Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Philippe_H
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
Philippe_H
2y ago
CrowdSec scans also firewall logs like PSAD and much more applicative logs types than fail2ban. That being said I use tailscale to ssh to my servers.
2.
▲
by
Philippe_H
2y ago
Hi all and @snorremd, (Philippe from the CrowdSec team) The $2.5K / month was for enterprise, but we didn't correctly understand the need and converted it to 2 optional prices: $1K for LTS and $1K for support. This will be reflec
3.
▲
CrowdSec scenario to partially mitigate Log4j
(hub.crowdsec.net)
2 points
by
Philippe_H
5y ago
|
0 comments
4.
▲
IP addresses exploiting Log4j CVE-2021-44228
(gist.github.com)
6 points
by
Philippe_H
5y ago
|
1 comments
5.
▲
by
Philippe_H
6y ago
Well we have a consensus system that's quite advanced to avoid poisoning and false positives. To put it short, all members have a Trust rank, only TR1 can publish an IP without counter verification, and only if it doesn't shoot a
6.
▲
by
Philippe_H
6y ago
CrowdSec is not designed specifically for SSH. It can ingest any type of logs and answer with a bouncer at pretty much any level. IP/Session/User/software stack. Ie, we are working on Magento to parse all logs (apache, magent
7.
▲
by
Philippe_H
6y ago
Absolutely. We owe that transparency to our users. The 1.0 should be out in a month from now, and it will include a Local API, an abstraction layer between the core and the bouncers & data sources. This will help the community to dev th
8.
▲
by
Philippe_H
6y ago
I should maybe have told you also, team members are from pentesting and high security hosting background. We also have created some other OSS components before, like NAXSI (Waf over Nginx), Snuffleupagus, PHP malware finder, etc. So we face
9.
▲
by
Philippe_H
6y ago
no risk here. Tool is MIT, if community doesn't like our approach, you fork it. So we'll be faithful to our commitments and this licensing model is the best insurance for it. Now, I can also tell you that people using the free sof
10.
▲
by
Philippe_H
6y ago
Sure, People activate the sharing of what they spot or not. If they do, no money is asked for them benefiting from the global IP rep DB. The one willing to use it without contributing will be able to do so, through API calls, but at a (mode
11.
▲
by
Philippe_H
6y ago
Well actually Spoofing on a private network is trivial, but in TCP over a public network, it's another story entirely and it's not simple at all. UDP can be easily spoofed though, hence we do not treat reports in the same way so f
12.
▲
by
Philippe_H
6y ago
well just whitelist your Public IPs or use a combo of IPset & port knockd. Works fine for me for variable IPs.
13.
▲
by
Philippe_H
6y ago
yepn indeed, we call it private sharding or private consensus. Far on the roadmap (4 months), but nevertheless, the team is thinking about it. You could also include or exclude some Geographics for ex if you don't trust a country or ha
14.
▲
by
Philippe_H
6y ago
this is accounted for. By default you have a whitelist containing local lan IP ;)
15.
▲
by
Philippe_H
6y ago
We'll (soon) provide a Backoffice, where you can choose which IP you decide to ban (based on their activities, like bot scrapping, bruteforcing, etc.) but also add some 3rd party blacklist, block some AS or ranges, Tor exit nodes or VP
16.
▲
by
Philippe_H
6y ago
Perfwise, we have a user that previously used fail2ban to block some http botnets. He crunches 7000 IPs worth of logs in 50 mins with F2B. under a minute with CrowdSec. Another block 3000 IPs doing credit card stuffing directly at payment p
17.
▲
by
Philippe_H
6y ago
CrowdSec is for all protocoles / system generating logs (can be Cloud trail, syslog, kafka, etc.) and can ban at an applicative, user or IP level.
18.
▲
by
Philippe_H
6y ago
Sorry, we should have made it clear, it is totally optional. You just don't get the IP rep DB part of the soft if you don't share, but the behavior is still 100% functional.
19.
▲
by
Philippe_H
6y ago
(but I think they already send it through HTTPS)
20.
▲
by
Philippe_H
6y ago
Well hashing is (usually) a symmetric function and we are open source... Meaning you could recover the key in the code (or intercept it during transfer). I think Private/Public key is a simpler approach, reusable elsewhere in the code
21.
▲
by
Philippe_H
6y ago
Sure. To put it very short, we give every user a trust rank. It varies overtime. If you consistently, and for a long while, reported attacks that could be correlated by others and our own botnet, you progress, until you reach trust rank 1.
22.
▲
by
Philippe_H
6y ago
different approach, but I'm sure at some point we'll get close to one another.
23.
▲
by
Philippe_H
6y ago
Hi Guys, thanks for all your feedbacks. (I'm part of the CS team) I'll try to address some few questions. 1/ You don't have to communicate. If you don't, you get a modern, fast, decoupled fail2ban with many various
24.
▲
by
Philippe_H
6y ago
Thank you, don't hesitate to reach us through gitter or discourse or else.
25.
▲
Show HN: CrowdSec, an open-source, modernized and collaborative fail2ban
(github.com)
15 points
by
Philippe_H
6y ago
|
2 comments
26.
▲
by
Philippe_H
6y ago
We would love to hear your comments if you feel like. To have a more textual version: TL;DR: CrowdSec parses logs from various Data sources, normalizes and enriches them before applying heuristic scenarii to identify aggressive behaviors an
27.
▲
Show HN: Crowdsec, the behavior and reputation-based collaborative firewall
(crowdsec.net)
17 points
by
Philippe_H
6y ago
|
2 comments