Set scripts (.pl,.cgi,.php,.sh,.py) in /etc/csf/ to chmod 700
Simplified PACKET_FILTER rules for dropping INVALID connection tracking states. This feature now only applies a single rule for incoming INVALID packets
DROP_PF_LOGGING enabled by default on new installs
INVALID added as an option to PS_PORTS so that PACKET_FILTER logs will be ignored by Port Scan Tracking by default, but can be added if desired
Modified ST_ENABLE locking
Regex updates to cater for Plesk 12 – thanks to Marcel Evenson
Fixed issue with temporary allow/deny comment not being parsed correctly when port * specified