BFD Updated Rules, Ban'em Faster, Better (V0.9)

Jun 22, 2008

These new "rules" make BFD ban faster, checks every minute. BFD only checked every 10 minutes and could miss attackers that show up at the right time. Now we keep 10 minutes of IPs, and ban using that list.

I feel that APF and BFD are still the best choices for protecting my server. Cpanel's new "cphulk" feature has a lot more to go to be as good, plus you have total control with BFD where you can add and change rules to suit your needs as they grow, or modify them for particular problems.

The changes I made are based on the latest version of BFD V0.9, you should have that version installed and WORKING ALREADY.

Remember, they are simply shell scripts that define the log file to keep track of and what keywords to trigger on. You can view them with any text reader.

WARNING: These work for me, USE AT YOUR OWN RISK, always make sure you add your current IP in /usr/local/bfd/ignore.hosts (and) /etc/apf/allow_hosts.rules so you don't accidentally ban yourself!

Inside the below tar.gz file are my modified "rules" files for exim, pure-ftpd, rh_imap, rh_pop3, sendmail and sshd. No changes to the BFD V0.9 main program are needed.

You should change the cron job to run BFD every minute, edit this file:
/etc/cron.d/bfd

Change the line in that file to this so it runs every minute:
*/1 * * * * root /usr/local/sbin/bfd -q

I checked the CPU load and since it's reading only a small part of the log file every minute, the CPU load isn't bad, it's done in about 8 seconds on my system. Expect a small rise in load average since it is doing work more often.

The "rules" files are contained in your server directory:
/usr/local/bfd/rules

The "rules" files should be REPLACED with the new ones, if you want to keep the old ones around then MOVE THEM OUT to another directory NOT INSIDE the "rules" directory, or else they will be run when BFD runs.

If you need apache, proftpd or other "rules" then you will have to modify them yourself, otherwise you should move these out of the "rules" DIRECTORY, they will not do much with BFD set to run every minute (unless you modify them yourself). I only modified the rules I needed for my server, feel free to post your own mods here.

OK enough, here's the file:

[url]

(it's also attached to this message, see below)

This file will only be around for a few months on this free upload site. Someone please put it in a good place/mirror and post a link, thanks.

Technical details:

This runs every minute but keeps a list of the last 10 minutes of bad IPs in a file in tmp, trimming the file every minute so only new IPs are saved.

You can see the list of IPs in files such as:
/usr/local/bfd/tmp/.exim
/usr/local/bfd/tmp/.sshd

The marker "----" (four dashes) is used to mark each minute and is ignored by BFD but used to trim the old IPs off the file.

If the number of "----" are more than 10, it trims the top of the file up to the marker every run. If the file doesn't exist it's created.

The exim filter "grep" part was modified slightly because the old one was producing bad data every once and a while. The others are all the default filters that come with V0.9.

(BFD people feel free to add this to the next version update, I consider it GPL)

View 0 Replies


ADVERTISEMENT

Php 4 Faster Than 5

Apr 7, 2008

I've read that php 4 is faster than 5, is this true? I'm not sure which one I should use to host my invision powerboard. It's the only php/mysql site on the server.

View 5 Replies View Related

VPS Faster Than Shared

Mar 9, 2009

I know the assumption is that VPS is faster than shared, but my site currently runs on a shared server with a host that does not oversell, and it runs very fast for a WordPress and gallery site.

I'm certain the shared server is at least a dual CPU monster, and it rarely goes above 5% usage. So if I move this site to a VPS it seems logical to me that it might not be as fast.

View 9 Replies View Related

More RAM = Faster Website

Jun 30, 2008

I just changed hosts, thinking it would be faster. My homepage uses 53MB of RAM. My old host lets me use ini_set to change this (currently have it at 128MB), my new host doesn't (48MB).

So, I've cut some of the functionality of the site to make it work on the new host. Should I upgrade the hosting plan to higher RAM? Given that the site already works reasonably well on the new host, what type of performance boosts could I expect to see by doubling the RAM?

View 14 Replies View Related

Which One Be Propagated Faster

Jan 5, 2007

I am going to upgrade my servers and move all the accounts. Of course DNS IP's will change.

Last time I did this, I just created exactly same DNS on new server (eg. ns11.server.com and ns12.server.com) and updated the IP address of the DNS on the registrar. However it took more than 2 days for some domains to update the new DNS IP address. It was a nightmare.

So my options are:
1) Do the samething as before
2) Create new DNS addresses (eg. ns5.server.com and ns6.server.com) and update the DNS info of all the domains.

View 4 Replies View Related

VPS Host On California Faster For Me

Jun 5, 2008

I live in Hawaii and half my sites serve Hawaii. Webhosts in Hawaii are really expensive. Does it matter where on the mainland US that I host my sites? Would they serve the fastest if I host them in California considering it's the closest to Hawaii?

View 10 Replies View Related

Making Faster Downloads

Apr 17, 2008

I've ordered 1gbit/s port with one my dedicated servers. But I am still unhappy with the speed of download.

I have 2 mbit DSL connection at home and I can download files with 90 kb/s from the server. I also see the same speed on a 100mbit port server. But I can download files from RapidShare with 210 kb/s..

What do you recommend me to do make faster downloads from server-side?

View 12 Replies View Related

Which Would Be Faster? Ram = 128 With DirectAdmin Or 256 With Cpanel

Jul 4, 2007

I have heard that Direct Admin is much faster then cpanel & require much less resources then cpanel... I was just wondering if I get vps with 128 ram with Direct admin on it, would it be better than vps with 256 ram with cpanel installed... I am running 3 websites with almost 10 to 20 users at a time (at max 50).... I like both cpanel & directadmin but was thinking if 128 ram with DirectAdmin can give more speed on 128 then I won't spend more money on 256 with cpanel... If anybody have an opinion then please put it here...

View 14 Replies View Related

Last Longer Or Spin Faster

Jul 28, 2007

In a system with all-in-one solution -- WEB, EMAIL, MySQL, FTP..in a same hard-disk.

Would you prefer a "Last Longer" - SATA2 Enterprise Harddisk (Western Digital or Seagate)
OR
Would you prefer a "Spin Faster" - SATA1 RAPTOR (Western Digital)

View 5 Replies View Related

IIS & ISAPI Redirects...anything Faster Than The GUI

Apr 10, 2007

So I have been reduced, I am a firm *nix Apache user, to using IIS along with ISAPI for redirection at work. Now I can setup the redirection(s) just fine using the GUI, but I am a *nix man and doing this through the GUI is SLOW! That is when it has to be done on 3 servers at a time plus I can only access those servers through a Citrix environment.

And I need to be adding redirects many times a week. Is there any way to setup ISAPI redirects from a command line? Google has offered me nothing.

View 2 Replies View Related

Updated Website

Dec 29, 2007

I recently just started working at a party shop, and being the only one there with a computer at home, they've unloaded a few computer problems on me - most specifically, one dealing with website hosting and all that jazz; An area which i am completely unfamiliar with, so here's hoping that I can understand half the stuff required of me!

A few weeks ago, in collaboration with a company which specializes in website design, they submitted and successfully(?) updated the new coding for the domain (they've kept the same url, just remodeled the site); However recently customers began complaining that the website which they view at home is that of the old one, not the newly updated one.

When viewing the url at the computer which is located at our store (the computer which we used to register and update the website*), we’re able to see the new website; but, viewing the url at an external computer shows the old website.

*I'm not too certain what happened at this step, but apparently they sent the domain hoster their code along with some registration key or something, and it was enough to change the website on the computer at work.

We’re not too certain why this is happening, and any information on measures we could take to resolve this issue would be greatly appreciated. I'm going to take a guess and say that they probably didn't update the website properly, and the website they're viewing at work is the website stored in cache?

View 2 Replies View Related

Top 10 Things To Ensure Faster/Friendlier Support

Mar 27, 2009

I've been working in this industry for 5 years now. Over the years, I've come to realize the little things that customers do that REALLY piss tech support off. This is a guide for customers for 10 things NOT do when contacting their host's technical support team.

This is a repost of what I already posted before the big catastrophe.

Please forgive the brutal honesty. It's for your own good.

1. One ticket per issue.
Emailing your issue to Support, Sales, Billing, Abuse, the owner, each individual tech, and the mayor of your town is not going to get your ticket answered any quicker. Additionally, opening 2, 3, 4, or 10 tickets isn't going to get things done any faster. Seriously - all it will do is irritate the support guy

2. Contact the proper department
If your account is suspended due to non-payment, or your account hasn't yet been setup, or you want to upgrade your account - please don't bother contacting support hoping it'll get done faster. All it will do is slow down their response time to customers that have actual support issues. Billing issues goto Billing. Sales issues goto Sales. Abuse issues goto abuse. Get the picture?

3. Contact support via ONE medium
If you put in a support ticket, don't get on live chat and call too. Trust me - you'll get the same answer on live chat and the phone as you will in the ticket . Same goes for requesting "updates" on your ticket - if your ticket is in queue, wait patiently for a response. If you don't get a timely response, contact the management to complain.

4. Everyone thinks their ticket is CRITICAL
Tech support reps realize that you think your issue is CRITICAL and must be dealt with IMMEDIATELY. But, guess what, so does everyone else that submitted their ticket before you. Your CRITICAL ticket will be answered in the order received after everyone else's CRITICAL ticket has been answered.

5. Do not try to "bump" your ticket
Making continuous replies to your ticket in an event to get a faster response won't work. In fact, in most common helpdesk applications, each reply made rotates the ticket to the bottom of the queue. So really, by bumping your ticket, you're just making yourself wait longer. Not getting service fast enough? Contact the manager of the company!

6. Include all relevant information, but only relevant information
Seriously - we don't care to hear your life story. Submit your ticket with your client ID, domain name, username, password, error messages, steps to reproduce, and other information directly pertinent to your issue. If your website is inaccessible, check http://www.downforeveryoneorjustme.com/ and include your local IP address (from www.whatismyip.com) and a traceroute. That will save you a reply.

7. Just because YOU can't see the website does NOT mean the server is down
So please - don't come shouting at us claiming we're fraudsters and have horrible uptime and demand a credit. Most of the time you will find there is either a firewall issue or a routing issue - or scheduled maintenance. Check http://www.downforeveryoneorjustme.com/ and your host's forums before screaming at them.

8. Avoid live chat & phone support
Unless you have a quick question, live chat and phone support are probably not going to be good avenues. Chances are, if your issue requires someone to login to the server to investigate, you're just going to be escalated to a support ticket. Instead of whining about how long the support ticket will take to get answered - just get it in queue. Figure if you spend 5-10 minutes on the phone only for them to tell you that you need to submit a ticket - that's 5-10 minutes that your ticket could have been looked into. Think about it. If you do call or chat - be brief - and keep in mind we have other customers to help.

9. We don't make the rules
If you don't like a company's policies or procedures, don't complain to your support tech about it. They don't make the rules, they just follow them. If you want a change, contact the management of the company.

10. Do NOT disrespect or mistreat support people
If you curse at us, disrespect us, or mistreat us in any way - you can almost be guaranteed that we won't be going out of our way to help you beyond the minimum. By polite, cordial, and courteous to your support tech and it will get you a LOT farther. We don't get paid enough to deal with people's abuse.

11 (Free bonus ). The amount of money you pay does not matter to us
Seriously - the fact that you pay us $9.95/month does not matter to us. We're going to provide you with the same support that we provide somebody that's paying $3.95/month or $99.95/month. Don't expect better treatment based on the amount of money you pay.

View 14 Replies View Related

Make Site Load Faster Other Than Replication?

May 7, 2008

what can make site load faster other than replication

(well lets assume that design wise it is ok and doesnt content heavy contents...)


i have heard that increasing networking speed at the server level can make site much faster...
is it true..?

is there any tweak bandwidth wise...

suppose we get 1tb bandwidth per month compared to 100gb ...
will that make site faster...

we want to host a photogalley site...which is fast or images are shown in faster way....

View 8 Replies View Related

Downloading Files From My Site/server Faster

Dec 22, 2008

Ive been recieving some complaints/feedback that the download speed on my site is too slow.

I test it myself and at night i download at about 60k/s, late at night, mornings its around 300kb/s

Im guessing my site is basically getting high traffic and load issues in the evenings.

(average daily bandwidth is around 200-300gb)

So basically i need to rectify this pronto.

What are the possible solutions?

i thought if i bought a second cheaper server that could step in when the load gets too much for my primary server this could help out the speeds.

Am i correct, are there cheaper ways of speeding things up?

View 10 Replies View Related

Top 10 Things To Ensure Faster/Friendlier Support

Dec 22, 2008

I've been working in this industry for 5 years now. Over the years, I've come to realize the little things that customers do that REALLY piss tech support off. This is a guide for customers for 10 things NOT do when contacting their host's technical support team.

Please forgive the brutal honesty. It's for your own good.1. One ticket per issue.

Emailing your issue to Support, Sales, Billing, Abuse, the owner, each individual tech, and the mayor of your town is not going to get your ticket answered any quicker.

Additionally, opening 2, 3, 4, or 10 tickets isn't going to get things done any faster.

Seriously - all it will do is irritate the support guy 2. Contact the proper department
If your account is suspended due to non-payment, or your account hasn't yet been setup, or you want to upgrade your account - please don't bother contacting support hoping it'll get done faster. All it will do is slow down their response time to customers that have actual support issues. Billing issues goto Billing. Sales issues goto Sales. Abuse issues goto abuse. Get the picture?3. Contact support via ONE medium

If you put in a support ticket, don't get on live chat and call too. Trust me - you'll get the same answer on live chat and the phone as you will in the ticket . Same goes for requesting "updates" on your ticket - if your ticket is in queue, wait patiently for a response. If you don't get a timely response, contact the management to complain.4. Everyone thinks their ticket is CRITICAL

Tech support reps realize that you think your issue is CRITICAL and must be dealt with IMMEDIATELY. But, guess what, so does everyone else that submitted their ticket before you. Your CRITICAL ticket will be answered in the order received after everyone else's CRITICAL ticket has been answered.5. Do not try to "bump" your ticket

Making continuous replies to your ticket in an event to get a faster response won't work. In fact, in most common helpdesk applications, each reply made rotates the ticket to the bottom of the queue. So really, by bumping your ticket, you're just making yourself wait longer. Not getting service fast enough? Contact the manager of the company!6. Include all relevant information, but only relevant information

Seriously - we don't care to hear your life story. Submit your ticket with your client ID, domain name, username, password, error messages, steps to reproduce, and other information directly pertinent to your issue. If your website is inaccessible, check [url] and include your local IP address (from www.whatismyip.com) and a traceroute. That will save you a reply.7. Just because YOU can't see the website does NOT mean the server is down

So please - don't come shouting at us claiming we're fraudsters and have horrible uptime and demand a credit. Most of the time you will find there is either a firewall issue or a routing issue - or scheduled maintenance. Check [url]and your host's forums before screaming at them.8. Avoid live chat

View 10 Replies View Related

Stats Not Updating In CPanel But WHM Says They Were Updated

Jun 24, 2008

I can't seem to solve, perhaps you could give me some pointers or tips on how to fix this.

All the cPanel stats programs (Awstats etc..) haven't been updated since the 17th June but when I login to WHM it says the stats have been updated (within the past 24 hours).

On the 17th June I moved my hosting operations from the USA to the UK onto a new webserver.

How can I make sure these statistic programs are updated and shown from cPanel, even though I can tell it to update via SSH (completes) and claims in WHM with no problems (updated with in 24 hours), the new stats still fail to appear.

View 5 Replies View Related

What Server Programs Need To Be Updated Regularly

Jun 12, 2008

- Cpanel (I do this everytime security releases are out)

- Firewall (Anyone know what the latest version for APF is, or how to figure it out?)

I know how to figure out what version I have, just not the latest release.

View 6 Replies View Related

Disk Usage Not Being Updated In WHM & CPanel

Jul 12, 2008

Running the latest version of WHM 11.23.2 & cPanel 11.23.4-C26138

So far tried the following commands:

/scripts/initquotas
/scripts/resetquotas
/scripts/fixquotas

the above commands done nothing - really waste of time!

The cPanel asked my to contact my VPS provider and ask them to reinitialize quotas for your VE and possibly check further into the node to correct the issue. As for VPS provider they did some tests & told me that they "fixed" & can't find any issues on the node, but the problem is still exists.

asked by VPS provider to do:
/scripts/fixquotas
restart VPS
/scripts/upcp --force

how to fix cPanel bug?

The attached image are proof of Disk usage not being updated in WHM & cPanel, as this account contains 17.6 MB (18,472,960 bytes).

View 2 Replies View Related

Plesk 12.x / Linux :: Doesn't Want To Be Updated

Jan 27, 2015

When loggin into the Plesk, it says:Failed to update Plesk. To solve this problem, you can send the update log to Parallels support.View the update logs (Jan 23, 2015).Copy the logs to your computer before you close this message. To close this message, clickhere.How to proceed with that? Whom should I send this log-file?

View 8 Replies View Related

Make Downloading Files From My Site/server Faster

Dec 22, 2008

Ive been recieving some complaints/feedback that the download speed on my site is too slow.

I test it myself and at night i download at about 60k/s, late at night, mornings its around 300kb/s

Im guessing my site is basically getting high traffic and load issues in the evenings. (average daily bandwidth is around 200-300gb)

So basically i need to rectify this pronto.

What are the possible solutions?

i thought if i bought a second cheaper server that could step in when the load gets too much for my primary server this could help out the speeds.

Am i correct, are there cheaper ways of speeding things up?

View 14 Replies View Related

LXadmin Main Server - Best Way To Get My Secondary DNS Updated

Jun 27, 2008

Just moved to a lxadmin based system from my current plesk system and I have a dilema

Configuration
Server 1: Main Web/CP/Primary DNS/Mail/etc
Server 2: Secondary DNS/Backup Mail forwarding

With Plesk I generated a transfer file from named.conf (plesk runs bind/named for dns) sent that over to server 2 a couple of times a day.

Problem is I've converted lxadmin to run with bind instead and named.conf only contains an include to lxadmin.named.conf and this is empty. So where does lxadmin put its conf files for named?

I'm not restricted to using named, I'd use djbdns if there was an equally simple way of transferring the zones across to server 2

View 1 Replies View Related

Plesk 12.x / Linux :: Updated From 11.5 - Outgoing Spam Not Working

Jul 2, 2014

I just did the update to 12.0.18 #6 and everything seemed to go pretty well. One feature we were really interested in was the Outgoing Spam Filter. Unfortunately, the error I see when I go to that feature reads, "Protection : Not active. There are some problems that prevent the service from being started."

When I Google that error, I'm brought to some KB articles but they are all for the older Outgoing Spam Filter that you need a license key for. I don't believe that is the case any more - if it is, I don't know where to get the key. I will say point out I'm a bit of a Linux novice (we are running CentOS 6.5 on this server), so I'm not really sure where to look....

View 4 Replies View Related

Plesk 12.x / Linux :: How To Disable Xcache Being Installed Or Updated Automatically

Apr 29, 2015

I wanted to permanently get rid of xcache from my Plesk 12 as some softwares we are using crashes if xcache is installed or enabled on server.

At present I am doing yum remove to remove xcache php extension from server which is allowing our software to work but after couple of days, its coming back again.

I found traces in autoinstaller log, but I am not sure how to completely disable only xcache for all php versions installed on server i.e. PHP 5.3, 5.4, 5.5

View 6 Replies View Related

Plesk 11.x / Linux :: New Mailbox Variable From (Mail Account Updated) Event

Jan 15, 2015

PRODUCT, VERSION, MICROUPDATE, OPERATING SYSTEM, ARCHITECTURE
Parallels Plesk, 11.5, .30_build115130819.13, Debian 7.0, Intel 64bit

PROBLEM DESCRIPTION
When triggering the events 'Mail account created' or 'Mail account modified' the returned variable NEW_MAILBOX will always state TRUE regardless of the mailbox option being ticked or not ticked on the 'New mail account' option located on the 'Mail' tab of a subscription.

STEPS TO REPRODUCE
1: Log in to plesk.
2. Select 'Tools & Settings'
3: Select 'Event Manager'
4: Select 'Add New Event Handler'
5: Select Event 'Mail account updated'
6: Enter in '/usr/bin/php /root/scripts/dbmail/mail_mod.php' to the Command box.

[Code] ....

ACTUAL RESULT

[NEW_MAILBOX] => true

EXPECTED RESULT

[NEW_MAILBOX] => false

ANY ADDITIONAL INFORMATION

I submitted this with parallels support and they stated that the variable NEW_MAILBOX will always return as TRUE regardless of if the mailbox option is ticked or not. They also stated the NEW_MAILBOX variable will be true regardless of any action taken on the panel with mail accounts.
The actual documentation on this variable is very sparse

Component name/description Old component value New component value
Mailbox old_mailbox new_mailbox

We previously had some code that would trigger on this variable and would create a mail account on our mail server with or without a mailbox.

if (!strcmp(getenv('NEW_MAILBOX'),"true") && !strcmp(getenv('OLD_MAILBOX'),"false")){
//Create a mailbox on the external mail service
}
if (!strcmp(getenv('NEW_MAILBOX'),"false") && !strcmp(getenv('OLD_MAILBOX'),"true")){
//Create a mail forwarder on the external mail service
}

At some point this variable has stopped working with newer versions of plesk. Having a variable that is always true regardless of what is done when creating a mail account seems pointless and requesting a new feature that was already there in older versions doesnt seem like something that should be requested on a new feature request.

QUESTION: Is there anyway to get this functionality restored other than requesting it gets re added via [URL] ....

View 2 Replies View Related

Name Servers Have Updated, But Site Still Points To Old Host! (was "")

Mar 22, 2007

I updated my name servers to reflect my new web host two days ago. The name servers have updated, but the site is still pointing to the old host!

I emailed my host about this and they told me to email my registrar. The host says the domain is registered with the new name servers but these name servers are registered with IPs outside of their network. I'm confused and have never had this problem before when changing DNS.

View 3 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved