Skip to main content

cpanel-csf 16.20 WHM temporary IP form stores “-p” as comment and ignores later arguments

Comments

8 comments

  • cPRex Jurassic Moderator

    Hey there!  I've reached out to the CSF team about this and I'll let you know once I have an update to share.

    0
  • cPRex Jurassic Moderator

    Our team was able to confirm this behavior and we've created case CPANEL-55408 to have the developers work on this.  I've also linked this thread to the case so I'll be sure to post any updates as I hear them.

    Thanks for reaching out to us about this!

     

    0
  • Dezdan

    Thanks for the update! 

    0
  • cPRex Jurassic Moderator

    You're very welcome!

    0
  • Metro2

    cPRex

    Just ran into this today on csf v16.30 (cPanel), and I think there may be a little more to this bug than what was originally reported here.

    I was trying to temporarily block one IP from mail access while leaving HTTPS/Webmail available.

    First I tried:

    csf -td 203.0.113.86 3600 -p 25,110,143,465,587,993,995 -d in "Temporary mail block"
    

    CSF accepted it, but created:

    csf: 203.0.113.86 blocked on port * for 3600 seconds inbound
    

    I assumed maybe the comma-separated port list was the problem, so I removed it and tried the simplest possible test with one port:

    csf -td 203.0.113.86 3600 -p 993 -d in "Temporary mail block"
    

    Same result:

    csf: 203.0.113.86 blocked on port * for 3600 seconds inbound
    

    csf -g confirmed that it actually installed an all-port DROP, and csf -t showed:

    DENY  203.0.113.86  *  in
    

    So this is still present in 16.30, and at least in my testing it is also reproducible directly from the command line with a single -p 993.

    That seems worth noting because the original report here was centered around the WHM temporary-IP form and argument handling. In this case there is no form involved at all - the CLI command itself is accepting the port argument and then silently applying the block to all ports.

    Hopefully that helps with CPANEL-55408.

    0
  • cPRex Jurassic Moderator

    Thanks for sharing!

    0
  • Dezdan

    Looks like it was fixed in the patch released today, thanks! 

    0
  • cPRex Jurassic Moderator

    Yes it made it into the security release!

    1

Please sign in to leave a comment.