I put up a vps with nginx and the logs show dodgy requests within minutes, how do you guys deal with these?
Edit: Thanks for the tips everyone!
I put up a vps with nginx and the logs show dodgy requests within minutes, how do you guys deal with these?
Edit: Thanks for the tips everyone!
Fail2ban and Nginx Proxy Manager. Here’s a tutorial on getting started with Fail2ban:
https://github.com/yes-youcan/bitwarden-fail2ban-libressl
Crowdsec is more advanced
Does it integrate with NPM?
Yes it does! You find everything on the site. It is very well documented.
Ok, so I spent way too much time tonight trying to figure this out, made a mess of my npm, and fixed it.
Official documentation on using crowdsec with NPM is out of date and relies on a fork that’s no longer maintained. I’m trying to find any documentation on how to integrate the bouncer into the official NPM project and am really coming up empty.
You only need the unmaintaind version (official PR is in the works: https://github.com/NginxProxyManager/nginx-proxy-manager/pull/2677 ) if you want to bounce at the NPM level (aka: with a captcha). At the moment I am using crowdsec to parse the NPM logs (and some other logs) and bounce at the IP tables level on my VPS ( block only) and at the opnsense firewall level (also block only) at home.
I’m not sure if it’s the fact that I was up at 1am trying to figure this all out or what but it wasn’t clicking last night. So the NPM (nginx) integration would strictly be the captcha and I would need to bounce at the firewall to block? That makes way more sense to me now. Thanks.
No problem, crowdsec is not super simple. There is a new learning platform you need to check out! Feel free to DM me when you are stuck on something.