HEX
Server: LiteSpeed
System:
User: ()
PHP: 7.4.33
Disabled: sendmail,mail,exec,shell_exec,dl,system,passthru,pclose,proc_open,proc_nice,proc_terminate,proc_get_status,proc_close,leak,apache_child_terminate,posix_kill,posix_mkfifo,posix_setpgid,posix_setsid,posix_setuid,escapeshellcmd,escapeshellarg shell-exec,fpassthru,crack_check,crack_closedict,crack_getlastmessage,crack_opendict,psockopen,php_uname,symlink,ini_restore,posix_getpwuid,posix_getegid,posix_getcwd,posix_geteuid,posix_getgroups,posix_uname,posix_setuid,eval,show_source,passthru,popen,allow_url_fopen,get_current_user,getmyuid,getmygid,entre2v2,index_changer_wp,index_changer_joomla,exec_mode_1,exec_mode_2,exec_mode_3,wsoFooter,wsoEx,wsoViewSize,wsoPerms,wsoPermsColor,ukuran,tulis,ambil,tukar,entre2v2,rapih,magicboom,goaction,scookie,showstat,index_changer
Upload Files
File: //lib/systemd/system/imunify360-dos-protection.service
[Unit]
Description=Imunify360 DoS Protection
Before=cagefs.service

[Service]
Type=simple
ExecStart=/usr/bin/imunify360-dos-protection
ExecReload=/bin/kill -HUP $MAINPID
Restart=on-failure
KillMode=mixed
CPUAccounting=true
MemoryAccounting=true
BlockIOAccounting=true
# WARN: systemd interprets '-' as '/' and creates redundant nested slices!
# Full name: /Imunify.slice/Imunify-dos_protection.slice/imunify360-dos-protection.service
Slice=Imunify-dos_protection.slice
NoNewPrivileges=true
# Daemon opens NETLINK_NETFILTER for conntrack events (cmd/srv/server.go)
# and sets NETLINK_LISTEN_ALL_NSID to monitor all network namespaces.
# The NETLINK_LISTEN_ALL_NSID setsockopt is gated on CAP_NET_BROADCAST
# (kernel 5.14.0+ af_netlink.c) in init_user_ns — without it the daemon
# crash-loops on "setsockopt: operation not permitted" before reaching
# "Daemon is ready." (verified live on CL9 + cPanel via strace bisect).
CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_RAW CAP_NET_BROADCAST CAP_KILL
# NoNewPrivileges=true disables the kernel's UID-0 effective-capability
# raise on exec, so even this unit's own ExecStart= binary needs
# AmbientCapabilities= to start with effective != empty. Without it,
# socket(AF_NETLINK, *, NETLINK_NETFILTER) returns EPERM at startup.
AmbientCapabilities=CAP_NET_ADMIN CAP_NET_RAW CAP_NET_BROADCAST CAP_KILL
ProtectSystem=full
ProtectHome=yes
PrivateTmp=yes
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK

[Install]
WantedBy=multi-user.target