Server Software and Configuration Services
New csf v5.63
Changes: – Implemented a locking and retry system to try to mitigate an iptables bug when issuing concurrent iptables commands
Changes: – Implemented a locking and retry system to try to mitigate an iptables bug when issuing concurrent iptables commands
Changes: – Added ModSecurity connection dropping to the LF_MODSEC regex – Added new option – ETH6_DEVICE. By adding a device to this option, ip6tables can be configured only on the specified device. Otherwise, ETH_DEVICE and then the default setting will…
Changes: – Improvements to cxs Watch daemon ignore/xtra and new update reloading without restart – Switched to using Sys::Hostname in cxs Watch daemon – Exploit regex definitions database additions – Exploit fingerprint definitions database additions
Changes: – On Debian systems, check for my.cnf in in Server Check – Add missing/changed images in the DA/Webmin installs. For webmin, the csf webmin module will need to be reinstalled – Another fix for LF_NETBLOCK to skip IPv6…
ClamAV 0.97.6 includes minor bug fixes and detection improvements:
Changes: – Switched to using Sys::Hostname to determine hostname as CloudLinux restricts access to /proc/sys/kernel/hostname for some reason
Changes: – Modified POD and UI to show full rather than abbreviated commands – Added new option –template [file]. When using –mail [email] a standard email format is used. To customise this format an email template file can be used…
Changes: – NOTE: If you are using the cxs ModSecurity hook and ModSecurity v2.6, you must now specify the ModSecurity configuration setting SecTmpDir. If you have not set SecTmpDir in your ModSecurity configuration, then you need to add the following…
Changes: – Added new options to include the Spamhaus Extended DROP list. These additional netblocks are included in the main Spamhaus chain. The feature uses LF_SPAMHAUS_EXTENDED and LF_SPAMHAUS_EXTENDED_URL which are enabled by default, but used only if LF_SPAMHAUS is enabled.…
Changes: – Improvements to string detection in –decode ([D]) – Added new advanced PHP decoder for –decode ([D]) – Removed a false-positive fingerprint detection – Exploit regex definitions database additions – Exploit fingerprint definitions database additions