I have searched for and tried just about everything I can in regards to this particular problem but I am still without resolution and the timer is ticking. I have tried reinstalling Fail2ban several times, I have looked ant error logs, configuration files, etc and think I know what the problem is but I don’t know how to resolve it. The biggest issue is that I work remotely and can only access the server via the web GUI as I can’t even SSH. Putty gives me Connection Error: Connection Refused so I have to have someone, usually my assistant but he’s on sick leave, help do the typing at the terminal. This also means no screenshots. But what I do have is the data from the intrusion detection error messages (Sorry ahead of time):
Exception
HELP
Could not get banned list
/var/www/html/admin/config.php
- // load language info if available
- modgettext::textdomain($module_name);
- if ( isset($currentcomponent) ) {
- $bmo->GuiHooks->doGUIHooks($module_name, $currentcomponent);
- }
- if ($bmo->GuiHooks->needsIntercept($module_name, $module_file)) {
- $bmo->Performance->Start(“hooks-$module_name-$module_file”);
- $bmo->GuiHooks->doIntercept($module_name, $module_file);
- $bmo->Performance->Stop(“hooks-$module_name-$module_file”);
- } else {
GET Data
| display | sysadmin |
|---|---|
| view | intrusion_detection |
POST Data empty
Files empty
Cookies
| searchHide | 1 |
|---|---|
| dashboardShowAll | false |
| lang | en_US |
| destinationUsage | 0 |
| _ga | GA1.1.1304408792.1589854276 |
| PHPSESSID | v2dimgiplmrngogkdk2dei4s61 |
| _gid | GA1.1.89669409.1606227271 |
Session
| langdirection | ltr |
|---|---|
| module_name | sysadmin |
| module_page | sysadmin |
| AMP_user | ampuser Object ( [username] => admin [id] => [password:ampuser:private] => [extension_high:ampuser:private] => [extension_low:ampuser:private] => [sections:ampuser:private] => Array ( [0] => * ) [mode:ampuser:private] => database [opmode:ampuser:private] => [_lastactivity] => 1606318456 ) |
| fwmsg | Array ( [last_dest] => from-did-direct,4002,1 ) |
Server/Request Data
| SCRIPT_URL | /admin/config.php |
|---|---|
| SCRIPT_URI | http://XXX.XXX.XXX.XXX/admin/config.php |
| SSLSETUP | true |
| HTACCESS | on |
| HTTP_HOST | XXX.XXX.XXX.XXX |
| HTTP_CONNECTION | keep-alive |
| HTTP_UPGRADE_INSECURE_REQUESTS | 1 |
| HTTP_DNT | 1 |
| HTTP_USER_AGENT | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.66 Safari/537.36 |
| HTTP_ACCEPT | text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,/;q=0.8,application/signed-exchange;v=b3;q=0.9 |
| HTTP_REFERER | http://XXX.XXX.XXX.XXX/admin/config.php?display=sysadmin |
| HTTP_ACCEPT_ENCODING | gzip, deflate |
| HTTP_ACCEPT_LANGUAGE | en-US,en;q=0.9 |
| HTTP_COOKIE | searchHide=1; dashboardShowAll=false; lang=en_US; destinationUsage=0; dashboardShowAll=true; searchHide=1; _ga=GA1.1.1304408792.1589854276; PHPSESSID=v2dimgiplmrngogkdk2dei4s61; _gid=GA1.1.89669409.1606227271 |
| PATH | /sbin:/usr/sbin:/bin:/usr/bin |
| SERVER_SIGNATURE | <address>Apache/2.2.15 (CentOS) Server at XXX.XXX.XXX.XXX Port 80</address> |
| SERVER_SOFTWARE | Apache/2.2.15 (CentOS) |
| SERVER_NAME | XXX.XXX.XXX.XXX |
| SERVER_ADDR | XXX.XXX.XXX.XXX |
| SERVER_PORT | 80 |
| REMOTE_ADDR | XXX.XXX.XXX.XXX |
| DOCUMENT_ROOT | /var/www/html |
| SERVER_ADMIN | root@localhost |
| SCRIPT_FILENAME | /var/www/html/admin/config.php |
| REMOTE_PORT | 51010 |
| GATEWAY_INTERFACE | CGI/1.1 |
| SERVER_PROTOCOL | HTTP/1.1 |
| REQUEST_METHOD | GET |
| QUERY_STRING | display=sysadmin&view=intrusion_detection |
| REQUEST_URI | /admin/config.php?display=sysadmin&view=intrusion_detection |
| SCRIPT_NAME | /admin/config.php |
| PHP_SELF | /admin/config.php |
| REQUEST_TIME | 1606318455 |
Environment Variables empty
Registered Handlers
Exception
HELP
Could not get banned list
/var/www/html/admin/libraries/BMO/GuiHooks.class.php
- $hooks = $this->getHooks($moduleToCall, $filename);
- if (!isset($hooks[‘INTERCEPT’])) {
- return true;
- }
- \modgettext::push_textdomain(strtolower($moduleToCall));
- $output = $this->getOutput($filename);
- \modgettext::pop_textdomain();
GET Data
| display | sysadmin |
|---|---|
| view | intrusion_detection |
POST Data empty
Files empty
Cookies
| searchHide | 1 |
|---|---|
| dashboardShowAll | false |
| lang | en_US |
| destinationUsage | 0 |
| _ga | GA1.1.1304408792.1589854276 |
| PHPSESSID | v2dimgiplmrngogkdk2dei4s61 |
| _gid | GA1.1.89669409.1606227271 |
Session
| langdirection | ltr |
|---|---|
| module_name | sysadmin |
| module_page | sysadmin |
| AMP_user | ampuser Object ( [username] => admin [id] => [password:ampuser:private] => [extension_high:ampuser:private] => [extension_low:ampuser:private] => [sections:ampuser:private] => Array ( [0] => * ) [mode:ampuser:private] => database [opmode:ampuser:private] => [_lastactivity] => 1606319323 ) |
| fwmsg | Array ( [last_dest] => from-did-direct,4002,1 ) |
Server/Request Data
| SCRIPT_URL | /admin/config.php |
|---|---|
| SCRIPT_URI | http://XXX.XXX.XXX.XXX/admin/config.php |
| SSLSETUP | true |
| HTACCESS | on |
| HTTP_HOST | XXX.XXX.XXX.XXX |
| HTTP_CONNECTION | keep-alive |
| HTTP_DNT | 1 |
| HTTP_UPGRADE_INSECURE_REQUESTS | 1 |
| HTTP_USER_AGENT | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.66 Safari/537.36 |
| HTTP_ACCEPT | text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,/;q=0.8,application/signed-exchange;v=b3;q=0.9 |
| HTTP_REFERER | http://XXX.XXX.XXX.XXX/admin/config.php?display=sysadmin |
| HTTP_ACCEPT_ENCODING | gzip, deflate |
| HTTP_ACCEPT_LANGUAGE | en-US,en;q=0.9 |
| HTTP_COOKIE | searchHide=1; dashboardShowAll=false; lang=en_US; destinationUsage=0; dashboardShowAll=true; searchHide=1; _ga=GA1.1.1304408792.1589854276; PHPSESSID=v2dimgiplmrngogkdk2dei4s61; _gid=GA1.1.89669409.1606227271 |
| PATH | /sbin:/usr/sbin:/bin:/usr/bin |
| SERVER_SIGNATURE | <address>Apache/2.2.15 (CentOS) Server at XXX.XXX.XXX.XXXPort 80</address> |
| SERVER_SOFTWARE | Apache/2.2.15 (CentOS) |
| SERVER_NAME | XXX.XXX.XXX.XXX |
| SERVER_ADDR | XXX.XXX.XXX.XXX |
| SERVER_PORT | 80 |
| REMOTE_ADDR | 10.57.10.116 |
| DOCUMENT_ROOT | /var/www/html |
| SERVER_ADMIN | root@localhost |
| SCRIPT_FILENAME | /var/www/html/admin/config.php |
| REMOTE_PORT | 51544 |
| GATEWAY_INTERFACE | CGI/1.1 |
| SERVER_PROTOCOL | HTTP/1.1 |
| REQUEST_METHOD | GET |
| QUERY_STRING | display=sysadmin&view=intrusion_detection |
| REQUEST_URI | /admin/config.php?display=sysadmin&view=intrusion_detection |
| SCRIPT_NAME | /admin/config.php |
| PHP_SELF | /admin/config.php |
| REQUEST_TIME | 1606319323 |
Environment Variables empty
Exception
HELP
Could not get banned list
/var/www/html/admin/libraries/BMO/GuiHooks.class.php
- echo $output;
- }
- private function getOutput($filename) {
- ob_start();
- include $filename;
- $output = ob_get_contents();
- ob_end_clean();
GET Data
| display | sysadmin |
|---|---|
| view | intrusion_detection |
POST Data empty
Files empty
Cookies
| searchHide | 1 |
|---|---|
| dashboardShowAll | false |
| lang | en_US |
| destinationUsage | 0 |
| _ga | GA1.1.1304408792.1589854276 |
| PHPSESSID | v2dimgiplmrngogkdk2dei4s61 |
| _gid | GA1.1.89669409.1606227271 |
Session
| langdirection | ltr |
|---|---|
| module_name | sysadmin |
| module_page | sysadmin |
| AMP_user | ampuser Object ( [username] => admin [id] => [password:ampuser:private] => [extension_high:ampuser:private] => [extension_low:ampuser:private] => [sections:ampuser:private] => Array ( [0] => * ) [mode:ampuser:private] => database [opmode:ampuser:private] => [_lastactivity] => 1606319323 ) |
| fwmsg | Array ( [last_dest] => from-did-direct,4002,1 ) |
Server/Request Data
| SCRIPT_URL | /admin/config.php |
|---|---|
| SCRIPT_URI | http://XXX.XXX.XXX.XXX/admin/config.php |
| SSLSETUP | true |
| HTACCESS | on |
| HTTP_HOST | XXX.XXX.XXX.XXX |
| HTTP_CONNECTION | keep-alive |
| HTTP_DNT | 1 |
| HTTP_UPGRADE_INSECURE_REQUESTS | 1 |
| HTTP_USER_AGENT | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.66 Safari/537.36 |
| HTTP_ACCEPT | text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,/;q=0.8,application/signed-exchange;v=b3;q=0.9 |
| HTTP_REFERER | http://XXX.XXX.XXX.XXX/admin/config.php?display=sysadmin |
| HTTP_ACCEPT_ENCODING | gzip, deflate |
| HTTP_ACCEPT_LANGUAGE | en-US,en;q=0.9 |
| HTTP_COOKIE | searchHide=1; dashboardShowAll=false; lang=en_US; destinationUsage=0; dashboardShowAll=true; searchHide=1; _ga=GA1.1.1304408792.1589854276; PHPSESSID=v2dimgiplmrngogkdk2dei4s61; _gid=GA1.1.89669409.1606227271 |
| PATH | /sbin:/usr/sbin:/bin:/usr/bin |
| SERVER_SIGNATURE | <address>Apache/2.2.15 (CentOS) Server at XXX.XXX.XXX.XXXPort 80</address> |
| SERVER_SOFTWARE | Apache/2.2.15 (CentOS) |
| SERVER_NAME | XXX.XXX.XXX.XXX |
| SERVER_ADDR | XXX.XXX.XXX.XXX |
| SERVER_PORT | 80 |
| REMOTE_ADDR | 10.57.10.116 |
| DOCUMENT_ROOT | /var/www/html |
| SERVER_ADMIN | root@localhost |
| SCRIPT_FILENAME | /var/www/html/admin/config.php |
| REMOTE_PORT | 51544 |
| GATEWAY_INTERFACE | CGI/1.1 |
| SERVER_PROTOCOL | HTTP/1.1 |
| REQUEST_METHOD | GET |
| QUERY_STRING | display=sysadmin&view=intrusion_detection |
| REQUEST_URI | /admin/config.php?display=sysadmin&view=intrusion_detection |
| SCRIPT_NAME | /admin/config.php |
| PHP_SELF | /admin/config.php |
| REQUEST_TIME | 1606319323 |
Environment Variables empty
Registered Handlers
Exception
HELP
Could not get banned list
/var/www/html/admin/modules/sysadmin/page.sysadmin.php
GET Data
| display | sysadmin |
|---|---|
| view | intrusion_detection |
POST Data empty
Files empty
Cookies
| searchHide | 1 |
|---|---|
| dashboardShowAll | false |
| lang | en_US |
| destinationUsage | 0 |
| _ga | GA1.1.1304408792.1589854276 |
| PHPSESSID | v2dimgiplmrngogkdk2dei4s61 |
| _gid | GA1.1.89669409.1606227271 |
Session
| langdirection | ltr |
|---|---|
| module_name | sysadmin |
| module_page | sysadmin |
| AMP_user | ampuser Object ( [username] => admin [id] => [password:ampuser:private] => a [extension_high:ampuser:private] => [extension_low:ampuser:private] => [sections:ampuser:private] => Array ( [0] => * ) [mode:ampuser:private] => database [opmode:ampuser:private] => [_lastactivity] => 1606319323 ) |
| fwmsg | Array ( [last_dest] => from-did-direct,4002,1 ) |
Server/Request Data
| SCRIPT_URL | /admin/config.php |
|---|---|
| SCRIPT_URI | http://XXX.XXX.XXX.XXX/admin/config.php |
| SSLSETUP | true |
| HTACCESS | on |
| HTTP_HOST | XXX.XXX.XXX.XXX |
| HTTP_CONNECTION | keep-alive |
| HTTP_DNT | 1 |
| HTTP_UPGRADE_INSECURE_REQUESTS | 1 |
| HTTP_USER_AGENT | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.66 Safari/537.36 |
| HTTP_ACCEPT | text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,/;q=0.8,application/signed-exchange;v=b3;q=0.9 |
| HTTP_REFERER | http://XXX.XXX.XXX.XXX/admin/config.php?display=sysadmin |
| HTTP_ACCEPT_ENCODING | gzip, deflate |
| HTTP_ACCEPT_LANGUAGE | en-US,en;q=0.9 |
| HTTP_COOKIE | searchHide=1; dashboardShowAll=false; lang=en_US; destinationUsage=0; dashboardShowAll=true; searchHide=1; _ga=GA1.1.1304408792.1589854276; PHPSESSID=v2dimgiplmrngogkdk2dei4s61; _gid=GA1.1.89669409.1606227271 |
| PATH | /sbin:/usr/sbin:/bin:/usr/bin |
| SERVER_SIGNATURE | <address>Apache/2.2.15 (CentOS) Server at XXX.XXX.XXX.XXX Port 80</address> |
| SERVER_SOFTWARE | Apache/2.2.15 (CentOS) |
| SERVER_NAME | XXX.XXX.XXX.XXX |
| SERVER_ADDR | XXX.XXX.XXX.XXX |
| SERVER_PORT | 80 |
| REMOTE_ADDR | 10.57.10.116 |
| DOCUMENT_ROOT | /var/www/html |
| SERVER_ADMIN | root@localhost |
| SCRIPT_FILENAME | /var/www/html/admin/config.php |
| REMOTE_PORT | 51544 |
| GATEWAY_INTERFACE | CGI/1.1 |
| SERVER_PROTOCOL | HTTP/1.1 |
| REQUEST_METHOD | GET |
| QUERY_STRING | display=sysadmin&view=intrusion_detection |
| REQUEST_URI | /admin/config.php?display=sysadmin&view=intrusion_detection |
| SCRIPT_NAME | /admin/config.php |
| PHP_SELF | /admin/config.php |
| REQUEST_TIME | 1606319323 |
Environment Variables empty
Registered Handlers
Exception
HELP
Could not get banned list
/var/www/html/admin/modules/sysadmin/functions.inc/intrusion.php
GET Data
| display | sysadmin |
|---|---|
| view | intrusion_detection |
POST Data empty
Files empty
Cookies
| searchHide | 1 |
|---|---|
| dashboardShowAll | false |
| lang | en_US |
| destinationUsage | 0 |
| _ga | GA1.1.1304408792.1589854276 |
| PHPSESSID | v2dimgiplmrngogkdk2dei4s61 |
| _gid | GA1.1.89669409.1606227271 |
Session
| langdirection | ltr |
|---|---|
| module_name | sysadmin |
| module_page | sysadmin |
| AMP_user | ampuser Object ( [username] => admin [id] => [password:ampuser:private] => [extension_high:ampuser:private] => [extension_low:ampuser:private] => [sections:ampuser:private] => Array ( [0] => * ) [mode:ampuser:private] => database [opmode:ampuser:private] => [_lastactivity] => 1606319323 ) |
| fwmsg | Array ( [last_dest] => from-did-direct,4002,1 ) |
Server/Request Data
| SCRIPT_URL | /admin/config.php |
|---|---|
| SCRIPT_URI | http://XXX.XXX.XXX.XXX/admin/config.php |
| SSLSETUP | true |
| HTACCESS | on |
| HTTP_HOST | XXX.XXX.XXX.XXX |
| HTTP_CONNECTION | keep-alive |
| HTTP_DNT | 1 |
| HTTP_UPGRADE_INSECURE_REQUESTS | 1 |
| HTTP_USER_AGENT | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.66 Safari/537.36 |
| HTTP_ACCEPT | text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,/;q=0.8,application/signed-exchange;v=b3;q=0.9 |
| HTTP_REFERER | http://XXX.XXX.XXX.XXX/admin/config.php?display=sysadmin |
| HTTP_ACCEPT_ENCODING | gzip, deflate |
| HTTP_ACCEPT_LANGUAGE | en-US,en;q=0.9 |
| HTTP_COOKIE | searchHide=1; dashboardShowAll=false; lang=en_US; destinationUsage=0; dashboardShowAll=true; searchHide=1; _ga=GA1.1.1304408792.1589854276; PHPSESSID=v2dimgiplmrngogkdk2dei4s61; _gid=GA1.1.89669409.1606227271 |
| PATH | /sbin:/usr/sbin:/bin:/usr/bin |
| SERVER_SIGNATURE | <address>Apache/2.2.15 (CentOS) Server at XXX.XXX.XXX.XXXPort 80</address> |
| SERVER_SOFTWARE | Apache/2.2.15 (CentOS) |
| SERVER_NAME | XXX.XXX.XXX.XXX |
| SERVER_ADDR | XXX.XXX.XXX.XXX |
| SERVER_PORT | 80 |
| REMOTE_ADDR | 10.57.10.116 |
| DOCUMENT_ROOT | /var/www/html |
| SERVER_ADMIN | root@localhost |
| SCRIPT_FILENAME | /var/www/html/admin/config.php |
| REMOTE_PORT | 51544 |
| GATEWAY_INTERFACE | CGI/1.1 |
| SERVER_PROTOCOL | HTTP/1.1 |
| REQUEST_METHOD | GET |
| QUERY_STRING | display=sysadmin&view=intrusion_detection |
| REQUEST_URI | /admin/config.php?display=sysadmin&view=intrusion_detection |
| SCRIPT_NAME | /admin/config.php |
| PHP_SELF | /admin/config.php |
| REQUEST_TIME | 1606319323 |
Environment Variables empty
Registered Handlers
Exception
HELP
Could not get banned list
/var/www/html/admin/modules/sysadmin/Sysadmin.class.php
GET Data
| display | sysadmin |
|---|---|
| view | intrusion_detection |
POST Data empty
Files empty
Cookies
| searchHide | 1 |
|---|---|
| dashboardShowAll | false |
| lang | en_US |
| destinationUsage | 0 |
| _ga | GA1.1.1304408792.1589854276 |
| PHPSESSID | v2dimgiplmrngogkdk2dei4s61 |
| _gid | GA1.1.89669409.1606227271 |
Session
| langdirection | ltr |
|---|---|
| module_name | sysadmin |
| module_page | sysadmin |
| AMP_user | ampuser Object ( [username] => admin [id] => [password:ampuser:private] => [extension_high:ampuser:private] => [extension_low:ampuser:private] => [sections:ampuser:private] => Array ( [0] => * ) [mode:ampuser:private] => database [opmode:ampuser:private] => [_lastactivity] => 1606319323 ) |
| fwmsg | Array ( [last_dest] => from-did-direct,4002,1 ) |
Server/Request Data
| SCRIPT_URL | /admin/config.php |
|---|---|
| SCRIPT_URI | http://XXX.XXX.XXX.XXX/admin/config.php |
| SSLSETUP | true |
| HTACCESS | on |
| HTTP_HOST | XXX.XXX.XXX.XXX |
| HTTP_CONNECTION | keep-alive |
| HTTP_DNT | 1 |
| HTTP_UPGRADE_INSECURE_REQUESTS | 1 |
| HTTP_USER_AGENT | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.66 Safari/537.36 |
| HTTP_ACCEPT | text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,/;q=0.8,application/signed-exchange;v=b3;q=0.9 |
| HTTP_REFERER | http://XXX.XXX.XXX.XXX/admin/config.php?display=sysadmin |
| HTTP_ACCEPT_ENCODING | gzip, deflate |
| HTTP_ACCEPT_LANGUAGE | en-US,en;q=0.9 |
| HTTP_COOKIE | searchHide=1; dashboardShowAll=false; lang=en_US; destinationUsage=0; dashboardShowAll=true; searchHide=1; _ga=GA1.1.1304408792.1589854276; PHPSESSID=v2dimgiplmrngogkdk2dei4s61; _gid=GA1.1.89669409.1606227271 |
| PATH | /sbin:/usr/sbin:/bin:/usr/bin |
| SERVER_SIGNATURE | <address>Apache/2.2.15 (CentOS) Server at XXX.XXX.XXX.XXXPort 80</address> |
| SERVER_SOFTWARE | Apache/2.2.15 (CentOS) |
| SERVER_NAME | XXX.XXX.XXX.XXX |
| SERVER_ADDR | XXX.XXX.XXX.XXX |
| SERVER_PORT | 80 |
| REMOTE_ADDR | 10.57.10.116 |
| DOCUMENT_ROOT | /var/www/html |
| SERVER_ADMIN | root@localhost |
| SCRIPT_FILENAME | /var/www/html/admin/config.php |
| REMOTE_PORT | 51544 |
| GATEWAY_INTERFACE | CGI/1.1 |
| SERVER_PROTOCOL | HTTP/1.1 |
| REQUEST_METHOD | GET |
| QUERY_STRING | display=sysadmin&view=intrusion_detection |
| REQUEST_URI | /admin/config.php?display=sysadmin&view=intrusion_detection |
| SCRIPT_NAME | /admin/config.php |
| PHP_SELF | /admin/config.php |
| REQUEST_TIME | 1606319323 |
Environment Variables empty
Registered Handlers
And that is all I have. This happened on another server that is nearly identical but a reboot of the server fixed it. The other thing is that it was working prior to the last System Admin Module upgrade (Commercial). The sense of urgency is that I need to off load a bunch of voice recordings to free up space and the storage is filling up fast. I appreciate any helpful suggestions. Thank you.