Zen Cart Logo
Forums / All Other Contributions/Addons / AbuseIPDB Integration module

AbuseIPDB Integration module

Views: 22,005

Results 121 to 132 of 132
1 Sep 2025, 12:54 PM
#121
heathenmagic avatar

heathenmagic

Totally Zenned

Join Date:
May 2005
Location:
England
Posts:
733
Plugin Contributions:
0

AbuseIPDB Integration module

I had a customer say they tried to get on site for a few days, but it said 'access denied'. I am not sure what the message screen for abuse is actually, when blocked. They were able to get on okay at weekend though. I would say there was a massive bot scraping operation going on around same time apparently, I told server and they said they had come across this for the other sites on their systems. So they blocked that whole range. I don't have country flood enabled, do you think octet flood or session rate settings might be culprit? I am guessing the two are related, maybe the customer got caught in the crossfire with this big bot attack thing. Thanks in advance.

1 Sep 2025, 1:20 PM
#122
marcopolo avatar

marcopolo

Totally Zenned

Join Date:
May 2008
Location:
United States
Posts:
520
Plugin Contributions:
2

Re: AbuseIPDB Integration module

HeathenMagic:

I had a customer say they tried to get on site for a few days, but it said 'access denied'. I am not sure what the message screen for abuse is actually, when blocked. They were able to get on okay at weekend though. I would say there was a massive bot scraping operation going on around same time apparently, I told server and they said they had come across this for the other sites on their systems. So they blocked that whole range. I don't have country flood enabled, do you think octet flood or session rate settings might be culprit? I am guessing the two are related, maybe the customer got caught in the crossfire with this big bot attack thing. Thanks in advance.

If it had been a session rate limiting block, that would show up as a permanent Deny from <IP> entry in the .htaccess under the AbuseIPDB section. Since you don’t see their IP there, it wasn’t SRL.

You can see exactly what the customer would have seen by using the plugin’s Test Mode—that forces the “Access Denied” message regardless of score.

Another possibility is that the customer was on a VPN or mobile network where IPs tend to rotate. Those often carry higher AbuseIPDB scores and can be blocked even if you’re not using country flood.

To be sure, I’d recommend turning on logging in the plugin. That way you can look up their IP and see whether it was caught by:

Score block (exceeded your confidence threshold)

Octet flood (2- or 3-octet prefix got busy during the scrape)

Or if it was just your host’s server-level range ban

A couple other good practices from the README:

Whitelist trusted customer IPs if needed.

Keep an eye on the Who’s Online shields—they’ll show if it was score, blacklist, flood, or country that triggered.

Remember the Score-Safe rule: even if a flood threshold is hit, an IP still needs to meet the minimum score before blocking occurs. That helps avoid catching bursts of legit traffic like newsletters or sales.

If you’re not sure which feature bit, the log files are your best friend (abuseipdb_blocked_*, abuseipdb_session_blocks.log, etc.).

And yes—all of this is outlined in the README, so it’s worth a quick re-read whenever you’re tracking down one of these cases.

1 Sep 2025, 5:41 PM
#123
heathenmagic avatar

heathenmagic

Totally Zenned

Join Date:
May 2005
Location:
England
Posts:
733
Plugin Contributions:
0

Re: AbuseIPDB Integration module

marcopolo:

If it had been a session rate limiting block, that would show up as a permanent Deny from <IP> entry in the .htaccess under the AbuseIPDB section. Since you don’t see their IP there, it wasn’t SRL.

You can see exactly what the customer would have seen by using the plugin’s Test Mode—that forces the “Access Denied” message regardless of score.

Another possibility is that the customer was on a VPN or mobile network where IPs tend to rotate. Those often carry higher AbuseIPDB scores and can be blocked even if you’re not using country flood.

To be sure, I’d recommend turning on logging in the plugin. That way you can look up their IP and see whether it was caught by:

Score block (exceeded your confidence threshold)

Octet flood (2- or 3-octet prefix got busy during the scrape)

Or if it was just your host’s server-level range ban

A couple other good practices from the README:

Whitelist trusted customer IPs if needed.

Keep an eye on the Who’s Online shields—they’ll show if it was score, blacklist, flood, or country that triggered.

Remember the Score-Safe rule: even if a flood threshold is hit, an IP still needs to meet the minimum score before blocking occurs. That helps avoid catching bursts of legit traffic like newsletters or sales.

If you’re not sure which feature bit, the log files are your best friend (abuseipdb_blocked_*, abuseipdb_session_blocks.log, etc.).

And yes—all of this is outlined in the README, so it’s worth a quick re-read whenever you’re tracking down one of these cases.

Thanks so much for your reply! I just checked the customer account today, and it seems it is a different IP login than it was yesterday. They said not on VPN, so must be a mobile network. Both were BT. I didn't realise VPN would be high score rated sometimes. I guess some VPNs are more questionable than others. Perhaps I could increase threshold score from 41.

1 Sep 2025, 9:36 PM
#124
oldngrey avatar

oldngrey

Zen Follower

Join Date:
Apr 2008
Location:
Qld, Australia
Posts:
425
Plugin Contributions:
0

Re: AbuseIPDB Integration module

I use the following steps and have reduced the spam accounts, email abuse etc to a minimum:
threshold set to 45;
notice on front page re use of VPN and octet blocking by Wikimedia; and
I also use AccessBlocker on all 'Contact' forms.This can block a lot of tor sites and VPNs

10 Oct 2025, 5:11 PM
#125
heathenmagic avatar

heathenmagic

Totally Zenned

Join Date:
May 2005
Location:
England
Posts:
733
Plugin Contributions:
0

Re: AbuseIPDB Integration module

Not sure if an intermittent glitch, but doing an order for a customer in their account (pay via phone, select cash as method and put through) once logged in it showed the forbidden access screen. I tried my test account and the same thing for that also. Though it was 2 hours after abuseipdb daily limit exhausted. Though doing the same process just now, it is fine. I am guessing it may be AbuseIPDB service may do this due to exhausted access?
I also tried after exhaustion on mobile data, and the same forbidden once logging in. But not logging, it seemed okay.

11 Oct 2025, 2:51 PM
#126
shop_suey avatar

shop_suey

Zen Follower

Join Date:
Feb 2014
Location:
Germany
Posts:
375
Plugin Contributions:
0

Re: AbuseIPDB Integration module

Did you check the IP score at their website?

11 Oct 2025, 4:40 PM
#127
marcopolo avatar

marcopolo

Totally Zenned

Join Date:
May 2008
Location:
United States
Posts:
520
Plugin Contributions:
2

Re: AbuseIPDB Integration module

Shop Suey:

Did you check the IP score at their website?

When the AbuseIPDB daily quota was exhausted, older builds could treat the “-1” score in a way that kept incrementing flood counters on each refresh. That could tip your 2-octet/3-octet thresholds and show the Forbidden page especially right after login.

This is now fixed in v4.0.9:

“-1” (API exhausted) is now treated as safe (like score 0),

flood is seeded once (no per-refresh increments), and

no flood-based blocking occurs while the API is exhausted.

Download and install the updated v4.0.9 module available on GitHub: https://github.com/CcMarc/AbuseIPDB/releases/download/v4.0.9/AbuseIPDB_v4.0.9.zip

11 Oct 2025, 4:41 PM
#128
marcopolo avatar

marcopolo

Totally Zenned

Join Date:
May 2008
Location:
United States
Posts:
520
Plugin Contributions:
2

Re: AbuseIPDB Integration module

HeathenMagic:

Not sure if an intermittent glitch, but doing an order for a customer in their account (pay via phone, select cash as method and put through) once logged in it showed the forbidden access screen. I tried my test account and the same thing for that also. Though it was 2 hours after abuseipdb daily limit exhausted. Though doing the same process just now, it is fine. I am guessing it may be AbuseIPDB service may do this due to exhausted access?
I also tried after exhaustion on mobile data, and the same forbidden once logging in. But not logging, it seemed okay.

When the AbuseIPDB daily quota was exhausted, older builds could treat the “-1” score in a way that kept incrementing flood counters on each refresh. That could tip your 2-octet/3-octet thresholds and show the Forbidden page especially right after login.

This is now fixed in v4.0.9:

“-1” (API exhausted) is now treated as safe (like score 0),

flood is seeded once (no per-refresh increments), and

no flood-based blocking occurs while the API is exhausted.

Download and install the updated v4.0.9 module available on GitHub: https://github.com/CcMarc/AbuseIPDB/...PDB_v4.0.9.zip

28 Oct 2025, 4:18 AM
#129
siliconbug avatar

siliconbug

Zen Follower

Join Date:
Apr 2009
Posts:
125
Plugin Contributions:
0

Re: AbuseIPDB Integration module

In v2.1.2 (for ZC 1.5.8),
what's the difference between "Enable IP Blacklist File?" and "IP Address: Blacklist"?

28 Oct 2025, 10:05 AM
#130
marcopolo avatar

marcopolo

Totally Zenned

Join Date:
May 2008
Location:
United States
Posts:
520
Plugin Contributions:
2

Re: AbuseIPDB Integration module

siliconbug:

In v2.1.2 (for ZC 1.5.8),
what's the difference between "Enable IP Blacklist File?" and "IP Address: Blacklist"?

The admin blacklist setting lets you manually enter specific IPs to block right in the configuration panel.

If you enable the IP Blacklist File, the module will also check that file for matches and once that’s enabled, you can add IPs directly to the file or blacklist them instantly from the “Who’s Online” page using the 🚫 button.

21 May 2026, 8:12 PM
#131
njcyx avatar

njcyx

Zen Follower

Join Date:
Apr 2019
Posts:
368
Plugin Contributions:
0

Re: AbuseIPDB Integration module

My site recently was very very slow. Tried several ways to improve but no help. Then I installed this abuseipdb. When I enabled it, the website is no more slow!

Thanks for your contribution. Also thank you for your tips to increase api call to 5k per day in your installation guide.

21 May 2026, 8:43 PM
#132
njcyx avatar

njcyx

Zen Follower

Join Date:
Apr 2019
Posts:
368
Plugin Contributions:
0

Re: AbuseIPDB Integration module

One question. Regarding the whitelist/blacklist in the setting page, other than single IP address, can we also use IP ranges such as 192.168.1.0/23, or 192.168.1. ?