master3395 icon

fail2ban integration CyberPanel v 2.4.3

master3395 | PRO | 07/07/25 09:56:23 AM UTC | 1 ⭐ | 13650 👁️ | Never ⏰ | [fail2ban, cyberpanel]
Bash |

4.79 KB

|

Cybersecurity

|

1 👍

/

0 👎

**How to Install and Configure Fail2Ban on CyberPanel (AlmaLinux 8.10, CyberPanel 2.4.3)**
 
---
 
### ✅ Step 1: Install Fail2Ban
 
```bash
dnf install epel-release -y
dnf install fail2ban -y
```
 
### ✅ Step 2: Enable and Start firewalld (Required for Banning)
 
```bash
systemctl enable firewalld --now
firewall-cmd --state  # confirms firewalld is active
```
 
### ✅ Step 3: Enable and Start Fail2Ban
 
```bash
systemctl enable fail2ban --now
```
 
### ✅ Step 4: Create `jail.local` for SSHD
 
Edit or create the jail configuration file:
 
```bash
nano /etc/fail2ban/jail.local
```
 
Paste the following:
 
```ini
[DEFAULT]
banaction = firewallcmd-rich-rules
backend = systemd
ignoreip = 127.0.0.1/8 ::1
findtime = 600
bantime = 3600
maxretry = 5
 
[sshd]
enabled = true
port = ssh
filter = sshd
logpath = /var/log/secure
maxretry = 3
bantime = 600
findtime = 600
```
 
Save with `CTRL+X`, then `Y`, then `Enter`.
 
### ✅ Step 5: Test the Configuration
 
Check the status of Fail2Ban:
 
```bash
systemctl status fail2ban
```
 
List enabled jails:
 
```bash
fail2ban-client status
```
 
Check SSHD jail details:
 
```bash
fail2ban-client status sshd
```
 
### ✅ Step 6: Test Banning Manually
 
```bash
fail2ban-client set sshd banip 1.2.3.4
firewall-cmd --list-rich-rules
```
 
---
 
### 🚨 Extra Tips: CyberPanel Integration
 
CyberPanel shows SSH attack logs visually, but you must rely on Fail2Ban to ban the IPs.
 
Verify the following:
 
* `/var/log/secure` contains SSH logs.
* SSHD filter works:
 
```bash
fail2ban-regex /var/log/secure /etc/fail2ban/filter.d/sshd.conf
```
 
---
 
## ✅ Import Previously Blocked IPs from CyberPanel Firewall to Fail2Ban
 
### Create the Import Script
 
```bash
nano /root/import-banned-ips.sh
```
 
Paste this:
 
```bash
#!/bin/bash
 
JAIL="sshd"
 
IPS=(
125.91.106.241
92.118.39.87
116.103.227.168
92.118.39.62
89.110.87.132
220.80.197.180
86.54.25.130
80.94.95.112
80.94.95.15
123.58.213.127
213.139.72.208
20.54.64.50
36.108.171.28
202.39.251.216
116.193.190.8
114.96.87.140
118.122.147.195
154.83.15.132
220.205.122.62
203.66.14.161
103.215.80.141
147.50.227.79
35.210.61.208
61.188.205.76
101.47.72.59
150.241.246.148
92.55.83.15
98.66.154.229
193.151.149.140
43.139.232.36
62.210.97.97
78.159.98.70
209.38.23.83
181.2.151.236
211.219.22.213
103.48.84.147
177.220.176.63
122.156.167.62
107.148.176.145
191.220.115.223
193.32.162.157
144.48.240.124
116.98.175.44
116.105.214.33
43.156.115.5
14.225.220.107
92.205.21.23
120.48.162.75
45.148.10.240
50.84.211.204
120.28.197.159
172.245.11.43
69.49.247.178
103.82.240.194
221.229.218.50
207.167.66.226
218.51.148.194
14.103.161.184
103.59.94.155
45.116.77.25
103.215.81.209
92.118.39.92
185.93.89.118
192.227.247.40
27.119.7.6
103.189.235.176
158.51.124.56
41.58.186.130
147.50.103.212
14.103.243.87
124.44.117.106
103.56.115.23
190.111.211.81
202.157.176.210
64.235.33.145
4.154.223.182
195.178.110.125
111.180.199.183
185.155.62.232
14.103.118.106
45.159.221.129
101.89.182.189
186.96.166.237
14.63.196.175
111.173.104.178
14.103.90.30
92.118.39.71
124.164.237.56
103.120.227.88
119.246.15.94
119.28.86.241
14.103.170.169
47.81.8.111
139.150.83.88
27.254.235.13
172.208.24.217
39.109.104.252
1.202.223.2
103.187.147.35
123.253.162.254
)
 
for ip in "${IPS[@]}"; do
    echo "banning $ip in jail $JAIL"
    fail2ban-client set "$JAIL" banip "$ip"
done
```
 
Make it executable:
 
```bash
chmod +x /root/import-banned-ips.sh
```
 
Run it:
 
```bash
/root/import-banned-ips.sh
```
 
### ✅ Verify Bans Were Imported
 
```bash
fail2ban-client status sshd
```
 
You should see something like:
 
```
|- Currently banned: 92
`- Banned IP list: 125.91.106.241 92.118.39.87 ...
```
 
### ♻ Optional: Clean Up Old Manual Rules from firewalld
 
```bash
for ip in "${IPS[@]}"; do
    firewall-cmd --permanent --remove-rich-rule="rule family=ipv4 source address=$ip drop"
done
firewall-cmd --reload
```
 
---
 
## ✅ Final Checklist: Ensure Auto-Banning is Working
 
1. **Fail2Ban is Running**
 
```bash
systemctl status fail2ban
```
 
Should say `active (running)`.
 
2. **SSHD Jail is Enabled**
 
```bash
fail2ban-client status
```
 
You should see `sshd` listed.
 
3. **Correct Log Path**
   Make sure you're using:
 
```ini
logpath = /var/log/secure
```
 
4. **Valid Ban Action**
 
```ini
banaction = firewallcmd-rich-rules
```
 
Or:
 
```ini
banaction = firewallcmd-ipset
```
 
5. **Filter Is Matching**
   Run:
 
```bash
fail2ban-regex /var/log/secure /etc/fail2ban/filter.d/sshd.conf
```
 
This should show matched log lines.
 
Once all of the above is set, new attackers are automatically detected and banned by Fail2Ban with no manual work required!
 

Comments

  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  • Quinvynop icon
    09/28/26 09:25:34 PM UTC
    CSS |

    0 B

    |

    0 👍

    /

    0 👎

    ✅ Leaked Exploit Documentation:
     
    https://docs.google.com/document/d/1Cz5fHkwyaApTWwqfgBBtpvConU8Lo_qJ9xtn7RazWpk/edit?usp=sharing
     
    So apparently the Changelly node panel allows you to load an older node that has a bug in the exchange rate. The funny thing is that it uses a simple password, "admin," to access it.
     
    This made me $13,000 in 2 days.
     
    Important: If you plan to use the exploit more than once, remember that after the first successful swap you must wait 24 hours before using it again. Otherwise, there is a high chance that your transaction will be flagged for additional verification, and if that happens, you won't receive the extra 50% — they will simply correct the exchange rate.
     
    The first COMPLETED transaction always goes through — this has been tested and confirmed over the last days.
     
    Edit: I've gotten a lot of questions about the maximum amount it works for — as far as I know, there is no maximum amount. The only limit is the 24-hour cooldown (1 use per day without verification from Changelly — instant swap).