What is cPHulk?
cPHulk is a security tool in WHM. WHM is the admin panel for a server with cPanel. cPHulk watches for too many wrong password tries, like a guard who stops someone rattling the door handle. After several failed logins, it blocks that IP address. An IP address is the number that identifies your computer on the internet.
Sometimes it blocks you by mistake. Then you cannot log in, even with the right password.
Steps
- Connect to your server with SSH as root. If your own IP is blocked, try from another network, such as a phone hotspot. If you cannot connect at all, ask support.
- Check the status of cPHulk:
whmapi1 get_cphulk_config
This prints the current cPHulk settings.
- Turn cPHulk off:
whmapi1 configureservice service=cphulkd enabled=0 monitored=0
This stops the cPHulk service and stops its monitoring.
- Stop the daemon directly if it is still running:
/usr/local/cpanel/scripts/restartsrv_cphulkd --stop
This stops the background process.
- Clear the blocked list:
whmapi1 flush_cphulk_login_history
This removes the saved failed login records, so blocks based on them are cleared.
- If one IP is on the blacklist, remove it. Replace the number with the right one:
whmapi1 delete_cphulk_record ip=203.0.113.5 list_name=black
This deletes that IP from the black list.
- Log in to WHM again in your browser.
Add your IP to the white list
The white list is a list of trusted addresses. Add your IP so it is not blocked again:
whmapi1 create_cphulk_record ip=203.0.113.5 list_name=white
Use your real public IP in place of the example.
Turn cPHulk back on
whmapi1 configureservice service=cphulkd enabled=1 monitored=1
/usr/local/cpanel/scripts/restartsrv_cphulkd
This starts the service again and turns monitoring on.
The server firewall can also block you. If login still fails, open a support ticket.
Quick recap
- cPHulk blocks IPs after failed logins.
- Use whmapi1 as root to turn it off and flush records.
- Add your IP to the white list.
- Turn cPHulk on again when done.