Hi Team,
We have an ongoing issue with the global whitelisting that imunify360 sets and enables. it leads to a big flaw in your product that needs to be addressed
Over the course of the last year several times we have seen IP addresses that are involved in repeated incidents and never get blocked. Often as obvious as repeated SSH bruteforces
We only see this because we have CSF integrated and it places a block, and then imunify360 removes it. over and over
Each time we have reported it to imunify360 they advise it's because the IP is listed in a imunify360 global white list.
This is a huge problem and has reduced the trust we have in the firewall product altogether. You cant be whitelisting IP's that are obviously involved in an attack thereby giving them unlimited attempts at attacks.
Over the year this has happened numerous times and it seems to most often be russian IP's example of a recent IP - 178.154.203.82
Here is another CSF log today
Time: Thu Feb 2 03:41:12 2023 +1100
IP: 130.193.42.43 (RU/Russia/-)
Failures: 3 (sshd)
Interval: 3600 seconds
Blocked: Permanent Block [LF_SSHD]
This whitelist needs to be cleaned and maintained more often. i would suggest repeated failures from a whitelisted IP flag for investigation or similar.
Any ideas how i can increase the trust i can have in imunify360?
We have an ongoing issue with the global whitelisting that imunify360 sets and enables. it leads to a big flaw in your product that needs to be addressed
Over the course of the last year several times we have seen IP addresses that are involved in repeated incidents and never get blocked. Often as obvious as repeated SSH bruteforces
We only see this because we have CSF integrated and it places a block, and then imunify360 removes it. over and over
Each time we have reported it to imunify360 they advise it's because the IP is listed in a imunify360 global white list.
This is a huge problem and has reduced the trust we have in the firewall product altogether. You cant be whitelisting IP's that are obviously involved in an attack thereby giving them unlimited attempts at attacks.
Over the year this has happened numerous times and it seems to most often be russian IP's example of a recent IP - 178.154.203.82
Here is another CSF log today
Time: Thu Feb 2 03:41:12 2023 +1100
IP: 130.193.42.43 (RU/Russia/-)
Failures: 3 (sshd)
Interval: 3600 seconds
Blocked: Permanent Block [LF_SSHD]
This whitelist needs to be cleaned and maintained more often. i would suggest repeated failures from a whitelisted IP flag for investigation or similar.
Any ideas how i can increase the trust i can have in imunify360?
Comment