Skip to content

[Bug] Whitelist configuration is ignored, resulting in explicitly whitelisted IPs getting banned #363

Description

@juckee

Environment:OS: Windows Server 2019 Standard (10.0.17763) IPBan Version: 4.1.0 (Windows-x64) Database: SQLite (ipban.sqlite) Description:
In version 4.1.0, the standard Whitelist key in ipban.config fails to parse or match incoming IP addresses. Even when an IP is explicitly defined as a single value (or as part of a comma-separated list/CIDR block), the application ignores it and proceeds to ban the IP after the FailedLoginAttemptsBeforeBan threshold is reached. Steps to Reproduce:Stop the IPBan service.Delete the ipban.sqlite database to start clean.Configure ipban.config with a single explicit IP in the Whitelist key:XML
Run IPBan (Console or Service). Trigger failed logins from xx.xx.xx.51 (e.g., MSSQL event 18456). Observe the console or log file.Expected Behavior:The IP should be recognized as whitelisted, and no ban/firewall addition should occur despite the failed login attempts.Actual Behavior:
The whitelist is ignored. The log explicitly states user name whitelisted: False, and the IP is added to the firewall block list. Log Output:Plaintext2026-09-26 10:30:24.3343|WARN|IPBan|Login failure: xx.xx.xx.51, uTest, MSSQL, 5, 18456, reason:
2026-09-26 10:30:24.3343|INFO|IPBan|IP blacklisted: False, user name blacklisted: False, user name edit distance blacklisted: False, user name whitelisted: False
2026-09-26 10:30:24.3503|WARN|IPBan|Banning ip address: xx.xx.xx.51, user name: uTest, config blacklisted: False, count: 5, extra info: , duration: 00:05:00
2026-09-26 10:30:24.3706|WARN|IPBan|Updating firewall with 1 entries...
2026-09-26 10:30:24.3706|INFO|IPBan|Firewall entries updated: xx.xx.xx.51:add
Additional Context / Workaround:The issue persists regardless of formatting (removing spaces, removing CIDR notation, using a single IP). No duplicate <add key="Whitelist"... entries exist in the config file. Using WhitelistRegex (e.g., ) or UserNameWhitelist successfully bypasses the ban, confirming that the bug is specifically isolated to the standard Whitelist string parsing/matching logic.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions