Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Topics - Babynemo

Pages: [1]
1
Yesterday i did the MariaDB-Server 10.2 update

https://wiki.centos-webpanel.com/mariadb-upgrade-to-new-version

Now firewall blocks CWP, SSH, Apache and other Ports. How can i fix this as best?

Did disable CFS and Blocked things are working...

Code: [Select]
service mysqld status
 ERROR! MariaDB is running but PID file could not be found

Log information extracted from: "/var/log/lfd.log" (last 200 lines)

Code: [Select]
May 23 07:39:25 srv1 lfd[27234]: *System Integrity* has detected modified file(s): /usr/bin/agentxtrap /usr/bin/aria_chk /usr/bin/aria_dump_log /usr/bin/aria_ftdump /usr/bin/aria_pack /usr/bin/aria_read_log /usr/bin/arpaname /usr/bin/at /usr/bin/atq /usr/bin/atrm /usr/bin/bootctl /usr/bin/busctl /usr/bin/clambc /usr/bin/clamconf /usr/bin/clamdscan /usr/bin/clamdtop /usr/bin/clamscan /usr/bin/clamsubmit /usr/bin/coredumpctl /usr/bin/corepack /usr/bin/cpupower /usr/bin/crontab /usr/bin/delv /usr/bin/dig /usr/bin/freshclam /usr/bin/funzip /usr/bin/getconf /usr/bin/grub2-editenv /usr/bin/grub2-file /usr/bin/grub2-fstest /usr/bin/grub2-glue-efi /usr/bin/grub2-menulst2cfg /usr/bin/grub2-mkfont /usr/bin/grub2-mkimage /usr/bin/grub2-mklayout /usr/bin/grub2-mknetdir /usr/bin/grub2-mkpasswd-pbkdf2 /usr/bin/grub2-mkrelpath /usr/bin/grub2-mkrescue /usr/bin/grub2-mkstandalone /usr/bin/grub2-render-label /usr/bin/grub2-script-check /usr/bin/grub2-syslinux2cfg /usr/bin/gzip /usr/bin/host /usr/bin/hostnamectl /usr/bin/innochecksum /usr/bin/journalctl /usr/bin/kernel-install /usr/bin/localectl /usr/bin/loginctl /usr/bin/machinectl /usr/bin/mariadb_config /usr/bin/mdig /usr/bin/myisamchk /usr/bin/myisam_ftdump /usr/bin/myisamlog /usr/bin/myisampack /usr/bin/my_print_defaults
/usr/bin/mysql /usr/bin/mysqladmin /usr/bin/mysqlbinlog /usr/bin/mysqlbug /usr/bin/mysqlcheck /usr/bin/mysql_config /usr/bin/mysqld_multi /usr/bin/mysqld_safe /usr/bin/mysqld_safe_helper /usr/bin/mysqldump /usr/bin/mysql_embedded /usr/bin/mysqlimport /usr/bin/mysql_install_db /usr/bin/mysql_plugin /usr/bin/mysql_setpermission /usr/bin/mysqlshow /usr/bin/mysqlslap /usr/bin/mysql_tzinfo_to_sql /usr/bin/mysql_upgrade /usr/bin/mysql_waitpid /usr/bin/mysql_zap /usr/bin/named-rrchecker /usr/bin/node /usr/bin/nslookup /usr/bin/nsupdate /usr/bin/openssl /usr/bin/perror /usr/bin/pkaction /usr/bin/pkcheck /usr/bin/pkexec /usr/bin/pkttyagent /usr/bin/replace /usr/bin/resolveip /usr/bin/resolve_stack_dump /usr/bin/sasl2-sample-client /usr/bin/sasl2-sample-server /usr/bin/sigtool /usr/bin/systemctl /usr/bin/systemd-analyze /usr/bin/systemd-ask-password /usr/bin/systemd-cat /usr/bin/systemd-cgls /usr/bin/systemd-cgtop /usr/bin/systemd-coredumpctl /usr/bin/systemd-delta /usr/bin/systemd-detect-virt /usr/bin/systemd-escape /usr/bin/systemd-firstboot /usr/bin/systemd-hwdb /usr/bin/systemd-inhibit /usr/bin/systemd-loginctl /usr/bin/systemd-machine-id-setup /usr/bin/systemd-notify /usr/bin/systemd-nspawn /usr/bin/systemd-path /usr/bin/systemd-run /usr/bin/systemd-stdio-bridge /usr/bin/systemd-tmpfiles /usr/bin/systemd-tty-ask-password-agent /usr/bin/timedatectl /usr/bin/tokuftdump /usr/bin/tokuft_logprint /usr/bin/udevadm /usr/bin/unzip /usr/bin/unzipsfx /usr/bin/wsrep_sst_common /usr/bin/wsrep_sst_mariabackup /usr/bin/
wsrep_sst_mysqldump /usr/bin/wsrep_sst_rsync /usr/bin/wsrep_sst_rsync_wan /usr/bin/wsrep_sst_xtrabackup /usr/bin/wsrep_sst_xtrabackup-v2 /usr/bin/xmlwf /usr/bin/zgrep /usr/bin/zipinfo /usr/sbin/anacron /usr/sbin/atd /usr/sbin/clamd /usr/sbin/clamonacc /usr/sbin/crond /usr/sbin/ddns-confgen /usr/sbin/dnssec-dsfromkey /usr/sbin/dnssec-importkey /usr/sbin/dnssec-keyfromlabel /usr/sbin/dnssec-keygen /usr/sbin/dnssec-revoke /usr/sbin/dnssec-settime /usr/sbin/dnssec-signzone /usr/sbin/dnssec-verify /usr/sbin/genrandom /usr/sbin/grub2-bios-setup /usr/sbin/grub2-install /usr/sbin/grub2-macbless /usr/sbin/grub2-ofpathname /usr/sbin/grub2-probe /usr/sbin/grub2-rpm-sort /usr/sbin/grub2-sparc64-setup /usr/sbin/halt /usr/sbin/iconvconfig /usr/sbin/iconvconfig.x86_64 /usr/sbin/init /usr/sbin/isc-hmac-fixup /usr/sbin/lwresd
/usr/sbin/mysqld /usr/sbin/named /usr/sbin/named-checkconf /usr/sbin/named-checkzone /usr/sbin/named-compilezone /usr/sbin/named-journalprint /usr/sbin/nsec3hash /usr/sbin/pluginviewer /usr/sbin/poweroff /usr/sbin/rcmysql /usr/sbin/reboot /usr/sbin/rndc /usr/sbin/rndc-confgen /usr/sbin/rsyslogd /usr/sbin/runlevel /usr/sbin/sasl2-shared-mechlist /usr/sbin/saslauthd /usr/sbin/sasldblistusers2 /usr/sbin/saslpasswd2 /usr/sbin/shutdown /usr/sbin/snmpd /usr/sbin/snmptrapd /usr/sbin/telinit /usr/sbin/testsaslauthd /usr/sbin/tsig-keygen /usr/sbin/udevadm /bin/agentxtrap /bin/aria_chk /bin/aria_dump_log /bin/aria_ftdump /bin/aria_pack /bin/aria_read_log /bin/arpaname /bin/at /bin/atq /bin/atrm /bin/bootctl /bin/busctl /bin/clambc /bin/clamconf /bin/clamdscan /bin/clamdtop /bin/clamscan /bin/clamsubmit /bin/coredumpctl /bin/corepack /bin/cpupower /bin/crontab /bin/delv /bin/dig /bin/freshclam /bin/funzip /bin/getconf /bin/grub2-editenv /bin/grub2-file /bin/grub2-fstest /bin/grub2-glue-efi /bin/grub2-menulst2cfg /bin/grub2-mkfont /bin/grub2-mkimage /bin/grub2-mklayout /bin/grub2-mknetdir /bin/grub2-mkpasswd-pbkdf2 /bin/grub2-mkrelpath /bin/grub2-mkrescue /bin/grub2-mkstandalone /bin/grub2-render-label /bin/grub2-script-check /bin/grub2-syslinux2cfg /bin/gzip /bin/host /bin/hostnamectl /bin/innochecksum /bin/journalctl /bin/kernel-install /bin/localectl /bin/loginctl /bin/machinectl /bin/mariadb_config /bin/mdig /bin/myisamchk /bin/myisam_ftdump /bin/myisamlog /bin/myisampack /bin/my_print_defaults
/bin/mysql /bin/mysqladmin /bin/mysqlbinlog /bin/mysqlbug /bin/mysqlcheck /bin/mysql_config /bin/mysqld_multi /bin/mysqld_safe /bin/mysqld_safe_helper /bin/mysqldump /bin/mysql_embedded /bin/mysqlimport /bin/mysql_install_db /bin/mysql_plugin /bin/mysql_setpermission /bin/mysqlshow /bin/mysqlslap /bin/mysql_tzinfo_to_sql /bin/mysql_upgrade /bin/mysql_waitpid /bin/mysql_zap /bin/named-rrchecker /bin/node /bin/nslookup /bin/nsupdate /bin/openssl /bin/perror /bin/pkaction /bin/pkcheck /bin/pkexec /bin/pkttyagent /bin/replace /bin/resolveip /bin/resolve_stack_dump /bin/sasl2-sample-client /bin/sasl2-sample-server /bin/sigtool /bin/systemctl /bin/systemd-analyze /bin/systemd-ask-password /bin/systemd-cat /bin/systemd-cgls /bin/systemd-cgtop /bin/systemd-coredumpctl /bin/systemd-delta /bin/systemd-detect-virt /bin/systemd-escape /bin/systemd-firstboot /bin/systemd-hwdb /bin/systemd-inhibit /bin/systemd-loginctl /bin/systemd-machine-id-setup /bin/systemd-notify /bin/systemd-nspawn /bin/systemd-path /bin/systemd-run /bin/systemd-stdio-bridge /bin/systemd-tmpfiles /bin/systemd-tty-ask-password-agent /bin/timedatectl /bin/tokuftdump /bin/tokuft_logprint /bin/udevadm /bin/unzip /bin/unzipsfx /bin/wsrep_sst_common /bin/wsrep_sst_mariabackup /bin/wsrep_sst_mysqldump /bin/wsrep_sst_rsync /bin/wsrep_sst_rsync_wan /bin/wsrep_sst_xtrabackup /bin/wsrep_sst_xtrabackup-v2 /bin/xmlwf /bin/zgrep /bin/zipinfo /sbin/anacron /sbin/atd /sbin/clamd /sbin/clamonacc /sbin/crond /sbin/ddns-confgen /sbin/dnssec-dsfromkey /sbin/dnssec-importkey /sbin/dnssec-keyfromlabel /sbin/dnssec-keygen /sbin/dnssec-revoke /sbin/dnssec-settime /sbin/dnssec-signzone /sbin/dnssec-verify /sbin/genrandom /sbin/grub2-bios-setup /sbin/grub2-install /sbin/grub2-macbless /sbin/grub2-ofpathname /sbin/grub2-probe /sbin/grub2-rpm-sort /sbin/grub2-sparc64-setup /sbin/halt /sbin/iconvconfig /sbin/iconvconfig.x86_64 /sbin/init /sbin/isc-hmac-fixup /sbin/lwresd /sbin/mysqld /sbin/named /sbin/named-checkconf /sbin/named-checkzone /sbin/named-compilezone /sbin/named-journalprint /sbin/nsec3hash /sbin/pluginviewer /sbin/poweroff /sbin/rcmysql /sbin/reboot /sbin/rndc /sbin/rndc-confgen /sbin/rsyslogd /sbin/runlevel /sbin/sasl2-shared-mechlist /sbin/saslauthd /sbin/sasldblistusers2 /sbin/saslpasswd2 /sbin/shutdown /sbin/snmpd /sbin/snmptrapd /sbin/telinit /sbin/testsaslauthd /sbin/tsig-keygen /sbin/udevadm /etc/init.d/mysql /etc/init.d/mysqld
May 23 08:39:21 srv1 lfd[1799]: CC Error: Country Code Lookups setting MM_LICENSE_KEY must be set in /etc/csf/csf.conf to continue using the MaxMind databases
May 24 00:00:02 srv1 lfd[1799]: Main Process: TERM
May 24 00:00:02 srv1 lfd[1799]: daemon stopped
May 24 00:00:03 srv1 lfd[19941]: daemon started on srv1.mymymy.haus - csf v14.16 (CentOS Web Panel)
May 24 00:00:03 srv1 lfd[19941]: LF_APACHE_ERRPORT: Set to [2]
May 24 00:00:03 srv1 lfd[19941]: Restricted log file access (RESTRICT_SYSLOG)
May 24 00:00:03 srv1 lfd[19941]: RESTRICT_SYSLOG: Option LF_SSHD *Disabled*
May 24 00:00:03 srv1 lfd[19941]: RESTRICT_SYSLOG: Option LF_FTPD *Disabled*
May 24 00:00:03 srv1 lfd[19941]: RESTRICT_SYSLOG: Option LF_IMAPD *Disabled*
May 24 00:00:03 srv1 lfd[19941]: RESTRICT_SYSLOG: Option LF_POP3D *Disabled*
May 24 00:00:03 srv1 lfd[19941]: RESTRICT_SYSLOG: Option LF_SSH_EMAIL_ALERT *Disabled*
May 24 00:00:03 srv1 lfd[19941]: RESTRICT_SYSLOG: Option LF_SU_EMAIL_ALERT *Disabled*
May 24 00:00:03 srv1 lfd[19941]: RESTRICT_SYSLOG: Option LF_CONSOLE_EMAIL_ALERT *Disabled*
May 24 00:00:03 srv1 lfd[19941]: RESTRICT_SYSLOG: Option LF_WEBMIN_EMAIL_ALERT *Disabled*
May 24 00:00:03 srv1 lfd[19941]: CSF Tracking...
May 24 00:00:03 srv1 lfd[19941]: IPv6 Enabled...
May 24 00:00:03 srv1 lfd[19941]: LOAD Tracking...
May 24 00:00:03 srv1 lfd[19941]: *ERROR*: Country Code Lookups setting MM_LICENSE_KEY must be set in /etc/csf/csf.conf to continue updating the MaxMind databases
May 24 00:00:03 srv1 lfd[19941]: Country Code Lookups...
May 24 00:00:03 srv1 lfd[19941]: CC Error: Country Code Filters setting MM_LICENSE_KEY must be set in /etc/csf/csf.conf to continue using the MaxMind databases
May 24 00:00:03 srv1 lfd[19941]: *ERROR*: Country Code Filters setting MM_LICENSE_KEY must be set in /etc/csf/csf.conf to continue updating the MaxMind databases
May 24 00:00:03 srv1 lfd[19941]: Country Code Filters...
May 24 00:00:03 srv1 lfd[19941]: CC Error: Country Code Lookups setting MM_LICENSE_KEY must be set in /etc/csf/csf.conf to continue using the MaxMind databases
May 24 00:00:03 srv1 lfd[19941]: System Integrity Tracking...
May 24 00:00:03 srv1 lfd[19941]: Exploit Tracking...
May 24 00:00:03 srv1 lfd[19941]: Directory Watching...
May 24 00:00:03 srv1 lfd[19941]: Temp to Perm Block Tracking...
May 24 00:00:03 srv1 lfd[19941]: Process Tracking...
May 24 00:00:03 srv1 lfd[19941]: Account Tracking...
May 24 00:00:03 srv1 lfd[19941]: Watching /var/log/messages...
May 24 00:00:03 srv1 lfd[19941]: Watching /var/log/secure...
May 24 00:00:03 srv1 lfd[19941]: Watching /var/log/customlog...
May 24 00:00:03 srv1 lfd[19941]: Watching /usr/local/apache/logs/error_log...
May 24 00:00:03 srv1 lfd[19941]: Watching /var/log/cwp_client_login.log...
May 24 01:00:05 srv1 lfd[19941]: CC Error: Country Code Lookups setting MM_LICENSE_KEY must be set in /etc/csf/csf.conf to continue using the MaxMind databases



Found only this in a similar case:
https://forum.configserver.com/viewtopic.php?t=7743

I think i have to edit the csf.pėgnore,

but how?

2
Hello,
i am wondering why /etc/csf/csf.error
does not exist. If i create this file and reastart csf and lfd, the file automatically gets deleted. Can i change somewhere the path to csf.error config?

Other Point is, that  /etc/init.d/lfd status does not exist in this directory.

Latest lfd error log: 

Jul 19 08:07:10 srv1 lfd[997]: csf (re)start requested - running *csf startup*...
Jul 19 08:07:13 srv1 lfd[997]: csf (re)start completed
Jul 19 08:14:55 srv1 lfd[997]: Main Process: TERM
Jul 19 08:14:55 srv1 lfd[997]: daemon stopped
Jul 19 08:14:55 srv1 lfd[2652]: daemon started on srv1.mymymy.haus - csf v13.04 (generic)
Jul 19 08:14:56 srv1 lfd[2652]: LF_APACHE_ERRPORT: Set to [2]
Jul 19 08:14:56 srv1 lfd[2652]: Restricted log file access (RESTRICT_SYSLOG)
Jul 19 08:14:56 srv1 lfd[2652]: RESTRICT_SYSLOG: Option LF_SSHD *Disabled*
Jul 19 08:14:56 srv1 lfd[2652]: RESTRICT_SYSLOG: Option LF_FTPD *Disabled*
Jul 19 08:14:56 srv1 lfd[2652]: RESTRICT_SYSLOG: Option LF_IMAPD *Disabled*
Jul 19 08:14:56 srv1 lfd[2652]: RESTRICT_SYSLOG: Option LF_POP3D *Disabled*
Jul 19 08:14:56 srv1 lfd[2652]: RESTRICT_SYSLOG: Option LF_SSH_EMAIL_ALERT *Disabled*
Jul 19 08:14:56 srv1 lfd[2652]: RESTRICT_SYSLOG: Option LF_SU_EMAIL_ALERT *Disabled*
Jul 19 08:14:56 srv1 lfd[2652]: RESTRICT_SYSLOG: Option LF_CONSOLE_EMAIL_ALERT *Disabled*
Jul 19 08:14:56 srv1 lfd[2652]: RESTRICT_SYSLOG: Option LF_WEBMIN_EMAIL_ALERT *Disabled*
Jul 19 08:14:56 srv1 lfd[2652]: CSF Tracking...
Jul 19 08:14:56 srv1 lfd[2652]: IPv6 Enabled...
Jul 19 08:14:56 srv1 lfd[2652]: LOAD Tracking...
Jul 19 08:14:56 srv1 lfd[2652]: Country Code Filters...
Jul 19 08:14:56 srv1 lfd[2652]: Country Code Lookups...
Jul 19 08:14:56 srv1 lfd[2652]: System Integrity Tracking...
Jul 19 08:14:56 srv1 lfd[2652]: Exploit Tracking...
Jul 19 08:14:56 srv1 lfd[2667]: CC: Processing GeoLite2 CSV Country/ASN database
Jul 19 08:14:56 srv1 lfd[2652]: Directory Watching...
Jul 19 08:14:56 srv1 lfd[2652]: Temp to Perm Block Tracking...
Jul 19 08:14:56 srv1 lfd[2652]: Process Tracking...
Jul 19 08:14:56 srv1 lfd[2652]: Account Tracking...
Jul 19 08:14:56 srv1 lfd[2652]: Watching /var/log/messages...
Jul 19 08:14:56 srv1 lfd[2652]: Watching /var/log/secure...
Jul 19 08:14:56 srv1 lfd[2652]: Watching /var/log/customlog...
Jul 19 08:14:56 srv1 lfd[2652]: Watching /usr/local/apache/logs/error_log...
Jul 19 08:14:56 srv1 lfd[2652]: Watching /var/log/cwp_client_login.log...
Jul 19 08:14:59 srv1 lfd[2667]: CC: Extracting zone from GeoLite2 CSV Country/ASN database for [UK]
Jul 19 08:14:59 srv1 lfd[2667]: CC: No entries found for [UK] in /var/lib/csf/Geo/GeoLite2-Country-Blocks-IPv4.csv
Jul 19 08:14:59 srv1 lfd[2667]: CC: Repopulating ipset cc_cn with IP addresses from [CN]
Jul 19 08:14:59 srv1 lfd[2667]: IPSET: loading set new_cn with 7219 entries
Jul 19 08:14:59 srv1 lfd[2667]: IPSET: switching set new_cn to cc_cn
Jul 19 08:14:59 srv1 lfd[2667]: CC: Repopulating ipset cc_in with IP addresses from [IN]
Jul 19 08:14:59 srv1 lfd[2667]: IPSET: loading set new_in with 6208 entries
Jul 19 08:14:59 srv1 lfd[2667]: IPSET: switching set new_in to cc_in
Jul 19 08:14:59 srv1 lfd[2667]: *Error* IPSET: [ipset v6.38: Sets cannot be swapped: the second set does not exist]
Jul 19 08:14:59 srv1 lfd[2667]: CC: Repopulating ipset cc_ro with IP addresses from [RO]
Jul 19 08:14:59 srv1 lfd[2667]: IPSET: loading set new_ro with 2942 entries
Jul 19 08:15:00 srv1 lfd[2667]: IPSET: switching set new_ro to cc_ro
Jul 19 08:15:00 srv1 lfd[2667]: *Error* IPSET: [ipset v6.38: Sets cannot be swapped: the second set does not exist]
Jul 19 08:15:00 srv1 lfd[2667]: CC: Repopulating ipset cc_ru with IP addresses from [RU]
Jul 19 08:15:00 srv1 lfd[2667]: IPSET: loading set new_ru with 9648 entries
Jul 19 08:15:00 srv1 lfd[2667]: IPSET: switching set new_ru to cc_ru
Jul 19 08:15:00 srv1 lfd[2667]: *Error* IPSET: [ipset v6.38: Sets cannot be swapped: the second set does not exist]
Jul 19 08:15:00 srv1 lfd[2667]: CC: Repopulating ipset cc_br with IP addresses from

Jul 19 08:15:00 srv1 lfd[2667]: IPSET: loading set new_br with 5387 entries
Jul 19 08:15:00 srv1 lfd[2667]: IPSET: switching set new_br to cc_br
Jul 19 08:15:00 srv1 lfd[2667]: *Error* IPSET: [ipset v6.38: Sets cannot be swapped: the second set does not exist]
Jul 19 08:15:00 srv1 lfd[2667]: CC: Repopulating ipset cc_ua with IP addresses from [UA]
Jul 19 08:15:01 srv1 lfd[2667]: IPSET: loading set new_ua with 3577 entries
Jul 19 08:15:01 srv1 lfd[2667]: IPSET: switching set new_ua to cc_ua
Jul 19 08:15:01 srv1 lfd[2667]: *Error* IPSET: [ipset v6.38: Sets cannot be swapped: the second set does not exist]
Jul 19 08:15:06 srv1 lfd[2652]: csf (re)start requested - running *csf startup*...
Jul 19 08:15:09 srv1 lfd[2652]: csf (re)start completed


Thanks.

Pages: [1]