[-] Alfi@lemmy.alfi.casa 7 points 1 year ago* (last edited 1 year ago)

Then you're allowed

[-] Alfi@lemmy.alfi.casa 4 points 1 year ago

The details look great!

[-] Alfi@lemmy.alfi.casa 11 points 1 year ago

And summit isn't open source either

[-] Alfi@lemmy.alfi.casa 5 points 1 year ago

To be fair they probably had most of the code ready, and just had to port it to Lemmy.

[-] Alfi@lemmy.alfi.casa 11 points 1 year ago

Any reason why it's not FOSS?

[-] Alfi@lemmy.alfi.casa 5 points 1 year ago

... Directory?

[-] Alfi@lemmy.alfi.casa 3 points 1 year ago* (last edited 1 year ago)

Hi,

Reading the thread I decided to give it a go, I went ahead and configured crowdsec. I have a few questions, if I may, here's the setup:

  • I have set up the basic collections/parsers (mainly nginx/linux/sshd/base-http-scenarios/http-cve)
  • I only have two services open on the firewall, https and ssh (no root login, ssh key only)
  • I have set up the firewall bouncer.

If I understand correctly, any attack detected will result in the ip being banned via iptables rule (for a configured duration, by default 4 hours).

  • Is there any added value to run the nginx bouncer on top of that, or any other?
  • cscli hub update/upgrade will fetch new definitions for collections if I undestand correctly. Is there any need to run this regularly, scheduled with let's say a cron job, or does crowdsec do that automatically in the background?
[-] Alfi@lemmy.alfi.casa 8 points 1 year ago

sometimes I grab popcorn and "tail -f /var/log/secure"

[-] Alfi@lemmy.alfi.casa 7 points 1 year ago

Didn't have any crashes, the only small issue I have is that scrolling isn't always very smooth, although it's better with the latest release.

[-] Alfi@lemmy.alfi.casa 26 points 1 year ago* (last edited 1 year ago)

I went to the playstore, and looked for boost. Although it's not yet released, it already lists the data that will be collected (quite a lot).

Meanwhile jerboa states that it collects and shares no data. It has room for improvement, but it's fully functional and fits my needs for browsing Lemmy.

[-] Alfi@lemmy.alfi.casa 3 points 1 year ago

Do you have a link to a documentation concerning retention/cleanup for instances?

[-] Alfi@lemmy.alfi.casa 6 points 1 year ago

And comment posting bots. Since there's no karma there should be no market value for accounts right? Am I missing something or does that kind of solve the problem? We could still see trolls using Ai to comment randomly

view more: next ›

Alfi

joined 1 year ago