Add-Ons[XTR] IP Threat Monitor

Thread owner
A new update is available for [XTR] IP Threat Monitor by Offical.


[XTR] IP Threat Monitor 1.0.27

Update highlights​

This major update brings 6 significant new features and improvements based on customer feedback. We now offer a more flexible, powerful, and user-friendly IP protection experience!

🎯 Highlighted Features

🤖 Smart Bot Management
Now you have full control over which search engine bots are protected! Want to protect Google and Bing while excluding Yandex? Now it's possible!
  • 18 different bot options (Google, Bing, Facebook, Twitter, etc.)
  • Easy checkbox selection
  • Protect critical bots for SEO
  • Exclude unused bots
🛡️ Advanced Security Controls
Scraping bots can no longer ignore error pages! The new error page rate limiting system catches IPs that repeatedly hit 403 errors.
  • Separate error page thresholds
  • Specialized protection for 403/permission errors
  • Auto-ban integration
  • Scraping bot protection
🎛️ Flexible Configuration Options
Full control with manual IP blacklist and VPN whitelist!
  • Manual IP blocking (with CIDR support)
  • VPN provider whitelist
  • Temporary country blocking toggle
  • Comment support for organized management
🔧 User Experience Improvements

Setup Wizard Updates
• All new features integrated into 3 presets
• Starter: Simple setup for beginners
• Standard: Recommended balanced settings for most sites
• Aggressive: For sites requiring high security

Test Configuration Smart Adaptation
• Tests now adapt based on your selected preset
• No unnecessary warnings if you chose Starter preset
• Optimized test criteria for each preset

Diagnostics Page Expanded
• Bot protection status display
• List of protected bots
• SEO warnings and recommendations
• One-click navigation to settings pages

💡 Why Should You Update?
  1. Better SEO Control: Optimize your SEO by selecting which bots to protect
  2. Enhanced Security: Additional protection against error page attacks
  3. Easy Management: Instantly block problem IPs with manual IP list
  4. VPN Flexibility: Protect legitimate VPN users
  5. Smart Testing: Test system adapted to your configuration
⚠️ Update Recommendations
  • Run Setup Wizard after update
  • Verify your settings with Test Configuration
  • Review your bot protection settings
  • Visit Diagnostics page to explore new features


Complete Change Log​

🔧 Bug Fixes

ASN Comment Parsing Bug Fixed
• Comment usage (#) in ASN lists now works properly
• "AS12345 # DigitalOcean" format is supported
• Comments are parsed during input, only clean ASN numbers are stored
• Implemented following XenForo CensorWords pattern

🆕 New Features

Error Page Rate Limiting
• Separate rate limiting for IPs repeatedly hitting 403/permission errors
• Addresses scraping bots that ignore error pages
• Separate thresholds and time windows
• Auto-ban integration

Manual IP Blacklist
• Manual IP blacklist system like trusted IPs
• IP address + comment support
• CIDR notation support (192.168.1.0/24)
• Instant blocking (on first visit)

Country Blocking Toggle
• Option to temporarily disable country blocking
• Test without deleting country list
• Single checkbox toggle

VPN Provider Whitelist
• Whitelist specific VPN providers
• Protect legitimate VPNs like Opera VPN, ProtonVPN
• Provider name + comment support
• Flexible matching system (exact, contains, partial)

Search Engine Bot Configuration
• Select which bots to protect
• 18 different bot support (Google, Bing, Yandex, Baidu, etc.)
• Easy checkbox selection
• Protect critical bots for SEO

⚡ Improvements

Test Configuration Updates
• Added test support for all new features
• Smart test adaptation based on Setup Wizard presets
• Optimized test criteria for Starter preset
• 6 new test scenarios

Setup Wizard Integration
• All presets updated with new features
• Starter: Simple setup, essential bots
• Standard: Balanced protection, comprehensive bot list
• Aggressive: Maximum security, all bots

Diagnostics Page Updates
• Bot protection status check
• Protected bot count and list display
• SEO warnings and recommendations
• Automatic setting links

🔄 Technical Improvements

• XenForo AbstractOption pattern usage
• getCheckboxRow method for checkbox rendering
• Proper validation and error handling
• Cache-first approach optimizations
• Template syntax improvements
• Extended phrase system (50+ new phrases)

⚠️ Important Notes

• All new features are backward compatible
• Existing settings are preserved
• Setup Wizard recommended for quick configuration
• Test Configuration recommended for validation


Read more about this product...
 
Thread owner
A new update is available for [XTR] IP Threat Monitor by Offical.


[XTR] IP Threat Monitor 1.0.28

Update highlights​

This update fixes a critical bug in the error page rate limiting feature based on customer feedback. The feature now works as intended, providing better protection against scraping bots that ignore error responses!

Scraping bots often ignore error responses and continue hammering your site with requests to restricted pages, user profiles, and non-existent content. This fix ensures these bots are now properly detected and blocked, reducing server load and protecting your content.

⚙️ Configuration

Location:
Admin CP → Options → IP Threat Monitor
  • Enable Error Page Rate Limiting - Turn the feature on/off
  • Error Page Threshold - Number of errors before blocking (default: 10)
  • Error Page Time Window - Time period in seconds (default: 300)
Recommended Settings:
  • Balanced: Threshold 10-15, Window 300 seconds
  • Aggressive: Threshold 5-10, Window 180 seconds


Complete Change Log​

  • Expanded error detection (401, 403, 404 HTTP codes)
  • Login redirects now counted as errors (for guest users)
  • Added error template detection
  • Separate counter system working properly


Read more about this product...
 
Hello and good morning from germany

I'm getting since 2 versions the following error message in my server error log:

Dear Guests, welcome! Please, Log in or Register to view hide content!


#0 src/XF.php(270): XF\Error->logError('[XTR-LG] Licens...', false)
#1 src/addons/XENTR/IPThreatMonitor/Core/SystemCheck.php(103): XF::logError('[XTR-LG] Licens...')
#2 src/addons/XENTR/IPThreatMonitor/Core/CronCheck.php(23): XENTR\IPThreatMonitor\Core\SystemCheck::check()
#3 src/XF/Job/Cron.php(41): XENTR\IPThreatMonitor\Core\CronCheck::run(Object(XF\Entity\CronEntry))
#4 src/XF/Job/Manager.php(275): XF\Job\Cron->run(8)
#5 src/XF/Job/Manager.php(205): XF\Job\Manager->runJobInternal(Array, 8)
#6 src/XF/Job/Manager.php(89): XF\Job\Manager->runJobEntry(Array, 8)
#7 job.php(46): XF\Job\Manager->runQueue(false, 8)
#8 {main}

Greetings

Mike
 
Hi,

Thank you for reporting this. We've already identified and fixed this issue on our end.

The error you're seeing happens because your site currently has the older version of the add-on files. The fix has been applied to our download system, but your site still runs the previous code.

To resolve this, please follow these steps:
  1. Go to your Admin Panel → Add-ons
  2. Uninstall the IPThreatMonitor add-on
  3. Re-download the latest version from our store
  4. Upload and install the freshly downloaded file
After reinstalling, this error will no longer appear in your logs.

We apologize for the inconvenience!
 
Thanks for your quick reply.

Now I have a question, because I always install updates relatively quickly,
and I already had version 1.0.28 installed when I asked my question.
Am I doing something wrong with the updates (the way I'm doing it)?

I'm a little hesitant because I'd have to redo all the settings and the German translation.
That would mean again over 500 language changes in addition to the settings.
Currently, the error isn't occurring anymore. I initially tried recreating the files.

Sorry for asking again!

Mike
 
You don't need to uninstall anything. Your settings, translations, and all data are completely safe.
 
Thread owner
A new update is available for [XTR] IP Threat Monitor by Offical.


[XTR] IP Threat Monitor 1.0.29

Update highlights​

This exact release corrects a critical uninstallation bug experienced in certain specific server environments. In the previous architecture, if a server was utilizing in-memory cache systems (Redis/APCu) or if the add-on had not yet logged any visitor traffic, the local cache folder was never physically generated. Consequently, the XenForo core would throw an unhandled exception when attempting to delete the nonexistent folder during the uninstall procedure. With the newly integrated directory validation check, the uninstallation process now runs completely smooth and error-free across all environments.


Complete Change Log​

  • Fixed: Resolved the InvalidArgumentException: /internal_data/ip_threat_cache is not readable or not a directory error that occurred during uninstallation for users whose servers utilize Redis/APCu cache systems, or for installations that had not yet received any cache traffic.
  • Improved: Added extra safety and verification checks (directory existence) to the file/folder deletion methods triggered during the uninstallation process.


Read more about this product...
 
get a sore of 27/28, dont see whats the problem into config ti get full score.
 

Attachments

  • score.webp
    score.webp
    196 KB · Views: 0
Thread owner
A new update is available for [XTR] IP Threat Monitor by Offical.


[XTR] IP Threat Monitor 1.0.30

Update highlights​

In earlier versions, unforeseen connection drops midway through requests or strict password constraints on your Redis instance could result in unhandled internal server errors. Thanks to our newly robust structure, the add-on now correctly interprets your XenForo configuration passwords and authenticates natively. Furthermore, if your cache server suddenly unplugs, drops, or disconnects while your site is actively receiving traffic, the add-on will instantly catch the error. Instead of breaking down your forum, it will now gracefully and silently roll back to alternative fallback mechanisms in a split second.


Complete Change Log​

  • Fixed: Resolved the fatal authentication error (NOAUTH) that occasionally caused site crashes on forums utilizing strict password-protected Redis cache server architectures.
  • Improved: Increased overall system reliability by wrapping all internal Redis data operations inside strict fail-safe blocks within the cache manager. The add-on will no longer crash your site even if the server disconnects.
  • New Feature: Integrated an intelligent verification layer to immediately isolate misconfigurations or authentication anomalies upon connection, allowing the add-on to seamlessly transition to backup caching mechanisms without throwing unhandled exceptions.


Read more about this product...
 

Users found this thread by following these keywords:

  1. Bing tool
Quick Jump
Back
Top Bottom