jim.thornton
Verified User
- Joined
- Jan 1, 2008
- Messages
- 334
I've installed CSF & LFD and I really like it compared to the old APF & BFD setup I had on my other vps. That said, I'm noticing there are some attacks which DA is warning me of but CSF is not picking up on. Here is one:
It is the pure-ftpd1 filter in DA that is catching the attack, but CSF is missing it.
I've noticed the pattern is a brute force attack using a suspected username for 14 times, then switch usernames. This happened for 50 attempts. You would think that with 50 attempts that it must have been blocked by CSF/LFD but the IP has not been added to the IP list for some reason.
How can I ensure that CSF will pick this up?
It is the pure-ftpd1 filter in DA that is catching the attack, but CSF is missing it.
I've noticed the pattern is a brute force attack using a suspected username for 14 times, then switch usernames. This happened for 50 attempts. You would think that with 50 attempts that it must have been blocked by CSF/LFD but the IP has not been added to the IP list for some reason.
How can I ensure that CSF will pick this up?