I have searched for and tried just about everything I can in regards to this particular problem but I am still without resolution and the timer is ticking. I have tried reinstalling Fail2ban several times, I have looked ant error logs, configuration files, etc and think I know what the problem is but I don’t know how to resolve it. The biggest issue is that I work remotely and can only access the server via the web GUI as I can’t even SSH. Putty gives me Connection Error: Connection Refused so I have to have someone, usually my assistant but he’s on sick leave, help do the typing at the terminal. This also means no screenshots. But what I do have is the data from the intrusion detection error messages (Sorry ahead of time):
Exception
HELP
Could not get banned list
/var/www/html/admin/config.php
- // load language info if available
- modgettext::textdomain($module_name);
- if ( isset($currentcomponent) ) {
- $bmo->GuiHooks->doGUIHooks($module_name, $currentcomponent);
- }
- if ($bmo->GuiHooks->needsIntercept($module_name, $module_file)) {
- $bmo->Performance->Start(“hooks-$module_name-$module_file”);
- $bmo->GuiHooks->doIntercept($module_name, $module_file);
- $bmo->Performance->Stop(“hooks-$module_name-$module_file”);
- } else {
GET Data
display | sysadmin |
---|---|
view | intrusion_detection |
POST Data empty
Files empty
Cookies
searchHide | 1 |
---|---|
dashboardShowAll | false |
lang | en_US |
destinationUsage | 0 |
_ga | GA1.1.1304408792.1589854276 |
PHPSESSID | v2dimgiplmrngogkdk2dei4s61 |
_gid | GA1.1.89669409.1606227271 |
Session
langdirection | ltr |
---|---|
module_name | sysadmin |
module_page | sysadmin |
AMP_user | ampuser Object ( [username] => admin [id] => [password:ampuser:private] => [extension_high:ampuser:private] => [extension_low:ampuser:private] => [sections:ampuser:private] => Array ( [0] => * ) [mode:ampuser:private] => database [opmode:ampuser:private] => [_lastactivity] => 1606318456 ) |
fwmsg | Array ( [last_dest] => from-did-direct,4002,1 ) |
Server/Request Data
SCRIPT_URL | /admin/config.php |
---|---|
SCRIPT_URI | http://XXX.XXX.XXX.XXX/admin/config.php |
SSLSETUP | true |
HTACCESS | on |
HTTP_HOST | XXX.XXX.XXX.XXX |
HTTP_CONNECTION | keep-alive |
HTTP_UPGRADE_INSECURE_REQUESTS | 1 |
HTTP_DNT | 1 |
HTTP_USER_AGENT | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.66 Safari/537.36 |
HTTP_ACCEPT | text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,/;q=0.8,application/signed-exchange;v=b3;q=0.9 |
HTTP_REFERER | http://XXX.XXX.XXX.XXX/admin/config.php?display=sysadmin |
HTTP_ACCEPT_ENCODING | gzip, deflate |
HTTP_ACCEPT_LANGUAGE | en-US,en;q=0.9 |
HTTP_COOKIE | searchHide=1; dashboardShowAll=false; lang=en_US; destinationUsage=0; dashboardShowAll=true; searchHide=1; _ga=GA1.1.1304408792.1589854276; PHPSESSID=v2dimgiplmrngogkdk2dei4s61; _gid=GA1.1.89669409.1606227271 |
PATH | /sbin:/usr/sbin:/bin:/usr/bin |
SERVER_SIGNATURE | <address>Apache/2.2.15 (CentOS) Server at XXX.XXX.XXX.XXX Port 80</address> |
SERVER_SOFTWARE | Apache/2.2.15 (CentOS) |
SERVER_NAME | XXX.XXX.XXX.XXX |
SERVER_ADDR | XXX.XXX.XXX.XXX |
SERVER_PORT | 80 |
REMOTE_ADDR | XXX.XXX.XXX.XXX |
DOCUMENT_ROOT | /var/www/html |
SERVER_ADMIN | root@localhost |
SCRIPT_FILENAME | /var/www/html/admin/config.php |
REMOTE_PORT | 51010 |
GATEWAY_INTERFACE | CGI/1.1 |
SERVER_PROTOCOL | HTTP/1.1 |
REQUEST_METHOD | GET |
QUERY_STRING | display=sysadmin&view=intrusion_detection |
REQUEST_URI | /admin/config.php?display=sysadmin&view=intrusion_detection |
SCRIPT_NAME | /admin/config.php |
PHP_SELF | /admin/config.php |
REQUEST_TIME | 1606318455 |
Environment Variables empty
Registered Handlers
Exception
HELP
Could not get banned list
/var/www/html/admin/libraries/BMO/GuiHooks.class.php
- $hooks = $this->getHooks($moduleToCall, $filename);
- if (!isset($hooks[‘INTERCEPT’])) {
- return true;
- }
- \modgettext::push_textdomain(strtolower($moduleToCall));
- $output = $this->getOutput($filename);
- \modgettext::pop_textdomain();
GET Data
display | sysadmin |
---|---|
view | intrusion_detection |
POST Data empty
Files empty
Cookies
searchHide | 1 |
---|---|
dashboardShowAll | false |
lang | en_US |
destinationUsage | 0 |
_ga | GA1.1.1304408792.1589854276 |
PHPSESSID | v2dimgiplmrngogkdk2dei4s61 |
_gid | GA1.1.89669409.1606227271 |
Session
langdirection | ltr |
---|---|
module_name | sysadmin |
module_page | sysadmin |
AMP_user | ampuser Object ( [username] => admin [id] => [password:ampuser:private] => [extension_high:ampuser:private] => [extension_low:ampuser:private] => [sections:ampuser:private] => Array ( [0] => * ) [mode:ampuser:private] => database [opmode:ampuser:private] => [_lastactivity] => 1606319323 ) |
fwmsg | Array ( [last_dest] => from-did-direct,4002,1 ) |
Server/Request Data
SCRIPT_URL | /admin/config.php |
---|---|
SCRIPT_URI | http://XXX.XXX.XXX.XXX/admin/config.php |
SSLSETUP | true |
HTACCESS | on |
HTTP_HOST | XXX.XXX.XXX.XXX |
HTTP_CONNECTION | keep-alive |
HTTP_DNT | 1 |
HTTP_UPGRADE_INSECURE_REQUESTS | 1 |
HTTP_USER_AGENT | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.66 Safari/537.36 |
HTTP_ACCEPT | text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,/;q=0.8,application/signed-exchange;v=b3;q=0.9 |
HTTP_REFERER | http://XXX.XXX.XXX.XXX/admin/config.php?display=sysadmin |
HTTP_ACCEPT_ENCODING | gzip, deflate |
HTTP_ACCEPT_LANGUAGE | en-US,en;q=0.9 |
HTTP_COOKIE | searchHide=1; dashboardShowAll=false; lang=en_US; destinationUsage=0; dashboardShowAll=true; searchHide=1; _ga=GA1.1.1304408792.1589854276; PHPSESSID=v2dimgiplmrngogkdk2dei4s61; _gid=GA1.1.89669409.1606227271 |
PATH | /sbin:/usr/sbin:/bin:/usr/bin |
SERVER_SIGNATURE | <address>Apache/2.2.15 (CentOS) Server at XXX.XXX.XXX.XXXPort 80</address> |
SERVER_SOFTWARE | Apache/2.2.15 (CentOS) |
SERVER_NAME | XXX.XXX.XXX.XXX |
SERVER_ADDR | XXX.XXX.XXX.XXX |
SERVER_PORT | 80 |
REMOTE_ADDR | 10.57.10.116 |
DOCUMENT_ROOT | /var/www/html |
SERVER_ADMIN | root@localhost |
SCRIPT_FILENAME | /var/www/html/admin/config.php |
REMOTE_PORT | 51544 |
GATEWAY_INTERFACE | CGI/1.1 |
SERVER_PROTOCOL | HTTP/1.1 |
REQUEST_METHOD | GET |
QUERY_STRING | display=sysadmin&view=intrusion_detection |
REQUEST_URI | /admin/config.php?display=sysadmin&view=intrusion_detection |
SCRIPT_NAME | /admin/config.php |
PHP_SELF | /admin/config.php |
REQUEST_TIME | 1606319323 |
Environment Variables empty
Exception
HELP
Could not get banned list
/var/www/html/admin/libraries/BMO/GuiHooks.class.php
- echo $output;
- }
- private function getOutput($filename) {
- ob_start();
- include $filename;
- $output = ob_get_contents();
- ob_end_clean();
GET Data
display | sysadmin |
---|---|
view | intrusion_detection |
POST Data empty
Files empty
Cookies
searchHide | 1 |
---|---|
dashboardShowAll | false |
lang | en_US |
destinationUsage | 0 |
_ga | GA1.1.1304408792.1589854276 |
PHPSESSID | v2dimgiplmrngogkdk2dei4s61 |
_gid | GA1.1.89669409.1606227271 |
Session
langdirection | ltr |
---|---|
module_name | sysadmin |
module_page | sysadmin |
AMP_user | ampuser Object ( [username] => admin [id] => [password:ampuser:private] => [extension_high:ampuser:private] => [extension_low:ampuser:private] => [sections:ampuser:private] => Array ( [0] => * ) [mode:ampuser:private] => database [opmode:ampuser:private] => [_lastactivity] => 1606319323 ) |
fwmsg | Array ( [last_dest] => from-did-direct,4002,1 ) |
Server/Request Data
SCRIPT_URL | /admin/config.php |
---|---|
SCRIPT_URI | http://XXX.XXX.XXX.XXX/admin/config.php |
SSLSETUP | true |
HTACCESS | on |
HTTP_HOST | XXX.XXX.XXX.XXX |
HTTP_CONNECTION | keep-alive |
HTTP_DNT | 1 |
HTTP_UPGRADE_INSECURE_REQUESTS | 1 |
HTTP_USER_AGENT | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.66 Safari/537.36 |
HTTP_ACCEPT | text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,/;q=0.8,application/signed-exchange;v=b3;q=0.9 |
HTTP_REFERER | http://XXX.XXX.XXX.XXX/admin/config.php?display=sysadmin |
HTTP_ACCEPT_ENCODING | gzip, deflate |
HTTP_ACCEPT_LANGUAGE | en-US,en;q=0.9 |
HTTP_COOKIE | searchHide=1; dashboardShowAll=false; lang=en_US; destinationUsage=0; dashboardShowAll=true; searchHide=1; _ga=GA1.1.1304408792.1589854276; PHPSESSID=v2dimgiplmrngogkdk2dei4s61; _gid=GA1.1.89669409.1606227271 |
PATH | /sbin:/usr/sbin:/bin:/usr/bin |
SERVER_SIGNATURE | <address>Apache/2.2.15 (CentOS) Server at XXX.XXX.XXX.XXXPort 80</address> |
SERVER_SOFTWARE | Apache/2.2.15 (CentOS) |
SERVER_NAME | XXX.XXX.XXX.XXX |
SERVER_ADDR | XXX.XXX.XXX.XXX |
SERVER_PORT | 80 |
REMOTE_ADDR | 10.57.10.116 |
DOCUMENT_ROOT | /var/www/html |
SERVER_ADMIN | root@localhost |
SCRIPT_FILENAME | /var/www/html/admin/config.php |
REMOTE_PORT | 51544 |
GATEWAY_INTERFACE | CGI/1.1 |
SERVER_PROTOCOL | HTTP/1.1 |
REQUEST_METHOD | GET |
QUERY_STRING | display=sysadmin&view=intrusion_detection |
REQUEST_URI | /admin/config.php?display=sysadmin&view=intrusion_detection |
SCRIPT_NAME | /admin/config.php |
PHP_SELF | /admin/config.php |
REQUEST_TIME | 1606319323 |
Environment Variables empty
Registered Handlers
Exception
HELP
Could not get banned list
/var/www/html/admin/modules/sysadmin/page.sysadmin.php
GET Data
display | sysadmin |
---|---|
view | intrusion_detection |
POST Data empty
Files empty
Cookies
searchHide | 1 |
---|---|
dashboardShowAll | false |
lang | en_US |
destinationUsage | 0 |
_ga | GA1.1.1304408792.1589854276 |
PHPSESSID | v2dimgiplmrngogkdk2dei4s61 |
_gid | GA1.1.89669409.1606227271 |
Session
langdirection | ltr |
---|---|
module_name | sysadmin |
module_page | sysadmin |
AMP_user | ampuser Object ( [username] => admin [id] => [password:ampuser:private] => a [extension_high:ampuser:private] => [extension_low:ampuser:private] => [sections:ampuser:private] => Array ( [0] => * ) [mode:ampuser:private] => database [opmode:ampuser:private] => [_lastactivity] => 1606319323 ) |
fwmsg | Array ( [last_dest] => from-did-direct,4002,1 ) |
Server/Request Data
SCRIPT_URL | /admin/config.php |
---|---|
SCRIPT_URI | http://XXX.XXX.XXX.XXX/admin/config.php |
SSLSETUP | true |
HTACCESS | on |
HTTP_HOST | XXX.XXX.XXX.XXX |
HTTP_CONNECTION | keep-alive |
HTTP_DNT | 1 |
HTTP_UPGRADE_INSECURE_REQUESTS | 1 |
HTTP_USER_AGENT | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.66 Safari/537.36 |
HTTP_ACCEPT | text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,/;q=0.8,application/signed-exchange;v=b3;q=0.9 |
HTTP_REFERER | http://XXX.XXX.XXX.XXX/admin/config.php?display=sysadmin |
HTTP_ACCEPT_ENCODING | gzip, deflate |
HTTP_ACCEPT_LANGUAGE | en-US,en;q=0.9 |
HTTP_COOKIE | searchHide=1; dashboardShowAll=false; lang=en_US; destinationUsage=0; dashboardShowAll=true; searchHide=1; _ga=GA1.1.1304408792.1589854276; PHPSESSID=v2dimgiplmrngogkdk2dei4s61; _gid=GA1.1.89669409.1606227271 |
PATH | /sbin:/usr/sbin:/bin:/usr/bin |
SERVER_SIGNATURE | <address>Apache/2.2.15 (CentOS) Server at XXX.XXX.XXX.XXX Port 80</address> |
SERVER_SOFTWARE | Apache/2.2.15 (CentOS) |
SERVER_NAME | XXX.XXX.XXX.XXX |
SERVER_ADDR | XXX.XXX.XXX.XXX |
SERVER_PORT | 80 |
REMOTE_ADDR | 10.57.10.116 |
DOCUMENT_ROOT | /var/www/html |
SERVER_ADMIN | root@localhost |
SCRIPT_FILENAME | /var/www/html/admin/config.php |
REMOTE_PORT | 51544 |
GATEWAY_INTERFACE | CGI/1.1 |
SERVER_PROTOCOL | HTTP/1.1 |
REQUEST_METHOD | GET |
QUERY_STRING | display=sysadmin&view=intrusion_detection |
REQUEST_URI | /admin/config.php?display=sysadmin&view=intrusion_detection |
SCRIPT_NAME | /admin/config.php |
PHP_SELF | /admin/config.php |
REQUEST_TIME | 1606319323 |
Environment Variables empty
Registered Handlers
Exception
HELP
Could not get banned list
/var/www/html/admin/modules/sysadmin/functions.inc/intrusion.php
GET Data
display | sysadmin |
---|---|
view | intrusion_detection |
POST Data empty
Files empty
Cookies
searchHide | 1 |
---|---|
dashboardShowAll | false |
lang | en_US |
destinationUsage | 0 |
_ga | GA1.1.1304408792.1589854276 |
PHPSESSID | v2dimgiplmrngogkdk2dei4s61 |
_gid | GA1.1.89669409.1606227271 |
Session
langdirection | ltr |
---|---|
module_name | sysadmin |
module_page | sysadmin |
AMP_user | ampuser Object ( [username] => admin [id] => [password:ampuser:private] => [extension_high:ampuser:private] => [extension_low:ampuser:private] => [sections:ampuser:private] => Array ( [0] => * ) [mode:ampuser:private] => database [opmode:ampuser:private] => [_lastactivity] => 1606319323 ) |
fwmsg | Array ( [last_dest] => from-did-direct,4002,1 ) |
Server/Request Data
SCRIPT_URL | /admin/config.php |
---|---|
SCRIPT_URI | http://XXX.XXX.XXX.XXX/admin/config.php |
SSLSETUP | true |
HTACCESS | on |
HTTP_HOST | XXX.XXX.XXX.XXX |
HTTP_CONNECTION | keep-alive |
HTTP_DNT | 1 |
HTTP_UPGRADE_INSECURE_REQUESTS | 1 |
HTTP_USER_AGENT | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.66 Safari/537.36 |
HTTP_ACCEPT | text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,/;q=0.8,application/signed-exchange;v=b3;q=0.9 |
HTTP_REFERER | http://XXX.XXX.XXX.XXX/admin/config.php?display=sysadmin |
HTTP_ACCEPT_ENCODING | gzip, deflate |
HTTP_ACCEPT_LANGUAGE | en-US,en;q=0.9 |
HTTP_COOKIE | searchHide=1; dashboardShowAll=false; lang=en_US; destinationUsage=0; dashboardShowAll=true; searchHide=1; _ga=GA1.1.1304408792.1589854276; PHPSESSID=v2dimgiplmrngogkdk2dei4s61; _gid=GA1.1.89669409.1606227271 |
PATH | /sbin:/usr/sbin:/bin:/usr/bin |
SERVER_SIGNATURE | <address>Apache/2.2.15 (CentOS) Server at XXX.XXX.XXX.XXXPort 80</address> |
SERVER_SOFTWARE | Apache/2.2.15 (CentOS) |
SERVER_NAME | XXX.XXX.XXX.XXX |
SERVER_ADDR | XXX.XXX.XXX.XXX |
SERVER_PORT | 80 |
REMOTE_ADDR | 10.57.10.116 |
DOCUMENT_ROOT | /var/www/html |
SERVER_ADMIN | root@localhost |
SCRIPT_FILENAME | /var/www/html/admin/config.php |
REMOTE_PORT | 51544 |
GATEWAY_INTERFACE | CGI/1.1 |
SERVER_PROTOCOL | HTTP/1.1 |
REQUEST_METHOD | GET |
QUERY_STRING | display=sysadmin&view=intrusion_detection |
REQUEST_URI | /admin/config.php?display=sysadmin&view=intrusion_detection |
SCRIPT_NAME | /admin/config.php |
PHP_SELF | /admin/config.php |
REQUEST_TIME | 1606319323 |
Environment Variables empty
Registered Handlers
Exception
HELP
Could not get banned list
/var/www/html/admin/modules/sysadmin/Sysadmin.class.php
GET Data
display | sysadmin |
---|---|
view | intrusion_detection |
POST Data empty
Files empty
Cookies
searchHide | 1 |
---|---|
dashboardShowAll | false |
lang | en_US |
destinationUsage | 0 |
_ga | GA1.1.1304408792.1589854276 |
PHPSESSID | v2dimgiplmrngogkdk2dei4s61 |
_gid | GA1.1.89669409.1606227271 |
Session
langdirection | ltr |
---|---|
module_name | sysadmin |
module_page | sysadmin |
AMP_user | ampuser Object ( [username] => admin [id] => [password:ampuser:private] => [extension_high:ampuser:private] => [extension_low:ampuser:private] => [sections:ampuser:private] => Array ( [0] => * ) [mode:ampuser:private] => database [opmode:ampuser:private] => [_lastactivity] => 1606319323 ) |
fwmsg | Array ( [last_dest] => from-did-direct,4002,1 ) |
Server/Request Data
SCRIPT_URL | /admin/config.php |
---|---|
SCRIPT_URI | http://XXX.XXX.XXX.XXX/admin/config.php |
SSLSETUP | true |
HTACCESS | on |
HTTP_HOST | XXX.XXX.XXX.XXX |
HTTP_CONNECTION | keep-alive |
HTTP_DNT | 1 |
HTTP_UPGRADE_INSECURE_REQUESTS | 1 |
HTTP_USER_AGENT | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.66 Safari/537.36 |
HTTP_ACCEPT | text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,/;q=0.8,application/signed-exchange;v=b3;q=0.9 |
HTTP_REFERER | http://XXX.XXX.XXX.XXX/admin/config.php?display=sysadmin |
HTTP_ACCEPT_ENCODING | gzip, deflate |
HTTP_ACCEPT_LANGUAGE | en-US,en;q=0.9 |
HTTP_COOKIE | searchHide=1; dashboardShowAll=false; lang=en_US; destinationUsage=0; dashboardShowAll=true; searchHide=1; _ga=GA1.1.1304408792.1589854276; PHPSESSID=v2dimgiplmrngogkdk2dei4s61; _gid=GA1.1.89669409.1606227271 |
PATH | /sbin:/usr/sbin:/bin:/usr/bin |
SERVER_SIGNATURE | <address>Apache/2.2.15 (CentOS) Server at XXX.XXX.XXX.XXXPort 80</address> |
SERVER_SOFTWARE | Apache/2.2.15 (CentOS) |
SERVER_NAME | XXX.XXX.XXX.XXX |
SERVER_ADDR | XXX.XXX.XXX.XXX |
SERVER_PORT | 80 |
REMOTE_ADDR | 10.57.10.116 |
DOCUMENT_ROOT | /var/www/html |
SERVER_ADMIN | root@localhost |
SCRIPT_FILENAME | /var/www/html/admin/config.php |
REMOTE_PORT | 51544 |
GATEWAY_INTERFACE | CGI/1.1 |
SERVER_PROTOCOL | HTTP/1.1 |
REQUEST_METHOD | GET |
QUERY_STRING | display=sysadmin&view=intrusion_detection |
REQUEST_URI | /admin/config.php?display=sysadmin&view=intrusion_detection |
SCRIPT_NAME | /admin/config.php |
PHP_SELF | /admin/config.php |
REQUEST_TIME | 1606319323 |
Environment Variables empty
Registered Handlers
And that is all I have. This happened on another server that is nearly identical but a reboot of the server fixed it. The other thing is that it was working prior to the last System Admin Module upgrade (Commercial). The sense of urgency is that I need to off load a bunch of voice recordings to free up space and the storage is filling up fast. I appreciate any helpful suggestions. Thank you.