Showing posts with label CSF. Show all posts
Showing posts with label CSF. Show all posts

Sunday, August 20, 2017

How to Disable CSF Blocked IP Email Alerts and Reduce Notification Noise

On busy production web servers running ConfigServer Security & Firewall (CSF) with Login Failure Daemon (LFD), automated brute-force attempts can trigger dozens of automated alert emails per hour. Even after disabling LF_PERMBLOCK_ALERT and LF_NETBLOCK_ALERT in /etc/csf/csf.conf, CSF often continues sending notification messages.

The Culprit: LF_EMAIL_ALERT acts as a global master override that dispatches email notifications regardless of individual sub-alert flags.

Configuration Solution

Open /etc/csf/csf.conf and ensure all three alert directives are disabled:

# Disable automated IP block email notifications
LF_PERMBLOCK_ALERT = "0"
LF_NETBLOCK_ALERT = "0"
LF_EMAIL_ALERT = "0"

Reload CSF and LFD for the settings to take effect:

csf -r
service lfd restart

Tuesday, February 2, 2016

Installing ShareLaTeX with Docker and CSF Firewall on Linux (CentOS & Ubuntu)

Self-hosting ShareLaTeX (now Overleaf Community Edition) enables collaborative scientific paper writing with full data privacy. Deploying ShareLaTeX via its official Docker container is straightforward, but servers protected by ConfigServer Security & Firewall (CSF) require specific iptables routing configurations to allow containerized network traffic without exposing internal services.

Components: Docker Engine • ShareLaTeX Container • CSF Firewall iptables rules

1. Deploying the Container

docker run -d   -v ~/sharelatex_data:/var/lib/sharelatex   --name=sharelatex   -p 3000:80   sharelatex/sharelatex

2. Resolving CSF Firewall and Docker Bridging Conflicts

By default, CSF disables Docker's automated iptables forwarding rules, cutting off outbound container traffic and external port mapping. Add the following exceptions to /etc/csf/csfpost.sh to restore seamless Docker connectivity:

#!/bin/bash
# Allow bridge network traffic for Docker containers
iptables -A FORWARD -i docker0 -o eth0 -j ACCEPT
iptables -A FORWARD -i eth0 -o docker0 -m state --state RELATED,ESTABLISHED -j ACCEPT
iptables -t nat -A POSTROUTING -s 172.17.0.0/16 -o eth0 -j MASQUERADE

Make /etc/csf/csfpost.sh executable and restart CSF:

chmod +x /etc/csf/csfpost.sh
csf -r

Tuesday, June 11, 2013

Automated Dynamic IP Whitelisting for CSF Firewall Using PHP and Bash

When administering remote Linux production servers protected by ConfigServer Security & Firewall (CSF), dynamic residential IPs frequently get blocked or locked out of management portals. Here is a lightweight, automated mechanism to dynamically whitelist your current IP address simply by visiting a private URL on your server.

Architecture: PHP capture endpoint • Fast-polling background Bash daemon • CSF Perl reload

1. The PHP Endpoint (whatis.php)

Create a secure PHP script in your web root that logs the visitor's remote client IP to a temporary staging file:

<?php
// Protect with an authentication token or secret parameter in production
file_put_contents("/tmp/iplog", $_SERVER["REMOTE_ADDR"]);
echo "IP captured: " . htmlspecialchars($_SERVER["REMOTE_ADDR"]);
?>

2. The Shell Whitelister Daemon (/script/ip)

Create a root shell script to inspect the staging file, update /etc/csf/csf.allow, and reload firewall rules:

#!/bin/bash
i=1
while [ $i -le 10 ]
do
    status=$(cat /tmp/iplog 2>/dev/null)
    if [ -n "$status" ] && [ "$status" != "0" ]; then
        echo "$status" >> /etc/csf/csf.allow
        echo "$status" >> /etc/csf/csf.ignore
        echo "0" > /tmp/iplog
        # Note: Use csf.pl -r inside scripts for reliable Perl-based reload
        /etc/csf/csf.pl -r > /tmp/csf.log 2>&1
    fi
    sleep 5
    (( i++ ))
done

Make the script executable:

chmod +x /script/ip

3. Cronjob Schedule

Add a root crontab entry to execute the daemon once every minute:

* * * * * /script/ip
Implementation Tip: Calling csf -r from non-interactive shell scripts often fails to reload properly. Invoking the underlying Perl script /etc/csf/csf.pl -r ensures firewall tables reload reliably.

How Google Antigravity Solved the Mysterious NVIDIA Sleep Reboot on My Dell Inspiron 7567 (Ubuntu Linux)

If you run modern Ubuntu or Linux on a Dell Inspiron 15 Gaming (7567) or a similar 7th-gen Intel laptop paired with an NVIDIA GeForce GTX ...