I believe that portsentry is not working properly on my system (cPanel).
Looking at the logs, i found out that some IP addresses could access my system even though portsentry had banned them.
For example, i looked at the banned IP's reported by portsentry in /var/log/messages and /var/portsentry/portsentry.history and compared them to the output of:
it seems that SOME of them are listed, while others are not.... hmm weird.Code:iptables --list -n
i've now edited my /etc/portsentry/portsentry.conf and switched from KILL_ROUTE to KILL_RUN_CMD. I'll let it run for a while and see if it works better this way (they both execute the same iptables command).


LinkBack URL
About LinkBacks



Reply With Quote
Bookmarks