aaPanel_Jose thanks. I just installed the free firewall whiteout any problems.
Third-party plug-in for aaPanel [Nginx Free Firewall]
can't install
- Edited
I can't update it from version 1.0 to version 5.0
I don't want to uninstall and reinstall because other people in here say they can't install it.
I don't want to lose my settings either.
Here's a video of what I get:
https://streamable.com/8zupzh
I can't download the plugin!
When I click "download" it redirects me to a login page.
What do I do?
@Pedro@MD#20053
Good afternoon, Sir.
You need to log in your aapanel account, login again, and then purchase and install.
If you have already logged in, try logging out again.
If it still cannot be installed, please send your aapanel account, the link of aapanel login and the account password to my email, and I will check it.
My email ID is: sniper@aapanel.com
185.191.171.13 - - [30/Sep/2021:10:46:22 +0300] "GET /home/Search/index.html?a_id=8_60_50_133_64&cate_id=75 HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; SemrushBot/7bl; +http://www.semrush.com/bot.html)"
185.191.171.20 - - [30/Sep/2021:10:46:25 +0300] "GET /home/Search/index.html?a_id=46_3_61_7_23_65&cate_id=75 HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; SemrushBot/7bl; +http://www.semrush.com/bot.html)"
185.191.171.20 - - [30/Sep/2021:10:46:25 +0300] "GET /home/Search/index.html?a_id=46_3_61_7_23_65&cate_id=75 HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; SemrushBot/7bl; +http://www.semrush.com/bot.html)"
114.119.135.199 - - [30/Sep/2021:10:46:26 +0300] "GET /home/Search/index.html?cate_id=573&key=2&order=2 HTTP/1.1" 200 46400 "-" "Mozilla/5.0 (Linux; Android 7.0AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; PetalBot;+https://webmaster.petalsearch.com/site/petalbot)"
-nginx-free-firewall does not block bots on IP, and does not block the URL.
Can you fix it?
Spido try this:
https://www.aapanel.com/forum/d/4237-nginx-free-firewall-modified-ua-filter-saved-me-1000-requests-in-12
my current filter is:
(HTTrack|Apache-HttpClient|harvest|dirbuster|pangolin|nmap|sqln|hydra|Parser|libwww|BBBike|sqlmap|w3af|owasp|Nikto|fimap|havij|zmeu|BabyKrokodil|netsparker|httperf|BLEXBot|barkrowler|SemrushBot|MJ12Bot|Nutch|MBCrawler|MegaIndex|GrapeshotCrawler|CriteoBot|admantx|newspaper|CF-UC|comscore|Zoominfobot|SeznamBot|Java| SF/)
jazz1611 This type of problem you do not solve with firewall, you are getting an application attack, this type of attack needs to be mitigated with htaccess. If you wish I'm an information security engineer, I can help you with that.
we need update plz
@aaPanel_Jose @aapanel_sniper any plan to support nginx free firewall on ARM instance please? If using nginx and nginx free firewall then nginx cannot run after reboot until uninstall nginx free firewall on ARM instance.
Hello aaP_Rajib
We are still working on the compatibility of the arm platform
aaPanel_Jose thanks for the quick response. Looking forward to it. While talking about ARM support, mail server also not supposed yet. Hope can look into that also.
False positive submit is failing.
How to set whitelist ip range ipv4 and ipv6 cloudflare as in fail2ban? Sometimes this app blocks cloudflare. I use this app because it is more effective in securing the server from ddos ββattacks than fail2ban.
adis0308
hello, try to set in ip whitelist
- Edited
Hi,
In URL blacklist, what should be the correct syntax to disallow all readme.txt file from all my web site ?
I want to disallow this /wp-content/plugins/contact-form-7/readme.txt but I don't want to set all my wordpress full paths one by one.
Raffi
Hi, try this, is it ok?
^/readme.txt
no
I had already tried, but as the syntax is particular there I just made with a copy/paste of your message.
Raffi
First check whether the firewall is in effect:
Is there any interception of using a browser to access the link? Replace xxx.com with your domain name. http://www.xxx.com/?id=1%27union%20select%20user(),1,3--
Effective diagram: