1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

WHM hack attempts

Discussion in 'Site & Server Administration' started by bengal, May 12, 2013.

  1. #1
    Hi,
    I have set whostmgrd allow to ONLY my IP and deny ALL and yet I am still receiving daily brute force protection emails from several IPs.
    Correct me if I'm wrong but Host Access Control apparently is not working.
    Can you please suggest a better solution to stop hackers from accessing WHM and CPanel?

    Here is my Host Access Control configuration:

    [​IMG]
     
    bengal, May 12, 2013 IP
  2. zacharooni

    zacharooni Well-Known Member

    Messages:
    346
    Likes Received:
    20
    Best Answers:
    4
    Trophy Points:
    120
    #2
    This is essentially leaving the port open, and relying on tcpwrappers to stop attacks. You will get much better results if you just open the port only for your IP address, and DROP all other traffic destined for the respective port (e.g. 2082/2083/2086/2087).
     
    zacharooni, May 12, 2013 IP
  3. SeerKan

    SeerKan Greenhorn

    Messages:
    11
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    23
    #3
    I would recommend installing CSF, it's very effective in securing a cpanel server.
     
    SeerKan, May 13, 2013 IP
  4. zacharooni

    zacharooni Well-Known Member

    Messages:
    346
    Likes Received:
    20
    Best Answers:
    4
    Trophy Points:
    120
    #4
    Expanding on SeerKan's post, is it recommended if you are the only one that's going to login to the server to manage it at the root-level, then don't put the respective ports in TCP_IN in /etc/csf/csf.conf, but rather, just whitelist the management IPs that you'll be connecting from, and the ports will respond to IPs in the whitelist.
     
    zacharooni, May 13, 2013 IP
  5. TiffanyJ.SSS

    TiffanyJ.SSS Member

    Messages:
    72
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    33
    #5
    Host Access Control does not work like that. It uses TCPWrappers so only SSHD there would work. I won't go in to details of that.

    1) Secure the server.
    2) Use LFD/CSF and tweak/fine tune for starters
    3) Use HID
    4) Use our whitelisting tool to only allow certain IPs into WHM on certain accounts.

    There are several other ways as well.
     
    TiffanyJ.SSS, May 13, 2013 IP