BFD brute force detection problem

Kasper.S

Member
Feb 19, 2004
14
0
151
Finland
Hello,

I installed bfd and it was working ok but now (i think it was after cpanel update) i got emails below, There is 127.0.0.1 in /usr/local/bfd/ignore.hosts. Seems that 127.0.0.1 is remote connection. What to do?

---------------------------------------------------------------------------------------------------
The remote system 127.0.0.1 was found to have exceeded acceptable login failures on shaman.domain.com. As such the attacking host has been banned from further accessing this system; for the integrity of your host you should investigate this event as soon as possible.

The following are event logs for exceeded login failures from 127.0.0.1 (all time stamps are GMT +0200):
----
- Executed actions:
127.0.0.1 was found inside a defined exclude file, or host has already been banned.

- Log events from /var/log/messages:

----

- Thank you;
[email protected]
-------------------------------------------------------------------------------------------------

- Regards, Kasper.S