#crowdsec

2026-01-21

Ich habe mal meinen crowdsec stack geupdated.

Der traefik-crowdsec-bouncer wurde durch as native crowdSec traefik plugin.

Das bringt einige vorteile mit sich, die du hier nachlesen kannst.

2tap2.be/crowdsec-plugin-appse

#homelab #traefik #crowdsec #waf #security #selfhost

@Doppellhelix #Crowdsec hat bei mir übrigens einen Wireguard-Tunnel als Angriff interpretiert und gesperrt. War doof. Deshalb habe ich Crowdsec erst mal wieder ausgeschaltet.

2026-01-19

Wahnsinn.
Ein kleiner privater Honeserver mit ner Nextcloud drauf.
Über 11k Angriffe in einer Woche.
Ich empfinde das als viel, wenn man bedenkt das ja nicht viele die URL dazu kennen.

Und das sind nur die erkannten Angriffe.

#Nextcloud
#Homeserver
#crowdsec

Tom :damnified:thomas@metalhead.club
2026-01-14

Is the CrowdSec Free Community version actually useful? :thaenkin:

#crowdSec

Nach ganzen 8 erfolgreichen Jahren die Nextcloud mit einzelnen Dockercontainern zu betreiben, erfolgt nun ein Upgrade mit einer neuen größeren Festplatte und einem #Nextcloud All-in-One Setup + #Traefik + #CrowdSec Container.

2026-01-03

Tối ưu bảo mật Homelab: Có cần CrowdSec khi đã dùng Pangolin & SSO?

Nhiều người dùng Homelab thắc mắc về việc thêm CrowdSec vào hệ thống đã có:
1. Pangolin VPS: Ẩn IP thật, tránh tấn công trực tiếp.
2. SSO + 2FA (Authentik): Chỉ người dùng tin cậy mới truy cập được ứng dụng.
3. Geoblocking: Chặn truy cập từ các quốc gia không mong muốn.

CrowdSec giúp chặn các IP xấu đã biết (community list) và chống DDoS, nhưng dễ gây "gậy ông đập lưng ông" (tự ban mình).

#SelfHosted #Security #CrowdSec #Pang

If you use CrowdSec with Pangolin, make sure you update the healthcheck for your crowdsec container to avoid getting banned. Apparently, the default healthcheck Pangolin recommended was hammering their API.

The healthcheck should look like this (using lapi & updated intervals):

healthcheck:
test:
- CMD
- cscli
- lapi
- status
interval: 10s
timeout: 5s
retries: 3
start_period: 30s

github.com/crowdsecurity/crowd

#selfhosted #crowdsec #pangolin

SP⟁CED GO⟁Tfinner@appdot.net
2025-12-08

#OpnSense #CrowdSec #Networking

I recently setup CrowdSec on my OpnSense server. I've never used it before. This is just on my home internet interface. It is typical/expected to see over 130k 'attacks' over 7 days? Or does that hint at me doing something wrong? Seems excessive, but then, maybe this is totally normal.

I need to do some more reading about the 'Unknown Behavior'. Maybe I have something mis-configured there.

Screencap from CrowdSec console showing the 'Distribution of Malicious Intents' chart showing that 133k attacks were prevented.
Jorijn Schrijvershofjorijn@toot.community
2025-12-07

Over 5,100 unique #Tencent IPs triggered the ban within roughly 2-3 hours of this scenario going live. These guys don't mess around...

#MastoAdmin #CrowdSec

Jorijn Schrijvershofjorijn@toot.community
2025-12-07

Update on the Tencent crawler situation:

Identified the fingerprint (Chrome/126 on Windows NT 6.1, always from AS132203/132591/45090) and deployed a #CrowdSec scenario to auto-ban them for 90 days.

Already blocked 100+ IPs within the first hour. They rotate constantly, but the fingerprint stays the same.

The attached chart shows traffic from the last 24 hours. All yellow spikes are recurring Tencent crawls.

#Tencent #MastoAdmin

The attached chart shows traffic from the last 24 hours. All yellow spikes are recurring Tencent crawls.
benzogaga33 :verified:benzogaga33@mamot.fr
2025-12-05
2025-12-04

The #Crowdsec Helm Chart version 0.21.0 comes with a surprise: Installing packages on container startup!

github.com/crowdsecurity/helm-

If you are looking for "how to not do containers", this is a textbook example!

Checked the CrowdSec stats today.
Turns out the Lighthouse has been quietly keeping the seas calm —
thousands of bad requests turned to mist before they ever reached the shore.
Always nice when the defences do exactly what they should.

#crowdsec #selfhosting #infosec #MastodonAdmin #FediverseOps

2025-11-30

Hew fellow selfhosters. Is there any problem if i would use crowdsec and ufw-blocklist together on my Debian Trixie Webserver?
Does anyone of you use that combination?

#crowdsec #ufw #selfhosting @homelab @homelab_de

2025-11-23

Just found out that the "http-crawl-non_statics" scenario from Crowdsec was accidentally banning PeerTube servers so I removed it. Sorry if your server ended up blocked.

#PeerTube #Crowdsec #sysadmin

2025-11-19

CrowdSec Manager (beta) đã ra mắt! Đây là giao diện web hiện đại (Go/React) giúp quản lý hệ thống bảo mật CrowdSec, tích hợp đặc biệt với Pangolin/Traefik. Các tính năng nổi bật: theo dõi sức khỏe hệ thống, quản lý IP, sao lưu tự động... Lưu ý: đây là bản beta, hãy thử nghiệm trong môi trường phi sản xuất!
#CrowdSec #BảoMật #WebUI #Pangolin #Traefik #Beta #TựHost #SelfHosted #Security

reddit.com/r/selfhosted/commen

Lucas Janin 🇨🇦🇫🇷lucas3d
2025-11-16

@tac @david Avec ou sans , permet ne granularité dans les permissions. Par exemple, il sera possible d’autoriser le SSH qu’à certaines personnes.

Pour ce qui est protéger les resources privées, j’ai mis deux reverse proxy et des VLANs séparés pour mes services publics et privés. J’ai aussi mis et des règles de firewall.

Certes, très overkill pour mon homelab personnel 😊

crowdsec.net

2025-11-12

Would love to be able to perform #CrowdSec #captcha with #Altcha, but I don't have the time to modify the CrowdSec HAproxy SPOE code, or create a PHP challenge provider and verifier. So, Anubis it is.
Bonus: CrowdSec could ban you while being redirected to Anubis, during user-agent parsing.

2025-11-12

Finally making progress on my #KeyHelp, #HAproxy, VPN, reverse proxy, #Anubis, #CrowdSec web host.

Until now I've only used CrowdSec, with rather aggressive User-Agent rules (blocking all the dark visitors).
Finally managed to get HAproxy to subrequest auth against Anubis working.
Last thing remaining: automated SSL certs.

mauri :verified:mauri@bonn.social
2025-11-12

#crowdsec ey… da arbeite ich mal ne Stunde in der Nextcloud, schon wird meine IP geblockt. Aber 50 fehlgeschlagene Wordpress Login Versuche von der gleichen IP aus Litauen sind in Ordnung… 🤦‍♂️

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst