From df88f452e8a7413328f5a3aa32cdf1b8131de0b0 Mon Sep 17 00:00:00 2001 From: bms8197 Date: Mon, 13 Feb 2023 12:11:16 +0200 Subject: [PATCH] saving uncommitted changes in /etc prior to dnf run --- .etckeeper | 6 +- csf/csf.conf | 2 +- csf/csf.conf.i360bak | 2 +- imunify360-webshield/common-proxies.conf | 1 + .../static-whitelist.conf | 277 ++++++++++-------- sysconfig/imunify360/imunify360-merged.config | 21 +- sysconfig/imunify360/imunify360.config | 22 +- .../imunify360-webshield.service | 1 - 8 files changed, 187 insertions(+), 145 deletions(-) delete mode 120000 systemd/system/multi-user.target.wants/imunify360-webshield.service diff --git a/.etckeeper b/.etckeeper index 3367aa8..3507bb2 100755 --- a/.etckeeper +++ b/.etckeeper @@ -1042,8 +1042,8 @@ maybe chmod 0644 'imunify360-webshield/blocked_country_codes.conf' maybe chmod 0755 'imunify360-webshield/captcha' maybe chmod 0644 'imunify360-webshield/captcha.conf' maybe chmod 0644 'imunify360-webshield/captcha/lang.conf' -maybe chmod 0644 'imunify360-webshield/common-proxies.conf' -maybe chmod 0644 'imunify360-webshield/country_ips.conf' +maybe chmod 0660 'imunify360-webshield/common-proxies.conf' +maybe chmod 0660 'imunify360-webshield/country_ips.conf' maybe chmod 0644 'imunify360-webshield/custom-blacklisted.conf' maybe chmod 0644 'imunify360-webshield/custom-whitelisted.conf' maybe chmod 0644 'imunify360-webshield/fastcgi.conf' @@ -1072,7 +1072,7 @@ maybe chmod 0755 'imunify360-webshield/webshield-captcha.conf.d' maybe chmod 0755 'imunify360-webshield/webshield-http.conf.d' maybe chmod 0660 'imunify360-webshield/webshield-http.conf.d/captchakeys.conf' maybe chmod 0644 'imunify360-webshield/webshield-http.conf.d/resolver.conf' -maybe chmod 0644 'imunify360-webshield/webshield-http.conf.d/static-whitelist.conf' +maybe chmod 0660 'imunify360-webshield/webshield-http.conf.d/static-whitelist.conf' maybe chmod 0644 'imunify360-webshield/webshield-http.conf.d/wscheckdata.conf' maybe chmod 0755 'imunify360-webshield/webshield-server.conf.d' maybe chmod 0755 'imunify360-webshield/webshield-splashscreen.conf.d' diff --git a/csf/csf.conf b/csf/csf.conf index 29db1ad..9032fb1 100644 --- a/csf/csf.conf +++ b/csf/csf.conf @@ -680,7 +680,7 @@ LF_ALERT_SMTP = "" # readme.txt for format details # # Leave this setting blank to disable -BLOCK_REPORT = "" +BLOCK_REPORT = "/opt/alt/python38/share/imunify360/scripts/lfd_block.py" # To also run an external script when a temporary block is unblocked. The # following setting can be the full path of the external script which must be diff --git a/csf/csf.conf.i360bak b/csf/csf.conf.i360bak index bf76cdd..29db1ad 100644 --- a/csf/csf.conf.i360bak +++ b/csf/csf.conf.i360bak @@ -139,7 +139,7 @@ LF_SPI = "1" TCP_IN = "20,21,22,25,26,53,80,88,110,143,443,465,587,873,904,953,992,993,995,1723,1986,2082,2083,2086,2087,2095,2096,5080,5222,5269,5432,5665,5666,8000,8001,8080,8443,8800,8988,9080,9391,9443,9999,11898,52222,65534,1907:1909,40000:40100" # Allow outgoing TCP ports -TCP_OUT = ",1:65535" +TCP_OUT = "8443,44445,55556,1:65535,7770:7800" # Allow incoming UDP ports UDP_IN = "20,21,53,67,68,123,161,500,514,517,518,1027,1194,1514,1701,1981,4500,33434:33523" diff --git a/imunify360-webshield/common-proxies.conf b/imunify360-webshield/common-proxies.conf index 652f17c..7d145d4 100644 --- a/imunify360-webshield/common-proxies.conf +++ b/imunify360-webshield/common-proxies.conf @@ -1227,6 +1227,7 @@ 98.190.94.128/25 stackpath; 103.28.248.0/22 incapsula; 107.154.0.0/16 incapsula; +131.125.128.0/17 incapsula; 149.126.72.0/21 incapsula; 185.11.124.0/22 incapsula; 192.230.64.0/18 incapsula; diff --git a/imunify360-webshield/webshield-http.conf.d/static-whitelist.conf b/imunify360-webshield/webshield-http.conf.d/static-whitelist.conf index 773cc19..504c274 100644 --- a/imunify360-webshield/webshield-http.conf.d/static-whitelist.conf +++ b/imunify360-webshield/webshield-http.conf.d/static-whitelist.conf @@ -24,38 +24,33 @@ geo $static_whitelisted { 74.50.63.0/24 1; 199.231.76.0/24 1; 103.11.1.4 1; -103.15.42.197 1; 103.196.232.134 1; 103.2.116.68 1; +103.2.116.69 1; +103.2.116.70 1; 103.206.152.4 1; 103.206.152.5 1; -103.206.152.6 1; 103.235.124.6 1; -103.241.58.6 1; -103.242.22.5 1; 104.132.20.81 1; -104.132.247.77 1; -104.132.247.80 1; 104.193.69.4 1; +104.193.69.5 1; 104.193.69.7 1; 105.187.240.10 1; 105.187.240.4 1; -105.187.240.5 1; +105.187.240.9 1; 105.187.241.4 1; 105.187.242.5 1; 105.187.242.6 1; 109.105.54.196 1; 109.166.251.36 1; 109.166.251.37 1; -109.166.251.39 1; 109.166.251.40 1; 109.166.251.5 1; 109.166.251.6 1; 109.166.251.7 1; 109.166.251.8 1; -109.166.251.9 1; +109.226.50.7 1; 109.226.50.8 1; -109.245.221.6 1; 109.62.68.4 1; 109.62.68.5 1; 109.88.203.68 1; @@ -72,38 +67,36 @@ geo $static_whitelisted { 114.23.44.37 1; 114.31.1.70 1; 115.164.140.4 1; +115.164.140.5 1; 115.164.140.6 1; 115.84.159.68 1; 115.84.159.69 1; 118.175.45.4 1; -118.175.45.5 1; -118.175.45.6 1; 118.175.45.7 1; 119.40.97.196 1; -119.40.97.198 1; -120.89.97.7 1; 120.89.97.70 1; 120.89.97.71 1; 124.158.72.5 1; 131.161.24.164 1; 131.161.24.165 1; +131.221.224.196 1; 132.198.200.197 1; 138.0.73.69 1; -138.122.223.228 1; +138.0.73.70 1; 138.185.180.198 1; 138.186.0.4 1; 138.186.0.5 1; 138.44.223.5 1; 138.97.127.228 1; +138.97.127.229 1; 142.166.12.197 1; 142.166.12.199 1; 142.166.12.201 1; 142.166.12.203 1; 143.137.113.4 1; -150.100.16.71 1; 150.129.59.5 1; 150.129.7.4 1; -153.107.192.133 1; +152.200.140.50 1; 154.118.140.5 1; 154.126.74.4 1; 154.126.74.5 1; @@ -113,71 +106,77 @@ geo $static_whitelisted { 157.157.135.38 1; 157.157.135.68 1; 157.157.135.71 1; +160.202.147.5 1; +162.211.40.132 1; 162.221.128.165 1; 162.252.127.133 1; 163.153.215.68 1; 163.153.215.69 1; 165.90.191.132 1; 165.90.191.133 1; +167.249.134.132 1; 168.187.143.5 1; 168.90.226.6 1; -168.90.226.7 1; -168.90.226.9 1; -170.51.244.4 1; +168.90.226.8 1; +168.90.64.36 1; 170.82.222.228 1; 170.84.132.4 1; 175.45.186.196 1; -176.22.242.68 1; +176.22.242.69 1; 177.10.160.133 1; 177.10.57.228 1; +177.101.143.196 1; +177.101.143.197 1; 177.101.143.198 1; +177.125.210.36 1; 177.129.16.68 1; 177.129.8.36 1; -177.129.8.37 1; 177.131.55.4 1; 177.154.223.4 1; -177.20.208.197 1; +177.154.223.6 1; +177.155.141.4 1; 177.21.96.68 1; -177.23.168.132 1; 177.23.168.133 1; 177.36.38.164 1; -177.36.38.165 1; 177.38.247.5 1; 177.39.144.36 1; 177.39.144.37 1; -177.46.79.228 1; 177.47.173.6 1; 177.66.115.132 1; 177.69.110.231 1; 177.69.110.232 1; +177.69.110.233 1; 177.75.75.228 1; +177.75.75.229 1; 177.75.75.230 1; -177.75.75.231 1; 177.91.160.132 1; +177.91.160.133 1; +177.91.160.134 1; 177.91.174.36 1; 178.168.3.4 1; 178.168.3.5 1; 178.168.3.6 1; -178.235.206.4 1; -178.235.206.5 1; 178.60.128.5 1; -178.60.128.7 1; 178.60.195.196 1; 178.60.195.197 1; 178.60.195.198 1; 179.108.192.198 1; -179.109.31.196 1; -179.127.81.4 1; -179.127.81.5 1; +179.127.142.133 1; 179.190.108.6 1; 179.190.108.7 1; +179.190.108.8 1; 179.190.108.9 1; 179.49.26.5 1; 179.97.42.4 1; 179.97.42.5 1; +179.97.42.6 1; 180.149.91.69 1; 180.150.1.6 1; +180.150.2.132 1; 180.150.2.133 1; +180.151.66.198 1; +181.15.96.135 1; +181.15.96.7 1; 181.174.135.6 1; 181.199.158.4 1; 181.210.15.68 1; @@ -185,11 +184,12 @@ geo $static_whitelisted { 181.40.16.69 1; 182.176.130.6 1; 183.182.124.6 1; +183.182.124.8 1; 183.182.97.132 1; 185.106.115.36 1; 185.124.53.5 1; +185.125.220.36 1; 185.180.12.132 1; -185.180.12.133 1; 185.180.12.135 1; 185.38.241.4 1; 185.38.241.5 1; @@ -201,55 +201,58 @@ geo $static_whitelisted { 185.49.170.197 1; 185.52.172.230 1; 185.52.172.232 1; +185.57.71.197 1; 185.58.203.4 1; 185.59.69.10 1; 185.59.69.4 1; +185.59.69.5 1; 185.59.69.6 1; 185.59.69.9 1; 186.148.159.68 1; 186.160.223.5 1; 186.160.223.6 1; 186.166.151.164 1; +186.166.151.165 1; 186.166.151.196 1; 186.166.151.197 1; -186.179.71.196 1; +186.195.109.4 1; 186.208.225.70 1; +186.209.75.101 1; 186.209.78.100 1; 186.235.189.132 1; -186.235.189.133 1; 186.235.31.196 1; +186.235.31.197 1; 186.237.52.4 1; 186.237.52.6 1; 186.250.215.132 1; -186.251.10.4 1; 186.251.10.6 1; 186.46.140.73 1; 187.1.14.132 1; 187.1.14.133 1; -187.103.72.4 1; 187.103.72.5 1; +187.109.16.196 1; 187.109.16.197 1; 187.109.238.5 1; 187.121.160.68 1; 187.121.160.69 1; 187.17.155.68 1; -187.63.166.197 1; +187.17.155.69 1; +187.19.17.4 1; 187.63.166.198 1; 187.72.192.201 1; -187.72.192.203 1; 187.73.144.229 1; 187.86.12.165 1; 187.86.12.167 1; -187.86.49.4 1; 187.94.208.132 1; 187.94.208.133 1; 187.94.208.134 1; 187.94.208.135 1; 188.43.69.69 1; -189.112.10.11 1; +189.112.10.10 1; 189.112.10.4 1; -189.112.10.7 1; +189.112.10.6 1; 189.112.10.8 1; +189.126.224.102 1; 189.198.158.5 1; 189.199.105.5 1; 189.199.71.4 1; @@ -257,23 +260,25 @@ geo $static_whitelisted { 189.199.71.6 1; 189.199.71.7 1; 189.199.71.8 1; +189.39.192.133 1; 189.45.196.4 1; +190.0.175.68 1; 190.102.57.198 1; 190.113.97.197 1; 190.94.74.5 1; +190.94.74.6 1; +190.94.74.72 1; 191.102.224.197 1; 191.242.112.101 1; 191.6.136.132 1; 192.232.16.71 1; -193.212.4.133 1; -193.212.4.136 1; +193.212.4.134 1; 193.212.4.4 1; 193.212.4.5 1; 193.219.73.164 1; 193.229.108.11 1; 193.229.108.38 1; 193.229.108.5 1; -193.229.108.6 1; 193.90.147.4 1; 193.90.147.6 1; 194.106.173.132 1; @@ -286,30 +291,27 @@ geo $static_whitelisted { 195.12.176.134 1; 195.12.177.6 1; 195.12.179.70 1; -195.138.80.199 1; 195.222.64.229 1; -195.222.64.235 1; +196.200.161.4 1; +196.200.161.6 1; +196.29.35.133 1; 196.29.35.134 1; -197.136.0.6 1; 197.155.95.4 1; 197.158.80.4 1; 197.158.80.5 1; -197.158.80.6 1; 197.218.0.69 1; -197.218.0.70 1; 197.220.0.5 1; 197.220.0.6 1; 197.230.59.4 1; 197.230.59.5 1; 198.235.201.68 1; 198.235.201.69 1; -198.92.97.36 1; 198.92.97.37 1; 199.180.84.70 1; 199.185.92.197 1; -200.125.225.71 1; 200.187.85.4 1; -200.189.63.134 1; +200.189.63.132 1; +200.195.155.196 1; 200.195.155.199 1; 200.195.155.200 1; 200.229.223.30 1; @@ -416,34 +418,39 @@ geo $static_whitelisted { 2001:4860:4860::8888 1; 201.0.238.196 1; 201.0.238.197 1; +201.0.238.198 1; 201.0.238.199 1; 201.149.59.68 1; 201.149.59.69 1; 201.157.30.134 1; 201.157.30.136 1; 201.157.30.137 1; -201.16.134.70 1; -201.16.134.71 1; 201.16.134.74 1; 201.16.134.75 1; 201.191.202.133 1; 201.191.202.135 1; 201.191.202.137 1; +201.20.107.228 1; +201.20.107.229 1; 201.20.117.228 1; 201.218.56.132 1; 201.218.56.196 1; 201.55.137.4 1; 201.55.137.5 1; +201.57.60.101 1; 201.57.60.69 1; +201.57.60.70 1; 201.57.60.72 1; -201.57.60.73 1; 201.62.48.100 1; -201.64.116.198 1; -201.64.116.199 1; +201.62.48.101 1; 201.64.116.201 1; -201.64.241.4 1; +201.64.116.202 1; 201.64.241.5 1; +201.64.241.6 1; 201.64.241.7 1; +201.64.241.72 1; +201.64.241.73 1; +201.76.0.69 1; 201.76.0.70 1; 201.77.112.132 1; 201.77.112.133 1; @@ -451,17 +458,26 @@ geo $static_whitelisted { 202.123.176.4 1; 202.123.176.5 1; 202.128.15.4 1; -202.43.172.4 1; +202.49.135.165 1; 202.88.68.69 1; 202.93.153.68 1; 202.93.153.69 1; 202.93.153.70 1; +203.118.245.36 1; 203.118.245.37 1; +203.13.161.69 1; +203.139.206.69 1; 203.153.17.36 1; 203.219.219.132 1; -203.219.219.4 1; -203.219.219.72 1; +203.219.219.134 1; +203.219.219.6 1; +203.219.219.68 1; +203.219.219.69 1; +203.219.219.70 1; +203.5.76.196 1; 203.5.76.197 1; +203.5.76.228 1; +203.92.54.68 1; 204.116.80.37 1; 204.19.203.228 1; 204.19.203.229 1; @@ -491,9 +507,10 @@ geo $static_whitelisted { 210.139.253.6 1; 210.209.18.229 1; 211.1.149.6 1; +212.0.195.10 1; 212.0.195.100 1; +212.0.195.102 1; 212.0.195.11 1; -212.0.195.4 1; 212.0.195.5 1; 212.0.195.68 1; 212.0.195.69 1; @@ -507,6 +524,8 @@ geo $static_whitelisted { 212.113.167.165 1; 212.113.167.166 1; 212.113.167.167 1; +212.113.167.168 1; +212.113.167.196 1; 212.113.167.197 1; 212.113.167.198 1; 212.113.167.199 1; @@ -514,8 +533,7 @@ geo $static_whitelisted { 212.113.167.202 1; 212.113.172.10 1; 212.113.172.11 1; -212.113.172.4 1; -212.113.172.8 1; +212.142.160.101 1; 212.142.160.103 1; 212.142.160.197 1; 212.142.160.198 1; @@ -524,15 +542,14 @@ geo $static_whitelisted { 212.142.160.5 1; 212.142.160.69 1; 212.142.160.7 1; -212.142.160.71 1; -212.204.53.197 1; -212.24.165.70 1; 212.24.165.71 1; 212.24.165.72 1; 212.24.165.73 1; 212.3.203.133 1; 212.3.203.134 1; +212.3.203.135 1; 212.30.5.196 1; +212.39.86.100 1; 212.39.86.103 1; 212.39.86.104 1; 212.39.86.73 1; @@ -541,30 +558,30 @@ geo $static_whitelisted { 212.89.24.5 1; 212.89.24.6 1; 212.89.5.70 1; +212.90.49.69 1; 212.92.207.132 1; +212.92.207.134 1; 212.98.160.4 1; -213.139.49.122 1; -213.140.213.196 1; +213.151.35.132 1; 213.151.35.134 1; 213.151.35.135 1; 213.151.35.136 1; -213.153.34.132 1; 213.153.34.133 1; 213.153.34.134 1; 213.157.199.4 1; -213.157.199.5 1; -213.157.199.6 1; 213.157.199.7 1; 213.157.199.8 1; 213.157.199.9 1; -213.163.23.69 1; 213.163.23.71 1; 213.163.23.72 1; 213.163.23.73 1; -213.30.114.197 1; +213.30.114.198 1; +213.30.117.197 1; 213.30.117.198 1; +213.30.18.132 1; 213.30.18.134 1; 213.30.18.136 1; +213.30.5.5 1; 213.30.5.7 1; 213.30.5.9 1; 216.177.189.132 1; @@ -578,51 +595,59 @@ geo $static_whitelisted { 217.146.165.196 1; 217.15.102.5 1; 217.15.106.5 1; +217.168.95.5 1; 217.168.95.6 1; +217.20.185.197 1; +217.73.128.196 1; 217.75.205.196 1; -219.88.188.197 1; +217.75.205.197 1; 219.88.188.8 1; +219.88.189.5 1; +220.244.136.134 1; 220.244.136.135 1; 220.244.136.196 1; 220.244.136.197 1; 220.244.136.198 1; 220.244.136.199 1; 220.244.136.200 1; +220.244.136.201 1; +220.244.136.203 1; +220.244.136.4 1; +220.244.136.5 1; 220.244.136.68 1; -223.27.237.4 1; +220.244.136.69 1; 23.236.5.133 1; 23.236.5.134 1; 24.124.17.165 1; 24.220.112.132 1; 24.220.112.133 1; 24.220.112.166 1; -24.246.130.228 1; 24.246.130.229 1; 24.51.113.68 1; 24.51.113.71 1; +24.51.113.72 1; 24.51.113.73 1; 24.56.144.100 1; 24.56.144.101 1; 27.100.64.228 1; 27.100.64.229 1; 27.121.46.197 1; +27.121.51.70 1; 27.2.226.70 1; 27.2.226.72 1; -31.186.166.196 1; 31.186.166.197 1; 31.186.166.198 1; 31.209.136.68 1; 31.209.136.69 1; 31.24.56.132 1; 31.24.56.133 1; -31.24.56.134 1; 31.3.94.132 1; +31.3.94.133 1; 31.3.94.134 1; 31.3.94.135 1; 31.3.94.196 1; 31.3.94.197 1; 31.3.94.198 1; -31.31.48.134 1; 34.100.182.96/28 1; 34.101.50.144/28 1; 34.118.254.0/28 1; @@ -665,37 +690,32 @@ geo $static_whitelisted { 41.21.236.70 1; 41.220.162.229 1; 41.221.196.4 1; -41.226.16.199 1; 41.226.22.134 1; 41.244.244.5 1; 41.74.64.165 1; 42.117.10.6 1; -42.117.10.7 1; 45.116.219.5 1; 46.21.52.4 1; -46.21.52.6 1; 46.227.113.4 1; 46.227.113.6 1; 46.229.224.4 1; 46.229.224.6 1; 46.29.169.36 1; -46.29.169.37 1; -5.186.12.38 1; -5.186.12.39 1; 5.186.12.41 1; 5.21.229.133 1; 5.21.230.132 1; 5.21.230.133 1; 5.22.190.10 1; -5.22.190.137 1; -5.22.190.139 1; 5.22.190.68 1; +5.22.190.72 1; 50.0.2.196 1; 50.0.2.197 1; +58.27.225.6 1; 58.27.225.7 1; -59.153.102.48 1; 60.199.175.136 1; 60.199.175.137 1; +60.199.175.138 1; +61.19.1.199 1; 61.19.1.201 1; 61.19.2.134 1; 61.19.2.199 1; @@ -710,23 +730,23 @@ geo $static_whitelisted { 62.201.216.68 1; 62.201.216.73 1; 62.206.166.5 1; -62.209.24.4 1; +62.209.24.5 1; 62.214.62.38 1; 62.231.75.198 1; -62.231.75.200 1; 62.231.75.201 1; 62.231.75.202 1; 62.231.75.203 1; 62.231.78.4 1; -62.231.78.8 1; 62.231.78.9 1; 64.203.194.197 1; 64.222.212.196 1; +64.222.212.197 1; 64.222.84.196 1; 64.222.84.197 1; 64.246.133.4 1; 64.246.133.5 1; 65.79.192.5 1; +65.79.192.6 1; 66.112.178.68 1; 66.112.178.69 1; 66.112.178.70 1; @@ -735,9 +755,10 @@ geo $static_whitelisted { 66.171.92.70 1; 66.201.170.4 1; 66.201.170.5 1; -66.201.170.6 1; 66.201.170.68 1; +66.244.74.69 1; 66.244.74.70 1; +66.248.191.164 1; 66.248.191.165 1; 66.249.64.0/27 1; 66.249.64.128/27 1; @@ -862,7 +883,6 @@ geo $static_whitelisted { 66.54.121.5 1; 66.58.255.6 1; 66.60.182.69 1; -66.60.182.71 1; 67.218.56.4 1; 67.218.56.5 1; 67.219.192.37 1; @@ -895,9 +915,9 @@ geo $static_whitelisted { 74.51.221.36 1; 74.51.221.37 1; 77.214.52.133 1; -77.214.52.134 1; -77.214.52.196 1; 77.214.53.199 1; +77.214.53.201 1; +77.239.64.69 1; 77.239.64.70 1; 77.243.18.68 1; 77.26.12.6 1; @@ -905,7 +925,9 @@ geo $static_whitelisted { 77.79.14.6 1; 79.101.110.11 1; 79.101.110.133 1; -79.101.110.138 1; +79.101.110.201 1; +79.101.110.203 1; +79.101.110.4 1; 79.101.110.5 1; 79.101.110.69 1; 79.101.110.74 1; @@ -913,10 +935,11 @@ geo $static_whitelisted { 79.121.0.68 1; 79.121.0.69 1; 79.121.0.70 1; -79.134.129.197 1; 8.8.4.4 1; 8.8.8.8 1; 80.251.202.4 1; +80.251.202.5 1; +80.251.202.7 1; 81.17.82.6 1; 82.114.163.196 1; 82.114.163.197 1; @@ -927,28 +950,23 @@ geo $static_whitelisted { 82.147.54.4 1; 82.147.54.5 1; 82.147.54.6 1; -82.76.231.4 1; 82.76.231.68 1; -82.76.231.70 1; 82.76.231.71 1; 82.76.231.72 1; 82.76.231.73 1; 82.76.231.74 1; -82.76.231.75 1; 82.76.79.132 1; 82.76.79.133 1; 82.76.79.134 1; 82.76.79.136 1; 82.76.79.68 1; +82.76.79.70 1; 82.76.79.72 1; -82.76.79.73 1; -83.139.106.196 1; -83.139.106.197 1; 83.139.67.5 1; 83.139.67.6 1; +83.174.198.69 1; 83.94.121.197 1; 83.94.121.200 1; -84.243.4.4 1; 84.243.4.5 1; 85.14.28.196 1; 85.18.0.133 1; @@ -957,6 +975,7 @@ geo $static_whitelisted { 85.18.0.137 1; 85.18.30.100 1; 85.18.30.101 1; +85.18.30.102 1; 85.18.30.103 1; 85.18.30.135 1; 85.18.30.137 1; @@ -968,6 +987,7 @@ geo $static_whitelisted { 85.18.30.8 1; 85.18.30.9 1; 85.18.87.101 1; +85.18.87.102 1; 85.18.87.104 1; 85.234.204.196 1; 85.234.204.198 1; @@ -979,7 +999,7 @@ geo $static_whitelisted { 86.127.118.135 1; 86.60.255.70 1; 87.199.3.5 1; -87.79.22.197 1; +87.79.22.228 1; 88.201.14.6 1; 88.201.15.4 1; 88.201.15.5 1; @@ -995,38 +1015,41 @@ geo $static_whitelisted { 89.111.192.6 1; 89.111.192.68 1; 89.111.192.69 1; +89.16.131.133 1; 89.201.175.164 1; 89.201.175.165 1; -89.201.175.166 1; 89.201.175.167 1; 89.205.125.4 1; 89.205.125.5 1; 89.205.125.6 1; 89.45.2.4 1; -90.160.195.6 1; +89.45.2.5 1; +90.160.195.4 1; 90.160.195.7 1; 91.102.199.228 1; 91.102.199.229 1; +91.149.142.228 1; 91.149.142.229 1; 91.185.4.165 1; 91.205.69.4 1; -91.205.69.5 1; 91.205.69.6 1; 91.232.101.197 1; 92.87.175.13 1; 92.87.175.15 1; 92.87.175.17 1; 92.87.175.7 1; -93.175.137.133 1; +92.87.175.8 1; +94.129.129.69 1; 94.198.143.164 1; +94.20.252.4 1; 94.228.16.166 1; 94.248.240.228 1; 94.248.240.229 1; 95.142.107.4 1; 95.142.107.5 1; 95.160.205.164 1; +95.160.205.167 1; 95.168.222.4 1; -95.168.222.8 1; 95.180.157.4 1; 95.180.157.5 1; 95.180.157.6 1; @@ -1764,6 +1787,7 @@ geo $static_whitelisted { 110.93.150.214 1; 110.93.150.215 1; 110.93.150.216 1; +110.93.150.217 1; 110.93.150.218 1; 110.93.150.219 1; 110.93.150.22 1; @@ -1771,6 +1795,7 @@ geo $static_whitelisted { 110.93.150.23 1; 110.93.150.24 1; 110.93.150.25 1; +110.93.150.26 1; 110.93.150.27 1; 110.93.150.28 1; 110.93.150.29 1; @@ -2385,6 +2410,8 @@ geo $static_whitelisted { 138.201.146.168 1; 138.201.61.185 1; 138.201.61.188 1; +146.185.240.112 1; +146.185.240.56 1; 149.72.131.196 1; 17.111.110.102 1; 17.111.110.108 1; @@ -5570,19 +5597,19 @@ geo $static_whitelisted { 17.58.106.86 1; 17.58.106.94 1; 17.58.106.99 1; -172.225.10.40 1; 172.225.10.41 1; -172.225.10.44 1; 172.225.10.45 1; -172.225.10.47 1; +172.225.100.135 1; 172.225.139.113 1; 172.225.145.127 1; 172.225.145.133 1; 172.225.156.148 1; 172.225.156.149 1; 172.225.176.240 1; +172.225.178.195 1; 172.225.181.90 1; 172.225.206.117 1; +172.225.224.136 1; 172.225.229.32 1; 172.225.244.182 1; 172.225.245.100 1; @@ -5590,19 +5617,16 @@ geo $static_whitelisted { 172.225.245.102 1; 172.225.250.120 1; 172.225.250.96 1; -172.225.253.65 1; -172.225.27.70 1; -172.225.43.177 1; 172.225.84.152 1; 172.225.84.155 1; -172.226.156.37 1; +172.226.134.48 1; 172.226.16.53 1; -172.226.16.68 1; 172.226.16.69 1; 172.226.214.32 1; 172.226.214.40 1; 172.226.214.44 1; 172.226.38.48 1; +172.226.38.51 1; 172.226.67.28 1; 172.226.96.35 1; 172.232.11.101 1; @@ -8125,13 +8149,13 @@ geo $static_whitelisted { 45.84.130.228 1; 45.84.130.233 1; 45.84.130.237 1; +45.84.130.238 1; 45.84.130.239 1; 45.84.130.241 1; 45.84.130.243 1; 45.84.130.244 1; 45.84.130.251 1; 46.165.223.16 1; -49.7.20.101 1; 49.7.20.104 1; 49.7.20.106 1; 49.7.20.107 1; @@ -8175,23 +8199,20 @@ geo $static_whitelisted { 49.7.20.83 1; 49.7.20.89 1; 49.7.20.90 1; -49.7.20.92 1; 49.7.20.95 1; 49.7.20.98 1; 49.7.20.99 1; 49.7.21.100 1; 49.7.21.104 1; 49.7.21.105 1; -49.7.21.107 1; 49.7.21.108 1; 49.7.21.110 1; +49.7.21.113 1; 49.7.21.114 1; 49.7.21.116 1; 49.7.21.121 1; 49.7.21.122 1; 49.7.21.123 1; -49.7.21.124 1; -49.7.21.126 1; 49.7.21.64 1; 49.7.21.65 1; 49.7.21.67 1; @@ -8200,8 +8221,8 @@ geo $static_whitelisted { 49.7.21.71 1; 49.7.21.73 1; 49.7.21.74 1; -49.7.21.76 1; 49.7.21.78 1; +49.7.21.80 1; 49.7.21.81 1; 49.7.21.83 1; 49.7.21.85 1; @@ -8518,6 +8539,7 @@ geo $static_whitelisted { 84.53.185.28 1; 84.53.185.7 1; 84.53.185.86 1; +87.239.107.213 1; 87.245.209.212 1; 87.245.209.220 1; 88.221.128.45 1; @@ -8531,7 +8553,6 @@ geo $static_whitelisted { 88.221.24.39 1; 88.221.87.46 1; 88.221.96.28 1; -89.208.197.192 1; 89.208.230.2 1; 92.122.154.108 1; 92.122.154.92 1; diff --git a/sysconfig/imunify360/imunify360-merged.config b/sysconfig/imunify360/imunify360-merged.config index c55ab41..400cf01 100644 --- a/sysconfig/imunify360/imunify360-merged.config +++ b/sysconfig/imunify360/imunify360-merged.config @@ -4,7 +4,8 @@ ############################################################################ ADMIN_CONTACTS: - emails: [] + emails: + - bogdan@898.ro enable_icontact_notifications: true AUTO_WHITELIST: after_unblock_timeout: 1440 @@ -23,7 +24,7 @@ CAPTCHA_DOS: time_frame: 21600 timeout: 864000 CSF_INTEGRATION: - catch_lfd_events: false + catch_lfd_events: true DOS: default_limit: 250 enabled: true @@ -81,12 +82,12 @@ KERNELCARE: LOGGER: backup_count: 5 max_log_file_size: 62914560 - syscall_monitor: true + syscall_monitor: false MALWARE_CLEANUP: keep_original_files_days: 14 trim_file_instead_of_removal: true MALWARE_DATABASE_SCAN: - enable: false + enable: true MALWARE_SCANNING: cloud_assisted_scan: true crontabs: false @@ -109,7 +110,7 @@ MALWARE_SCANNING: try_restore_from_backup_first: false MALWARE_SCAN_INTENSITY: cpu: 2 - io: 2 + io: 1 ram: 2048 user_scan_cpu: 2 user_scan_io: 2 @@ -121,9 +122,9 @@ MALWARE_SCAN_SCHEDULE: interval: week MOD_SEC: app_specific_ruleset: true - cms_account_compromise_prevention: false + cms_account_compromise_prevention: true prev_settings: '' - ruleset: FULL + ruleset: MINIMAL MOD_SEC_BLOCK_BY_CUSTOM_RULE: 33332: check_period: 120 @@ -142,12 +143,12 @@ NETWORK_INTERFACE: eth_device: null eth_device_skip: [] OSSEC: - active_response: false + active_response: true PAM: enable: true exim_dovecot_native: false exim_dovecot_protection: true - ftp_protection: false + ftp_protection: true PERMISSIONS: advisor: true allow_malware_scan: false @@ -185,7 +186,7 @@ STOP_MANAGING: WEBSHIELD: captcha_secret_key: '' captcha_site_key: '' - enable: true + enable: false invisible_captcha: false known_proxies_support: true splash_screen: true diff --git a/sysconfig/imunify360/imunify360.config b/sysconfig/imunify360/imunify360.config index 0967ef4..2fd3371 100644 --- a/sysconfig/imunify360/imunify360.config +++ b/sysconfig/imunify360/imunify360.config @@ -1 +1,21 @@ -{} +ADMIN_CONTACTS: + emails: + - bogdan@898.ro +CSF_INTEGRATION: + catch_lfd_events: true +LOGGER: + syscall_monitor: false +MALWARE_DATABASE_SCAN: + enable: true +MALWARE_SCAN_INTENSITY: + cpu: 2 + io: 1 +MOD_SEC: + cms_account_compromise_prevention: true + ruleset: MINIMAL +OSSEC: + active_response: true +PAM: + ftp_protection: true +WEBSHIELD: + enable: false diff --git a/systemd/system/multi-user.target.wants/imunify360-webshield.service b/systemd/system/multi-user.target.wants/imunify360-webshield.service deleted file mode 120000 index 00862d2..0000000 --- a/systemd/system/multi-user.target.wants/imunify360-webshield.service +++ /dev/null @@ -1 +0,0 @@ -/usr/lib/systemd/system/imunify360-webshield.service \ No newline at end of file