Imunify360: number of the failed captcha requests until block IP in the black list

Hi friends,

If you have installed Imunify360, you can see in "Firewall -> Black List" that Imunify add here an IP when fail 101 times the captcha requests . 101 is the default value.

I think that maybe this is a very big value: if a user fail 20-30 times the captcha request so is 100% safe that is a bot.

With this command we can change de dafault value:

Code:
imunify360-agent config update '{"CAPTCHA_DOS": {"max_count": 30}}'
You have any other value in your servers?, your recommend me change number of failed captcha request for block better the bots?. Or this can create any issue?.

Thank you very much. Have a nice day.


Similar Content



300 MB/s good for SSD?

Code:
 dd if=/dev/zero of=test bs=64k count=16k conv=fdatasync && rm -rf test
16384+0 records in
16384+0 records out
1073741824 bytes (1.1 GB) copied, 3.43371 s, 313 MB/s
Code:
 I/O Speed(1st run)    : 311 MB/s
 I/O Speed(2nd run)    : 333 MB/s
 I/O Speed(3rd run)    : 316 MB/s
 Average I/O speed     : 320.0 MB/s
Code:
fio Disk Speed Tests (Mixed R/W 50/50):
---------------------------------
Block Size | 4k            (IOPS) | 64k           (IOPS)
  ------   | ---            ----  | ----           ----
Read       | 129.06 MB/s  (32.2k) | 212.07 MB/s   (3.3k)
Write      | 129.40 MB/s  (32.3k) | 213.18 MB/s   (3.3k)
Total      | 258.47 MB/s  (64.6k) | 425.25 MB/s   (6.6k)
           |                      |
Block Size | 512k          (IOPS) | 1m            (IOPS)
  ------   | ---            ----  | ----           ----
Read       | 239.80 MB/s    (468) | 234.09 MB/s    (228)
Write      | 252.54 MB/s    (493) | 249.68 MB/s    (243)
Total      | 492.34 MB/s    (961) | 483.77 MB/s    (471)
Code:
ioping: seek rate
    min/avg/max/mdev = 158.9 us / 195.5 us / 1.41 ms / 21.4 us
ioping: sequential read speed
    generated 2.78 k requests in 5.00 s, 694 MiB, 555 iops, 138.8 MiB/s

dd: sequential write speed
    1st run:    293.73 MiB/s
    2nd run:    302.31 MiB/s
    3rd run:    306.13 MiB/s
    average:    300.73 MiB/s
Good for a SSD Dedicated Server?

Webserver: some requests are taking forever while all others are handled super fast - reason?

I'm hosting an online forum on this server:

Intel® Core i9-9900K (8 core) 128gb RAM NVMe SSD 2x1TB


running Ubuntu. I'm using Plesk for webserver configuration. My online forum is completely developed by me in PHP and JS. The site is using web-sockets for logged in users for chatting etc. I'm running the default configuration of Plesk for the most part with Nginx handling static files and otherwise forwarding the request to Apache. As explained by Plesk here.

I use the default nginx config with 1 worker_process and 1024 worker_connections. On PHP-FPM I use pm = static, max_requests = 2000 and max_children = 500. I have more than enough RAM left running the forum and also the CPU stays below 40% workload all the time.

Now the problem: Visiting the site on any browser works just fine. But then out of 20-30 ajax requests one just takes waaaay too long. Like every ajax request gets an instant answer and from time to time one takes >10 seconds, a few forever. And I have no clue why. I looked through nginx and website error logs and cannot find any answer to this problem.

I would be very happy about any possible hint. I know it's hard to guess based on the little information. But maybe someone here experienced something similiar?

Warning: MariaDB error in last cPanel version + Solution

Hi friends,

In last MariaDB version have an error which block cPanel Database interface with this message:

The MySQL server is currently offline.
The adminbin “cpmysql” in the “Cpanel” namespace call to function “DBCACHE” ended prematurely: The subprocess reported the “” (255) error when it ended Various sysadmins reported this error in cPanel forum, I too had him.

MariaDB version with error: 10.3.26

For solve him you have 2 posibilities:

1- Outdate to version 10.3.25, I solved him with this command:

Code:
yum downgrade MariaDB-server MariaDB-common MariaDB-shared MariaDB-client MariaDB-compat MariaDB-devel -y
2- Disable this option (this not works always, some sysadmins notified that need change MariaDB version to 10.3.25 for solve the problem):

Code:
WHM » Server Configuration » Tweak Settings » SQL » Use INFORMATION_SCHEMA to acquire MySQL disk usage
You have more information in cPanel forum: https://forums.cpanel.net/threads/th...ffline.474561/

I hope that this problem not broke your servers. Have a nice day.

Caution: PhoenixNAP/Secured Servers

Greetings WHT,

I wanted to issue a large dose of caution for fellow WHT users regarding our recent experience with PhoenixNAP/Secured Servers as their new policies run the possibility of breaking your integrations and create undue headache.

On May 7th, PhoenixNAP/Secured Servers sent an email to us asking us for feedback on a support ticket that had been opened, apparently on our behalf. We had no knowledge of this and our email filters actually flagged the message as SPAM. We found the email in the SPAM filter and it had a few obvious red flags. First, the ticket was titled "Password Rotations" and it came from their support at securedservers email, which is an email we typically do not get messages from. Obviously as soon as we read the message, we immediately reached out to them to find out who authorized the "password rotations" on a production, client facing server.

In speaking with their support agent via live chat, PhoenixNAP/Secured Servers has implemented a new company wide policy to start changing customer's root and user account passwords, without their permission, and without verifying with the customer. In the original email (which we did not get as it appears someone incorrectly opened the ticket in their system to show it was "us" that opened the ticket rather than the support agent), it states:

"Dear Customer,

We are notifying you that we have updated the root and user passwords for your
server in accordance with industry standard password maintenance
recommendations. We will continue to update the passwords on a regular schedule
that coincides with your patching schedule and the passwords will be posted to
your servers device page where you can view them in your portal. If you have any
questions please don't hesitate to contact us and we will be happy to answer
them.
Regards,"

The email is unsigned as to who sent it.

This server has their managed services on it at the client's request as they want a prompt response from the NOC should there be any issues, however the client did not, does not, and never asked for their passwords to be changed in this manner. As a result, our client experienced a broken integration for their custom environment, which we had to deal with their frustrations, (this is not the first time that PhoenixNAP/Secured Servers has broken this specific client's machine. They took the server offline for several hours back in December 2019, without permission, without a request to do so, and with no notice, because another customer of theirs opened a support request for a mem test. They also only gave us approximately a 10$ credit for their mistake.), and the best we get from them is, paraphrasing, "opps, sorry, but if you want this practice to stop, you need to drop the managed services."

We have less than 90 days left on the contract with them and have asked to be let out of that term so we can move our client to our primary datacenter vendor, with whom we know will not pull this kind of monkey poo with us. Thus far they are refusing to let us out per the "management team" so I have asked for a call directly with them. I'll update once that happens. This is the last machine we have with them and I am hoping our primary DC vendor can get us a deal to make this move happen as quickly as possible.

I'm not sure who in their right mind thinks its perfectly acceptable to randomly change a customer's root and user account passwords without their permission, knowledge, and without verifying with the customer if they even want this performed. Yes it's good practice to always change your passwords, however for a party who is once removed from the client, this should in no way be acceptable unless they have received, in writing, to do so. If this was one of our servers that housed our programs, I wouldn't be as upset about it, but when it starts affecting our client's and this is the second time you've done so, I am beyond upset. And the best you can do is offer us the 10$ credit in December and an empty apology this time around?

Word to the wise, if you're using PhoenixNAP/Secured Servers, watch your accounts closely, especially if you are using their managed services. They will monkey with your stuff without your permission.

James

Patriot Burst SSds any experience with them on servers in hardware raid?

I been using Crucial mx500s and they work fine, but need to change them out about every year just keep safe on nand wear on the hosting server. As was going go with higher wear drive to get 2 or 3+ years, but not seeing any available. I have used Patriot SSds in the past and notice they seem to fail with drive still readable to recover on home user computers more often then other drives in my personal experience. SO checking I notice the nand write endurance is over double of crucial. So I was just wondering if anyone has tried the Patriot burst on their servers or not and experience they have had. I am considering trying a couple.

Thanks in advance for any and all comments.

Paul

Hotmail/Outlook blocked server's IP, but this server not sent emails yet NEVER

This isn't serious. I bought a new server with a new IP, we not sent never emails yet.

When my client try to send email to Gmail, Yahoo and other companies receive him without problems. But Hotmail/Outlook block the IP and return this message:

Code:
"host hotmail-com.olc.protection.outlook.com [x.x.x.x]
SMTP error from remote mail server after pipelined MAIL FROM:email@email.com SIZE=1797:
550 5.7.1 Unfortunately, messages from [x.x.x.x] weren't sent. Please contact your Internet service provider since part of their network is on our block list (S3140). You can also refer your provider to http://mail.live.com/mail/troubleshooting.aspx#errors. [.eop-EUR01.prod.protection.outlook.com]"
WTF!!!, this is frustrating. How can happens this if we never used this server and have a new IP. I did test with many blacklist tools and the IP is clean.

Hotmail/Outlook need disapear, they are blocking IPs for nothing.

Scam Dedi Report. Server.Trading.

TLRD Version

1. Offer very attractive deal in Webhostingtalk
2. Offer to sign with Monthly + No Setup Fee
3. Once Payment Done. Tell You no Stock
4. Option = You have to pay 1 year in advance. (because no stock, they need to buy hardware) Or Refund
5. Ask to change to available spec, still refuse. Request buyer Pay 1 year in advance.
6. Request refund. >24hours, no more reply.
7. Still posting new threads to promote this "UNAVAILABLE" Package in Dedicated Server Offer section (After tell me there is no stock)

i cannot post link, 1st 5 post....
Follow This thread ID : ?t=1846296
Company : Server Trading

Communication
-----------------------------------
Good morning,
I'm sorry, but we do not have spare dedics with such configuration.
We can get such a server if you pay for a year.

If you want refund, please write to support@server.trading or create ticket in support panel.
If you want to pay for a year, please write there too.

Witold Filipczyk,
server.trading ( 1 Days ago )

-- > Request to change to other spec from me. ( 2cpu, 4gb ram, large storage, anything )

Sorry we don't have it. We can order one (one of 3 types), but if you buy dedic for a year.
Other way is not remunerative for us. Sorry.

-----------------------------------
Change to anything also REQUEST ME TO PAY 1 year upfront


This happened 24 hours ago, and i found they still ADVERTISE THIS PROMO fews hours ago in Webhostingtalk, Dedicated server offer section
Thread link ID : ?t=1846296 ( i cannot post link . new user )


-----------------------------------
Conclusion
1. They might Refund me. They might Not.
2. If they dont have the hardware, Why still push the Offer ?
3. In their website, Still allowed for monthly payment for ( Unavailable package )
4. Once you pay, You are trapped.

Basic questions about Cluster DNS configuration

Hi friends,

I configured a Cluster DNS with:

-1 Master server (WHM/cPanel)
-3 slave servers (with 3 VPS, cPanel DNSOnly): dns1.mydomain.com -> VPS 1, dns2.mydomain.com -> VPS 2, dns3.mydomain.com -> VPS3

But I have some questions and not found replies in google. I never used Cluster DNS (I always create 3 DNS for each webhosting server). This is the last step for finalize the migration's odyssey and can forgot the old server with her problems. I'll be very grateful if you reply me this last questions:

1- I goes to Master server (WHM/cPanel) -> DNS Cluster -> "Enable DNS Clustering". I need do the same step in Salve servers or not is needed?.

2- I went to Master server (WHM/cPanel) -> DNS Cluster -> Add a new server to the cluster -> Configure -> And I added the 3 slave servers here. I keep the default options: Setup Reverse Trust Relationship = Enabled, Synchronize Zones Immediately = Enabled, Debug mode = disabled, DNS Role = Standalone.

I need do the same step between the slave servers?, for example: go to to slave server 1 -> DNS Cluster -> Add a new server to the cluster -> Configure -> Add the SLAVE SERVER 2 AND 3.

Also I need add the master server to the slave servers?.

My current configuration is: ONLY ADDED SLAVE SERVERS TO MASTER SERVER.

3- The "Standalone" mode is the correct mode? or "Synchronize changes" is better?.

4- I added this 3 new DNS to the webhosting server (WHM/cPanel -> Basic WebHost Manager -> Nameservers). But I see that anybody can add my DNS to her WHM/cPanel and send her Zone DNS to my Cluster DNS. How can I block other webhosting servers and only permit Zone DNS from my webhosting servers?.

Thanks in advance. Have a nice day.

More email Deliverability problems WHM/cPanel

Hi,

I received some tickets from clients hosted in the old server that says have a problems when try to send emails.

I did some tests and when send email to some accounts I received this warning:

This message was created automatically by mail delivery software.

A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:

info@receiver.com
retry timeout exceeded
Reporting-MTA: dns; nameserver.domain.com

Action: failed
Final-Recipient: rfc822;info@receiver.com
Status: 5.0.0
From: info@sender.com
To: info@receiver.com Too I checked "Email Deliverability" in WHM and appear this message:

-DKIM: The system failed to complete validation of nameserver.domain.coms DKIM because of an error: (XID z736ms) DNS query (default._domainkey.nameserver.domain.com/TXT) timeout!
-SPF: This system does not control DNS for the nameserver.domain.com domain and the system did not find any authoritative nameservers for this domain. You can install the suggested SPF record locally. However, this server is not the authoritative nameserver. If you install this record, this change will not be effective. Contact your domain registrar to verify this domains registration.
-PTR: The system failed to complete validation of nameserver.domain.coms PTR because of an error: (XID 958s2v) DNS query (IP.in-addr.arpa/PTR) timeout!

The server where I have the DNS work correctly. Why happens this?. How can I solve him?.

Thank you very much for your suggestions. Have a nice day.

Create Live Streaming server

I want create Streaming server, i have more than 100K online users.
this is the first time that i will use servers for Streaming, so i want know how many servers i need for this number of online users?
Will I find support that can equip servers and link them together?