ConfigServer Services Blog

New csf v4.26

Changes:

  • New Feature – Country Code to CIDR allow/deny. This feature can allow or deny whole country CIDR ranges. The CIDR blocks are downloaded from http://www.ipdeny.com/ipblocks/. For more information, see CC_ALLOW, CC_DENY and CC_INTERVAL in csf.conf
  • Expanded the dovecot regex to include more login failure permutations
  • Added exe:/var/cpanel/3rdparty/bin/php to csf.pignore on cPanel servers
  • SMTP_ALLOWLOCAL set to 1 on new cPanel installations by default

New csf v4.25

Changes:

  • Fixed bug in csf –grep when CIDRs used in advanced port filters
  • Fixed problems with aborted Server Check Report
  • Fixed position of the lo device rule in the OUTPUT chain which broke SMTP_BLOCK
  • Added new option SMTP_PORTS which is used by SMTP_BLOCK to block all listed ports (not just port 25). This is populated on installation or when TESTING = 1 if an additional port is listed in “WHM > Service Manager > exim on another port”. Otherwise, SMTP_PORTS needs to be updated manually. The default setting contains port 25
  • SMTP_BLOCKs will now log if DROP_IP_LOGGING is enabled

New csf v4.24

Changes:

  • Added workaround for issue with WHM image display in the addon header for cPanel v11.24
  • *Added cPanel v11.24 FTP Anonymous Upload checks in Server Report
  • *Added cPanel v11.24 FTP Cipher Suite checks in Server Report
  • *Added cPanel v11.24 Apache Cipher Suite checks in Server Report
  • *Added cPanel v11.24 Exim Cipher Suite checks in Server Report
  • Added Fedora v8 to the obsolete OS list now that v10 is out
  • Updated dovecot regex in regex.pm for v1.1.6 used by cPanel

* Will only display if cPanel version is >= 11.24

New csf v4.23

Changes:

  • Added skip to connection and process tracking for empty tcp6 connection data
  • Fixed PT_LOAD email output of ps and vmstat

New csf v4.22

Changes:

  • Additional fixes for an issue on VPS servers where temporary block removal from csf.tempban failed

New cmm v1.11

Changes:

  • Modified cmm to remove cPanel process limits when run
  • Modified code to skip orphaned domains in /etc/localdomains