Allowing customers to whitelist IP address's from their control panel.
Giving the customer the option to whitelist any IP address from their control panel.
At the moment, if a customer wants to whitelist an IP address they cannot without server admin whitelisting the IP across the server.
cPanel have this option with Mod Security Manager.
Allowing endusers to allowlist themselves can result in significant security risks. For example malicious users could use this tactic to drive brute-force attacks against the server or other users on the same server which cannot be noticed when that malicious user has whitelisted his own IP.
No arguments have been given why it is not risk to allow endusers to allowlist themselves. We must decline this request.
-- PD
-
Anonymous commented
Allowing endusers to whitelist themselves wil not result in any significant security risks. We have bigger problems to solve if or when a malicious user has access to Plesk CP.
We now simply have a hook in WHMCS customer dashboard that does "plesk bin ip_ban --add-trusted 1.2.3.4" for every customer IP we see.