Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
klausagnoletti
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
klausagnoletti
4y ago
Hey and thanks for your reply. This is done easily in the cscli with the 'decisions' command: https://doc.crowdsec.net/docs/next/cscli/cscli_decisions . 'sudo cscli decisions list' lists al
2.
▲
by
klausagnoletti
4y ago
https://hub.crowdsec.net/author/crowdsecurity/collections/do...
3.
▲
by
klausagnoletti
4y ago
Hey, head of community at CrowdSec here. Could you elaborate on your situation and the 'opaque' replies from the agent you're receiving in a mail to klaus at crowdsec dot net? Very interested in understanding your issues and
4.
▲
by
klausagnoletti
4y ago
I'll challenge you on that :-) https://www.crowdsec.net/blog/crowdsec-not-your-typical-fail...
5.
▲
by
klausagnoletti
4y ago
As someone else mentions, CrowdSec can do just that. It's FOSS and can act as a modern Fail2Ban replacement that can detect all sorts of attacks - in this case ssh bruteforce/slow brute force attacks - and shares very basic inform
6.
▲
by
klausagnoletti
5y ago
I don't know exaxtly what you mean by a distributed community run firewall but https://crowdsec.net/ collects information (anonymously) on the attacks users see and shares it with all other users after vetting them. So
7.
▲
by
klausagnoletti
5y ago
https://crowdsec.net/ can also do something like that, only more advanced in the attacks it detects and because it's sharing bad ips from users to everyone else. I love that users in this way are watching each other&#x
8.
▲
by
klausagnoletti
5y ago
How about using a tool like https://crowdsec.net/ that collects (basic, anonymious) information from users on the attacks they see, vets it and shares it back to all users via blocklists? Currently around 800k signals are c
9.
▲
by
klausagnoletti
5y ago
Same thing is possible using https://app.crowdsec.net/ (just create a free user account and use the search feature) - and if you install the accompanying agent, those bad actors already known will be blocked automatically (
10.
▲
by
klausagnoletti
5y ago
That's one of many reason why https://crowdsec.net/ was created. It collects (anonymized) threat intelligence from all users, vets it and distributes it as relevant blocklists. Once there's enough users it will be
11.
▲
by
klausagnoletti
5y ago
You could also consider https://crowdsec.net/ - it's a pretty advanced framework for detecting malevolent traffic by using a combination of local rules and threat intelligence from other users. Apache is supported htt
12.
▲
by
klausagnoletti
5y ago
Fail2ban is decent indeed. But consider https://crowdsec.net/ instead if you want a tool that can detect pretty advanced L7 attacks, mitigate bad traffic using captcha and use crowd sourced threat intelligence to block bad
13.
▲
by
klausagnoletti
5y ago
Great project. Collaboration is the way to go!