Skip to main content

POST /login/?login_only=1 HTTP/1.1 entries in access log

Comments

5 comments

  • Infopro
    More of the message should say: FAILED LOGIN cpaneld: invalid cpanel user
    0
  • Amgeek
    More of the message should say: FAILED LOGIN cpaneld: invalid cpanel user

    Thanks. Don't see that in the access.log. I looked there because I saw that The file "login_log" does not include successful authentications. So, since it is in the access.log file I assumed it had been successfull and so was wondering what the codes meant.
    0
  • Infopro
    Do you have CSF installed? I get emails about these failed logins all the time.
    0
  • Amgeek
    Do you have CSF installed? I get emails about these failed logins all the time.

    Yes I do. That is what peaked my interest. Have gotten emails saying so and so failed attempt to log into one account or another (usually not a real account name but close enough to make you think they knew something). I understand failed attempts are to be expected and it is good news - the firewall is really working. My concern was what if they succeed, how would I know, that led me to the access.log which, as I understand it, logs successful attempts. I find several entries in the access.log from suspicious IPs with the codes in my first post. I don't know what those codes mean they succeeded in doing.
    0
  • Infopro
    usually not a real account name but close enough to make you think they knew something

    When you create an account, if you don't specify a unique username the system defaults to using some part of the domain name itself. I suppose that's one reason why the attempted login might be close at times. Enabling cPanel login alerts in the users cPanel in Contact Preferences, configuring cPHulk and CSF for logins, can all be useful. Enabling two-Factor Authentication is a really good way to lock user accounts down as well. Using Two-Factor for all logins you possibly can, including on these very forums, is suggested.
    0

Please sign in to leave a comment.