Skip to main content

How do I best handle cphulk reports and emails and IPs?

Comments

1 comment

  • cPanelMichael
    Hello :) The notification you received indicates someone logged in as "root" under that IP address. Since it was through SSH, you can browse /var/log/secure to see if the log indicates any information about the login from that IP. Blacklisting IP addresses in cPHulk is fine, but generally if you know the IP addresses that should have access you could use "Host Access Control" in WHM to only allow access to those services from specified IP addresses. Also, administrators will typically block IP addresses with excessive failed login attempts in their firewall (CSF is often used). Thank you.
    0

Please sign in to leave a comment.