For webmasters, digital marketing agencies, and WooCommerce store owners in Pakistan, sudden web server sluggishness and high CPU alerts often trace back to a single culprit: aggressive rogue traffic.
Whether it is an overseas competitor launching a Layer 7 HTTP flood to take your e-commerce checkout offline, unauthorized AI scrapers scraping your product catalogs, or automated botnets hammering /wp-login.php with thousands of password guesses, rogue traffic steals precious server memory and CPU cycles.
While enterprise edge networks like Cloudflare provide frontline protection, knowing how to block malicious traffic directly inside your hosting environment is a fundamental sysadmin skill.
In this practical guide, we show you how to identify attacking IP addresses using cPanel Raw Access Logs and neutralize them using the cPanel IP Blocker and CIDR subnet rules.
π Step 1: Identifying Attacking IPs via cPanel Raw Access Logs
Before blocking random IPs, you must inspect the actual HTTP requests hitting your web server.
Method A: Download Raw Access Logs via cPanel GUI
- Log into your cPanel Dashboard.
- Under the Metrics section, click on Raw Access.
- Under Download Current Raw Access Logs, click on your domain name.
- A compressed
.log.gzfile will download to your computer. Extract it using 7-Zip or WinRAR.
Method B: Real-Time Log Analysis via Terminal / SSH (Fastest)
If you have SSH access to your server or VPS, navigate to the web server access log directory:
# View the top 10 most aggressive IP addresses hitting your site right now:
tail -n 10000 /var/log/apache2/domlogs/yourdomain.pk | awk '{print $1}' | sort | uniq -c | sort -nr | head -n 10
Example Terminal Output:
4,821 198.51.100.42 <--- Attacking IP making 4,800+ requests!
2,104 203.0.113.15 <--- Rogue scraper crawling product URLs
42 39.40.12.88 <--- Normal Pakistani residential visitor
18 182.180.4.12 <--- Normal Pakistani mobile visitor
If a single IP address from Russia, China, or an overseas hosting datacenter has generated 4,000+ requests in a few minutes, you have found your target!
π οΈ Step 2: Blocking IPs via the cPanel IP Blocker
The cPanel IP Blocker translates your input into Apache web server access control rules without requiring you to write complex code.
Step-by-Step Instructions:
- In cPanel, navigate to the Security section and click on IP Blocker.
- Under Add an IP or Domain, enter the target address:
- Single IP Address: e.g.,
198.51.100.42 - Full CIDR Subnet: e.g.,
198.51.100.0/24(Blocks all 256 IPs in that subnet). - IP Range: e.g.,
198.51.100.1-198.51.100.50 - Domain / Hostname: e.g.,
badbot.crawler.com(cPanel will perform a reverse DNS lookup to block the host).
- Single IP Address: e.g.,
- Click Add.
cPanel immediately modifies your root .htaccess file, instructing Apache to return a 403 Forbidden error whenever that IP attempts to access your site.
π¬ Step 3: Inspecting the Underlying .htaccess Apache Directives
Behind the scenes, the cPanel IP Blocker writes standard Apache mod_authz_core rules to your /public_html/.htaccess file:
# BEGIN cPanel IP Blocker
<RequireAll>
Require all granted
Require not ip 198.51.100.42
Require not ip 198.51.100.0/24
Require not host badbot.crawler.com
</RequireAll>
# END cPanel IP Blocker
Why .htaccess Blocking Has Limitations:
While .htaccess blocking stops rogue bots from executing PHP scripts and loading your database:
- Apache must still accept the TCP handshake and process the HTTP request before rejecting it with a 403 response.
- If a distributed DDoS attack floods your server with 50,000 requests per second, Apacheβs connection table can still become exhausted!
π Step 4: Upgrading to Kernel-Level Firewall Defense (CSF / iptables)
For enterprise-grade attack deflection, IP blocking should occur at the Linux Kernel / Firewall layer before traffic ever reaches the Apache web server daemon.
If you run a Nextgen Cloud VPS in Pakistan or bare-metal Dedicated Servers with ConfigServer Security & Firewall (CSF):
# Block an attacking IP permanently at the Linux kernel firewall level:
csf -d 198.51.100.42 "Layer 7 HTTP flood attack"
# Block an entire malicious ASN or foreign country range if not doing business there:
# In /etc/csf/csf.conf:
CC_DENY = "CN,RU,VN"
# Reload the kernel firewall tables:
csf -r
When an IP is blocked in CSF, the Linux kernel drops the TCP SYN packet instantly (iptables DROP). The server uses zero CPU cycles, zero Apache threads, and zero RAM, rendering high-volume flood attacks completely harmless!
π Nextgen DDoS-Protected Cloud Infrastructure
In todayβs threat landscape, relying exclusively on shared hosting controls is dangerous for revenue-generating businesses:
- Deploy on Nextgen Cloud VPS in Pakistan with dedicated KVM virtualization, automated CSF brute-force protection (LFD), and hardware firewall filters.
- For high-volume e-commerce platforms and fintech portals requiring automated Layer 3/4 and Layer 7 attack mitigation, deploy on Nextgen enterprise Dedicated Servers in Pakistan with unmetered bandwidth and Tier-3 Islamabad datacenter peering.
π Related Security, cPanel & Server Architecture Guides
- cPanel Email Filters & SpamAssassin Rules: Complete Anti-Spam Guide β Eliminate phishing and malicious script attachments.
- How to Set Up cPanel Email Autoresponders & Forwarders in Pakistan β Master email routing and loop defense.
- How to Use cPanel to Manage Your Web Hosting: Complete Beginner to Pro Guide β Master MySQL, File Manager, and email configuration.
Upgrade to a High-Security Cloud VPS in Pakistan
Protect your web applications from Layer 7 floods, rogue scrapers, and brute-force botnets. Nextgen delivers developer-first KVM Cloud VPS and Dedicated Servers with automated firewall hardening and Tier-3 Islamabad datacenter peering.
