Zen Cart Logo
Forums / All Other Contributions/Addons / AbuseIPDB Integration module

AbuseIPDB Integration module

Views: 22,005

Results 81 to 100 of 132
17 May 2025, 7:10 PM
#82
marcopolo avatar

marcopolo

Totally Zenned

Join Date:
May 2008
Location:
United States
Posts:
520
Plugin Contributions:
2

Re: AbuseIPDB Integration module

🛡️ Major Release – AbuseIPDB v4.0.0

This version introduces advanced flood detection and blocking, giving you full control over how your site handles aggressive traffic patterns.

🚨 What’s New:
Flood Blocking by IP Range
You can now automatically block 2-octet (e.g., 192.168.) or 3-octet (e.g., 192.168.1.) IP ranges.
Example: If 192.168.x.x exceeds the request limit (default 25 hits in 30 minutes), the entire 2-octet range will be blocked. If 30 minutes pass with no further hits, the block resets.

Country & Foreign Blocking
Works the same way — if traffic from a country exceeds the flood threshold, the country is temporarily blocked.
You can choose to allow low-score IPs through by setting a minimum AbuseIPDB score (or set it to 0 to block all traffic from that country).
Manual country blocking is also supported.

High Score Caching
New AbuseIPDB high-score cache prevents repeated API calls. If an IP already scored above the block threshold, it won’t be rechecked for X days (default: 7).

New Visual Shields in Who’s Online
Clearly see why an IP is being blocked:

🔴 Red – Score-blocked by AbuseIPDB

🟣 Purple – Manually blacklisted

🔵 Blue – Manually country-blocked

🟠 Orange – Flood-blocked (range, country, or foreign)

Personal Recommendation:
For daily use, I recommend enabling only the 2-octet, 3-octet, and foreign flood protection.
Use country-based blocking only during an active attack — because it will also block IPs from your default country.

That’s why foreign blocking is preferred for general use — it works the same way but will never block your default country.

Enjoy!

17 May 2025, 7:38 PM
#83
dbltoe avatar

dbltoe

Totally Zenned

Join Date:
Jan 2004
Location:
N of San Antonio TX
Posts:
9,816
Plugin Contributions:
16

Re: AbuseIPDB Integration module

Installed and did cleanup. 500 error with this debug

[17-May-2025 14:26:37 America/Chicago] PHP Fatal error:  Uncaught Error: Undefined constant "ABUSEIPDB_HIGH_SCORE_CACHE_ENABLED" in /home/MY_USER/public_html/zc_plugins/AbuseIPDB/v4.0.0/catalog/includes/classes/observers/abuseipdb_observer.php:222Stack trace:
#0 /home/MY_USER/public_html/zc_plugins/AbuseIPDB/v4.0.0/catalog/includes/classes/observers/abuseipdb_observer.php(22): abuseipdb_observer->checkAbusiveIP()
#1 /home/MY_USER/public_html/includes/classes/traits/NotifierManager.php(107): abuseipdb_observer->update(Object(notifier), 'NOTIFY_HTML_HEA...', 'index', 'MY_TEMPLATE', NULL, NULL, NULL, NULL, NULL, NULL, NULL)
#2 /home/MY_USER/public_html/includes/templates/MY_TEMPLATE/common/html_header.php(19): base->notify('NOTIFY_HTML_HEA...', 'index', 'MY_TEMPLATE')
#3 /home/MY_USER/public_html/index.php(48): require('/home/MY_USER/...')
#4 {main}
  thrown in /home/MY_USER/public_html/zc_plugins/AbuseIPDB/v4.0.0/catalog/includes/classes/observers/abuseipdb_observer.php on line 222


[17-May-2025 14:26:37 America/Chicago] Request URI: /, IP address: 123.234.134.255
--> PHP Fatal error: Uncaught Error: Undefined constant "ABUSEIPDB_HIGH_SCORE_CACHE_ENABLED" in /home/MY_USER/public_html/zc_plugins/AbuseIPDB/v4.0.0/catalog/includes/classes/observers/abuseipdb_observer.php:222
Stack trace:
#0 /home/MY_USER/public_html/zc_plugins/AbuseIPDB/v4.0.0/catalog/includes/classes/observers/abuseipdb_observer.php(22): abuseipdb_observer->checkAbusiveIP()
#1 /home/MY_USER/public_html/includes/classes/traits/NotifierManager.php(107): abuseipdb_observer->update(Object(notifier), 'NOTIFY_HTML_HEA...', 'index', 'MY_TEMPLATE', NULL, NULL, NULL, NULL, NULL, NULL, NULL)
#2 /home/MY_USER/public_html/includes/templates/MY_TEMPLATE/common/html_header.php(19): base->notify('NOTIFY_HTML_HEA...', 'index', 'MY_TEMPLATE')
#3 /home/MY_USER/public_html/index.php(48): require('/home/MY_USER/...')
#4 {main}
  thrown in /home/MY_USER/public_html/zc_plugins/AbuseIPDB/v4.0.0/catalog/includes/classes/observers/abuseipdb_observer.php on line 222.


[17-May-2025 14:26:37 America/Chicago] Request URI: /, IP address: 123.234.134.255
--> PHP Fatal error: Uncaught Error: Undefined constant "ABUSEIPDB_HIGH_SCORE_CACHE_ENABLED" in /home/MY_USER/public_html/zc_plugins/AbuseIPDB/v4.0.0/catalog/includes/classes/observers/abuseipdb_observer.php:222
Stack trace:
#0 /home/MY_USER/public_html/zc_plugins/AbuseIPDB/v4.0.0/catalog/includes/classes/observers/abuseipdb_observer.php(22): abuseipdb_observer->checkAbusiveIP()
#1 /home/MY_USER/public_html/includes/classes/traits/NotifierManager.php(107): abuseipdb_observer->update(Object(notifier), 'NOTIFY_HTML_HEA...', 'index', 'MY_TEMPLATE', NULL, NULL, NULL, NULL, NULL, NULL, NULL)
#2 /home/MY_USER/public_html/includes/templates/MY_TEMPLATE/common/html_header.php(19): base->notify('NOTIFY_HTML_HEA...', 'index', 'MY_TEMPLATE')
#3 /home/MY_USER/public_html/index.php(48): require('/home/MY_USER/...')
#4 {main}
  thrown in /home/MY_USER/public_html/zc_plugins/AbuseIPDB/v4.0.0/catalog/includes/classes/observers/abuseipdb_observer.php on line 222.
17 May 2025, 8:04 PM
#84
marcopolo avatar

marcopolo

Totally Zenned

Join Date:
May 2008
Location:
United States
Posts:
520
Plugin Contributions:
2

Re: AbuseIPDB Integration module

dbltoe:

Installed and did cleanup. 500 error with this debug

[17-May-2025 14:26:37 America/Chicago] PHP Fatal error: Uncaught Error: Undefined constant "ABUSEIPDB_HIGH_SCORE_CACHE_ENABLED" in /home/MY_USER/public_html/zc_plugins/AbuseIPDB/v4.0.0/catalog/includes/classes/observers/abuseipdb_observer.php:222Stack trace:
#0 /home/MY_USER/public_html/zc_plugins/AbuseIPDB/v4.0.0/catalog/includes/classes/observers/abuseipdb_observer.php(22): abuseipdb_observer->checkAbusiveIP()
#1 /home/MY_USER/public_html/includes/classes/traits/NotifierManager.php(107): abuseipdb_observer->update(Object(notifier), 'NOTIFY_HTML_HEA...', 'index', 'MY_TEMPLATE', NULL, NULL, NULL, NULL, NULL, NULL, NULL)
#2 /home/MY_USER/public_html/includes/templates/MY_TEMPLATE/common/html_header.php(19): base->notify('NOTIFY_HTML_HEA...', 'index', 'MY_TEMPLATE')
#3 /home/MY_USER/public_html/index.php(48): require('/home/MY_USER/...')
#4 {main}
thrown in /home/MY_USER/public_html/zc_plugins/AbuseIPDB/v4.0.0/catalog/includes/classes/observers/abuseipdb_observer.php on line 222

[17-May-2025 14:26:37 America/Chicago] Request URI: /, IP address: 123.234.134.255
--> PHP Fatal error: Uncaught Error: Undefined constant "ABUSEIPDB_HIGH_SCORE_CACHE_ENABLED" in /home/MY_USER/public_html/zc_plugins/AbuseIPDB/v4.0.0/catalog/includes/classes/observers/abuseipdb_observer.php:222
Stack trace:
#0 /home/MY_USER/public_html/zc_plugins/AbuseIPDB/v4.0.0/catalog/includes/classes/observers/abuseipdb_observer.php(22): abuseipdb_observer->checkAbusiveIP()
#1 /home/MY_USER/public_html/includes/classes/traits/NotifierManager.php(107): abuseipdb_observer->update(Object(notifier), 'NOTIFY_HTML_HEA...', 'index', 'MY_TEMPLATE', NULL, NULL, NULL, NULL, NULL, NULL, NULL)
#2 /home/MY_USER/public_html/includes/templates/MY_TEMPLATE/common/html_header.php(19): base->notify('NOTIFY_HTML_HEA...', 'index', 'MY_TEMPLATE')
#3 /home/MY_USER/public_html/index.php(48): require('/home/MY_USER/...')
#4 {main}
thrown in /home/MY_USER/public_html/zc_plugins/AbuseIPDB/v4.0.0/catalog/includes/classes/observers/abuseipdb_observer.php on line 222.

[17-May-2025 14:26:37 America/Chicago] Request URI: /, IP address: 123.234.134.255
--> PHP Fatal error: Uncaught Error: Undefined constant "ABUSEIPDB_HIGH_SCORE_CACHE_ENABLED" in /home/MY_USER/public_html/zc_plugins/AbuseIPDB/v4.0.0/catalog/includes/classes/observers/abuseipdb_observer.php:222
Stack trace:
#0 /home/MY_USER/public_html/zc_plugins/AbuseIPDB/v4.0.0/catalog/includes/classes/observers/abuseipdb_observer.php(22): abuseipdb_observer->checkAbusiveIP()
#1 /home/MY_USER/public_html/includes/classes/traits/NotifierManager.php(107): abuseipdb_observer->update(Object(notifier), 'NOTIFY_HTML_HEA...', 'index', 'MY_TEMPLATE', NULL, NULL, NULL, NULL, NULL, NULL, NULL)
#2 /home/MY_USER/public_html/includes/templates/MY_TEMPLATE/common/html_header.php(19): base->notify('NOTIFY_HTML_HEA...', 'index', 'MY_TEMPLATE')
#3 /home/MY_USER/public_html/index.php(48): require('/home/MY_USER/...')
#4 {main}
thrown in /home/MY_USER/public_html/zc_plugins/AbuseIPDB/v4.0.0/catalog/includes/classes/observers/abuseipdb_observer.php on line 222.



Can you confirm the following admin setting for the module that it says: (third one down)

Total Settings	47

Also confirm you see the admin setting:  Enable High Score Cache Extension
17 May 2025, 8:22 PM
#85
dbltoe avatar

dbltoe

Totally Zenned

Join Date:
Jan 2004
Location:
N of San Antonio TX
Posts:
9,816
Plugin Contributions:
16

Re: AbuseIPDB Integration module

Can't access the admin settings with the mod disabled, but the database still shows 3.0.4 version and 27 for total settings.

17 May 2025, 8:25 PM
#86
marcopolo avatar

marcopolo

Totally Zenned

Join Date:
May 2008
Location:
United States
Posts:
520
Plugin Contributions:
2

Re: AbuseIPDB Integration module

marcopolo:

Let me know what module is using the file: jscript_framework.php as it is not part of this modules files, if you can upload the file here so I can take a look at the code and see what it is doing.

Put back your old files. Sounds like you did not uninstall it first. This was not upgrade you have to uninstall first then do a fresh install as noted.

17 May 2025, 8:29 PM
#87
dbltoe avatar

dbltoe

Totally Zenned

Join Date:
Jan 2004
Location:
N of San Antonio TX
Posts:
9,816
Plugin Contributions:
16

Re: AbuseIPDB Integration module

Plugin Manager was still showing 3.0.4, did an uninstall, zc_plugins directory showed only 4.0.0 as I had done the cleanup.

Reinstalled using Plugin Manager and all is fine. Got the 47 and the Enable High Score...

17 May 2025, 8:30 PM
#88
marcopolo avatar

marcopolo

Totally Zenned

Join Date:
May 2008
Location:
United States
Posts:
520
Plugin Contributions:
2

Re: AbuseIPDB Integration module

dbltoe:

Can't access the admin settings with the mod disabled, but the database still shows 3.0.4 version and 27 for total settings.

You can upload the files from 3.0.4 into 4.0.0 that should allow you to login and uninstall it.

just manually upload:

zc_plugins\AbuseIPDB\v3.0.4*

into

zc_plugins\AbuseIPDB\v4.0.0*

or just

zc_plugins\AbuseIPDB\v3.0.4\catalog\includes\classes\observers\abuseipdb_observer.php

into

zc_plugins\AbuseIPDB\v4.0.0\catalog\includes\classes\observers\abuseipdb_observer.php

that should let you back into admin.

17 May 2025, 8:33 PM
#89
marcopolo avatar

marcopolo

Totally Zenned

Join Date:
May 2008
Location:
United States
Posts:
520
Plugin Contributions:
2

Re: AbuseIPDB Integration module

dbltoe:

Plugin Manager was still showing 3.0.4, did an uninstall, zc_plugins directory showed only 4.0.0 as I had done the cleanup.

Reinstalled using Plugin Manager and all is fine. Got the 47 and the Enable High Score...

Ok great glad it is working!

So for others not to have this issue as noted in the readme:

Major Update Notice: If you are upgrading from v3.0.4 or earlier, you must uninstall the previous module before installing v4.0.0.
⚡ Important: Be sure to screen-capture your existing settings before uninstalling AbuseIPDB v3.0.4 or lower to preserve your configuration.

17 May 2025, 8:40 PM
#90
dbltoe avatar

dbltoe

Totally Zenned

Join Date:
Jan 2004
Location:
N of San Antonio TX
Posts:
9,816
Plugin Contributions:
16

Re: AbuseIPDB Integration module

Please review your README.md and identify the steps from an encapsulated plugin to a newer plugin. Otherwise, others will lose their API data as we did.

I would note that, normally, a plugin notifies the owner of an update, the update is done, and the option to clean old files follows the upgrade. https://docs.zen-cart.com/dev/plugins/encapsulated_plugins/upgrading/

17 May 2025, 9:00 PM
#91
dbltoe avatar

dbltoe

Totally Zenned

Join Date:
Jan 2004
Location:
N of San Antonio TX
Posts:
9,816
Plugin Contributions:
16

Re: AbuseIPDB Integration module

You might want to move that message inside the INSTALLATTION AND UPGRADE section.

17 May 2025, 9:02 PM
#92
marcopolo avatar

marcopolo

Totally Zenned

Join Date:
May 2008
Location:
United States
Posts:
520
Plugin Contributions:
2

Re: AbuseIPDB Integration module

dbltoe:

Please review your README.md and identify the steps from an encapsulated plugin to a newer plugin. Otherwise, others will lose their API data as we did.

I would note that, normally, a plugin notifies the owner of an update, the update is done, and the option to clean old files follows the upgrade. https://docs.zen-cart.com/dev/plugins/encapsulated_plugins/upgrading/

As stated, the instructions are clear — you need to uninstall. I could’ve made it an upgrade, but that would’ve meant a lot more work for the installer. Unfortunately, this means you’ll lose your database data. It is possible to skip uninstalling certain tables, but that’s more of an advanced option. Since I’m offering this for free, I don’t have the time to troubleshoot those kinds of setups. This update adds a lot of new features, so it had to be done this way.

17 May 2025, 9:25 PM
#93
marcopolo avatar

marcopolo

Totally Zenned

Join Date:
May 2008
Location:
United States
Posts:
520
Plugin Contributions:
2

Re: AbuseIPDB Integration module

Posting again so everyone is clear on this:

INSTALLATION AND UPGRADE
Major Update Notice: If you are upgrading from v3.0.4 or earlier, you must uninstall the previous module before installing v4.0.0.
⚡ Important: Be sure to screen-capture your existing settings before uninstalling AbuseIPDB v3.0.4 or lower to preserve your configuration.

Advanced Uninstallation: Preserving Cache Database
If you are an advanced user and do not want to lose your cache database when uninstalling the plugin, you can modify the installer to preserve the database tables (abuseipdb_cache, abuseipdb_maintenance, and abuseipdb_flood). Follow these steps:

Open the installer file for your current version (e.g., ScriptedInstaller.php) in a text editor.
Locate the executeUninstall() method near the end of the file.
Delete the following lines to prevent dropping the tables during uninstallation:

$this->executeInstallerSql("DROP TABLE IF EXISTS " . TABLE_ABUSEIPDB_CACHE);
$this->executeInstallerSql("DROP TABLE IF EXISTS " . TABLE_ABUSEIPDB_MAINTENANCE);

Save the file and proceed with the uninstallation via the Zen Cart admin panel. This will remove the plugin settings but leave the tables intact.
When you install the new version, the installer will skip creating these tables if they already exist, preserving your data.

🛡️ Major Release – AbuseIPDB v4.0.0

This version introduces advanced flood detection and blocking, giving you full control over how your site handles aggressive traffic patterns.

🚨 What’s New:
Flood Blocking by IP Range
You can now automatically block 2-octet (e.g., 192.168.) or 3-octet (e.g., 192.168.1.) IP ranges.
Example: If 192.168.x.x exceeds the request limit (default 25 hits in 30 minutes), the entire 2-octet range will be blocked. If 30 minutes pass with no further hits, the block resets.

Country & Foreign Blocking
Works the same way — if traffic from a country exceeds the flood threshold, the country is temporarily blocked.
You can choose to allow low-score IPs through by setting a minimum AbuseIPDB score (or set it to 0 to block all traffic from that country).
Manual country blocking is also supported.

High Score Caching
New AbuseIPDB high-score cache prevents repeated API calls. If an IP already scored above the block threshold, it won’t be rechecked for X days (default: 7).

New Visual Shields in Who’s Online
Clearly see why an IP is being blocked:

🔴 Red – Score-blocked by AbuseIPDB

🟣 Purple – Manually blacklisted

🔵 Blue – Manually country-blocked

🟠 Orange – Flood-blocked (range, country, or foreign)

Personal Recommendation:
For daily use, I recommend enabling only the 2-octet, 3-octet, and foreign flood protection.
Use country-based blocking only during an active attack — it will block IPs from your default country as well.

NOTE:
The 2-octet and 3-octet flood logic will block IPs even from your default country — there's no skip setting for those.
This is by design, as tight-range IP floods are typically bot attacks.
I may add an option to bypass default-country IPs in a future version.

Enjoy!

17 May 2025, 9:43 PM
#94
marcopolo avatar

marcopolo

Totally Zenned

Join Date:
May 2008
Location:
United States
Posts:
520
Plugin Contributions:
2

Re: AbuseIPDB Integration module

marcopolo:

Posting again so everyone is clear on this:

INSTALLATION AND UPGRADE
Major Update Notice: If you are upgrading from v3.0.4 or earlier, you must uninstall the previous module before installing v4.0.0.
⚡ Important: Be sure to screen-capture your existing settings before uninstalling AbuseIPDB v3.0.4 or lower to preserve your configuration.

Advanced Uninstallation: Preserving Cache Database
If you are an advanced user and do not want to lose your cache database when uninstalling the plugin, you can modify the installer to preserve the database tables (abuseipdb_cache, abuseipdb_maintenance, and abuseipdb_flood). Follow these steps:

Open the installer file for your current version (e.g., ScriptedInstaller.php) in a text editor.
Locate the executeUninstall() method near the end of the file.
Delete the following lines to prevent dropping the tables during uninstallation:

$this->executeInstallerSql("DROP TABLE IF EXISTS " . TABLE_ABUSEIPDB_CACHE);
$this->executeInstallerSql("DROP TABLE IF EXISTS " . TABLE_ABUSEIPDB_MAINTENANCE);

> Save the file and proceed with the uninstallation via the Zen Cart admin panel. This will remove the plugin settings but leave the tables intact.
> When you install the new version, the installer will skip creating these tables if they already exist, preserving your data.
> 
> 
> 🛡️ Major Release – AbuseIPDB v4.0.0
> 
> This version introduces advanced flood detection and blocking, giving you full control over how your site handles aggressive traffic patterns.
> 
> 🚨 What’s New:
> Flood Blocking by IP Range
> You can now automatically block 2-octet (e.g., 192.168.*) or 3-octet (e.g., 192.168.1.*) IP ranges.
> Example: If 192.168.x.x exceeds the request limit (default 25 hits in 30 minutes), the entire 2-octet range will be blocked. If 30 minutes pass with no further hits, the block resets.
> 
> Country & Foreign Blocking
> Works the same way — if traffic from a country exceeds the flood threshold, the country is temporarily blocked.
> You can choose to allow low-score IPs through by setting a minimum AbuseIPDB score (or set it to 0 to block all traffic from that country).
> Manual country blocking is also supported.
> 
> High Score Caching
> New AbuseIPDB high-score cache prevents repeated API calls. If an IP already scored above the block threshold, it won’t be rechecked for X days (default: 7).
> 
> New Visual Shields in Who’s Online
> Clearly see why an IP is being blocked:
> 
> 🔴 Red – Score-blocked by AbuseIPDB
> 
> 🟣 Purple – Manually blacklisted
> 
> 🔵 Blue – Manually country-blocked
> 
> 🟠 Orange – Flood-blocked (range, country, or foreign)
> 
> 
> **Personal Recommendation:**
> For daily use, I recommend enabling only the 2-octet, 3-octet, and foreign flood protection.
> Use country-based blocking only during an active attack — it will block IPs from your default country as well.
> 
> **NOTE:**
> The 2-octet and 3-octet flood logic will block IPs even from your default country — there's no skip setting for those.
> This is by design, as tight-range IP floods are typically bot attacks.
> I may add an option to bypass default-country IPs in a future version.
> 
> Enjoy!

Important Note:
Actually, do not keep the old tables — the new version of the plugin includes an updated abuseipdb_cache table with a new column I forgot to mention (flood_tracked).
17 May 2025, 9:49 PM
#95
marcopolo avatar

marcopolo

Totally Zenned

Join Date:
May 2008
Location:
United States
Posts:
520
Plugin Contributions:
2

Re: AbuseIPDB Integration module

Ignore the post before this one where I gave you a option to preserve your tables that will not work. The new version of the plugin includes an updated abuseipdb_cache table with a new column I forgot to mention (flood_tracked).

18 May 2025, 9:56 AM
#96
pilou2 avatar

pilou2

Zen Follower

Join Date:
Jun 2008
Location:
Japan
Posts:
395
Plugin Contributions:
6

Re: AbuseIPDB Integration module

I submitted a PR on GitHub for a new installer version that should resolve most of your problems.
If you adopt it, you still have to update the install explanation in the readme...

18 May 2025, 1:55 PM
#97
marcopolo avatar

marcopolo

Totally Zenned

Join Date:
May 2008
Location:
United States
Posts:
520
Plugin Contributions:
2

Re: AbuseIPDB Integration module

dbltoe:

Plugin Manager was still showing 3.0.4, did an uninstall, zc_plugins directory showed only 4.0.0 as I had done the cleanup.

Reinstalled using Plugin Manager and all is fine. Got the 47 and the Enable High Score...

New Version Available: AbuseIPDB v4.0.1

The latest version is now available on GitHub: v4.0.1
This update adds full upgrade support — you can now upgrade without uninstalling.

Special thanks to @piloujp for contributing to the improved upgrade logic.

[@swguy] — please disregard my previously submitted v4.0.0 release. I’ll be submitting v4.0.1 instead.

GitHub: https://github.com/CcMarc/AbuseIPDB

18 May 2025, 4:00 PM
#98
pilou2 avatar

pilou2

Zen Follower

Join Date:
Jun 2008
Location:
Japan
Posts:
395
Plugin Contributions:
6

Re: AbuseIPDB Integration module

I installed 4.01 release over an old version without any problem. :)
I just have one question, why do you keep version number in configuration table? With encapsulated plugins, Plugin Manager saves this information in plugin_control_version table already.

18 May 2025, 4:19 PM
#99
marcopolo avatar

marcopolo

Totally Zenned

Join Date:
May 2008
Location:
United States
Posts:
520
Plugin Contributions:
2

Re: AbuseIPDB Integration module

pilou2:

I installed 4.01 release over an old version without any problem. :)
I just have one question, why do you keep version number in configuration table? With encapsulated plugins, Plugin Manager saves this information in plugin_control_version table already.

You're absolutely right — I could pull it from the plugin_control_version table. The encapsulated plugin logic is still fairly new to me, and I haven’t fully transitioned to Zen Cart v2.1.0 yet — I’m in the middle of that upgrade process. The version number in the configuration table was part of the older approach, and I just left it in place when converting the plugin to an encapsulated version.

24 May 2025, 6:51 PM
#100
marcopolo avatar

marcopolo

Totally Zenned

Join Date:
May 2008
Location:
United States
Posts:
520
Plugin Contributions:
2

Re: AbuseIPDB Integration module

I’m exploring a possible new feature for the AbuseIPDB plugin to prevent bots from rapidly creating sessions in Zen Cart (e.g., 1000+ sessions in a short time), which can overload the server. I’ve seen this happen a few times—bots create thousands of sessions and cause major performance issues. Since Zen Cart’s session_start() in application_top.php runs before the plugin can intervene, we need to block these requests before session creation.

Goal:
Block session creation for IPs that exceed a rate threshold (e.g., 100 sessions in 1 minute), while allowing normal browsing patterns (e.g., 100 sessions over 30 minutes).

Proposed Approach:

Use an auto-loader or similar method to run a check before session_start() in application_top.php.

Track session rates per IP in TABLE_ABUSEIPDB_CACHE (session count and window start time).

Use a sliding window (e.g., 60 seconds): increment count per request, reset after window expires.

If the count exceeds the threshold, return a 403 Forbidden response and exit.

Alternative (Not Preferred):
Dynamically write deny rules to .htaccess to block IPs at the Apache level before PHP runs. We’d prefer to avoid this for compatibility with non-Apache servers.

This issue is rare but impactful, so we need to address it. I’d really appreciate input from anyone who’s tackled similar problems, or ideas on the cleanest and most portable way to intercept or throttle session creation before session_start() runs. Any advice on standard mechanisms, code examples, or pitfalls to watch out for would be greatly appreciated!

If there isn’t a clean way to accomplish this in the current Zen Cart architecture, I’d suggest considering it for a future version. It would be ideal if Zen Cart provided a standard pre-session hook or filtering mechanism—either in the core or through a well-documented extension point—so modules like AbuseIPDB (or others) can intercept and block abusive requests before sessions are created. This would make handling rate-limiting and abuse much more robust and portable going forward.

Thanks,