Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 6 of 6
  1. #1
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Oct 2004
    Posts
    30

    Default Root User locked out (CPHULKD)

    I was curious has anyone else seen this happen or know of a solution. It's been a known case recently that repeat failed logins from a single user may result in the user's access getting temporarily terminated. I'm wondering if it's possible for some sort of feature request to whitelist root user from an IP range. I know it's possible to whitelist a range as that's done, but there are times where root may be brute forced, thus locking out root user, not allowing us to login to a server for a half hour or so.

  2. #2
    BANNED
    Join Date
    Jun 2005
    Location
    Wild Wild West
    Posts
    2,025

    Default

    I'm not sure I entirely follow your question exactly ...

    On our servers, we generally whitelist the IPs for the administrators
    so that cpHulk ignores login attempts originating from us and we
    have never had any problems getting "locked out" ourselves.

  3. #3
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Oct 2004
    Posts
    30

    Default

    I guess if you want to test this occurrence, whitelist your IP, then fail a login with root user using another IP 10 times, then try to login with root via another IP or the white listed IP. For some reason on several of our servers, our root user actually gets blocked.

  4. #4
    BANNED
    Join Date
    Jun 2005
    Location
    Wild Wild West
    Posts
    2,025

    Lightbulb

    Quote Originally Posted by BattousaiX View Post
    I guess if you want to test this occurrence, whitelist your IP, then fail a login with root user using another IP 10 times, then try to login with root via another IP or the white listed IP. For some reason on several of our servers, our root user actually gets blocked.
    You sure it's CpHulkd doing that?

    I just brute force attempted WHM with the root account until it got blocked and then tried to login from an IP that was whitelisted and didn't have any problems connecting back in again.

    We do have a back door "trigger" URL that when it shows up in the server logs file tells a monitoring process to wipe all blocks and reset both CpHulk and CSF blocks on our servers. We have not really ever had to use it but you might want to do something similar as a "failsafe" measure.
    Last edited by Spiral; 09-05-2009 at 12:22 PM.

  5. #5
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Oct 2004
    Posts
    30

    Default

    We were only allowed back into the server when flushing the cphulkd database. Of course this user was already logged into WHM to flush at this occurrence. This has happened in more than one occasion and I have not been able to find anything on this event.

  6. #6
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Oct 2004
    Posts
    30

    Default

    Any other users experience this or have a solution?

Similar Threads & Tags
Similar threads

  1. Locked out by cPHulkd
    By dhairya90 in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 04-24-2011, 05:13 AM
  2. API to check whether the suspended domain is locked by root
    By SunShellNET in forum cPanel Developers
    Replies: 1
    Last Post: 07-01-2009, 01:52 PM
  3. cphulk has locked out "root"
    By pramsey in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 06-02-2009, 09:57 AM
  4. Replies: 1
    Last Post: 11-25-2007, 02:35 PM
  5. Does the user for cpanel is the root user for mysql?
    By hungboy in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 03-30-2006, 10:55 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube