Skip to content
Changes:
Added to RECOMMENDATIONS to still run a regular scan without –ctime [hours] to ensure new scan techniques and exploit signatures are used to check all existing files
Fixed directory creation on installation for unofficial DA plugin
Improved performance of file slurping and therefore scanning
Added new –options [s] that will search for a few common web script installations and report if older than the latest version on record. See documentation for more information
Exploit fingerprint definitions database additions
Changes:
Changed –throttle [num] to prevent throttling triggering a –timemax [secs] timeout
Added detection for some PHP JPEG and TIFF EXIF exploits
Improvements to image and zip file type detection
Exploit fingerprint definitions database additions
Changes:
Modified LF_PERMBLOCK to perform IP lookup on blocked IP
Perform modprobe when using FASTSTART on server boot to ensure iptables modules are loaded
Modified migration detection for particularly old csf installations
Check that TAIL and GREP exist and are executable in UI
Changes:
Improvements to Virtuozzo/OpenVZ system detection where /proc/vz/veinfo does not exist
Added TimeStamp to the top of the scan report
If /etc/csuibuttondisable exists then the UI buttons will revert for those that cannot cope with the themed ones
Changes:
Applied UI changes to inbuilt cse and Reseller UI’s
Improvements to Virtuozzo/OpenVZ system detection where /proc/vz/veinfo does not exist
Added System Check on cPanel servers for disable-security-tokens
If /etc/csuibuttondisable exists then the UI buttons will revert for those that cannot cope with the themed ones
Changes:
Implemented new cxswatch log tail code
UI display changes
Exploit fingerprint definitions database additions
Changes:
Fixed “Deny Server IPs” option in UI
Additional SSHD regex
Enable account tracking for LF_CPANEL login failures to allow for LF_DISTATTACK detection
Ignore Server Check for register_globals for PHP v5.4+
Added new option UI_SSL_VERSION, to allow the setting of the SSL protocol version that the UI server allows
Added window Detach option to UI search system logs
UI display changes
Fixed files permissions issue affecting System Graphs and lfd Graphs in DA
Changes:
Prevent HTML rendering of watch and search system log file output
Changes:
Removed CLUSTER_PORT from sanity checking
Modified changelog to state that HTACCESS_LOG needs to be correct for nginx LF_HTACCESS regexes
Added new UI option to watch (tail) system log files listed in /etc/csf/csf.syslogs
Added new UI option to search (grep) system log files listed in /etc/csf/csf.syslogs
Improvements to “View iptables Log” output in UI
Enable “SSL_honor_cipher_order” for UI IO::Socket::SSL sessions
Changes:
Fixed sanity check for UID_INTERVAL