The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Where Does an IP get Blacklisted on cpHulk?

Discussion in 'Security' started by Ruan, Oct 5, 2015.

  1. Ruan

    Ruan Registered

    Joined:
    Jul 21, 2015
    Messages:
    2
    Likes Received:
    0
    Trophy Points:
    1
    Location:
    South Africa
    cPanel Access Level:
    Root Administrator
    I recently became aware of:

    /scripts/cphulkdblacklist

    and

    /scripts/cphulkdwhitelist.

    I used /scripts/cphulkdblacklist to blacklist an IP, 196.5.4.3. When I browse to the WHM interface of cpHulk, I see the IP has indeed been blacklisted. However, when I check the MySQL database, I cannot find the IP in the table "blacklist":


    mysql> select IP from blacklist;
    Empty set (0.00 sec)

    mysql> select ISPREFIX from blacklist;
    Empty set (0.00 sec)

    If cpHulk does not store this blacklisted IP in the MySQL database, where does it store it?

    Kind regards,

    Ruan
     
  2. Jcats

    Jcats Well-Known Member

    Joined:
    May 25, 2011
    Messages:
    275
    Likes Received:
    31
    Trophy Points:
    28
    Location:
    New Jersey
    cPanel Access Level:
    DataCenter Provider
    I just ran an strace when running that script and noticed:

    sendto(3, "\267\0\0\0\3INSERT INTO ip_lists (START"..., 187, MSG_NOSIGNAL, NULL, 0) = 187

    so its storing it in the ip_lists table however its stored using varbinary
     
    Ruan likes this.
  3. 24x7ss

    24x7ss Well-Known Member

    Joined:
    Sep 30, 2014
    Messages:
    271
    Likes Received:
    16
    Trophy Points:
    18
    Location:
    India
    cPanel Access Level:
    Root Administrator
    Twitter:
    cphulk will restore the ips in cphulk db. You can use below command to check the list of IP.

    select IP, LOGINTIME FROM logins order by LOGINTIME;

    select IP, BRUTETIME from brutes order by BRUTETIME;

    Make sure you are running these commands in mysql cphulk db.
     
Loading...

Share This Page