146
submitted 3 years ago* (last edited 3 years ago) by jcal@lemmy.dbzer0.com to c/selfhosted@lemmy.world

I put up a vps with nginx and the logs show dodgy requests within minutes, how do you guys deal with these?

Edit: Thanks for the tips everyone!

you are viewing a single comment's thread
view the rest of the comments
[-] AngryHippy@lemmy.world 23 points 3 years ago

Fail2ban and Nginx Proxy Manager. Here's a tutorial on getting started with Fail2ban:

https://github.com/yes-youcan/bitwarden-fail2ban-libressl

[-] AES@lemmy.ronsmans.eu 3 points 3 years ago
[-] SeeJayEmm@lemmy.procrastinati.org 1 points 3 years ago
[-] AES@lemmy.ronsmans.eu 4 points 3 years ago

Yes it does! You find everything on the site. It is very well documented.

[-] SeeJayEmm@lemmy.procrastinati.org 1 points 3 years ago

Ok, so I spent way too much time tonight trying to figure this out, made a mess of my npm, and fixed it.

It is very well documented.

Official documentation on using crowdsec with NPM is out of date and relies on a fork that's no longer maintained. I'm trying to find any documentation on how to integrate the bouncer into the official NPM project and am really coming up empty.

[-] AES@lemmy.ronsmans.eu 1 points 3 years ago* (last edited 3 years ago)

You only need the unmaintaind version (official PR is in the works: https://github.com/NginxProxyManager/nginx-proxy-manager/pull/2677 ) if you want to bounce at the NPM level (aka: with a captcha). At the moment I am using crowdsec to parse the NPM logs (and some other logs) and bounce at the IP tables level on my VPS ( block only) and at the opnsense firewall level (also block only) at home.

[-] SeeJayEmm@lemmy.procrastinati.org 1 points 3 years ago

I'm not sure if it's the fact that I was up at 1am trying to figure this all out or what but it wasn't clicking last night. So the NPM (nginx) integration would strictly be the captcha and I would need to bounce at the firewall to block? That makes way more sense to me now. Thanks.

[-] AES@lemmy.ronsmans.eu 1 points 3 years ago

No problem, crowdsec is not super simple. There is a new learning platform you need to check out! Feel free to DM me when you are stuck on something.

[-] Pete90@feddit.de 3 points 3 years ago

I really wanted to use this and set it up a while ago. Works great but in the end I had to deactivate it, because my nextcloud instance would cause too many false positives (404s and such) and I would ban my own up way too often.

this post was submitted on 08 Jul 2023
146 points (100.0% liked)

Selfhosted

60910 readers
842 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS