • OSTAD (17)
  • Oxwall (3)
  • Payment Methods (1)
    • Paypal (1)
  • PC Tips and Tricks (14)
    • MS Office (2)
      • PowerPoint (1)
    • Windows (4)
  • PHP Parse error (2)
  • phpBB (2)
  • Server and Hosting (213)
    • Billing and Management (10)
      • Blesta (5)
      • Boxbilling (2)
      • WHMCS (5)
    • Email (10)
      • Postfix (3)
    • Error and Fix (17)
    • FTP (2)
    • Linux Distribusion (28)
      • Almalinux (13)
      • CentOS (17)
      • Debian (21)
      • Ubuntu (19)
    • Mail Server Solusion (7)
      • iRedMain (6)
    • MySQL (12)
    • Providers (69)
      • AWS (37)
      • Bluehost (37)
      • Cloudcone (26)
      • Contabo (40)
      • Digitalocean (68)
      • Hetzner (3)
      • HostGator (36)
      • Hostinger (8)
      • RackNerd (10)
      • VPSDime (38)
    • Security (21)
      • SSH (8)
    • VPS Management (72)
    • Web Control Panel (147)
      • aaPanel (14)
      • CentOS Web Panel (46)
      • cPanel (33)
      • CyberPanel (7)
      • DirectAdmin (96)
        • Find & fix (38)
      • ISPConfig (17)
      • KeyHelp (7)
      • Plesk (26)
      • Webmin (25)
        • Usermin (2)
        • Virtualmin (13)
      • WHM (18)
  • Uncategorized (19)
  • Wordpress (89)
    • Elementor (2)
    • Find and Fix (11)
    • Functions (5)
    • Genesis (9)
    • Glossary (1)
    • How to (22)
    • Neuron TD (15)
      • Console Error (1)
      • functions (5)
        • register_post_type (1)
        • register_sidebar (1)
        • theme_files (1)
        • theme_supports (1)
      • Image Directory (1)
      • Menu (2)
      • Query (4)
    • Plugins (13)
      • Contact Form 7 (5)
      • Duplicator (1)
      • Essential Grid (2)
    • Softaculous (3)
    • Speed and Security (4)
    • Stock Theme Development (6)
      • Header Footer (1)
      • PHP (1)
      • VC (1)
    • Theme Development (2)
      • Issues (1)
      • Menu (1)
    • Timer Theme Development (3)
    • Update (2)
    • Woocommerce (2)
    • WP Basic Guideline (8)

Important DEV links

  • Premium Themes
    • Themeforest
    • Envato Market
  • Built With (What Theme is That?)
    • What WP theme is that
    • Joomla Template Detector
    • Drupal Template Detector
    • Prestashop Template Detector
    • Shopify Theme Detector
    • Squarespace Template Detector
    • OpenCart Detector
    • WordPress.com Theme Detector
  • Domain/IP history checker
    • Who IS request
    • Hosting Info
  • Check DNS Propagation
    • DNS Checker
    • intoDNS
  • What is my IP
    • What is My IP Address
    • What is My IP
    • IP location
    • What is My IP
    • Porkbun
  • SEO Tools
    • Visitor Traffic
    • Broken Link
    • Website Speed Test
      • SEMrush
      • GTmetrix
      • Pingdom
      • PageSpeed Insights
      • DebugBear
      • keyCDN
  • Photo Image
    • Remove Background 50 Free Preview Image 375 × 666 per month
  • Domain Registrars
    • 123-Reg
    • Porkbun
    • Freenom
    • Namecheap NEWCOM598
  • Hosting Providers
    • Bluehost
    • Hostgator
    • Inmotion
  • Hosting Control Panel
    • CWPpro (FREE)
    • DirectAdmin (Trial 60 Days, One account $2/month)
    • ISPConfig (Free)
  • Webmaster Tools
    • Google
    • Bing
    • Yandex
  • Miscellaneous
    • Time Calculator

 

Categories

  • Affiliate Marketing (1)
  • Customization (4)
    • CSS (2)
  • Email Solutions (23)
    • FrontApp (2)
    • Google Spreadsheet (2)
    • Microsoft Outlook (1)
    • PHP Email Form (3)
    • PolyMail (2)
    • Recaptcha (1)
    • Roundcube (4)
    • Thunderbird (3)
    • WebMail (5)
  • Games (1)
  • How to (87)
  • Joomla (6)
    • Akeeba (1)
    • Fix & Tricks (3)
  • jQuery (4)
  • jQuery Plugins (4)
    • BX Slider (1)
    • Slick (1)
  • Laravel (5)
  • Marketplace (5)
  • Miscellaneous (31)
  • MultiSaaS (1)
  • OJS (56)
    • Crossref (1)
    • Help (37)
    • Installation (10)
      • Issues (5)
    • Plugins (8)
    • Scholar Indexing (2)
    • Theme (7)
      • Templates (7)
        • Frontend (6)
        • legacy (1)
    • Theme Customization (10)
    • Theme Development (14)
    • TPL CSS JS (2)
    • Upgrade (11)
  • OSTAD (17)
  • Oxwall (3)
  • Payment Methods (1)
    • Paypal (1)
  • PC Tips and Tricks (14)
    • MS Office (2)
      • PowerPoint (1)
    • Windows (4)
  • PHP Parse error (2)
  • phpBB (2)
  • Server and Hosting (213)
    • Billing and Management (10)
      • Blesta (5)
      • Boxbilling (2)
      • WHMCS (5)
    • Email (10)
      • Postfix (3)
    • Error and Fix (17)
    • FTP (2)
    • Linux Distribusion (28)
      • Almalinux (13)
      • CentOS (17)
      • Debian (21)
      • Ubuntu (19)
    • Mail Server Solusion (7)
      • iRedMain (6)
    • MySQL (12)
    • Providers (69)
      • AWS (37)
      • Bluehost (37)
      • Cloudcone (26)
      • Contabo (40)
      • Digitalocean (68)
      • Hetzner (3)
      • HostGator (36)
      • Hostinger (8)
      • RackNerd (10)
      • VPSDime (38)
    • Security (21)
      • SSH (8)
    • VPS Management (72)
    • Web Control Panel (147)
      • aaPanel (14)
      • CentOS Web Panel (46)
      • cPanel (33)
      • CyberPanel (7)
      • DirectAdmin (96)
        • Find & fix (38)
      • ISPConfig (17)
      • KeyHelp (7)
      • Plesk (26)
      • Webmin (25)
        • Usermin (2)
        • Virtualmin (13)
      • WHM (18)
  • Uncategorized (19)
  • Wordpress (89)
    • Elementor (2)
    • Find and Fix (11)
    • Functions (5)
    • Genesis (9)
    • Glossary (1)
    • How to (22)
    • Neuron TD (15)
      • Console Error (1)
      • functions (5)
        • register_post_type (1)
        • register_sidebar (1)
        • theme_files (1)
        • theme_supports (1)
      • Image Directory (1)
      • Menu (2)
      • Query (4)
    • Plugins (13)
      • Contact Form 7 (5)
      • Duplicator (1)
      • Essential Grid (2)
    • Softaculous (3)
    • Speed and Security (4)
    • Stock Theme Development (6)
      • Header Footer (1)
      • PHP (1)
      • VC (1)
    • Theme Development (2)
      • Issues (1)
      • Menu (1)
    • Timer Theme Development (3)
    • Update (2)
    • Woocommerce (2)
    • WP Basic Guideline (8)
  • Home
  • WordPress
  • OJS
  • Oxwall
  • Server and Hosting

Copyright © 2025 · Executive Pro Theme on Genesis Framework · WordPress · Log in