My Experience With Liquid Web.

Jul 31, 2007

I signed up with liquidweb 1 month ago. I am having their 50 dollar vps account.

why i pick liquid web?
I searched on WHT, i see its highly recommanded by some users, its bit expensive than others, but for me , money is not big deal, i want to have stable server.

Here's my experience with them.

1. Dont trust their sale person 100%.
my site was hosted at dreamhost, i talked to one of liquidweb sale person. I asked him if some1 at liquidweb can help me to move my files over from dreamhost to my new vps account. I never use vps before, have no clue how to do it. he said its easy, we can help you.

Acutally, they cannot do that. later, I emailed them asking for help, they emailed me back said if dreamhost using cpanel, its easy blah blah blah...., but dreamhost is not using it, and they cann't do anything.

fortunately, my site is small, and i just reupload all the files, and dump the database, my problem sovlved. but if you plan to purchase vps from liquidweb, and got questions to ask, you should double check with their tech support team, they know much better than those guys in sale department.

2. how's their support? answer is great and sux
Sux. take forever for them to reply my emails. On average is 10-12hrs. oh well, i cannot blame on them cause when you submit your ticket they said they will get back to you in 24-48 hrs ( dont remember exact time).

But, I got really pissed off. first, they didnt give me the complete answer. I email they "is imagemagick installed? if so,whats the path to imagemagick command? I got answer, said yes, its installed, its version xxxx. but didnt tell me the path, i got to email them again, and wait another 10-12 hr. I dont mind to wait, i know those guys are busy,but I got to email them twice for same question. that pissed me off.

another thing is when they email you back, they assume you already know something. everytime, i emailed them i said I just swtich from dreamhost to liquidweb, never use vps before, i am newbie of vps, please guide me through hwo to set DNS step by step. and they always give me short answer. I m still clueless hwo to do it. I got to email 5-6 times on this stupid question.

How do I got my problem sovled.
I called them, I know they have great phone support, but I was on the biz trip, I am in asia, coudlnt' make any phone call. I got so pissed off by their email support, and installed skype and called them. (btw only 2 cents / min for international long distant, its cheap), I called them, and one indian guy picked up the call, and got my problem solved rite away.

Ok, if you have any problems , dont not email liquidweb, cuz, it sux, they cannot get your problem sovled on email, call them, those guys on the phone are great, they know how to get your problem solved.

Speed and uptime
uptime, i think its good, but i dont really know to test it, any good free 3rd party appliation, i can use to check the uptime?

speed, its ok, I am in china now, it is slow. i think its much faster you r from US and Euro, I will go back to NJ next month, I will check after I get back.

www.johnqin.com
this is my blog, let me know how fast to load it, and where you test it.

View 14 Replies


ADVERTISEMENT

Liquid Web TOS

Oct 25, 2009

I wonder in Liquid Web's TOS is talks about not being able to distribute things that are not your copyright. I understand if this simply means "no piracy," but this wording could apply to video sharing sites where users post their own copyrighted work. Would we then not be able to host with Liquid Web because our users are posting their copyrighted works and we do not claim copyright on their works? The users agree by signing up and posting a video that they are allowing it to be distributed on the site, so this should be fine. I guess the lack of DMCA information or clarification on Liquid Web makes me wonder how they handle video sharing sites with legal copyrighted works being shared by the copyright holders (though they are not the direct Liquid Web user). I may be over thinking this, but I have had other hosts have issues (mainly because I believe it was shared accounts and they did not want their oversold servers to get that much traffic, so it may not be an issue with Liquid Web). Does anyone here have a video sharing site hosted with Liquid Web? If so, if you they ever received a copyright infringement complaint about a video on your site did they handle it professionally as the DMCA requires or hastily suspend your account?

View 8 Replies View Related

Thanks To Liquid Web

Aug 10, 2008

I just wanted to give my thanks to the guys/gals at Liquid Web for they're help in getting my VPS setup and ready.

I've only been with them for 5 days, which I know isn't very long at all but for a complete newbie to the VPS scene (I like to try and run before I can walk), they're support has been second to none.

All tickets and request have been dealt with swiftly and professionally and I certainly couldn't ask for anymore from these guys.

I wasn't on planning on spending $50 a month for a VPS but I think I will carry on with these guys as they have proven they are more than worth it.

View 6 Replies View Related

Liquid VPS

Nov 2, 2008

I asked liquid web to backup my complete vps account. They mentioned to me that I could not remotely backup my account. And then asked for them to send a backedup file. They said it was 4gig in size.

View 9 Replies View Related

Liquid Web Review ...

Oct 20, 2009

Background
Well, my first venture into VPS did not go as smoothly as anticipated. I originally signed up for the VPS1024 at Wired Tree on special offer and although setup was fast and extremely smooth and ticket responses were extremely fast and helpful, they failed on one fundament - security.

A hacker managed to get into my WHM (on three occasions) and Grove Portal at Wired Tree (on numerous occasions) and deleted my site through WHM as well as messed up WHM settings. Although Wired Tree did their best and did help with my problems, security flaws (on my behalf perhaps), I felt it would be best to join another VPS provider.

Liquid Web
So after browsing WHT and the VPS section for offers, I eventually decided to get an account at Liquid Web, what with their glowing reputation.

Sign-Up and Account Activation
Signing up was painless and after receiving a telephone call from their sales team to confirm the order, I received my VPS account info on Monday morning gone via email.

Security
The main concern was making sure I secured WHM as best I could from the start as I did not want my WHM hacked into again. It was suggested by myself that we protect WHM to only allow IPs I provided to access WHM. This was then set up within a few hours by their technician. Now the support ticket at the end was brilliant. These guys explain what they have done and how they have done it - I've never had this kind of response from a provider before. WHM was well and truly secure and was done in a prompt and highly effective manner.

Support Tickets
You may have read my earlier post where I had to wait 42 minutes to receive a response to a support ticket. Well, prior to this, responses were extremely fast to numerous support tickets I did post and it was only this isolated time where they failed to mimic their 30-minute response SLA and so were forgiven as the work they carried out in securing the server, installing GD and Imagick and generally taking the time to make sure I was happy at all times whilst communicating with them over these tickets was way and beyond the call of duty for me.

What I will say though is that it would have been good to receive a response when I was asking for progress of a ticket. I had to post two times before I got an answer and it would have been good just to say "we are working on this for you" as a sign of courtesy and acknowledgement of my response to a ticket for an update.

Well, so far so good. Its only been 3 days with LW but I think I have found a great provider and no disrepect to Wired Tree but I think LW have an edge in terms of their technicians and the knowledge based on tickets I posted at both hosts for info. You just feel the LW techies are more knowledgeable in the way they go about working and responding to tickets.

View 7 Replies View Related

Liquid Web Support

May 19, 2009

I've got give LW some props.

I was at a crossroads on my server running php 4x and needed to be able to run 5 and allow the sites using 4 to still run it. I read about how to do it but would of totally screwed it up.

LW support came to the rescue, installed both the 4 and 5 and now I can select the php version to run from the accounts cpanel.

Took a while to work through it but it's up and running and I'm a happy camper.

That's why I've had my server with them going on 3 years now.

View 8 Replies View Related

Liquid Web Review ....

Jan 15, 2009

I got one server with them for about half a year now (360 dollars a month). I'm very please with their service including the network, and support. They are 100% fully managed. I have never had a downtime. E-mails are always responded very quickly and fast. I sent in atleast 30 e-mails so far. Real humans, not some crappy automated response I get from a lot of services out there.

The hardware is nice, I'm able to support like 20k visitors per day and about 30-100gb of bandwidth per day fine on one machine. Large forums, 2million + posts, and large sites that do a lot of bandwidth I guess.

Also I have had some billing problems aka, money problems, my own fault and they usually seem to understand and give me a slight break (last couple of months)
I'm happy with their service and hope to continue to work with them.

View 7 Replies View Related

Liquid Web, A Review

Aug 29, 2008

I have been with Liquid Web for several months. I propose to give my experiences here, the good and the bad. Hopefully others will join in the discussion.

View 14 Replies View Related

Liquid Web Accolades

May 15, 2008

Sometimes I feel compelled to reward excellence, and this is one of those times. We have 22 dedicated servers, 18 of them at Liquid Web. We have been in business for over 10 years and have seen all kinds of support levels, with various server providers. Liquid Web has, time an time again, proved to be the best server provider for us, bar none.

This week in particular they have gone way beyond our expectations, and provided us with personal, one on one support that truly is outstanding..

Some companies have come close,from time to time, but none have reached the level of excellence that Liquid Web has for us. They simply are the best, in our eyes, and readers of this post who are looking for a GREAT company to use for VPS's or dedicated servers.. need look no furhter.

View 0 Replies View Related

Anyone Used Liquid Web For Hosting

Jul 31, 2008

I'm thinking of signing up for a Liquid Web Linux VPS Basic account.

I wonder if any of you have experience using this web host - especially if you've used this kind of account.

If so, I'd be really interested to know your impressions / feedback.

View 6 Replies View Related

Liquid Web Now Charging For Using Their DNS

Jun 19, 2008

I found out that now LiquidWeb is charging $15 per domain for using their name servers.

That's right. To use their name servers, you need to pay $15 for EACH and EVERY domain name.

When I first joined I talked to support because I needed a solution that used an anonymous domain server and they said that they could do it with no problem. (We're talking about under 100 domains total)

Now that all my servers are moved there, they screw it all up by charging $15 per domain.

I HIGHLY Recommend staying away from this company until they fix this issue.

I have private nameservers but the whole fact of me signing up with them was the fact that they could provide name servers.

The worst part is that there was no notice, no email, nothing notifying me of this change. It just happened one day.

I'll be posting on my blog (sig) and recommending all the people I have referred don't use their services.

View 14 Replies View Related

Liquid Web Vs. PowerVPS

May 18, 2008

A partner and I are in the beginning stages of consolidating our website operations.

I have a managed dedicated server account with Liquid Web whom I am extremely happy with. I have been with them for about 4 years and have nothing but good experiences with them. They have always been there for me.

My partner is with PowerVPS. He is just as happy with them as I am with Liquid Web and has nothing but good things to say about them and their services.

With that said, we only need one. I have compared the plans and prices for fully managed dedicated servers on both sites and it does appear that Liquid Web is slightly more expensive between the two for similar specs. However, the most important issue with me (as well as my partner) is not price...but the level of support we get for the price.

What other factors can any of you provide about either Liquid Web or PowerVPS that we may have overlooked in the comparison process?

View 12 Replies View Related

Liquid Web Vs Colo4Dallas

Feb 10, 2007

I want the absolute best quality possible, Im open to other providers also

ips and about 5-10 servers tower based

1-5mbps

I honestly cant decide Ive used both of the above and am torn between this

View 14 Replies View Related

Liquid Web Support Team

Oct 19, 2009

I am trying to get into contact with LW's support team but I have not had a response to a support ticket I raised 40 minutes ago. Just wondering if anyone else is having problems corresponding with their support team at the moment?

View 13 Replies View Related

Load Spike On VPS (Liquid Web)

Sep 28, 2008

I just moved my site from other VPS hosting into Liquid Web for around 2weeks now. I choose the VPS1 package with WHT promotion..

First impression, I do really satisfied with the VPS performance (server load average bellow 1), also the support team. All of my eMail was replied pretty fast in under 15minutes.

But, I do have one problem. Please note that I'm not complaining here.. I just want to ask other user of LW or maybe other hosting.

Almost everyday (well, I think it is).. I got a load spike on my VPS. It's always around midnight (GMT -5). Based on LW staff have informed me, it's because of the main node full backup process, which is can't be altered. The load spike make my site sometimes temporary can't be accessed, because the server load might become above 5, and the highest one is around 28.

Do WHT user has any similar issue like me? Any solution or suggestion I can take to minimize the effect of the backup process?

View 13 Replies View Related

Has Liquid Web Support Went Downhill

Jan 16, 2008

I've been with Liquid Web for around 2 years after reading on these forums that they were good.

Problems did not start until this year. On the 7th I raised a critical ticket - that pretty much the only site I have on a dedicated server was giving me server 500 errors when trying to do necessary and basic things with Movable Type.

Liquid Web persuaded me to take it up with the makers of Movable Type which I did (Six Apart). Six Apart have now had a look and bounced it back saying it appears to be a server problem and have fairly isolated the problem area or so it seems.

Between the 7th and now I raised a few tickets complaining that they were not fixing a critical ticket. That did not seem to help too much.

The problem then got worse around half a week back - I can not even log into Movable Type without the server core dumping.

They told me to have Six Apart look at the cores and Six Apart did. They said it was a server problem. I bounced that back to Liquid Web this over 10 hours ago - raised another priority ticket and have not heard anything.

Now I call them on an international call - and I've been on old - wait for it - 45 minutes and counting - WAITING on a manager since nobody can tell me straight what the situation is!

This is not my idea of heroic support by a long shot.

Open a P1 and going on 10 days later no solution, nobody knows what is happening and 45+ minute hold times (still counting will hang up if it hits 60 minutes) and no proper responses to emails. NOT GOOD ENOUGH.

And so liquid web know this is for real - the original ticket number is 890340.

View 14 Replies View Related

1and1 Vs Liquid Web Vs ServerBeach

May 1, 2008

Currently hosted with hostway but i am thinking of moving

i want a windows server for sure either 03 or 08
and i don't need managed really

i was looking at 1&1
because they have a windows vps for only 29.00 a month

but i seen liquid web's offering in the offer section
and i have noticed they have not changed their offers in months are there any new offers and is liquidweb good

and serverbeach a friend told me about but i am wondering should i get a full server and they charge 20.00 more for windows

i run a blog about gun rights & nra stuff and i get about 100 visitors a month
also please don't recommend shared hosting because i don't want to check my site one day to see the word suspened so either vps or dedi

and this may sound stupid but can you use a windows server like a computer like play movies and music and stuff using remote asst?

View 6 Replies View Related

Managed Hosting (Liquid Web VS Rackspace)

Jan 27, 2008

For reliable managed hosting, with some research, I can find...

Liquid Web
Rackspace

It seems like Liquid Web is definitely the bang for the bucks.. but it also makes me think if it's too good to be true. I feel Rackspace is more "professional" and they're more "high-end". But I definitely love the pricing from LiquidWeb. for the same price, I can get a quad core + 4GB from LiquidWeb, and maybe an AMD dual-core + 1GB from Rackspace..

My question is : Do LiquidWeb and Rackspace offer the same kind of "managed services"? Rackspace told me that they would give me an account manager which makes me feel more personalized. but I also had a live chat with LiquidWeb and the sales kept marketing the "Heroic support"

Let me give you some statistics of my site

Nature : E-commerce
Target : UK/Europe
Daily Visitor : 7000-13000
App : PHP + MySQL

View 9 Replies View Related

My Review Of Liquid Web VPS After One Year, It Is All Good

Nov 10, 2008

I have promised the good guys at Liquid Web which is the excellent host for my real estate web-site Las Vega Homes, Condos, Land and Commercial Real Estate to write a review about them after being with them for a year.I chose Liquid Web after having a bad experience with my previous host Aplus.net. I lost a PR4 Blog due to the fact that my database got corrupted and couldn’t be restored; I had more than 40 trouble tickets in six month most of which did not get fixed. I had a one year contract with Aplus.net which I terminated in six month and never got my money back. Now about Liquid Web and their heroic support, they are not kidding, the support is exemplary. While a good hosting company is supposed to keep away intruders, it can’t and should not keep the web-site owner out; I have repeatedly brought my web-site, blog and forum down due to inexperience only to have them restored in 1minte-couple of hours.I have never had to Waite more than 20 seconds to talk to a tech and they have never failed to fix the problem quickly and I am taking about a minimum of 50 calls to Liquid Web, they had to guide me through installing my web-site which they did with distinction.Liquid Web provides their customers with many add-ons that you can install with one click, I have found them helpful and have used many of the add-ons to make my web-site better.In more than one year with Liquid Web I have nothing but praise for Liquid Web and recommend them without reservation to all. I really like these Lansing, Michigan guys. Their tech center is in Michigan and their customers are not transferred to some Asian Country where the tech doesn’t have any idea about what you are talking about.

View 2 Replies View Related

My Review Of Liquid Web’s Heroic Support

Oct 17, 2007

Due to my endless problems with my current host Aplus.net I purchased a VPS1 Account from Liquid Web. Liquid Web calls their support heroic and these guys are my heroes. I told the sales staff that I have had no experience running servers and would need a whole lot of hand holding to set up my accounts and get them running, I was promised their help and boy do they deliver. All my calls have been answered promptly, kindly and efficiently by knowledgeable support staff that helped resolve my problems as we were talking on the phone. I chose Liquid Web by researching Web hosting talk’s forum and am very happy with my choice. Kudos for Web hosting talk and Liquid Web.

View 2 Replies View Related

Air Cooling Versus Liquid Cooling

Mar 15, 2008

I seem to have gone over this a hundred times, but wanted to get feedback from the community. Has anyone out there been able to really make liquid cooling work in their data center considering the additional space utilization and expensive price point.

We've found that liquid cooling vastly more expensive than what we are doing and am curious what some out there might be doing.

For us we've found that high density air cooling (top down, and capped hot/cold row configuration, and overhead air extraction) can get us to a max density of about 10 kW per rack. We use a chilled water system for the additional HVAC needed to get us above the standard 5 kW max, but this is for the air handlers themselves and not chilled water for the in row rack cooling. The problem is the in row chilled water cooling makes us lose a cabinet of space for every cabinet of higher density. For this to work (simple situation) we would need to attain rack densities of at least 20 kW given the loss of floor space.

We use APC Cabinets and infrastructure and even they have said if you try and get about 20 kW with the liquid cooling it becomes problematic. Given these governing characteristics in addition to the overwhelming cost, is anyone out there actually pursuing this in a colocation environment. To me it just doesn't seem to make sense.

Perhaps the cost needs to come down, but even then what are you gaining if it is a 1 for 1 trade off.

View 12 Replies View Related

VPS.net Experience

Apr 8, 2009

I thought I would try the new "cloud" VPS service that WestHost is using to handle all their VPS customers now.

First, if you have a billing issue, expect at least a two day response time. I have had two questions for the billing department. The first was handled in two days with great apologies from the responder on the length of time it took to get back to me. I sent a followup ticket to the same billing department -- that was two days ago and still no response. So obviously, the apology was not genuine or they wouldn't have let it happen again.

Just wanted to make sure everyone understands that:

1) VPS.net has no refund policy in place. No refunds. I asked for one only one day after signing up, and the response is no refunds period.

2) My other hosting experiences allowed me to keep the same base price I signed up for as long as I maintained the hosting account with them. Not VPS.net. Pricing will change at their whim. If you sign up in April, you will receive a huge increase in May. Yeah, they say they "may" have some coupons or something in the future, but hey -- how can you budget your hosting expenses if you don't know what they will be exactly?

I have had accounts with a lot of hosting companies in my many years in this industry, but none as uncustomer friendly as VPS.net -- and its such a shame since their shared hosting sister company -- WestHost -- is famous for their customer service and friendliness.

View 8 Replies View Related

My Experience With M6.net

May 7, 2008

This is a lesson for everyone, regardless of the type of hosting you're looking for, ALWAYS do your homework first!

I'm a bit embarrassed to admit it, but in March I signed up with a hosting company based solely on the claims on their website, and their wonderful presales responses to my questions. The company is M6.net.

It started off well enough, sales responded to my list of about 20 questions, and I received my reply during the weekend, which impressed me because I thought I was going to wait until the following Monday to hear back from them. I signed up for their Designer plan, which offers 200gb storage, and 1.2tb of bandwidth, with a max of 17 websites.

I signed up for the account and waited. No account setup confirmation email, nothing. So I submitted a support ticket, and it was resolved quickly. So I'm on my way now. I'm a .Net developer, so the first thing I notice is that .Net is disabled on my account. So I submit a support ticket, it was resolved within an hour.

So now I go about checking on all the other things that are supposed to be included with the account, one of which was smartermail. It was setup using hoarde. So I submit a support ticket. Along the way, there were 3 or 4 other things that I noticed that weren't setup right and needed to be corrected, so I submitted support tickets. This was all on day 1.
Unlike the first 2 issues, rather than hearing that it's resolved, for all my subsequent tickets I get a response telling me that my issue has been escalated to level3. I don't know what that means because there's no explanation included, but I figure it must mean that my tickets are important.

I don't hear anything back the first day, which is acceptable, because my requests obviously require more attention than my first tickets. So the next day (day 2), I submit another ticket inquiring about the status of all my outstanding tickets. I get a reply telling me that they are working on them.

All of day 2 passes with no resolution on what should be fairly simple fixes. Day 3 rolls around, and that's when I started getting annoyed. I submitted, you guessed it, a support ticket asking for a status, and I get the same reply, "they are working on them". At this point I'm getting really irritated so I decided to call them to see what was going on.

This was where I started to see the light. A man answered the phone, I could barely understand him because he had a heavy accent (which is no problem in and of itself) but there was also a lot of background noise that sounded like a tv. He answered and mumbled a company name that I could not understand, but it was not "M6", when I replied to him "Oh, I'm sorry, I was trying to reach M6 tech support", he stammered a bit and said something to the effect of "Oh, yes, right, this is M6, can I help you?". To which I replied "No, I really don't think you can", and I hung up.

I had a sinking feeling in my gut, because I realized at that point what a mistake I had made. It was then that I started researching them and found one blistering negative review after another. So on day 3 I submitted a ticket (my last one I might add) and requested that they cancel my account and issue my refund per their 30-day money back guarantee.

I've yet to see the refund.

The fact that you're reading this shows that you're already doing the right thing. Read reviews, weigh the good against the bad, especially watch for hosts who care enough to log on and rebut negative reviews, and ask lots of questions here on WHT.

View 2 Replies View Related

Xio.net - Your Experience

May 28, 2008

I've been using Xilo.net for just over a year now using a reseller account but the time has come to expand to a dedicated server. The level of support I've received from Xilo hasn't been 100% fantastic and my account is sometimes offline for one reason or another - impacting my sites.

I was just wondering if anyone else has any experience with Xilo and if so what your thoughts are on them? I read the other post from last year about Xilo being useless in setting up a VPN but just wondered if anyone else has dealt with them since?

I'm really not sure whether or not to stay with Xilo for a dedicated server or to move on.

View 0 Replies View Related

Bad Experience With 3fn.net

Apr 16, 2007

I have recently ordered webhosting on not so well known 3fn webhosting company. The reason why I decided for them is because I had some money on my webmoney account, and I needed new webhosting (they accept webmoney payment).

I decided to go for starter plan to test their quality of service, because they didnt want to give me test account, although their site says they offer them. When my account was set up, it all seemed good - I got Plesk which I prefer over cPanel, etc. But when I connected to ftp server I noticed the server isnt that fast as its supposed to be.

After a few days server speed started to annoy me. My website went offline so frequently so that I couldnt belive. I told the admin im unsatisfied with hosting speed, any their uptime - he said they're going to fix it (or something like that).

Website worked fine after a few minutes, but then it went offline again. Today I wanted to access some files I host on my webserver from school, but I noticed the site was offline again.

I sent complaint to them by email and told them my website uptime is only like 60%, and got no response.

I havent been so dissapointed for a long time..

View 3 Replies View Related

MochaHost Experience

Sep 30, 2009

I was looking for a windows reseller plan. I researched lots and found mochahost. They seemed to have a good deal and had all the features I wanted. Anyway, I signed up and immediately requested that they add ClientExec to my account. (Extra $4/month).

After a few hours I received a welcome email and all was good, but no info on ClientExec. I contacted tech support through their chat program (which appears to always be a guy named "Tod"). He told me I needed to open a separate ticket for it. So I did that.

After 24 HOURS, I received a response telling me they generated an invoice that I need to pay. Which I did right away. The response also told me that I needed to re-open the support ticket after I paid for it so they would know to turn on ClientExec for me. The only problem is the ticket was already open.??

I waited about 6 hours and then I contacted "Tod" in tech support again via chat. He told me to open another ticket letting them know I paid, which I did, now 48 HOURS AGO.
No response at all. I contacted "Tod" again right now and he can't help at all. In fact he told me to open another ticket. lol.

I did read some bad stuff about Mochahost, and now Im pretty worried. If I ever need support for my customers I can't wait 48 hours for a response.

View 14 Replies View Related

Experience With Lunarpages?

Sep 24, 2006

Do you have some experiences with Lunarpages.com ?

I purchased win host and I have some negative experiences with them at this time.

View 9 Replies View Related

How Was The Experience With Lunarpages

Aug 10, 2008

I bought their hosting 8 months ago and they are simply jerk for hosting a big site on their shared hosting plans. Now I have transfered my domains to one.com which is very good for huge traffic sites.

View 4 Replies View Related

3 Day Experience With Lunarpages

Oct 2, 2009

I want to tell you guys about my lunarpages experience. First, I found them through a top 10 website review. BIG mistake I understand now. Not really that big of a deal if I can rely on them which is reall all I want. But I don't think I can.

First thing I did after creating my account was go to setup my email. I was very excited, this is my first domain ever. I set it up and then find out I can't receive email! After reporting this to their staff and setting up a ticket, I find out the next day that I wasn't receiving email because I had set my mailbox quota limit to 5000mb. Apparently that was too high they said! Why would they give you the option of doing that if it's just going to screw things up? That's just stupid. I knew I didn't need that much but I figured I'd set it and forget it and it would be no problem.

Then the next thing was just yesterday when I went to check my website and it was down. And so was their LPCP (control panel). I don't know how long it was down for but I noticed it for about half an hour.

I'm still within their 30 day refund policy since I only started the account on tuesday. What do you guys think I should do? Is it commomplace for websites to go down from time to time?

I would really appreciate any suggestions you guys might have as a reliable host. Also, how do I go about tranfering my domain name? Do i tell lunarpages I want to cancel first and then tranfer the domain or do I setup an account where I want to domain to go, then cancel?

View 14 Replies View Related

VPSLand Bad Experience

Oct 29, 2008

writing this post to share with the community my "experience" with VPSLand.I've read a mix of good and bad experiences with this company, and this is just another... I'll let the dialog speak for itself......

View 5 Replies View Related

Anyone Here With CSF Firewall Experience

Apr 3, 2009

CSF firewall official forum is pretty dull.. no answer there in last 3-4 days, so I turned to our good old WHT community.

1. In CSF, how do I block range of IP ?
Say I want to block IPs starting 164.44.x.x

2.
Btw, I found that my CSF is not able to catch DOS attack at all !!
below is my csf config file

Code:
###############################################################################
# Copyright 2006-2009, Way to the Web Limited
# URL: http://www.waytotheweb.com
# Email: sales@waytotheweb.com
###############################################################################
# Testing flag - enables a CRON job that clears iptables incase of
# configuration problems when you start csf. This should be enabled until you
# are sure that the firewall works - i.e. incase you get locked out of your
# server! Then do remember to set it to 0 and restart csf when you're sure
# everything is OK. Stopping csf will remove the line from /etc/crontab
TESTING = "0"

# The interval for the crontab in minutes. Since this uses the system clock the
# CRON job will run at the interval past the hour and not from when you issue
# the start command. Therefore an interval of 5 minutes means the firewall
# will be cleared in 0-5 minutes from the firewall start
TESTING_INTERVAL = "5"

# Enabling auto updates creates a cron job called /etc/cron.d/csf_update which
# runs once per day to see if there is an update to csf+lfd and upgrades if
# available and restarts csf and lfd. Updates do not overwrite configuration
# files or email templates. An email will be sent to the root account if an
# update is performed
AUTO_UPDATES = "0"

# By default, csf will auto-configure iptables to filter all traffic except on
# the local (lo:) device. If you only want iptables rules applied to a specific
# NIC, then list it here (e.g. eth1, or eth+)
ETH_DEVICE = ""

# If you don't want iptables rules applied to specific NICs, then list them in
# a comma separated list (e.g "eth1,eth2")
ETH_DEVICE_SKIP = ""

# Lists of ports in the following comma separated lists can be added using a
# colon (e.g. 30000:35000).

# Allow incoming TCP ports
TCP_IN = "20,21,22,25,53,80,110,143,443,465,587,993,995,2222,2221"

# Allow outgoing TCP ports
TCP_OUT = "20,21,22,25,53,80,110,113,443,2222"

# Allow incoming UDP ports
UDP_IN = "20,21,53"

# Allow outgoing UDP ports
# To allow outgoing traceroute add 33434:33523 to this list
UDP_OUT = "20,21,53,113,123"

# Allow incoming PING
ICMP_IN = "1"

# Set the per IP address incoming ICMP packet rate
# To disable rate limiting set to "0"
ICMP_IN_RATE = "1/s"

# Allow outgoing PING
ICMP_OUT = "1"

# Set the per IP address outgoing ICMP packet rate
# To disable rate limiting set to "0"
ICMP_OUT_RATE = "1/s"

# Block outgoing SMTP except for root, exim and mailman (forces scripts/users
# to use the exim/sendmail binary instead of sockets access). This replaces the
# protection as WHM > Tweak Settings > SMTP Tweaks
#
# This option uses the iptables ipt_owner module and must be loaded for it to
# work. It may not be available on some VPS platforms
#
# Note: Run /etc/csf/csftest.pl to check whether this option will function on
# this server
SMTP_BLOCK = "0"

# If SMTP_BLOCK is enabled but you want to allow local connections to port 25
# on the server (e.g. for webmail or web scripts) then enable this option to
# allow outgoing SMTP connections to 127.0.0.1
SMTP_ALLOWLOCAL = "1"

# This is a comma separated list of the ports to block. You should list all
# ports that exim is configured to listen on
SMTP_PORTS = "25"

# Drop target for iptables rules. This can be set to either DROP ot REJECT.
# REJECT will send back an error packet, DROP will not respond at all. REJECT
# is more polite, however it does provide extra information to a hacker and
# lets them know that a firewall is blocking their attempts. DROP hangs their
# connection, thereby frustrating attempts to port scan the server.
DROP = "DROP"

# Enable logging of dropped connections to blocked ports to syslog, usually
# /var/log/messages. This option needs to be enabled to use Port Scan Tracking
DROP_LOGGING = "1"

# Enable logging of dropped connections to blocked IP addresses in csf.deny or
# by lfd with temporary connection tracking blocks. Do not enable this option
# if you use Port Scan Tracking
DROP_IP_LOGGING = "0"

# Only log reserved port dropped connections (0:1023). Useful since you're not
# usually bothered about ephemeral port drops
DROP_ONLYRES = "0"

# Commonly blocked ports that you do not want logging as they tend to just fill
# up the log file. These ports are specifically blocked (applied to TCP and UDP
# protocols) for incoming connections
DROP_NOLOG = "67,68,111,113,135:139,445,513,520"

# Enable packet filtering for unwanted or illegal packets
PACKET_FILTER = "1"

# Log packets dropped by the packet filtering option PACKET_FILTER. This will
# show packet drops that iptables has deemed INVALID (i.e. there is no
# established TCP connection in the state table), or if the TCP flags in the
# packet are out of sequence or illegal in the protocol exchange.
#
# If you see packets being dropped that you would rather allow then disable the
# PACKET_FILTER option above by setting it to "0"
DROP_PF_LOGGING = "0"

# Enable SYN flood protection. This option configures iptables to offer some
# protection from tcp SYN packet DOS attempts. You should set the RATE so that
# false-positives are kept to a minimum otherwise visitors may see connection
# issues (check /var/log/messages for *SYNFLOOD Blocked*). See the iptables
# man page for the correct --limit rate syntax
SYNFLOOD = "1"
SYNFLOOD_RATE = "80/s"
SYNFLOOD_BURST = "150"

# Port Flood Protection. This option configures iptables to offer protection
# from DOS attacks against specific ports. This option limits the number of
# connections per time interval that new connections can be made to specific
# ports
#
# This feature does not work on servers that do not have the iptables module
# ipt_recent loaded. Typically, this will be with MONOLITHIC kernels. VPS
# server admins should check with their VPS host provider that the iptables
# module is included
#
# For further information and syntax refer to the Port Flood section of the csf
# readme.txt
#
# Note: Run /etc/csf/csftest.pl to check whether this option will function on
# this server
PORTFLOOD = ""

# Enable verbose output of iptables commands
VERBOSE = "1"

# Log lfd messages to SYSLOG in addition to /var/log/lfd.log. You must have the
# perl module Sys::Syslog installed to use this feature
SYSLOG = "0"

# Enable this option if you want lfd to ignore (i.e. don't block) IP addresses
# listed in csf.allow in addition to csf.ignore (the default). This option
# should be used with caution as it would mean that IP's allowed through the
# firewall from infected PC's could launch attacks on the server that lfd
# would ignore
IGNORE_ALLOW = "0"

# Enable the following option if you want to apply strict iptables rules to DNS
# traffic (i.e. relying on iptables connection tracking). Enabling this option
# could cause DNS resolution issues both to and from the server but could help
# prevent abuse of the local DNS server
DNS_STRICT = "0"

# Limit the number of IP's kept in the /etc/csf/csf.deny file. This can be
# important as a large number of IP addresses create a large number of iptables
# rules (4 times the number of IP's) which can cause problems on some systems
# where either the the number of iptables entries has been limited (esp VPS's)
# or where resources are limited. This can result in slow network performance,
# or, in the case of iptables entry limits, can prevent your server from
# booting as not all the required iptables chain settings will be correctly
# configured. The value set here is the maximum number of IPs/CIDRs allowed
# if the limit is reached, the entries will be rotated so that the oldest
# entries (i.e. the ones at the top) will be removed and the latest is added.
# The limit is only checked when using csf -d (which is what lfd also uses)
# Set to 0 to disable limiting
DENY_IP_LIMIT = "100"

# Limit the number of IP's kept in the temprary IP ban list. If the limit is
# reached the oldest IP's in the ban list will be removed and allowed
# regardless of the amount of time remaining for the block
# Set to 0 to disable limiting
DENY_TEMP_IP_LIMIT = "100"

# Enable login failure detection daemon (lfd). If set to 0 none of the
# following settings will have any effect as the daemon won't start.
LF_DAEMON = "1"

# By default, lfd will send alert emails using the relevant alert template to
# the To: address configured within that template. Setting the following
# option will override the configured To: field in all lfd alert emails
#
# Leave this option empty to use the To: field setting in each alert template
LF_ALERT_TO = "rickyjaffery@gmail.com"

# Block Reporting. lfd can run an external script when it performs and IP
# address block following for example a login failure. The following setting
# is to the full path of the external script which must be executable. See
# readme.txt for format details
#
# Leave this setting blank to disable
BLOCK_REPORT = ""

# Send an alert if log file flooding is detected which causes lfd to skip log
# lines to prevent lfd from looping. If this alert is sent you should check the
# reported log file for the reason for the flooding
LOGFLOOD_ALERT = "0"

# Temporary to Permanent IP blocking. The following enables this feature to
# permanently block IP addresses that have been temporarily blocked more than
# LF_PERMBLOCK_COUNT times in the last LF_PERMBLOCK_INTERVAL seconds. Set
# LF_PERMBLOCK to "1" to enable this feature
#
# Care needs to be taken when setting LF_PERMBLOCK_INTERVAL as it needs to be
# at least LF_PERMBLOCK_COUNT multiplied by the longest temporary time setting
# (TTL) for blocked IPs, to be effective
#
# Set LF_PERMBLOCK to "0" to disable this feature
LF_PERMBLOCK = "1"
LF_PERMBLOCK_INTERVAL = "86400"
LF_PERMBLOCK_COUNT = "4"

# Permanently block IPs by network class. The following enables this feature
# to permanently block classes of IP address where individual IP addresses
# within the same class LF_NETBLOCK_CLASS have already been blocked more than
# LF_NETBLOCK_COUNT times in the last LF_NETBLOCK_INTERVAL seconds. Set
# LF_NETBLOCK to "1" to enable this feature
#
# This can be an affective way of blocking DDOS attacks launched from within
# the same networ class
#
# Valid settings for LF_NETBLOCK_CLASS are "A", "B" and "C", care and
# consideration is required when blocking network classes A or B
#
# Set LF_NETBLOCK to "0" to disable this feature
LF_NETBLOCK = "0"
LF_NETBLOCK_INTERVAL = "86400"
LF_NETBLOCK_COUNT = "4"
LF_NETBLOCK_CLASS = "C"

# Safe Chain Update. If enabled, all dynamic update chains (GALLOW*, GDENY*,
# SPAMHAUS, DSHIELD, BOGON, CC_ALLOW, CC_DENY, ALLOWDYN*) will create a new
# chain when updating, and insert it into the relevant LOCALINPUT/LOCALOUTPUT
# chain, then flush and delete the old dynamic chain and rename the new chain.
#
# This prevents a small window of opportunity opening when an update occurs and
# the dynamic chain is flushed for the new rules.
#
# This option should not be enabled on servers with long dynamic chains (e.g.
# CC_DENY/CC_ALLOW lists) and low memory. It should also not be enabled on
# Virtuozzo VPS servers with a restricted numiptent value. This is because each
# chain will effectively be duplicated while the update occurs, doubling the
# number of iptables rules
SAFECHAINUPDATE = "0"

# If you wish to allow access from dynamic DNS records (for example if your IP
# address changes whenever you connect to the internet but you have a dedicated
# dynamic DNS record from the likes of dyndns.org) then you can list the FQDN
# records in csf.dyndns and then set the following to the number of seconds to
# poll for a change in the IP address. If the IP address has changed iptables
# will be updated.
#
# A setting of 600 would check for IP updates every 10 minutes. Set the value
# to 0 to disable the feature
DYNDNS = "0"

# To always ignore DYNDNS IP addresses in lfd blocking, set the following
# option to 1
DYNDNS_IGNORE = "0"

# The follow Global options allow you to specify a URL where csf can grab a
# centralised copy of an IP allow or deny block list of your own. You need to
# specify the full URL in the following options, i.e.:
# http://www.somelocation.com/allow.txt
#
# The actual retrieval of these IP's is controlled by lfd, so you need to set
# LF_GLOBAL to the interval (in seconds) when you want lfd to retrieve. lfd
# will perform the retrieval when it runs and then again at the specified
# interval. A sensible interval would probably be every 3600 seconds (1 hour)
#
# You do not have to specify both an allow and a deny file
#
# You can also configure a global ignore file for IP's that lfd should ignore
GLOBAL_ALLOW = ""
GLOBAL_DENY = ""
GLOBAL_IGNORE = ""
LF_GLOBAL = ""

# Country Code to CIDR allow/deny. In the following two options you can allow
# or deny whole country CIDR ranges. The CIDR blocks are downloaded from
# http://www.ipdeny.com/ipblocks/ and entirely rely on that service being
# available. The two-letter Country Code specified on that site should be used
# in the following settings. The iptables rules are for incoming connections
# only
#
# Warning: These lists are never 100% accurate and some ISP's (e.g. AOL) use
# non-geographic IP address designations for their clients
#
# Warning: Some of the CIDR lists are huge and each one requires a rule within
# the incoming iptables chain. This can result in significant performance
# overheads and could render the server inaccessible in some circumstances. For
# this reason (amongst others) we do not recommend using these options
#
# Warning: Due to the resource constraints on VPS servers this feature should
# not be used on such systems unless you choose very small CC zones
#
# Warning: CC_ALLOW allows access through all ports in the firewall. For this
# reason CC_ALLOW probably has very limited use
#
# Note: Use of this feature is bound by the TOS and Copyright agreements at
# http://www.ipdeny.com/usagelimits.php
#
# Each option is a comma separated list of CC's, e.g. "US,GB,DE"
CC_DENY = ""
CC_ALLOW = ""

# This option tells lfd how often to retrieve the CC CIDR's required for
# CC_ALLOW and CC_DENY (in days)
CC_INTERVAL = "7"

# Enable IP range blocking using the DShield Block List at
# http://www.dshield.org/diary.html?storyid=4483
# To enable this feature, set the following to the interval in seconds that you
# want the block list updated. The list is reasonably static during the length
# of a day, so it would be appropriate to only update once every 24 hours, so
# a value of "86400" is recommended
LF_DSHIELD = "0"

# The DShield block list URL. If you change this to something else be sure it
# is in the same format as the block list
LF_DSHIELD_URL = "http://feeds.dshield.org/block.txt"

# Enable IP range blocking using the Spamhaus DROP List at
# http://www.spamhaus.org/drop/index.lasso
# To enable this feature, set the following to the interval in seconds that you
# want the block list updated. The list is reasonably static during the length
# of a day, so it would be appropriate to only update once every 24 hours, so
# a value of "86400" is recommended
LF_SPAMHAUS = "1"

# The Spamhaus DROP List URL. If you change this to something else be sure it
# is in the same format as the drop list
LF_SPAMHAUS_URL = "http://www.spamhaus.org/drop/drop.lasso"

# Enable IP range blocking using the BOGON List at
# http://www.cymru.com/Bogons/
# To enable this feature, set the following to the interval in seconds that you
# want the block list updated. The list is reasonably static during the length
# of a day, so it would be appropriate to only update once every 24 hours, so
# a value of "86400" is recommended
#
# Do NOT use this option if your server uses IP's on the bogon list (e.g. this
# is often the case with servers behind a NAT firewall using ip routing)
LF_BOGON = "0"

# The BOGON List URL. If you change this to something else be sure it
# is in the same format as the drop list
LF_BOGON_URL = "http://www.cymru.com/Documents/bogon-bn-agg.txt"

# The following[*] triggers are application specific. If you set LF_TRIGGER to
# "0" the value of each trigger is the number of failures against that
# application that will trigger lfd to block the IP address
#
# If you set LF_TRIGGER to a value greater than "0" then the following[*]
# application triggers are simply on or off ("0" or "1") and the value of
# LF_TRIGGER is the total cumulative number of failures that will trigger lfd
# to block the IP address
#
# Setting the application trigger to "0" disables it
LF_TRIGGER = "0"

# If LF_TRIGGER is > 1 then the following can be set to "1" to permanently
# block the IP address, or if set to a value greater than "1" then the IP
# address will be blocked temporarily for the value in seconds. For example:
# LF_TRIGGER_PERM = "1" => the IP is blocked permanently
# LF_TRIGGER_PERM = "3600" => the IP is blocked temporarily for 1 hour
#
# If LF_TRIGGER is 0, then the application LF_[application]_PERM value works in
# the same way as above
LF_TRIGGER_PERM = "3600"

# To only block access to the failed application instead of a complete block
# for an ip address, you can set the following to "1", but LF_TRIGGER must be
# set to "0" with specific application[*] trigger levels also set
LF_SELECT = "0"

# Send an email alert if an IP address is blocked by one of the[*] triggers
LF_EMAIL_ALERT = "1"

#[*]Enable login failure detection of sshd connections
LF_SSHD = "5"
LF_SSHD_PERM = "1"

#[*]Enable login failure detection of pure-ftpd connections
LF_FTPD = "10"
LF_FTPD_PERM = "1"

#[*]Enable login failure detection of SMTP AUTH connections
LF_SMTPAUTH = "5"
LF_SMTPAUTH_PERM = "1"

#[*]Enable login failure detection of courier pop3 connections. This will not
# trap the older cppop daemon
LF_POP3D = "10"
LF_POP3D_PERM = "1"

#[*]Enable login failure detection of courier imap connections. This will not
# trap the older cpimap (uwimap) daemon
LF_IMAPD = "10"
LF_IMAPD_PERM = "1"

#[*]Enable login failure detection of Apache .htpasswd connections
# Due to the often high logging rate in the Apache error log, you might want to
# enable this option only if you know you are suffering from attacks against
# password protected directories
LF_HTACCESS = "5"
LF_HTACCESS_PERM = "1"

#[*]Enable failure detection of Apache mod_security connections
# Due to the often high logging rate in the Apache error log, you might want to
# enable this option only if you know you are suffering from attacks against
# web scripts
LF_MODSEC = "5"
LF_MODSEC_PERM = "1"

#[*]Enable detection of suhosin triggers and blocking of attackers
# Example: LF_SUHOSIN = "5"
LF_SUHOSIN = "0"
LF_SUHOSIN_PERM = "1"

# Check that csf appears to have been stopped. This checks the status of the
# iptables INPUT chain. If it's not set to DROP, LF will run csf. This will not
# happen if TESTING is enabled above. The check is done every 300 seconds
LF_CSF = "1"

# Send an email alert if anyone logs in successfully using SSH
LF_SSH_EMAIL_ALERT = "1"

# Send an email alert if anyone uses su to access another account. This will
# send an email alert whether the attempt to use su was successful or not
LF_SU_EMAIL_ALERT = "1"

# Enable Directory Watching. This enables lfd to check /tmp and /dev/shm
# directories for suspicious files, i.e. script exploits. If a suspicious
# file is found an email alert is sent. One alert per file per LF_FLUSH
# interval is sent
#
# To enable this feature set the following to the checking interval in seconds.
# Set to disable set to "0"
LF_DIRWATCH = "60"

# To remove any suspicious files found during directory watching, enable the
# following. These files will be appended to a tarball in
# /etc/csf/suspicious.tar
LF_DIRWATCH_DISABLE = "0"

# This option allows you to have lfd watch a particular file or directory for
# changes and should they change and email alert using watchalert.txt is sent
#
# To enable this feature set the following to the checking interval in seconds
# (a value of 60 would seem sensible) and add your entries to csf.dirwatch
#
# Set to disable set to "0"
LF_DIRWATCH_FILE = "0"

# This is the interval that is used to flush reports of usernames, files and
# pids so that persistent problems continue to be reported, in seconds.
# A value of 3600 seems sensible
LF_FLUSH = "3600"

# System Integrity Checking. This enables lfd to compare md5sums of the
# servers OS binary application files from the time when lfd starts. If the
# md5sum of a monitored file changes an alert is sent. This option is intended
# as an IDS (Intrusion Detection System) and is the last line of detection for
# a possible root compromise.
#
# There will be constant false-positives as the servers OS is updated or
# monitored application binaries are updated. However, unexpected changes
# should be carefully inspected.
#
# Modified files will only be reported via email once.
#
# To enable this feature set the following to the checking interval in seconds
# (a value of 3600 would seem sensible). This option may pur an increased I/O
# load onto the server as it checks system binaries.
#
# To disable set to "0"
LF_INTEGRITY = "10800"

# System Exploit Checking. This enables lfd to check for the Random JS Toolkit
# and may check for others in the future:
# http://www.cpanel.net/security/notes/random_js_toolkit.html
# It compares md5sums of the binaries listed in the exploit above for changes
# and also attempts to create and remove a number directory
#
# Modified files will only be reported via email once, though will be reset
# after an hour
#
# To enable this feature set the following to the checking interval in seconds
# (a value of 300 would seem sensible).
#
# To disable set to "0"
LF_EXPLOIT = "400"

# This comma separated list allows you to (de)select which tests LF_EXPLOIT
# performs
#
# For the SUPERUSER check, you can list usernames in csf.suignore to have them
# ignored for that test
#
# Valid tests are:
# JS,SUPERUSER
LF_EXPLOIT_CHECK = "JS,SUPERUSER"

# Set the time interval to track login failures within (seconds), i.e.
# LF_TRIGGER failures within the last LF_INTERVAL seconds
LF_INTERVAL = "300"

# This is how long the lfd process sleeps (in seconds) before processing the
# log file entries and checking whether other events need to be triggered
LF_PARSE = "5"

# Send an email alert if an account exceeds LT_POP3D/LT_IMAPD logins per hour
# per IP
LT_EMAIL_ALERT = "1"

# Block POP3 logins if greater than LT_POP3D times per hour per account per IP
# address (0=disabled)
LT_POP3D = "0"

# Block IMAP logins if greater than LT_IMAPD times per hour per account per IP
# address (0=disabled) - not recommended for IMAP logins due to the ethos
# within which IMAP works. If you want to use this, setting it quite high is
# probably a good idea
LT_IMAPD = "0"

# Connection Tracking. This option enables tracking of all connections from IP
# addresses to the server. If the total number of connections is greater than
# this value then the offending IP address is blocked. This can be used to help
# prevent some types of DOS attack.
#
# Care should be taken with this option. It's entirely possible that you will
# see false-positives. Some protocols can be connection hungry, e.g. FTP, IMAPD
# and HTTP so it could be quite easy to trigger, especially with a lot of
# closed connections in TIME_WAIT. However, for a server that is prone to DOS
# attacks this may be very useful. A reasonable setting for this option might
# be arround 200.
#
# To disable this feature, set this to 0
CT_LIMIT = "100"

# Connection Tracking interval. Set this to the the number of seconds between
# connection tracking scans
CT_INTERVAL = "5"

# Send an email alert if an IP address is blocked due to connection tracking
CT_EMAIL_ALERT = "1"

# If you want to make IP blocks permanent then set this to 1, otherwise blocks
# will be temporary and will be cleared after CT_BLOCK_TIME seconds
CT_PERMANENT = "0"

# If you opt for temporary IP blocks for CT, then the following is the interval
# in seconds that the IP will remained blocked for (e.g. 1800 = 30 mins)
CT_BLOCK_TIME = "1800"

# If you don't want to count the TIME_WAIT state against the connection count
# then set the following to "1"
CT_SKIP_TIME_WAIT = "0"

# If you only want to count specific states (e.g. SYN_RECV) then add the states
# to the following as a comma separated list. E.g. "SYN_RECV,TIME_WAIT"
#
# Leave this option empty to count all states against CT_LIMIT
CT_STATES = ""

# If you only want to count specific ports (e.g. 80,443) then add the ports
# to the following as a comma separated list. E.g. "80,443"
#
# Leave this option empty to count all ports against CT_LIMIT
CT_PORTS = ""

# Process Tracking. This option enables tracking of user and nobody processes
# and examines them for suspicious executables or open network ports. Its
# purpose is to identify potential exploit processes that are running on the
# server, even if they are obfuscated to appear as system services. If a
# suspicious process is found an alert email is sent with relevant information.
# It is then the responsibility of the recipient to investigate the process
# further as the script takes no further action. Processes (PIDs) are only
# reported once unless lfd is restarted.
#
# The following is the number of seconds a process has to be active before it
# is inspected. If you set this time too low, then you will likely trigger
# false-positives with CGI or PHP scripts.
# Set the value to 0 to disable this feature
PT_LIMIT = "60"

# How frequently processes are checked in seconds
PT_INTERVAL = "60"

# If you want process tracking to highlight php or perl scripts that are run
# through apache then disable the following,
# i.e. set it to 0
#
# While enabling this setting will reduce false-positives, having it set to 0
# does provide better checking for exploits running on the server
PT_SKIP_HTTP = "0"

# lfd will report processes, even if they're listed in csf.pignore, if they're
# tagged as (deleted) by Linux. This information is provided in Linux under
# /proc/PID/exe. A (deleted) process is one that is running a binary that has
# the inode for the file removed from the file system directory. This usually
# happens when the binary has been replaced due to an upgrade for it by the OS
# vendor or another third party (e.g. cPanel). You need to investigate whether
# this is indeed the case to be sure that the original binary has not been
# replaced by a rootkit
#
# To stop lfd reporting such process you need to restart the daemon to which it
# belongs and therefore run the process using the replacement binary (presuming
# one exists). This will normally mean running the associated startup script in
# /etc/init.d/
#
# If you don't want lfd to report deleted binary processes, set to 0
PT_DELETED = "1"

# User Process Tracking. This option enables the tracking of the number of
# process any given cPanel account is running at one time. If the number of
# processes exceeds the value of the following setting an email alert is sent
# with details of those processes. If you specify a user in csf.pignore it will
# be ignored
#
# Set to 0 to disable this feature
PT_USERPROC = "10"

# This User Process Tracking option sends an alert if any linux user process
# exceeds the memory usage set (MB). To ignore specific processes or users use
# csf.pignore
#
# Set to 0 to disable this feature
PT_USERMEM = "100"

# This User Process Tracking option sends an alert if any linux user process
# exceeds the time usage set (seconds). To ignore specific processes or users
# use csf.pignore
#
# Set to 0 to disable this feature
PT_USERTIME = "1800"

# If this option is set then processes detected by PT_USERMEM, PT_USERTIME or
# PT_USERPROC are killed
#
# Warning: We don't recommend enabling this option unless absolutely necessary
# as it can cause unexpected problems when processes are suddenly terminated.
# It is much better to leave this option disabled and to investigate each case
# as it is reported when the triggers above are breached
#
# Note: Processes that are running deleted excecutables (see PT_DELETED) will
# not be killed by lfd
PT_USERKILL = "0"

# Check the PT_LOAD_AVG minute Load Average (can be set to 1 5 or 15 and
# defaults to 5 if set otherwise) on the server every PT_LOAD seconds. If the
# load average is greater than or equal to PT_LOAD_LEVEL then an email alert is
# sent. lfd then does not report subsequent high load until PT_LOAD_SKIP
# seconds has passed to prevent email floods.
#
# Set PT_LOAD to "0" to disable this feature
PT_LOAD = "30"
PT_LOAD_AVG = "5"
PT_LOAD_LEVEL = "8"
PT_LOAD_SKIP = "3600"

# If a PT_LOAD event is triggered, then if the following contains the path to
# a script, it will be run in a child process. For example, the script could
# contain commands to terminate and restart httpd, php, exim, etc incase of
# looping processes
PT_LOAD_ACTION = "/sbin/service httpd restart"

# Port Scan Tracking. This feature tracks port blocks logged by iptables to
# syslog. If an IP address generates a port block that is logged more than
# PS_LIMIT within PS_INTERVAL seconds, the IP address will be blocked.
#
# This feature could, for example, be useful for blocking hackers attempting
# to access the standard SSH port if you have moved it to a port other than 22
# and have removed 22 from the TCP_IN list so that connection attempts to the
# old port are being logged
#
# This feature blocks all iptables blocks from the iptables logs, including
# repeated attempts to one port or SYN flood blocks, etc
#
# Note: This feature will only track iptables blocks from the log file set in
# IPTABLES_LOG below and if you have DROP_LOGGING enabled. However, it will
# cause redundant blocking with DROP_IP_LOGGING enabled
#
# Warning: It's possible that an elaborate DDOS (i.e. from multiple IP's)
# could very quickly fill the iptables rule chains and cause a DOS in itself.
# The DENY_IP_LIMIT should help to mitigate such problems with permanent blocks
# and the DENY_TEMP_IP_LIMIT with temporary blocks
#
# Set PS_INTERVAL to "0" to disable this feature. A value of between 60 and 300
# would be sensible to enable this feature
PS_INTERVAL = "300"
PS_LIMIT = "10"

# You can specify the ports and/or port ranges that should be tracked by the
# Port Scan Tracking feature. The following setting is a comma separated list
# of those ports and uses the same format as TCP_IN. The default setting of
# 0:65535 covers all ports
PS_PORTS = "0:65535"

# You can select whether IP blocks for Port Scan Tracking should be temporary
# or permanent. Set PS_PERMANENT to "0" for temporary and "1" for permanent
# blocking. If set to "0" PS_BLOCK_TIME is the amount of time in seconds to
# temporarily block the IP address for
PS_PERMANENT = "0"
PS_BLOCK_TIME = "3600"

# Set the following to "1" to enable Port Scan Tracking email alerts, set to
# "0" to disable them
PS_EMAIL_ALERT = "1"

# Account Tracking. The following options enable the tracking of modifications
# to the accounts on a server. If any of the enabled options are triggered by
# a modifications to an account, an alert email is sent. Only the modification
# is reported. The cause of the modification will have to be investigated
# manually
#
# You can set AT_ALERT to the following:
# 0 = disable this feature
# 1 = enable this feature for all accounts
# 2 = enable this feature only for accounts with uid 0 (e.g. root)
AT_ALERT = "2"

# This options is the interval between checks in seconds
AT_INTERVAL = "60"

# Send alert if a new account is created
AT_NEW = "1"

# Send alert if an existing account is deleted
AT_OLD = "1"

# Send alert if an account password has changed
AT_PASSWD = "1"

# Send alert if an account uid has changed
AT_UID = "1"

# Send alert if an account gid has changed
AT_GID = "1"

# Send alert if an account login directory has changed
AT_DIR = "1"

# Send alert if an account login shell has changed
AT_SHELL = "1"

# Display Country Code and Country for reported IP addresses
CC_LOOKUPS = "1"

# Messenger service. This feature allows the display of a message to a blocked
# connecting IP address to inform the user that they are blocked in the
# firewall. This can help when users get themselves blocked, e.g. due to
# multiple login failures. The service is provided by two daemons running on
# ports providing either an HTML or TEXT message.
#
# This feature does not work on servers that do not have the iptables module
# ipt_REDIRECT loaded. Typically, this will be with MONOLITHIC kernels. VPS
# server admins should check with their VPS host provider that the iptables
# module is included.
#
# For further information on features and limitations refer to the csf
# readme.txt
#
# Note: Run /etc/csf/csftest.pl to check whether this option will function on
# this server
#
# 1 to enable, 0 to disable
MESSENGER = "0"

# Provide this service to temporary IP address blocks
MESSENGER_TEMP = "1"

# Provide this service to permanent IP address blocks
MESSENGER_PERM = "1"

# User account to run the service servers under. We recommend creating a
# specific non-priv, non-shell account for this purpose
MESSENGER_USER = "csf"

# This is the maximum concurrent connections allowed to each service server
MESSENGER_CHILDREN = "10"

# Set this to the port that will receive the HTML message. You should configure
# this port to be >1023 and different from the TEXT port. Do NOT enable access
# to this port in TCP_IN
MESSENGER_HTML = "8888"

# This comma separated list are the HTML ports that will be redirected for the
# blocked IP address. If you are using per application blocking (LF_TRIGGER)
# then only the relevant block port will be redirected to the messenger port
MESSENGER_HTML_IN = "80,2082,2095"

# Set this to the port that will receive the TEXT message. You should configure
# this port to be >1023 and different from the HTML port. Do NOT enable access
# to this port in TCP_IN
MESSENGER_TEXT = "8889"

# This comma separated list are the TEXT ports that will be redirected for the
# blocked IP address. If you are using per application blocking (LF_TRIGGER)
# then only the relevant block port will be redirected to the messenger port
MESSENGER_TEXT_IN = "21"

# These settings limit the rate at which connections can be made to the
# messenger service servers. Its intention is to provide protection from
# attacks or excessive connections to the servers. If the rate is exceeded then
# iptables will revert for the duration to the normal blocking actiity
#
# See the iptables man page for the correct --limit rate syntax
MESSENGER_RATE = "30/m"
MESSENGER_BURST = "5"

# Statistics
#
# These options will be expanded in the future.
#
# This option enabled statistical data gathering
ST_ENABLE = "1"

# This option determines how many iptables log lines to store for reports
ST_IPTABLES = "100"

# This option indicates whether rDNS and CC lookups are performed at the time
# the log line is recorded (this is not performed when viewing the reports)
#
# Warning: If DROP_IP_LOGGING is enabled and there are frequent iptables hits,
# then enabling this setting could cause serious performance problems
ST_LOOKUP = "0"

# If you find ever increasing numbers of zombie lfd processes you may need to
# revert to the old child reaper code by enabling this option
OLD_REAPER = "0"


# OS settings
IPTABLES = "/sbin/iptables"
MODPROBE = "/sbin/modprobe"
IFCONFIG = "/sbin/ifconfig"
SENDMAIL = "/usr/sbin/sendmail"
PS = "/bin/ps"
FUSER = "/sbin/fuser"
VMSTAT = "/usr/bin/vmstat"
LS = "/bin/ls"
MD5SUM = "/usr/bin/md5sum"
TAR = "/bin/tar"
CHATTR = "/usr/bin/chattr"

# Log files
HTACCESS_LOG = "/var/log/httpd/error_log"
MODSEC_LOG = "/var/log/httpd/error_log"
SSHD_LOG = "/var/log/secure"
SU_LOG = "/var/log/secure"
FTPD_LOG = "/var/log/messages"
SMTPAUTH_LOG = "/var/log/secure"
POP3D_LOG = "/var/log/maillog"
IMAPD_LOG = "/var/log/maillog"
IPTABLES_LOG = "/var/log/messages"
SUHOSIN_LOG = "/var/log/messages"

CUSTOM1_LOG = "/var/log/messages"
CUSTOM2_LOG = "/var/log/messages"
CUSTOM3_LOG = "/var/log/messages"
CUSTOM4_LOG = "/var/log/messages"
CUSTOM5_LOG = "/var/log/messages"
CUSTOM6_LOG = "/var/log/messages"
CUSTOM7_LOG = "/var/log/messages"
CUSTOM8_LOG = "/var/log/messages"
CUSTOM9_LOG = "/var/log/messages"

# This configuration is for use with generic Linux servers, do not change the
# following setting:
GENERIC = "1"
DIRECTADMIN = "1"

# For internal use only. You should not enable this option as it could cause
# instability in csf and lfd
DEBUG = "0"

View 5 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved