Environment:OS: Windows Server 2019 Standard (10.0.17763) IPBan Version: 4.1.0 (Windows-x64) Database: SQLite (ipban.sqlite) Description:
In version 4.1.0, the standard Whitelist key in ipban.config fails to parse or match incoming IP addresses. Even when an IP is explicitly defined as a single value (or as part of a comma-separated list/CIDR block), the application ignores it and proceeds to ban the IP after the FailedLoginAttemptsBeforeBan threshold is reached. Steps to Reproduce:Stop the IPBan service.Delete the ipban.sqlite database to start clean.Configure ipban.config with a single explicit IP in the Whitelist key:XML
Run IPBan (Console or Service). Trigger failed logins from xx.xx.xx.51 (e.g., MSSQL event 18456). Observe the console or log file.Expected Behavior:The IP should be recognized as whitelisted, and no ban/firewall addition should occur despite the failed login attempts.Actual Behavior:
The whitelist is ignored. The log explicitly states user name whitelisted: False, and the IP is added to the firewall block list. Log Output:Plaintext2026-09-26 10:30:24.3343|WARN|IPBan|Login failure: xx.xx.xx.51, uTest, MSSQL, 5, 18456, reason:
2026-09-26 10:30:24.3343|INFO|IPBan|IP blacklisted: False, user name blacklisted: False, user name edit distance blacklisted: False, user name whitelisted: False
2026-09-26 10:30:24.3503|WARN|IPBan|Banning ip address: xx.xx.xx.51, user name: uTest, config blacklisted: False, count: 5, extra info: , duration: 00:05:00
2026-09-26 10:30:24.3706|WARN|IPBan|Updating firewall with 1 entries...
2026-09-26 10:30:24.3706|INFO|IPBan|Firewall entries updated: xx.xx.xx.51:add
Additional Context / Workaround:The issue persists regardless of formatting (removing spaces, removing CIDR notation, using a single IP). No duplicate <add key="Whitelist"... entries exist in the config file. Using WhitelistRegex (e.g., ) or UserNameWhitelist successfully bypasses the ban, confirming that the bug is specifically isolated to the standard Whitelist string parsing/matching logic.
Environment:OS: Windows Server 2019 Standard (10.0.17763) IPBan Version: 4.1.0 (Windows-x64) Database: SQLite (ipban.sqlite) Description:
In version 4.1.0, the standard Whitelist key in ipban.config fails to parse or match incoming IP addresses. Even when an IP is explicitly defined as a single value (or as part of a comma-separated list/CIDR block), the application ignores it and proceeds to ban the IP after the FailedLoginAttemptsBeforeBan threshold is reached. Steps to Reproduce:Stop the IPBan service.Delete the ipban.sqlite database to start clean.Configure ipban.config with a single explicit IP in the Whitelist key:XML
Run IPBan (Console or Service). Trigger failed logins from xx.xx.xx.51 (e.g., MSSQL event 18456). Observe the console or log file.Expected Behavior:The IP should be recognized as whitelisted, and no ban/firewall addition should occur despite the failed login attempts.Actual Behavior:
The whitelist is ignored. The log explicitly states user name whitelisted: False, and the IP is added to the firewall block list. Log Output:Plaintext2026-09-26 10:30:24.3343|WARN|IPBan|Login failure: xx.xx.xx.51, uTest, MSSQL, 5, 18456, reason:
2026-09-26 10:30:24.3343|INFO|IPBan|IP blacklisted: False, user name blacklisted: False, user name edit distance blacklisted: False, user name whitelisted: False
2026-09-26 10:30:24.3503|WARN|IPBan|Banning ip address: xx.xx.xx.51, user name: uTest, config blacklisted: False, count: 5, extra info: , duration: 00:05:00
2026-09-26 10:30:24.3706|WARN|IPBan|Updating firewall with 1 entries...
2026-09-26 10:30:24.3706|INFO|IPBan|Firewall entries updated: xx.xx.xx.51:add
Additional Context / Workaround:The issue persists regardless of formatting (removing spaces, removing CIDR notation, using a single IP). No duplicate <add key="Whitelist"... entries exist in the config file. Using WhitelistRegex (e.g., ) or UserNameWhitelist successfully bypasses the ban, confirming that the bug is specifically isolated to the standard Whitelist string parsing/matching logic.