Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to Turn Off cPHulk and Unblock IPs Using SSH

If you are locked out of WHM or cPanel, this guide shows how to clear the block from the command line. It needs root access.

Web Hosting2 min read7 steps

What is cPHulk?

cPHulk is a security tool in WHM. WHM is the admin panel for a server with cPanel. cPHulk watches for too many wrong password tries, like a guard who stops someone rattling the door handle. After several failed logins, it blocks that IP address. An IP address is the number that identifies your computer on the internet.

Sometimes it blocks you by mistake. Then you cannot log in, even with the right password.

Warning: cPHulk protects your server from password guessing. Turn it off only for a short time, and turn it on again after you finish.

Steps

  1. Connect to your server with SSH as root. If your own IP is blocked, try from another network, such as a phone hotspot. If you cannot connect at all, ask support.
  2. Check the status of cPHulk:
whmapi1 get_cphulk_config

This prints the current cPHulk settings.

  1. Turn cPHulk off:
whmapi1 configureservice service=cphulkd enabled=0 monitored=0

This stops the cPHulk service and stops its monitoring.

  1. Stop the daemon directly if it is still running:
/usr/local/cpanel/scripts/restartsrv_cphulkd --stop

This stops the background process.

  1. Clear the blocked list:
whmapi1 flush_cphulk_login_history

This removes the saved failed login records, so blocks based on them are cleared.

  1. If one IP is on the blacklist, remove it. Replace the number with the right one:
whmapi1 delete_cphulk_record ip=203.0.113.5 list_name=black

This deletes that IP from the black list.

  1. Log in to WHM again in your browser.

Add your IP to the white list

The white list is a list of trusted addresses. Add your IP so it is not blocked again:

whmapi1 create_cphulk_record ip=203.0.113.5 list_name=white

Use your real public IP in place of the example.

Turn cPHulk back on

whmapi1 configureservice service=cphulkd enabled=1 monitored=1
/usr/local/cpanel/scripts/restartsrv_cphulkd

This starts the service again and turns monitoring on.

The server firewall can also block you. If login still fails, open a support ticket.

Quick recap

  • cPHulk blocks IPs after failed logins.
  • Use whmapi1 as root to turn it off and flush records.
  • Add your IP to the white list.
  • Turn cPHulk on again when done.