csf

New csf v2.62

Changes:

  • Fixed CIDR support issue with csf.ignore only recognising the first listed entry

New csf v2.61

Changes:

  • Fixed problem (that happened on some OS’s) with lfd not being killed by /etc/init.d/lfd

New csf v2.60

Changes and additional OS support:

  • Added log file locations to csf.conf
  • openSUSE v10 compatible (generic)
  • Debian v3.1 (sarge) compatible (generic)
  • Unbuntu v6.06 LTS compatible (generic)
  • Added installation check for the LWP (libwww-perl) perl module
  • Ran spell checker against the readme.txt file

New csf v2.57

Changes:

  • New feature: WHM UI mod_security v1 display last X entries in the audit_log
  • New feature: WHM UI mod_security v1 edit files or directories in /usr/local/apache/conf/ that are prefixed with modsec or mod_sec
  • Tweaked the pre-configured Firewall Security Level settings

New csf v2.55

Changes:

  • Fix to to support current EDGE in csf WHM UI

New csf v2.54

Changes:

  • Tightened the mod_security v1 regex after the changes in v2.52

New csf v2.52

Changes:

  • Separated the log file regex’s into regex.pm for those feeling brave to tailor them for non-cPanel servers
  • Unified installer for cPanel and non-cPanel installations – so that only install.sh needs to be run (checks for the existence of /usr/local/cpanel/version If you install on a server intending to use cPanel before cPanel is installed, run the install.cpanel.sh script instead
  • Added mod_security v2 regex when running Apache2 to lfd
  • Added [iptext] tag for connectiontracking.txt to list all the connections of an offending IP. Add this manually for existing installations

New csf v2.51

This is a major landmark for us in the development of csf and lfd which provides installation of the firewall and daemon onto non-cPanel generic Linux distributions:

  • Major Enhancement: csf+lfd can now be installed and used on a generic Linux OS without cPanel using install.generic.sh – see readme.txt for more information
  • PF INVDROP entries made bi-directional if PF logging enabled (reduces the number of INVDROP LOG rules by half)
  • Fixed Process Tracking throttle control to correctly use PT_INTERVAL

New csf v2.50

Changes:

  • Removed option ALLOW_RES_PORTS from new installs, setting is ignored
  • Check for LF at the end of form data for files edited through the WHM UI and append one if omitted
  • Following the changes in 2.48 the LOGDROP chain doesn’t distinguish between incoming and outgoing blocks. So, LOGDROP has now been split into LOGDROPIN and LOGDROPOUT

New csf v2.49

Changes:

  • Fixed issue if ETH_DEVICE was set and from changes in 2.48