Add etc/crowdsec/config.yaml
Add etc/crowdsec/parsers/s02-enrich/bing-whitelist.yaml Add etc/crowdsec/parsers/s02-enrich/google-whitelist.yaml Add etc/crowdsec/parsers/s02-enrich/whitelist-our-ips.yaml Add etc/crowdsec/parsers/s02-enrich/whitelist-social.yaml Add etc/crowdsec/parsers/s02-enrich/yandex-whitelist.yaml Add etc/crowdsec/scenarios/0-ban-many-sorry.yaml Add etc/crowdsec/scenarios/0-ban-multiple-referers.disabled Add etc/crowdsec/scenarios/0-ban-smart-bot.disabled Add etc/crowdsec/scenarios/0-ban-sorry-from-search.disabled Add etc/crowdsec/scenarios/0-cap-all-clouds.yaml Add etc/crowdsec/scenarios/0-cap-asn-selectel.yaml Add etc/crowdsec/scenarios/0-cap-bad-asn.yaml Add etc/crowdsec/scenarios/0-cap-bad-other-asn-2.yaml Add etc/crowdsec/scenarios/0-cap-brousers.yaml Add etc/crowdsec/scenarios/0-cap-bukva.disabled Add etc/crowdsec/scenarios/0-cap-crossword-word.disabled Add etc/crowdsec/scenarios/0-cap-empty-asn.yaml Add etc/crowdsec/scenarios/0-cap-empty-referer.yaml Add etc/crowdsec/scenarios/0-cap-honeypot.yaml Add etc/crowdsec/scenarios/0-cap-http11.des Add etc/crowdsec/scenarios/0-cap-index-mobile.yaml Add etc/crowdsec/scenarios/0-cap-many-bukva.yaml Add etc/crowdsec/scenarios/0-cap-many-crossword-word.yaml Add etc/crowdsec/scenarios/0-cap-many-spisok.yaml Add etc/crowdsec/scenarios/0-cap-many-viktoriny.disabled Add etc/crowdsec/scenarios/0-cap-other-countries-asn.yaml Add etc/crowdsec/scenarios/0-cap-pikabu.ru.yaml Add etc/crowdsec/scenarios/0-cap-ru-asn.yaml Add etc/crowdsec/scenarios/0-cap-site-scan-30-10m.yaml Add etc/crowdsec/scenarios/0-cap-spisok.disabled Add etc/crowdsec/scenarios/0-cap-ukr-asn.yaml Add etc/crowdsec/scenarios/0-cap-unknown-country.yaml Add etc/crowdsec/scenarios/0-cap-ya-vk-clouds.yaml Add etc/crowdsec/scenarios/0-coraza-waf.yaml Add etc/crowdsec/scenarios/CVE-2017-9841.yaml Add etc/crowdsec/scenarios/CVE-2019-18935.yaml Add etc/crowdsec/scenarios/CVE-2022-26134.yaml Add etc/crowdsec/scenarios/CVE-2022-35914.yaml Add etc/crowdsec/scenarios/CVE-2022-37042.yaml Add etc/crowdsec/scenarios/CVE-2022-40684.yaml Add etc/crowdsec/scenarios/CVE-2022-41082.yaml Add etc/crowdsec/scenarios/CVE-2022-41697.yaml Add etc/crowdsec/scenarios/CVE-2022-42889.yaml Add etc/crowdsec/scenarios/CVE-2022-44877.yaml Add etc/crowdsec/scenarios/CVE-2022-46169.yaml Add etc/crowdsec/scenarios/CVE-2023-22515.yaml Add etc/crowdsec/scenarios/CVE-2023-22518.yaml Add etc/crowdsec/scenarios/CVE-2023-49103.yaml Add etc/crowdsec/scenarios/CVE-2024-0012.yaml Add etc/crowdsec/scenarios/CVE-2024-38475.yaml Add etc/crowdsec/scenarios/CVE-2024-9474.yaml Add etc/crowdsec/scenarios/apache_log4j2_cve-2021-44228.yaml Add etc/crowdsec/scenarios/disabled/0-ban-bad-ru-asn.disabled Add etc/crowdsec/scenarios/disabled/0-ban-countries.disabled Add etc/crowdsec/scenarios/disabled/0-ban-datacenters-by-name.disabled Add etc/crowdsec/scenarios/disabled/0-ban-dzen.disabled Add etc/crowdsec/scenarios/disabled/0-ban-saelmon-bot.disabled Add etc/crowdsec/scenarios/disabled/0-cap-countries.disabled Add etc/crowdsec/scenarios/disabled/0-cap-mailru.disabled Add etc/crowdsec/scenarios/f5-big-ip-cve-2020-5902.yaml Add etc/crowdsec/scenarios/fortinet-cve-2018-13379.yaml Add etc/crowdsec/scenarios/grafana-cve-2021-43798.yaml Add etc/crowdsec/scenarios/http-admin-interface-probing.yaml Add etc/crowdsec/scenarios/http-backdoors-attempts.yaml Add etc/crowdsec/scenarios/http-bad-user-agent.yaml Add etc/crowdsec/scenarios/http-crawl-non_statics.yaml Add etc/crowdsec/scenarios/http-cve-2021-41773.yaml Add etc/crowdsec/scenarios/http-cve-2021-42013.yaml Add etc/crowdsec/scenarios/http-cve-probing.yaml Add etc/crowdsec/scenarios/http-generic-bf.yaml Add etc/crowdsec/scenarios/http-generic-test.yaml Add etc/crowdsec/scenarios/http-open-proxy.yaml Add etc/crowdsec/scenarios/http-path-traversal-probing.yaml Add etc/crowdsec/scenarios/http-probing.yaml Add etc/crowdsec/scenarios/http-sap-interface-probing.yaml Add etc/crowdsec/scenarios/http-sensitive-files.yaml Add etc/crowdsec/scenarios/http-sqli-probing.yaml Add etc/crowdsec/scenarios/http-technology-probing.yaml Add etc/crowdsec/scenarios/http-w00tw00t.yaml Add etc/crowdsec/scenarios/http-wordpress-scan.yaml Add etc/crowdsec/scenarios/http-xss-probing.yaml Add etc/crowdsec/scenarios/jira_cve-2021-26086.yaml Add etc/crowdsec/scenarios/modsecurity.yaml Add etc/crowdsec/scenarios/netgear_rce.yaml Add etc/crowdsec/scenarios/nginx-req-limit-exceeded.yaml Add etc/crowdsec/scenarios/pulse-secure-sslvpn-cve-2019-11510.yaml Add etc/crowdsec/scenarios/spring4shell_cve-2022-22965.yaml Add etc/crowdsec/scenarios/ssh-bf.yaml Add etc/crowdsec/scenarios/ssh-slow-bf.yaml Add etc/crowdsec/scenarios/thinkphp-cve-2018-20062.yaml Add etc/crowdsec/scenarios/vmware-cve-2022-22954.yaml Add etc/crowdsec/scenarios/vmware-vcenter-vmsa-2021-0027.yaml Add etc/haproxy/coraza.cfg Add etc/haproxy/geo/GeoLite2-ASN.mmdb Add etc/haproxy/geo/GeoLite2-City.mmdb Add etc/haproxy/geo/GeoLite2-Country.mmdb Add etc/haproxy/haproxy.cfg Add etc/haproxy/lua/asn.lua Add etc/haproxy/lua/geoip_new2.lua Add etc/haproxy/lua/grease_detect.lua Add etc/haproxy/lua/ja3n.lua Add etc/haproxy/lua/ja4.lua Add etc/haproxy/update-whitelist.sh Add etc/haproxy/whitelists/whitelist-bots.txt Add etc/haproxy/whitelists/whitelist-manual.txt Add etc/haproxy/whitelists/whitelist-our-ips.txt Add etc/mysql/mysql.cnf Add etc/nginx/conf.d/99-fastpanel.conf Add etc/nginx/conf.d/block-bots.conf Add etc/nginx/conf.d/cloudflare.conf Add etc/nginx/conf.d/default.conf Add etc/nginx/conf.d/fastcgi-cache.conf Add etc/nginx/conf.d/parking.conf.disabled Add etc/nginx/conf.d/reuseport.conf.disabled Add etc/nginx/conf.d/searchbots.conf.disabled Add etc/nginx/conf.d/ssl.conf Add etc/nginx/conf.d/trust_haproxy.conf Add etc/nginx/fastpanel2-available/artegos/artegos.art.conf Add etc/nginx/fastpanel2-available/bratstvopera/test.bratstvopera.ru.conf Add etc/nginx/fastpanel2-available/kupidonia/kupidonia.ru.conf Add etc/nginx/fastpanel2-available/kupidonia/loba.kupidonia.ru.conf Add etc/nginx/fastpanel2-available/kupidonia/nobobo.kupidonia.ru.conf Add etc/nginx/fastpanel2-available/kupidonia/passs.kupidonia.ru.conf Add etc/nginx/fastpanel2-available/tishka/tishka.kupidonia.ru.conf Add etc/nginx/fastpanel2-includes/letsencrypt.conf Add etc/nginx/fastpanel2-sites/artegos/artegos.art.conf Add etc/nginx/fastpanel2-sites/artegos/artegos.art.includes Add etc/nginx/fastpanel2-sites/bratstvopera/test.bratstvopera.ru.conf Add etc/nginx/fastpanel2-sites/bratstvopera/test.bratstvopera.ru.includes Add etc/nginx/fastpanel2-sites/kupidonia/kupidonia.ru.conf Add etc/nginx/fastpanel2-sites/kupidonia/kupidonia.ru.includes Add etc/nginx/fastpanel2-sites/kupidonia/loba.kupidonia.ru.conf Add etc/nginx/fastpanel2-sites/kupidonia/loba.kupidonia.ru.includes Add etc/nginx/fastpanel2-sites/kupidonia/nobobo.kupidonia.ru.conf Add etc/nginx/fastpanel2-sites/kupidonia/nobobo.kupidonia.ru.includes Add etc/nginx/fastpanel2-sites/kupidonia/passs.kupidonia.ru.conf Add etc/nginx/fastpanel2-sites/kupidonia/passs.kupidonia.ru.includes Add etc/nginx/fastpanel2-sites/tishka/tishka.kupidonia.ru.conf Add etc/nginx/fastpanel2-sites/tishka/tishka.kupidonia.ru.includes Add etc/nginx/nginx.conf
This commit is contained in:
@@ -0,0 +1,62 @@
|
||||
common:
|
||||
daemonize: true
|
||||
log_media: file
|
||||
log_level: info
|
||||
log_dir: /var/log/
|
||||
log_max_size: 20
|
||||
compress_logs: true
|
||||
log_max_files: 10
|
||||
config_paths:
|
||||
config_dir: /etc/crowdsec/
|
||||
data_dir: /var/lib/crowdsec/data/
|
||||
simulation_path: /etc/crowdsec/simulation.yaml
|
||||
hub_dir: /etc/crowdsec/hub/
|
||||
index_path: /etc/crowdsec/hub/.index.json
|
||||
notification_dir: /etc/crowdsec/notifications/
|
||||
plugin_dir: /usr/lib/crowdsec/plugins/
|
||||
crowdsec_service:
|
||||
#console_context_path: /etc/crowdsec/console/context.yaml
|
||||
acquisition_path: /etc/crowdsec/acquis.yaml
|
||||
acquisition_dir: /etc/crowdsec/acquis.d
|
||||
parser_routines: 1
|
||||
cscli:
|
||||
output: human
|
||||
color: auto
|
||||
db_config:
|
||||
log_level: info
|
||||
type: sqlite
|
||||
db_path: /var/lib/crowdsec/data/crowdsec.db
|
||||
#max_open_conns: 100
|
||||
#user:
|
||||
#password:
|
||||
#db_name:
|
||||
#host:
|
||||
#port:
|
||||
flush:
|
||||
max_items: 5000
|
||||
max_age: 7d
|
||||
plugin_config:
|
||||
user: nobody # plugin process would be ran on behalf of this user
|
||||
group: nogroup # plugin process would be ran on behalf of this group
|
||||
api:
|
||||
client:
|
||||
insecure_skip_verify: false
|
||||
credentials_path: /etc/crowdsec/local_api_credentials.yaml
|
||||
server:
|
||||
log_level: info
|
||||
listen_uri: 127.0.0.1:8080
|
||||
profiles_path: /etc/crowdsec/profiles.yaml
|
||||
console_path: /etc/crowdsec/console.yaml
|
||||
online_client: # Central API credentials (to push signals and receive bad IPs)
|
||||
credentials_path: /etc/crowdsec/online_api_credentials.yaml
|
||||
trusted_ips: # IP ranges, or IPs which can have admin API access
|
||||
- 127.0.0.1
|
||||
- ::1
|
||||
# tls:
|
||||
# cert_file: /etc/crowdsec/ssl/cert.pem
|
||||
# key_file: /etc/crowdsec/ssl/key.pem
|
||||
prometheus:
|
||||
enabled: true
|
||||
level: full
|
||||
listen_addr: 127.0.0.1
|
||||
listen_port: 6060
|
||||
@@ -0,0 +1,33 @@
|
||||
name: custom/bing-whitelist
|
||||
description: "Strict Whitelist for Bingbot (Official API)"
|
||||
whitelist:
|
||||
reason: "Bingbot Official IP Ranges"
|
||||
cidr:
|
||||
- "157.55.39.0/24"
|
||||
- "207.46.13.0/24"
|
||||
- "40.77.167.0/24"
|
||||
- "13.66.139.0/24"
|
||||
- "13.66.144.0/24"
|
||||
- "52.167.144.0/24"
|
||||
- "13.67.10.16/28"
|
||||
- "13.69.66.240/28"
|
||||
- "13.71.172.224/28"
|
||||
- "139.217.52.0/28"
|
||||
- "191.233.204.224/28"
|
||||
- "20.36.108.32/28"
|
||||
- "20.43.120.16/28"
|
||||
- "40.79.131.208/28"
|
||||
- "40.79.186.176/28"
|
||||
- "52.231.148.0/28"
|
||||
- "20.79.107.240/28"
|
||||
- "51.105.67.0/28"
|
||||
- "20.125.163.80/28"
|
||||
- "40.77.188.0/22"
|
||||
- "65.55.210.0/24"
|
||||
- "199.30.24.0/23"
|
||||
- "40.77.202.0/24"
|
||||
- "40.77.139.0/25"
|
||||
- "20.74.197.0/28"
|
||||
- "20.15.133.160/27"
|
||||
- "40.77.177.0/24"
|
||||
- "40.77.178.0/23"
|
||||
@@ -0,0 +1,62 @@
|
||||
name: custom/google-whitelist
|
||||
description: "Strict Whitelist for Google Common Crawlers (Official API)"
|
||||
whitelist:
|
||||
reason: "Googlebot Official IP Ranges"
|
||||
cidr:
|
||||
# --- IPv4 подсети ---
|
||||
- "192.178.4.0/27"
|
||||
- "192.178.4.128/27"
|
||||
- "192.178.4.160/27"
|
||||
- "192.178.4.192/27"
|
||||
- "192.178.4.224/27"
|
||||
- "192.178.4.32/27"
|
||||
- "192.178.4.64/27"
|
||||
- "192.178.4.96/27"
|
||||
- "192.178.5.0/27"
|
||||
- "192.178.6.0/27"
|
||||
- "192.178.6.128/27"
|
||||
- "192.178.6.160/27"
|
||||
- "192.178.6.192/27"
|
||||
- "192.178.6.224/27"
|
||||
- "192.178.6.32/27"
|
||||
- "192.178.6.64/27"
|
||||
- "192.178.6.96/27"
|
||||
- "192.178.7.0/27"
|
||||
- "192.178.7.128/27"
|
||||
- "192.178.7.160/27"
|
||||
- "192.178.7.192/27"
|
||||
- "192.178.7.224/27"
|
||||
- "192.178.7.32/27"
|
||||
- "192.178.7.64/27"
|
||||
- "192.178.7.96/27"
|
||||
- "34.100.182.96/28"
|
||||
- "34.101.50.144/28"
|
||||
- "34.118.254.0/28"
|
||||
- "34.118.66.0/28"
|
||||
- "34.126.178.96/28"
|
||||
- "34.146.150.144/28"
|
||||
- "34.147.110.144/28"
|
||||
- "34.151.74.144/28"
|
||||
- "34.152.50.64/28"
|
||||
- "34.154.114.144/28"
|
||||
- "34.155.98.32/28"
|
||||
- "34.165.18.176/28"
|
||||
- "34.175.160.64/28"
|
||||
- "34.176.130.16/28"
|
||||
- "34.22.85.0/27"
|
||||
- "34.64.82.64/28"
|
||||
- "34.65.242.112/28"
|
||||
- "34.80.50.80/28"
|
||||
- "34.88.194.0/28"
|
||||
- "34.89.10.80/28"
|
||||
- "34.89.198.80/28"
|
||||
- "34.96.162.48/28"
|
||||
- "35.247.243.240/28"
|
||||
- "66.249.64.0/19"
|
||||
- "66.102.0.0/20"
|
||||
- "74.125.0.0/16"
|
||||
- "66.102.6.0/20"
|
||||
- "66.249.64.0/20" # Я объединил все ваши мелкие 66.249.x.x в одну для скорости работы фаервола
|
||||
# --- IPv6 подсети ---
|
||||
- "2001:4860:4801::/48" # Я объединил все ваши мелкие IPv6 в одну официальную крупную подсеть
|
||||
- "66.102.0.0/20" # <-- Добавлено для Google-Read-Aloud и других сервисов Google
|
||||
@@ -0,0 +1,9 @@
|
||||
name: kupidonia/whitelist_our_ips
|
||||
description: "Our personal whitelist"
|
||||
whitelist:
|
||||
reason: "Admin IP addresses"
|
||||
ip:
|
||||
- "185.137.233.123"
|
||||
- "91.206.14.87"
|
||||
- "188.187.103.53" #odina
|
||||
- "178.67.245.39" #allegory
|
||||
@@ -0,0 +1,7 @@
|
||||
name: kupidonia/whitelist_social
|
||||
description: "My personal whitelist"
|
||||
whitelist:
|
||||
reason: "IP addresses of social networks"
|
||||
ip:
|
||||
- "95.142.199.181" #VK автопубликации
|
||||
#- "54.236.1.1" #Пинтерест
|
||||
@@ -0,0 +1,22 @@
|
||||
name: custom/yandex-whitelist
|
||||
description: "Whitelist for Yandex search engine bots"
|
||||
whitelist:
|
||||
reason: "Yandex bot IP"
|
||||
cidr:
|
||||
- "5.45.192.0/18"
|
||||
- "5.255.192.0/18"
|
||||
- "37.9.64.0/18"
|
||||
- "37.140.128.0/18"
|
||||
- "77.88.0.0/18"
|
||||
- "84.252.160.0/19"
|
||||
- "87.250.224.0/19"
|
||||
- "90.156.176.0/20"
|
||||
- "92.255.112.0/20"
|
||||
- "93.158.128.0/18"
|
||||
- "95.108.128.0/17"
|
||||
- "141.8.128.0/18"
|
||||
- "178.154.128.0/18"
|
||||
- "185.32.187.0/24"
|
||||
- "213.180.192.0/19"
|
||||
- "2a02:6b8::/29"
|
||||
- "45.138.0.0/24"
|
||||
@@ -0,0 +1,38 @@
|
||||
type: leaky
|
||||
name: kupidonia/ban-many-sorry
|
||||
description: "Detects bots stuck in a loop or aggressively scraping the /sorry page"
|
||||
filter: "evt.Meta.log_type in ['http_access-log', 'http_error-log'] and evt.Parsed.request contains '/sorry'"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
capacity: 6
|
||||
leakspeed: "2s"
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: http
|
||||
type: scan
|
||||
remediation: true
|
||||
---
|
||||
type: leaky
|
||||
name: kupidonia/ban-many-sorry-8
|
||||
description: "Ban bots stuck in a loop and blindly hitting the /sorry page"
|
||||
filter: "evt.Meta.log_type == 'http_access-log' && evt.Meta.http_path contains '/sorry'"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
capacity: 8
|
||||
leakspeed: "1m"
|
||||
blackhole: 5m
|
||||
labels:
|
||||
service: http
|
||||
type: abuse
|
||||
remediation: true
|
||||
---
|
||||
type: leaky
|
||||
name: kupidonia/ban-slow-sorry
|
||||
description: "Catch low and slow bots hitting /sorry over a long period"
|
||||
filter: "evt.Meta.log_type in ['http_access-log', 'http_error-log'] and evt.Parsed.request contains '/sorry'"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
capacity: 10
|
||||
leakspeed: "30m"
|
||||
blackhole: 15m
|
||||
labels:
|
||||
service: http
|
||||
type: crawler
|
||||
remediation: true
|
||||
@@ -0,0 +1,103 @@
|
||||
#cscli decisions list | grep "kupidonia/ban-smart-bot-"
|
||||
#cscli decisions list | grep -E "ID|kupidonia/ban-smart-bot-"
|
||||
type: leaky
|
||||
name: kupidonia/ban-smart-bot-many-page-1
|
||||
description: "Detects aggressive scraping through deep pagination"
|
||||
filter: "evt.Meta.log_type == 'http_access-log' && evt.Parsed.request contains '/s/'"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
capacity: 15
|
||||
leakspeed: "30s"
|
||||
blackhole: 10m
|
||||
labels:
|
||||
service: http
|
||||
type: scan
|
||||
remediation: true
|
||||
---
|
||||
type: leaky
|
||||
name: kupidonia/ban-smart-bot-many-page-2
|
||||
description: "Detects aggressive scraping through deep pagination"
|
||||
filter: "evt.Meta.log_type == 'http_access-log' && evt.Parsed.request contains '/s/'"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
capacity: 20
|
||||
leakspeed: "1m"
|
||||
blackhole: 10m
|
||||
labels:
|
||||
service: http
|
||||
type: scan
|
||||
remediation: true
|
||||
---
|
||||
type: leaky
|
||||
name: kupidonia/ban-smart-bot-many-page-3
|
||||
description: "Detects aggressive scraping through deep pagination"
|
||||
filter: "evt.Meta.log_type == 'http_access-log' && evt.Parsed.request contains '/s/'"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
capacity: 40
|
||||
leakspeed: "160s"
|
||||
blackhole: 10m
|
||||
labels:
|
||||
service: http
|
||||
type: scan
|
||||
remediation: true
|
||||
---
|
||||
type: leaky
|
||||
name: kupidonia/ban-smart-bot-rotator-user-agent
|
||||
description: "Detects IPs rotating multiple different User-Agents"
|
||||
filter: "evt.Meta.log_type == 'http_access-log' && evt.Parsed.http_user_agent != ''"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
distinct: "evt.Parsed.http_user_agent"
|
||||
capacity: 6
|
||||
leakspeed: "24h"
|
||||
blackhole: "1h"
|
||||
labels:
|
||||
service: http
|
||||
type: scraper
|
||||
remediation: captcha
|
||||
---
|
||||
type: trigger
|
||||
name: kupidonia/ban-smart-bot-wordpress-scanner
|
||||
description: "Instantly bans IPs looking for WordPress specific files/paths"
|
||||
# Ищем совпадения: в URL есть куски wp-admin, wp-login и т.д., или xmlrpc.php
|
||||
filter: "evt.Meta.log_type == 'http_access-log' && (evt.Parsed.request matches '(?i).*wp-(admin|login|content|includes|config).*' || evt.Parsed.request contains 'xmlrpc.php')"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: "1h"
|
||||
labels:
|
||||
service: http
|
||||
type: exploit
|
||||
remediation: ban
|
||||
---
|
||||
type: leaky
|
||||
name: kupidonia/ban-smart-bot-many-404
|
||||
description: "Detects IPs generating too many 404 Not Found errors"
|
||||
filter: 'evt.Meta.log_type == "http_access-log" && evt.Parsed.status == "404" && not (evt.Parsed.request matches "(?i)\\.(jpg|jpeg|png|gif|css|js|ico|webp|svg|woff2?)(\\?.*)?$")'
|
||||
groupby: "evt.Meta.source_ip"
|
||||
capacity: 20
|
||||
leakspeed: "10s"
|
||||
blackhole: "1h"
|
||||
labels:
|
||||
service: http
|
||||
type: scan
|
||||
remediation: ban
|
||||
---
|
||||
type: trigger
|
||||
name: kupidonia/cap-mac-chrome146
|
||||
description: "Send fake Mac OS + Chrome 146 bots to CAPTCHA"
|
||||
filter: evt.Meta.service == 'http' and evt.Parsed.http_user_agent contains 'Mac OS X 10_15_7' and (evt.Parsed.http_user_agent contains 'Chrome/146.0.0.0' or evt.Parsed.http_user_agent contains 'Chrome/148.0.0.0')
|
||||
groupby: evt.Meta.source_ip
|
||||
blackhole: 2m
|
||||
labels:
|
||||
service: http
|
||||
type: antispam
|
||||
remediation: captcha
|
||||
---
|
||||
type: trigger
|
||||
name: custom/captcha-all-mac10-15-7
|
||||
description: "Send ALL Mac OS X 10_15_7 traffic to CAPTCHA"
|
||||
filter: >
|
||||
evt.Meta.service == 'http' and
|
||||
evt.Parsed.http_user_agent contains 'Mac OS X 10_15_7'
|
||||
groupby: evt.Meta.source_ip
|
||||
blackhole: 2m
|
||||
labels:
|
||||
service: http
|
||||
type: antispam
|
||||
remediation: captcha
|
||||
@@ -0,0 +1,16 @@
|
||||
type: trigger
|
||||
name: kupidonia/ban-sorry-from-search
|
||||
description: "/sorry from search"
|
||||
filter: >
|
||||
evt.Meta.log_type == 'http_access-log' and
|
||||
evt.Parsed.request startsWith '/sorry' and
|
||||
(evt.Parsed.http_referer contains 'yandex.ru' or
|
||||
evt.Parsed.http_referer contains 'google.ru' or
|
||||
evt.Parsed.http_referer contains 'google.com' or
|
||||
evt.Parsed.http_referer contains 'bing.ru' or
|
||||
evt.Parsed.http_referer contains 'bing.com' or
|
||||
evt.Parsed.http_referer contains 'dzen.ru')
|
||||
labels:
|
||||
service: http
|
||||
type: bot
|
||||
remediation: true
|
||||
@@ -0,0 +1,10 @@
|
||||
type: trigger
|
||||
name: kupidonia/cap-all-clouds
|
||||
description: "Instant captcha for ANY provider with Cloud in ASOrg name"
|
||||
filter: "evt.Meta.log_type == 'http_access-log' && evt.Enriched.ASOrg matches '(?i)cloud'"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: http
|
||||
type: captcha
|
||||
remediation: true
|
||||
@@ -0,0 +1,10 @@
|
||||
type: trigger
|
||||
name: kupidonia/cap-asn-selectel
|
||||
description: "Instant captcha for datacenter ASNs of Selectel"
|
||||
filter: "evt.Meta.log_type == 'http_access-log' && evt.Enriched.ASNNumber in ['49505', '50340', '61976', '60084', '50149']"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: http
|
||||
type: captcha
|
||||
remediation: true
|
||||
@@ -0,0 +1,10 @@
|
||||
type: trigger
|
||||
name: kupidonia/cap-bad-asn
|
||||
description: "Instant captcha for datacenter ASNs"
|
||||
filter: "evt.Meta.log_type == 'http_access-log' && evt.Enriched.ASNNumber in ['3209','200373','44964','16509', '213220', '396982', '19318', '51167', '47583', '14061', '394380', '393406', '202018', '24940', '213230', '2119', '197540', '24961', '16276', '137539', '35540', '63949', '20473', '45102', '37963', '132203', '45090', '8075', '205090', '12695', '50867', '48614', '44559', '9123', '44112', '197695', '197397', '41668', '48287', '197327', '44133', '50952', '49981', '50465', '39798', '42722', '17727', '138950', '214574', '9318', '55967', '36907', '36907', '150436', '55990', '136907', '45899', '17754', '55862', '4837', '209641', '26548', '7552', '9658', '28169', '4787', '4787', '263553', '208137', '212238', '23724', '271240', '270832', '268418', '52871', '8452', '8167', '28202', '61668']"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: http
|
||||
type: captcha
|
||||
remediation: true
|
||||
@@ -0,0 +1,10 @@
|
||||
type: trigger
|
||||
name: kupidonia/cap-bad-other-asn-2
|
||||
description: "Instant captcha for datacenter ASNs"
|
||||
filter: "evt.Enriched.ASNNumber in ['11556', '202991', '48614', '21001', '264750', '62240', '5384', '24691', '35916', '55933', '24691', '262638', '15169', '45090', '132203', '209854', '39238', '4249', '16276', '26548', '24940', '398781', '200373', '36924', '15169', '14061', '396982', '9808', '4134', '54994', '7029']"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: http
|
||||
type: ban
|
||||
remediation: true
|
||||
@@ -0,0 +1,56 @@
|
||||
type: trigger
|
||||
name: kupidonia/cap-bot-android10-chrome
|
||||
description: "Instant captcha for bots using Android 10 with Mobile Chrome 149/150/151"
|
||||
filter: "evt.Meta.service == 'http' and evt.Parsed.http_user_agent contains 'Android 10' and evt.Parsed.http_user_agent contains 'Mobile' and (evt.Parsed.http_user_agent contains 'Chrome/148' or evt.Parsed.http_user_agent contains 'Chrome/149' or evt.Parsed.http_user_agent contains 'Chrome/150' or evt.Parsed.http_user_agent contains 'Chrome/151')"
|
||||
groupby: evt.Meta.source_ip
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: http
|
||||
type: bot
|
||||
remediation: captcha
|
||||
---
|
||||
type: leaky
|
||||
name: kupidonia/ban-fast-quiz-solver
|
||||
description: "Ban bots that submit quiz results too fast or too many times"
|
||||
filter: "evt.Meta.service == 'http' and evt.Parsed.request contains '/viktoriny-result/' and evt.Parsed.verb == 'POST'"
|
||||
groupby: evt.Meta.source_ip
|
||||
leakspeed: 3m
|
||||
capacity: 10
|
||||
blackhole: 30m
|
||||
labels:
|
||||
service: http
|
||||
type: bot
|
||||
remediation: ban
|
||||
---
|
||||
type: trigger
|
||||
name: kupidonia/ban-smart-bot-android10
|
||||
description: "Instant ban for bot using Android 10 submitting quiz results"
|
||||
filter: "evt.Meta.service == 'http' and evt.Parsed.request contains '/viktoriny-result/' and evt.Parsed.verb == 'POST' and evt.Parsed.http_user_agent contains 'Android 10' and evt.Parsed.http_user_agent contains 'Mobile' and (evt.Parsed.http_user_agent contains 'Chrome/148' or evt.Parsed.http_user_agent contains 'Chrome/149' or evt.Parsed.http_user_agent contains 'Chrome/150')"
|
||||
groupby: evt.Meta.source_ip
|
||||
blackhole: 15m
|
||||
labels:
|
||||
service: http
|
||||
type: bot
|
||||
remediation: ban
|
||||
---
|
||||
type: trigger
|
||||
name: kupidonia/cap-old-os
|
||||
description: "Send ancient OS (Old Android, Win 7/8, Headless) to captcha"
|
||||
filter: >
|
||||
evt.Meta.service == 'http' and (
|
||||
evt.Parsed.http_user_agent contains 'Android 7' or
|
||||
evt.Parsed.http_user_agent contains 'Android 8' or
|
||||
evt.Parsed.http_user_agent contains 'Android 9' or
|
||||
evt.Parsed.http_user_agent contains 'Android 10' or
|
||||
evt.Parsed.http_user_agent contains 'Android 11' or
|
||||
evt.Parsed.http_user_agent contains 'Windows NT 6.1' or
|
||||
evt.Parsed.http_user_agent contains 'Windows NT 6.2' or
|
||||
evt.Parsed.http_user_agent contains 'Windows NT 6.3' or
|
||||
evt.Parsed.http_user_agent contains 'HeadlessChrome'
|
||||
)
|
||||
groupby: evt.Meta.source_ip
|
||||
blackhole: 2m
|
||||
labels:
|
||||
service: http
|
||||
type: bot
|
||||
remediation: captcha
|
||||
@@ -0,0 +1,8 @@
|
||||
type: trigger
|
||||
name: kupidonia/cap-bukva
|
||||
description: "Send users requesting /bukva/ to CAPTCHA"
|
||||
filter: "evt.Meta.log_type == 'http_access-log' && evt.Meta.http_path contains '/bukva/'"
|
||||
labels:
|
||||
service: http
|
||||
type: custom
|
||||
remediation: true
|
||||
@@ -0,0 +1,8 @@
|
||||
type: trigger
|
||||
name: kupidonia/cap-crossword-word
|
||||
description: "Send users requesting /crossword-word/ to CAPTCHA"
|
||||
filter: "evt.Meta.log_type == 'http_access-log' && evt.Meta.http_path contains '/crossword-word/'"
|
||||
labels:
|
||||
service: http
|
||||
type: custom
|
||||
remediation: true
|
||||
@@ -0,0 +1,11 @@
|
||||
type: trigger
|
||||
name: kupidonia/cap-empty-asn
|
||||
description: "Instant captcha for IPs with missing ASN"
|
||||
# Проверяем, что это HTTP и поле ASN пустое (или равно нулю)
|
||||
filter: "evt.Meta.service == 'http' and (evt.Enriched.ASNNumber == '' or evt.Enriched.ASNNumber == '0')"
|
||||
groupby: evt.Meta.source_ip
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: http
|
||||
type: antispam
|
||||
remediation: captcha
|
||||
@@ -0,0 +1,10 @@
|
||||
type: trigger
|
||||
name: kupidonia/cap-empty-referer
|
||||
description: "Instant captcha for empty referer"
|
||||
filter: "evt.Meta.service == 'http' and (evt.Parsed.http_referer == '' or evt.Parsed.http_referer == '-')"
|
||||
groupby: evt.Meta.source_ip
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: http
|
||||
type: antispam
|
||||
remediation: captcha
|
||||
@@ -0,0 +1,10 @@
|
||||
type: trigger
|
||||
name: kupidonia/cap-honeypot
|
||||
description: "Detects dumb bots appending /indev to random URLs"
|
||||
filter: "evt.Meta.log_type in ['http_access-log', 'http_error-log'] && evt.Parsed.request matches '^/.+/indev([/?].*)?$'"
|
||||
groupby: evt.Meta.source_ip
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: http
|
||||
type: capcha
|
||||
remediation: true
|
||||
@@ -0,0 +1,8 @@
|
||||
type: trigger
|
||||
name: kupidonia/cap-http11
|
||||
description: "Catches bots on HTTP/1.1 with fake modern User-Agent"
|
||||
filter: "evt.Meta.log_type == 'http_access-log' and evt.Parsed.http_version in ['1.1', '1.0'] and evt.Parsed.http_user_agent matches 'Chrome/1[1-9][0-9]|Firefox/1[1-9][0-9]|OS 1[6-9]_|OS [2-9][0-9]_|Version/1[6-9]|Version/[2-9][0-9]'"
|
||||
labels:
|
||||
service: http
|
||||
type: bot
|
||||
remediation: captcha
|
||||
@@ -0,0 +1,10 @@
|
||||
type: trigger
|
||||
name: kupidonia/cap-index-mobile
|
||||
description: "Instant captcha for Android Chrome 149/150 coming from search to index"
|
||||
filter: "evt.Meta.log_type == 'http_access-log' && evt.Parsed.request in ['/', '/index.php'] && evt.Parsed.http_referer matches '(?i)(google|yandex)' && evt.Parsed.http_user_agent matches '(?i)Android.*Chrome/(149|150).*Mobile'"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: http
|
||||
type: captcha
|
||||
remediation: true
|
||||
@@ -0,0 +1,12 @@
|
||||
type: leaky
|
||||
name: kupidonia/cap-many-bukva
|
||||
description: "Rate limit for /bukva/ and /bukv/ (catch slow scrapers)"
|
||||
filter: "evt.Meta.log_type == 'http_access-log' and (evt.Parsed.request contains '/bukva/' or evt.Parsed.request contains '/bukv/')"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
capacity: 15
|
||||
leakspeed: "1m"
|
||||
blackhole: "5m"
|
||||
labels:
|
||||
service: http
|
||||
type: bruteforce
|
||||
remediation: capcha
|
||||
@@ -0,0 +1,12 @@
|
||||
type: leaky
|
||||
name: kupidonia/cap-many-crossword-word
|
||||
description: "/crossword-word/ in url"
|
||||
filter: "evt.Meta.log_type == 'http_access-log' and evt.Parsed.request contains '/crossword-word/'"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
capacity: 15
|
||||
leakspeed: "1m"
|
||||
blackhole: "5m"
|
||||
labels:
|
||||
service: http
|
||||
type: bruteforce
|
||||
remediation: capcha
|
||||
@@ -0,0 +1,25 @@
|
||||
type: leaky
|
||||
name: kupidonia/cap-many-spisok
|
||||
description: "Rate limit for /spisok/ and /spiski/ (catch slow scrapers)"
|
||||
filter: "evt.Meta.log_type == 'http_access-log' and (evt.Parsed.request contains '/spisok/' or evt.Parsed.request contains '/spiski/')"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
capacity: 15
|
||||
leakspeed: "1m"
|
||||
blackhole: "5m"
|
||||
labels:
|
||||
service: http
|
||||
type: bruteforce
|
||||
remediation: capcha
|
||||
---
|
||||
type: leaky
|
||||
name: kupidonia/cap-many-spisok-20
|
||||
description: "Detects slow scrapers reading more than 20 /spisok/ pages per hour"
|
||||
filter: "evt.Meta.log_type in ['http_access-log', 'http_error-log'] and evt.Parsed.request contains '/spisok/'"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
capacity: 20
|
||||
leakspeed: "3m"
|
||||
blackhole: 15m
|
||||
labels:
|
||||
service: http
|
||||
type: scraper
|
||||
remediation: true
|
||||
@@ -0,0 +1,12 @@
|
||||
type: leaky
|
||||
name: kupidonia/cap-many-viktoriny
|
||||
description: "/viktoriny/"
|
||||
filter: "evt.Meta.log_type == 'http_access-log' and evt.Parsed.request contains '/viktoriny/'"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
capacity: 7
|
||||
leakspeed: "7s"
|
||||
blackhole: "1m"
|
||||
labels:
|
||||
service: http
|
||||
type: bruteforce
|
||||
remediation: capcha
|
||||
@@ -0,0 +1,10 @@
|
||||
type: trigger
|
||||
name: kupidonia/cap-other-countries-asn
|
||||
description: "Instant captcha for datacenter ASNs of other Countries"
|
||||
filter: "evt.Meta.log_type == 'http_access-log' && evt.Enriched.ASNNumber in ['24940', '55286', '203020', '5503', '43395', '3257', '134450', '212238', '8452', '12312', '212283', '3209', '132203', '200373']"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: http
|
||||
type: captcha
|
||||
remediation: true
|
||||
@@ -0,0 +1,13 @@
|
||||
type: trigger
|
||||
name: kupidonia/cap-pikabu
|
||||
description: "Instant captcha for pikabu.ru links"
|
||||
filter: |
|
||||
evt.Meta.log_type == 'http_access-log' and
|
||||
evt.Parsed.http_referer contains 'pikabu.ru' and
|
||||
not (evt.Parsed.request matches '(?i).*\\.(css|js|jpg|jpeg|png|gif|webp|svg|ico|woff|woff2).*')
|
||||
groupby: evt.Meta.source_ip
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: http
|
||||
type: antispam
|
||||
remediation: captcha
|
||||
@@ -0,0 +1,10 @@
|
||||
type: trigger
|
||||
name: kupidonia/cap-ru-asn
|
||||
description: "Instant captcha for datacenter ASNs "
|
||||
filter: "evt.Meta.log_type == 'http_access-log' && evt.Enriched.ASNNumber in ['13335', '199136', '213220', '208677', '60245', '207967', '41722', '43152', '61178', '48030', '29182', '35751','21051', '47764', '9123', '25532', '50867', '197695', '44112', '47385', '47595', '62082']"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: http
|
||||
type: captcha
|
||||
remediation: true
|
||||
@@ -0,0 +1,12 @@
|
||||
type: leaky
|
||||
name: kupidonia/cap-site-scan-30-10m
|
||||
description: "Crawling more than 30 pages in 10 minutes"
|
||||
filter: "evt.Meta.log_type == 'http_access-log' and evt.Parsed.static_resource == 'false'"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
capacity: 30
|
||||
leakspeed: "20s"
|
||||
blackhole: "1m"
|
||||
labels:
|
||||
service: http
|
||||
type: scan
|
||||
remediation: ban
|
||||
@@ -0,0 +1,8 @@
|
||||
type: trigger
|
||||
name: kupidonia/cap-spisok
|
||||
description: "Send users requesting /spisok/ to CAPTCHA"
|
||||
filter: "evt.Meta.log_type == 'http_access-log' && evt.Meta.http_path contains '/spisok/'"
|
||||
labels:
|
||||
service: http
|
||||
type: custom
|
||||
remediation: true
|
||||
@@ -0,0 +1,10 @@
|
||||
type: trigger
|
||||
name: kupidonia/cap-ukr-asn
|
||||
description: "Instant captcha for datacenter ASNs of Ukraine"
|
||||
filter: "evt.Meta.log_type == 'http_access-log' && evt.Enriched.ASNNumber in ['35381', '197327', '48031']"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: http
|
||||
type: captcha
|
||||
remediation: true
|
||||
@@ -0,0 +1,10 @@
|
||||
type: trigger
|
||||
name: kupidonia/cap-unknown-country
|
||||
description: "Send unknown countries to Captcha"
|
||||
filter: "evt.Meta.source_ip != '' && evt.Meta.source_ip not in ['127.0.0.1', '::1'] && evt.Enriched.IsoCode == ''"
|
||||
groupby: evt.Meta.source_ip
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: http
|
||||
type: geo-block
|
||||
remediation: true
|
||||
@@ -0,0 +1,10 @@
|
||||
type: trigger
|
||||
name: kupidonia/cap-ya-vk-clouds
|
||||
description: "Instant captcha for Yandex.Cloud and VK Cloud by ASOrg name"
|
||||
filter: "evt.Meta.log_type == 'http_access-log' && evt.Enriched.ASOrg matches '(?i)(yandex.*cloud|vk.*cloud|vk-as)'"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: http
|
||||
type: captcha
|
||||
remediation: true
|
||||
@@ -0,0 +1,12 @@
|
||||
#Block all from Coraza
|
||||
type: trigger
|
||||
name: custom/coraza-waf
|
||||
description: "Ban immediately on Coraza WAF hits"
|
||||
filter: "evt.Meta.log_type == 'modsecurity'"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: http
|
||||
type: exploit
|
||||
remediation: true
|
||||
|
||||
@@ -0,0 +1,21 @@
|
||||
type: trigger
|
||||
#debug: true
|
||||
name: crowdsecurity/CVE-2017-9841
|
||||
description: "Detect CVE-2017-9841 exploits"
|
||||
filter: |
|
||||
evt.Meta.log_type == 'http_access-log' &&
|
||||
Lower(evt.Meta.http_path) endsWith 'util/php/eval-stdin.php'
|
||||
blackhole: 1m
|
||||
groupby: "evt.Meta.source_ip"
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
classification:
|
||||
- attack.T1595
|
||||
- attack.T1190
|
||||
- cve.CVE-2017-9841
|
||||
spoofable: 0
|
||||
confidence: 3
|
||||
behavior: "http:exploit"
|
||||
label: "PHP Unit Test Framework CVE-2017-9841"
|
||||
service: PHP
|
||||
@@ -0,0 +1,20 @@
|
||||
type: trigger
|
||||
format: 2.0
|
||||
name: crowdsecurity/CVE-2019-18935
|
||||
description: "Detect Telerik CVE-2019-18935 exploitation attempts"
|
||||
filter: |
|
||||
evt.Meta.log_type in ['http_access-log', 'http_error-log'] && Upper(QueryUnescape(evt.Meta.http_path)) startsWith Upper('/Telerik.Web.UI.WebResource.axd?type=rau')
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 2m
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
classification:
|
||||
- attack.T1595
|
||||
- attack.T1190
|
||||
- cve.CVE-2019-18935
|
||||
spoofable: 0
|
||||
confidence: 3
|
||||
behavior: "http:exploit"
|
||||
label: "Telerik CVE-2019-18935"
|
||||
service: telerik
|
||||
@@ -0,0 +1,10 @@
|
||||
type: trigger
|
||||
#debug: true
|
||||
name: crowdsecurity/CVE-2022-26134
|
||||
description: "Detect CVE-2022-26134 exploits"
|
||||
filter: "Upper(PathUnescape(evt.Meta.http_path)) contains Upper('@java.lang.Runtime@getRuntime().exec(')"
|
||||
blackhole: 1m
|
||||
groupby: "evt.Meta.source_ip"
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
@@ -0,0 +1,10 @@
|
||||
type: trigger
|
||||
#debug: true
|
||||
name: crowdsecurity/CVE-2022-35914
|
||||
description: "Detect CVE-2022-35914 exploits"
|
||||
filter: "Upper(evt.Meta.http_path) contains Upper('/vendor/htmlawed/htmlawed/htmLawedTest.php')"
|
||||
blackhole: 1m
|
||||
groupby: "evt.Meta.source_ip"
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
@@ -0,0 +1,18 @@
|
||||
type: trigger
|
||||
#debug: true
|
||||
name: crowdsecurity/CVE-2022-37042
|
||||
description: "Detect CVE-2022-37042 exploits"
|
||||
filter: |
|
||||
(
|
||||
Upper(evt.Meta.http_path) contains Upper('/service/extension/backup/mboximport?account-name=admin&ow=2&no-switch=1&append=1') ||
|
||||
Upper(evt.Meta.http_path) contains Upper('/service/extension/backup/mboximport?account-name=admin&account-status=1&ow=cmd')
|
||||
)
|
||||
and evt.Meta.http_status startsWith ('40') and
|
||||
Upper(evt.Meta.http_verb) == 'POST'
|
||||
|
||||
|
||||
blackhole: 2m
|
||||
groupby: "evt.Meta.source_ip"
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
@@ -0,0 +1,11 @@
|
||||
type: trigger
|
||||
name: crowdsecurity/fortinet-cve-2022-40684
|
||||
description: "Detect cve-2022-40684 exploitation attempts"
|
||||
filter: |
|
||||
evt.Meta.log_type in ["http_access-log", "http_error-log"] and
|
||||
Upper(evt.Meta.http_path) startsWith Upper('/api/v2/cmdb/system/admin/') and Lower(evt.Parsed.http_user_agent) == 'report runner'
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 2m
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
@@ -0,0 +1,13 @@
|
||||
type: trigger
|
||||
#debug: true
|
||||
name: crowdsecurity/CVE-2022-41082
|
||||
description: "Detect CVE-2022-41082 exploits"
|
||||
filter: |
|
||||
Upper(evt.Meta.http_path) contains Upper('/autodiscover/autodiscover.json') &&
|
||||
Upper(evt.Parsed.http_args) contains Upper('powershell')
|
||||
|
||||
blackhole: 1m
|
||||
groupby: "evt.Meta.source_ip"
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
@@ -0,0 +1,14 @@
|
||||
type: leaky
|
||||
name: crowdsecurity/CVE-2022-41697
|
||||
description: "Detect CVE-2022-41697 enumeration"
|
||||
filter: |
|
||||
Upper(evt.Meta.http_path) contains Upper('/ghost/api/admin/session') &&
|
||||
Upper(evt.Parsed.verb) == 'POST' &&
|
||||
evt.Meta.http_status == '404'
|
||||
leakspeed: "10s"
|
||||
capacity: 5
|
||||
blackhole: 1m
|
||||
groupby: "evt.Meta.source_ip"
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
@@ -0,0 +1,17 @@
|
||||
type: trigger
|
||||
#debug: true
|
||||
name: crowdsecurity/CVE-2022-42889
|
||||
description: "Detect CVE-2022-42889 exploits (Text4Shell)"
|
||||
filter: |
|
||||
Upper(PathUnescape(evt.Meta.http_path)) contains Upper('${script:javascript:java.lang.Runtime.getRuntime().exec(')
|
||||
or
|
||||
Upper(PathUnescape(evt.Meta.http_path)) contains Upper('${script:js:java.lang.Runtime.getRuntime().exec(')
|
||||
or
|
||||
Upper(PathUnescape(evt.Meta.http_path)) contains Upper('${url:UTF-8:')
|
||||
or
|
||||
Upper(PathUnescape(evt.Meta.http_path)) contains Upper('${dns:address|')
|
||||
blackhole: 1m
|
||||
groupby: "evt.Meta.source_ip"
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
@@ -0,0 +1,15 @@
|
||||
type: trigger
|
||||
#debug: true
|
||||
name: crowdsecurity/CVE-2022-44877
|
||||
description: "Detect CVE-2022-44877 exploits"
|
||||
filter: |
|
||||
Lower(evt.Meta.http_path) contains '/index.php' &&
|
||||
Upper(evt.Parsed.verb) == 'POST' &&
|
||||
evt.Meta.http_status == '302' &&
|
||||
Lower(evt.Parsed.http_args) matches 'login=.*[$|%24][\\(|%28].*[\\)|%29]'
|
||||
|
||||
blackhole: 1m
|
||||
groupby: "evt.Meta.source_ip"
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
@@ -0,0 +1,29 @@
|
||||
type: leaky
|
||||
name: crowdsecurity/CVE-2022-46169-bf
|
||||
description: "Detect CVE-2022-46169 brute forcing"
|
||||
filter: |
|
||||
Upper(evt.Meta.http_path) contains Upper('/remote_agent.php') &&
|
||||
Upper(evt.Parsed.verb) == 'GET' &&
|
||||
Lower(evt.Parsed.http_args) contains 'host_id' &&
|
||||
Lower(evt.Parsed.http_args) contains 'local_data_ids'
|
||||
leakspeed: "10s"
|
||||
capacity: 5
|
||||
blackhole: 1m
|
||||
groupby: "evt.Meta.source_ip"
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
---
|
||||
type: trigger
|
||||
name: crowdsecurity/CVE-2022-46169-cmd
|
||||
description: "Detect CVE-2022-46169 cmd injection"
|
||||
filter: |
|
||||
Upper(evt.Meta.http_path) contains Upper('/remote_agent.php') &&
|
||||
Upper(evt.Parsed.verb) == 'GET' &&
|
||||
Lower(evt.Parsed.http_args) contains 'action=polldata' &&
|
||||
Lower(evt.Parsed.http_args) matches 'poller_id=.*(;|%3b)'
|
||||
blackhole: 1m
|
||||
groupby: "evt.Meta.source_ip"
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
@@ -0,0 +1,22 @@
|
||||
## CVE-2023-22515
|
||||
type: trigger
|
||||
name: crowdsecurity/CVE-2023-22515
|
||||
description: "Detect CVE-2023-22515 exploitation"
|
||||
filter: |
|
||||
Lower(evt.Parsed.file_ext) == '.action' &&
|
||||
(Lower(evt.Parsed.file_dir) contains '/setup' || Lower(evt.Parsed.file_frag) == 'server-info') &&
|
||||
evt.Parsed.file_frag != nil
|
||||
blackhole: 1m
|
||||
groupby: "evt.Meta.source_ip"
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
classification:
|
||||
- attack.T1595
|
||||
- attack.T1190
|
||||
- cve.CVE-2023-22515
|
||||
spoofable: 0
|
||||
confidence: 1
|
||||
behavior: "http:exploit"
|
||||
label: "Confluence CVE-2023-22515"
|
||||
service: confluence
|
||||
@@ -0,0 +1,21 @@
|
||||
type: trigger
|
||||
#debug: true
|
||||
name: crowdsecurity/CVE-2023-22518
|
||||
description: "Detect CVE-2023-22518 exploits"
|
||||
filter: |
|
||||
Upper(evt.Meta.http_path) contains Upper('/json/setup-restore.action') &&
|
||||
Upper(evt.Parsed.verb) == 'POST'
|
||||
blackhole: 1m
|
||||
groupby: "evt.Meta.source_ip"
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
classification:
|
||||
- attack.T1595
|
||||
- attack.T1190
|
||||
- cve.CVE-2023-22518
|
||||
spoofable: 0
|
||||
confidence: 1
|
||||
behavior: "http:exploit"
|
||||
label: "Atlassian Confluence Server CVE-2023-22518"
|
||||
service: confluence
|
||||
@@ -0,0 +1,20 @@
|
||||
type: trigger
|
||||
format: 2.0
|
||||
name: crowdsecurity/CVE-2023-49103
|
||||
description: "Detect owncloud CVE-2023-49103 exploitation attempts"
|
||||
filter: |
|
||||
evt.Meta.log_type in ['http_access-log', 'http_error-log'] && Lower(evt.Meta.http_path) contains '/owncloud/apps/graphapi/vendor/microsoft/microsoft-graph/tests/getphpinfo.php'
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 2m
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
classification:
|
||||
- attack.T1595
|
||||
- attack.T1190
|
||||
- cve.CVE-2023-49103
|
||||
spoofable: 1
|
||||
confidence: 2
|
||||
behavior: "http:exploit"
|
||||
label: "ownCloud CVE-2023-49103"
|
||||
service: owncloud
|
||||
@@ -0,0 +1,23 @@
|
||||
type: trigger
|
||||
format: 2.0
|
||||
name: crowdsecurity/CVE-2024-0012
|
||||
description: "Detect CVE-2024-0012 exploitation attempts"
|
||||
filter: |
|
||||
let request = Lower(evt.Parsed.request);
|
||||
evt.Meta.log_type in ['http_access-log', 'http_error-log'] &&
|
||||
evt.Meta.http_status in ['404', '403'] &&
|
||||
(request matches '/php/.*/\\.js\\.map' || request matches '/index.php/.*\\.js\\.map')
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 2m
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
classification:
|
||||
- attack.T1595
|
||||
- attack.T1190
|
||||
- cve.CVE-2024-0012
|
||||
confidence: 3
|
||||
spoofable: 0
|
||||
behavior: "http:exploit"
|
||||
label: "CVE-2024-0012"
|
||||
service: panos
|
||||
@@ -0,0 +1,25 @@
|
||||
type: leaky
|
||||
format: 2.0
|
||||
name: crowdsecurity/CVE-2024-38475
|
||||
description: "Detect CVE-2024-38475 exploitation attempts"
|
||||
filter: |
|
||||
evt.Meta.log_type in ['http_access-log', 'http_error-log'] &&
|
||||
evt.Meta.http_status in ['404', '403'] &&
|
||||
Lower(evt.Parsed.request) endsWith '%3f'
|
||||
groupby: "evt.Meta.source_ip"
|
||||
distinct: "evt.Parsed.request"
|
||||
capacity: 3
|
||||
blackhole: 2m
|
||||
leakspeed: 10s
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
classification:
|
||||
- attack.T1595
|
||||
- attack.T1190
|
||||
- cve.CVE-2024-38475
|
||||
confidence: 3
|
||||
spoofable: 0
|
||||
behavior: "http:exploit"
|
||||
label: "CVE-2024-38475"
|
||||
service: apache
|
||||
@@ -0,0 +1,24 @@
|
||||
type: trigger
|
||||
format: 2.0
|
||||
name: crowdsecurity/CVE-2024-9474
|
||||
description: "Detect CVE-2024-9474 exploitation attempts"
|
||||
filter: |
|
||||
let request = Lower(evt.Parsed.request);
|
||||
evt.Meta.log_type in ['http_access-log', 'http_error-log'] &&
|
||||
evt.Meta.http_status in ['404', '403'] &&
|
||||
evt.Meta.http_verb == 'POST' &&
|
||||
request contains '/php/utils/createremoteappwebsession.php/watchtowr.js.map'
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 2m
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
classification:
|
||||
- attack.T1595
|
||||
- attack.T1190
|
||||
- cve.CVE-2024-9474
|
||||
confidence: 3
|
||||
spoofable: 0
|
||||
behavior: "http:exploit"
|
||||
label: "CVE-2024-9474"
|
||||
service: panos
|
||||
@@ -0,0 +1,23 @@
|
||||
type: trigger
|
||||
format: 2.0
|
||||
#debug: true
|
||||
name: crowdsecurity/apache_log4j2_cve-2021-44228
|
||||
description: "Detect cve-2021-44228 exploitation attemps"
|
||||
filter: |
|
||||
evt.Meta.log_type in ["http_access-log", "http_error-log"] and
|
||||
(
|
||||
any(File("log4j2_cve_2021_44228.txt"), { Upper(evt.Meta.http_path) contains Upper(#)})
|
||||
or
|
||||
any(File("log4j2_cve_2021_44228.txt"), { Upper(evt.Parsed.http_user_agent) contains Upper(#)})
|
||||
or
|
||||
any(File("log4j2_cve_2021_44228.txt"), { Upper(evt.Parsed.http_referer) contains Upper(#)})
|
||||
)
|
||||
data:
|
||||
- source_url: https://raw.githubusercontent.com/crowdsecurity/sec-lists/master/web/log4j2_cve_2021_44228.txt
|
||||
dest_file: log4j2_cve_2021_44228.txt
|
||||
type: string
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 2m
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
@@ -0,0 +1,10 @@
|
||||
type: trigger
|
||||
name: kupidonia/ban-bad-ru-asn
|
||||
description: "Instant ban for datacenter ASNs "
|
||||
filter: "evt.Meta.log_type == 'http_access-log' && evt.Enriched.ASNNumber in ['9123', '12555', '50214', '61178', '214574', '208969', '35048', '205090', '213220']"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: http
|
||||
type: ban
|
||||
remediation: true
|
||||
@@ -0,0 +1,9 @@
|
||||
type: trigger
|
||||
name: kupidonia/ban-countries
|
||||
description: "Block traffic from countries"
|
||||
filter: "evt.Enriched.IsoCode in ['CN', 'IN', 'VN', 'SG', 'KR', 'ID', 'HK', 'TW', 'TH', 'MY', 'PH', 'PK', 'TW', 'BR', 'NG', 'EG']"
|
||||
groupby: evt.Meta.source_ip
|
||||
blackhole: 1m
|
||||
labels:
|
||||
type: geo-block
|
||||
remediation: true
|
||||
@@ -0,0 +1,10 @@
|
||||
type: trigger
|
||||
name: kupidonia/ban-datacenters-by-name
|
||||
description: "Instant ban for hosting and cloud providers"
|
||||
filter: "'ASNOrg' in evt.Enriched and evt.Enriched.ASNOrg matches '(?i).*(Biterika|WINDSTREAM|HOSTING|DigitalOcean|Hetzner|Amazon|AMAZON|Linode|Contabo|EGIHOSTING).*'"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: http
|
||||
type: ban
|
||||
remediation: true
|
||||
@@ -0,0 +1,14 @@
|
||||
type: trigger
|
||||
name: kupidonia/ban-dzen
|
||||
description: "Block Dzen immediately except allowed URLs"
|
||||
filter: |
|
||||
evt.Meta.log_type == 'http_access-log' and
|
||||
evt.Parsed.http_referer contains 'dzen.ru' and
|
||||
!(evt.Parsed.request contains '/otvety-' or evt.Parsed.request contains '/ezhednevnyj-test' or evt.Parsed.request contains 'for-dzen') and
|
||||
!(evt.Parsed.request matches '(?i).*\\.(css|js|jpg|jpeg|png|gif|webp|svg|ico|woff|woff2).*')
|
||||
groupby: evt.Meta.source_ip
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: http
|
||||
type: ban
|
||||
remediation: true
|
||||
@@ -0,0 +1,10 @@
|
||||
type: trigger
|
||||
name: kupidonia/ban-saelmon-bot
|
||||
description: "Мгновенный бан для бота saelmon"
|
||||
filter: "evt.Meta.log_type == 'http_access-log' and evt.Parsed.http_user_agent contains 'saelmon'"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: "1m"
|
||||
labels:
|
||||
service: http
|
||||
type: bot
|
||||
remediation: true
|
||||
@@ -0,0 +1,10 @@
|
||||
type: trigger
|
||||
name: kupidonia/cap-countries
|
||||
description: "Send Germany traffic to Captcha"
|
||||
filter: "evt.Enriched.IsoCode in ['JP', 'AD', 'AG', 'AI', 'AL', 'AT', 'AW', 'BA', 'BB', 'BE', 'BG', 'BL', 'BM', 'BS', 'BY', 'BZ', 'CA', 'CH', 'CL', 'CR', 'CU', 'CW', 'CY', 'CZ', 'DE', 'DK', 'DM', 'DO', 'EE', 'ES', 'FI', 'FR', 'GB', 'GD', 'GL', 'GP', 'GR', 'GT', 'HN', 'HR', 'HT', 'HU', 'IE', 'IS', 'IT', 'JM', 'KN', 'KY', 'LC', 'LI', 'LT', 'LU', 'LV', 'MC', 'MD', 'ME', 'MF', 'MK', 'MQ', 'MS', 'MT', 'MX', 'MY', 'NI', 'NL', 'NO', 'PA', 'PL', 'PM', 'PR', 'PT', 'RO', 'RS', 'SE', 'SI', 'SK', 'SM', 'SV', 'SX', 'TC', 'TT', 'UA', 'US', 'VA', 'VC', 'VG', 'VI']"
|
||||
groupby: evt.Meta.source_ip
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: http
|
||||
type: geo-block
|
||||
remediation: true
|
||||
@@ -0,0 +1,13 @@
|
||||
type: trigger
|
||||
name: kupidonia/cap-mailru
|
||||
description: "Instant captcha for mailru links"
|
||||
filter: |
|
||||
evt.Meta.log_type == 'http_access-log' and
|
||||
evt.Parsed.http_referer contains 'mail.ru' and
|
||||
not (evt.Parsed.request matches '(?i).*\\.(css|js|jpg|jpeg|png|gif|webp|svg|ico|woff|woff2).*')
|
||||
groupby: evt.Meta.source_ip
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: http
|
||||
type: antispam
|
||||
remediation: captcha
|
||||
@@ -0,0 +1,16 @@
|
||||
type: trigger
|
||||
format: 2.0
|
||||
name: crowdsecurity/f5-big-ip-cve-2020-5902
|
||||
description: "Detect cve-2020-5902 exploitation attemps"
|
||||
filter: |
|
||||
evt.Meta.log_type in ["http_access-log", "http_error-log"] and
|
||||
(
|
||||
Upper(evt.Meta.http_path) matches Upper('/tmui/login.jsp/..;/tmui/[^.]+.jsp\\?(fileName|command|directoryPath|tabId)=')
|
||||
or
|
||||
Upper(evt.Meta.http_path) matches Upper('/tmui/login.jsp/%2E%2E;/tmui/[^.]+.jsp\\?(fileName|command|directoryPath|tabId)=')
|
||||
)
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 2m
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
@@ -0,0 +1,12 @@
|
||||
type: trigger
|
||||
format: 2.0
|
||||
name: crowdsecurity/fortinet-cve-2018-13379
|
||||
description: "Detect cve-2018-13379 exploitation attemps"
|
||||
filter: |
|
||||
evt.Meta.log_type in ["http_access-log", "http_error-log"] and
|
||||
Upper(evt.Meta.http_path) contains Upper('/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession')
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 2m
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
@@ -0,0 +1,14 @@
|
||||
type: trigger
|
||||
format: 2.0
|
||||
name: crowdsecurity/grafana-cve-2021-43798
|
||||
description: "Detect cve-2021-43798 exploitation attemps"
|
||||
filter: |
|
||||
evt.Meta.log_type in ["http_access-log", "http_error-log"] and
|
||||
(Upper(evt.Meta.http_path) matches '/PUBLIC/PLUGINS/[^/]+/../[./]+/'
|
||||
or
|
||||
Upper(evt.Meta.http_path) matches '/PUBLIC/PLUGINS/[^/]+/%2E%2E/[%2E/]+/')
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 2m
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
@@ -0,0 +1,27 @@
|
||||
type: leaky
|
||||
#debug: true
|
||||
name: crowdsecurity/http-admin-interface-probing
|
||||
description: "Detect generic HTTP admin interface probing"
|
||||
filter: |
|
||||
evt.Meta.service == 'http' and
|
||||
evt.Meta.log_type in ['http_access-log', 'http_error-log'] and
|
||||
evt.Meta.http_status in ['404', '403'] and
|
||||
any(File("admin_interfaces.txt"), { Lower(evt.Meta.http_path) contains #})
|
||||
groupby: evt.Meta.source_ip
|
||||
distinct: "evt.Meta.http_path"
|
||||
data:
|
||||
- source_url: https://hub-data.crowdsec.net/web/admin_interfaces.txt
|
||||
dest_file: admin_interfaces.txt
|
||||
type: string
|
||||
capacity: 2
|
||||
leakspeed: "10s"
|
||||
blackhole: 1m
|
||||
labels:
|
||||
confidence: 3
|
||||
spoofable: 0
|
||||
classification:
|
||||
- attack.T1595
|
||||
behavior: "http:scan"
|
||||
label: "HTTP Admin Interface Probing"
|
||||
service: http
|
||||
remediation: true
|
||||
@@ -0,0 +1,18 @@
|
||||
type: leaky
|
||||
#debug: true
|
||||
name: crowdsecurity/http-backdoors-attempts
|
||||
description: "Detect attempt to common backdoors"
|
||||
filter: 'evt.Meta.log_type in ["http_access-log", "http_error-log"] and any(File("backdoors.txt"), { evt.Parsed.file_name == #})'
|
||||
groupby: "evt.Meta.source_ip"
|
||||
distinct: evt.Parsed.file_name
|
||||
data:
|
||||
- source_url: https://raw.githubusercontent.com/crowdsecurity/sec-lists/master/web/backdoors.txt
|
||||
dest_file: backdoors.txt
|
||||
type: string
|
||||
capacity: 1
|
||||
leakspeed: 5s
|
||||
blackhole: 5m
|
||||
labels:
|
||||
service: http
|
||||
type: discovery
|
||||
remediation: true
|
||||
@@ -0,0 +1,17 @@
|
||||
type: leaky
|
||||
format: 2.0
|
||||
#debug: true
|
||||
name: crowdsecurity/http-bad-user-agent
|
||||
description: "Detect bad user-agents"
|
||||
filter: 'evt.Meta.log_type in ["http_access-log", "http_error-log"] && RegexpInFile(evt.Parsed.http_user_agent, "bad_user_agents.regex.txt")'
|
||||
data:
|
||||
- source_url: https://raw.githubusercontent.com/crowdsecurity/sec-lists/master/web/bad_user_agents.regex.txt
|
||||
dest_file: bad_user_agents.regex.txt
|
||||
type: regexp
|
||||
capacity: 1
|
||||
leakspeed: 1m
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 2m
|
||||
labels:
|
||||
type: scan
|
||||
remediation: true
|
||||
@@ -0,0 +1,16 @@
|
||||
type: leaky
|
||||
name: crowdsecurity/http-crawl-non_statics
|
||||
description: "Detect aggressive crawl from single ip"
|
||||
filter: "evt.Meta.log_type in ['http_access-log', 'http_error-log'] && evt.Parsed.static_ressource == 'false' && evt.Parsed.verb in ['GET', 'HEAD']"
|
||||
distinct: "evt.Parsed.file_name"
|
||||
leakspeed: 0.5s
|
||||
capacity: 40
|
||||
#debug: true
|
||||
#this limits the memory cache (and event_sequences in output) to five events
|
||||
cache_size: 5
|
||||
groupby: "evt.Meta.source_ip + '/' + evt.Parsed.target_fqdn"
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: http
|
||||
type: crawl
|
||||
remediation: true
|
||||
@@ -0,0 +1,15 @@
|
||||
type: trigger
|
||||
format: 2.0
|
||||
#debug: true
|
||||
name: crowdsecurity/http-cve-2021-41773
|
||||
description: "cve-2021-41773"
|
||||
filter: |
|
||||
evt.Meta.log_type in ["http_access-log", "http_error-log"] and
|
||||
(Upper(evt.Meta.http_path) contains "/.%2E/.%2E/"
|
||||
or
|
||||
Upper(evt.Meta.http_path) contains "/%2E%2E/%2E%2E")
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 2m
|
||||
labels:
|
||||
type: scan
|
||||
remediation: true
|
||||
@@ -0,0 +1,14 @@
|
||||
type: trigger
|
||||
format: 2.0
|
||||
#debug: true
|
||||
#this is getting funny, it's the third patch on top of cve-2021-41773
|
||||
name: crowdsecurity/http-cve-2021-42013
|
||||
description: "cve-2021-42013"
|
||||
filter: |
|
||||
evt.Meta.log_type in ["http_access-log", "http_error-log"] and
|
||||
Upper(evt.Meta.http_path) contains "/%%32%65%%32%65/"
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 2m
|
||||
labels:
|
||||
type: scan
|
||||
remediation: true
|
||||
@@ -0,0 +1,27 @@
|
||||
type: trigger
|
||||
name: crowdsecurity/http-cve-probing
|
||||
description: "Detect generic HTTP cve probing"
|
||||
filter: |
|
||||
evt.Meta.service == 'http' and
|
||||
evt.Meta.log_type in ['http_access-log', 'http_error-log'] and
|
||||
evt.Meta.http_status in ['404', '403'] and
|
||||
any(File("trendy_cves_uris.json"), {
|
||||
evt.Meta.http_path contains JsonExtract(#, "uri") ? evt.SetMeta("cve", JsonExtract(#, "cve")) : false
|
||||
})
|
||||
groupby: evt.Meta.source_ip
|
||||
distinct: "evt.Meta.http_path"
|
||||
data:
|
||||
#
|
||||
- source_url: https://hub-data.crowdsec.net/web/trendy_cves_uris.json
|
||||
dest_file: trendy_cves_uris.json
|
||||
type: string
|
||||
blackhole: 1m
|
||||
labels:
|
||||
confidence: 3
|
||||
spoofable: 0
|
||||
classification:
|
||||
- attack.T1595
|
||||
behavior: "http:scan"
|
||||
label: "HTTP CVE Probing"
|
||||
service: http
|
||||
remediation: true
|
||||
@@ -0,0 +1,44 @@
|
||||
# 404 scan
|
||||
type: leaky
|
||||
#debug: true
|
||||
name: crowdsecurity/http-generic-bf
|
||||
description: "Detect generic http brute force"
|
||||
filter: "evt.Meta.service == 'http' && evt.Meta.sub_type == 'auth_fail'"
|
||||
groupby: evt.Meta.source_ip
|
||||
capacity: 5
|
||||
leakspeed: "10s"
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: http
|
||||
type: bf
|
||||
remediation: true
|
||||
---
|
||||
# Generic 401 Authorization Errors
|
||||
type: leaky
|
||||
#debug: true
|
||||
name: LePresidente/http-generic-401-bf
|
||||
description: "Detect generic 401 Authorization error brute force"
|
||||
filter: "evt.Meta.log_type == 'http_access-log' && evt.Parsed.verb == 'POST' && evt.Meta.http_status == '401'"
|
||||
groupby: evt.Meta.source_ip
|
||||
capacity: 5
|
||||
leakspeed: "10s"
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: http
|
||||
type: bf
|
||||
remediation: true
|
||||
---
|
||||
# Generic 403 Forbidden (Authorization) Errors
|
||||
type: leaky
|
||||
#debug: true
|
||||
name: LePresidente/http-generic-403-bf
|
||||
description: "Detect generic 403 Forbidden (Authorization) error brute force"
|
||||
filter: "evt.Meta.log_type == 'http_access-log' && evt.Parsed.verb == 'POST' && evt.Meta.http_status == '403'"
|
||||
groupby: evt.Meta.source_ip
|
||||
capacity: 5
|
||||
leakspeed: "10s"
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: http
|
||||
type: bf
|
||||
remediation: true
|
||||
@@ -0,0 +1,16 @@
|
||||
# EICAR style scenario
|
||||
# This scenario is used to test CrowdSec installation and configuration and doesn't generate any decisions.
|
||||
type: trigger
|
||||
name: crowdsecurity/http-generic-test
|
||||
description: "Crowdsec Generic Test Scenario: basic HTTP trigger"
|
||||
filter: evt.Meta.log_type in ["http_access-log", "http_error-log"] and
|
||||
evt.Meta.http_path == "/crowdsec-test-NtktlJHV4TfBSK3wvlhiOBnl"
|
||||
blackhole: 5m
|
||||
groupby: "evt.Meta.source_ip"
|
||||
labels:
|
||||
confidence: 0
|
||||
spoofable: 3
|
||||
behavior: "http:test"
|
||||
label: "CrowdSec Generic Test Scenario"
|
||||
service: http
|
||||
remediation: false
|
||||
@@ -0,0 +1,10 @@
|
||||
type: trigger
|
||||
name: crowdsecurity/http-open-proxy
|
||||
description: "Detect scan for open proxy"
|
||||
#apache returns 405, nginx 400
|
||||
filter: "evt.Meta.log_type == 'http_access-log' && evt.Meta.http_status in ['400','405'] && (evt.Parsed.verb == 'CONNECT' || evt.Parsed.request matches '^http[s]?://')"
|
||||
blackhole: 2m
|
||||
labels:
|
||||
service: http
|
||||
type: scan
|
||||
remediation: true
|
||||
@@ -0,0 +1,20 @@
|
||||
# path traversal probing
|
||||
type: leaky
|
||||
#debug: true
|
||||
name: crowdsecurity/http-path-traversal-probing
|
||||
description: "Detect path traversal attempt"
|
||||
filter: "evt.Meta.log_type in ['http_access-log', 'http_error-log'] && any(File('http_path_traversal.txt'),{evt.Meta.http_path contains #})"
|
||||
data:
|
||||
- source_url: https://raw.githubusercontent.com/crowdsecurity/sec-lists/master/web/path_traversal.txt
|
||||
dest_file: http_path_traversal.txt
|
||||
type: string
|
||||
groupby: "evt.Meta.source_ip"
|
||||
distinct: "evt.Meta.http_path"
|
||||
capacity: 3
|
||||
reprocess: true
|
||||
leakspeed: 10s
|
||||
blackhole: 2m
|
||||
labels:
|
||||
service: http
|
||||
type: scan
|
||||
remediation: true
|
||||
@@ -0,0 +1,16 @@
|
||||
# 404 scan
|
||||
type: leaky
|
||||
#debug: true
|
||||
name: crowdsecurity/http-probing
|
||||
description: "Detect site scanning/probing from a single ip"
|
||||
filter: "evt.Meta.service == 'http' && evt.Meta.http_status in ['404', '403', '400'] && evt.Parsed.static_ressource == 'false'"
|
||||
groupby: "evt.Meta.source_ip + '/' + evt.Parsed.target_fqdn"
|
||||
distinct: "evt.Meta.http_path"
|
||||
capacity: 10
|
||||
reprocess: true
|
||||
leakspeed: "10s"
|
||||
blackhole: 5m
|
||||
labels:
|
||||
service: http
|
||||
type: scan
|
||||
remediation: true
|
||||
@@ -0,0 +1,41 @@
|
||||
type: leaky
|
||||
#debug: true
|
||||
name: crowdsecurity/http-sap-interface-probing
|
||||
description: "Detect generic HTTP SAP interface probing"
|
||||
filter: |
|
||||
evt.Meta.service == 'http' and
|
||||
evt.Meta.log_type in ['http_access-log', 'http_error-log'] and
|
||||
evt.Meta.http_status in ['404', '403'] and (
|
||||
let uri = Lower(evt.Meta.http_path);
|
||||
uri contains "/sap/bc/gui/sap/its/webgui"
|
||||
or uri contains "/irj/portal"
|
||||
or uri contains "/sap/bc/"
|
||||
or uri contains "/sap/bc/ui2/flp"
|
||||
or uri contains "/sap/bc/ui5_ui5/"
|
||||
or uri contains "/sap/opu/odata/"
|
||||
or uri contains "/sap/bc/webdynpro/"
|
||||
or uri contains "/sap/public/bc/"
|
||||
or uri contains "/sap/public/info"
|
||||
or uri contains "/sap/public/icf_info"
|
||||
or uri contains "/sap/admin/publicicp/"
|
||||
or uri contains "/sap/admin/public/"
|
||||
or uri == "/nwa"
|
||||
or uri contains "/webdynpro/dispatcher/sap.com/tc~sec~ume~wd~umeadmin/umeadminapp"
|
||||
or uri contains "/sap/hana/xs/admin"
|
||||
or uri contains "/sap/hana/xs/formlogin"
|
||||
or uri contains "/irj/go/km/navigation"
|
||||
)
|
||||
groupby: evt.Meta.source_ip
|
||||
leakspeed: "10s"
|
||||
capacity: 1
|
||||
distinct: evt.Meta.http_path
|
||||
blackhole: 1m
|
||||
labels:
|
||||
confidence: 3
|
||||
spoofable: 0
|
||||
classification:
|
||||
- attack.T1595
|
||||
behavior: "http:scan"
|
||||
label: "HTTP SAP Interface Probing"
|
||||
service: http
|
||||
remediation: true
|
||||
@@ -0,0 +1,19 @@
|
||||
type: leaky
|
||||
format: 2.0
|
||||
#debug: true
|
||||
name: crowdsecurity/http-sensitive-files
|
||||
description: "Detect attempt to access to sensitive files (.log, .db ..) or folders (.git)"
|
||||
filter: 'evt.Meta.log_type in ["http_access-log", "http_error-log"] and any(File("sensitive_data.txt"), { evt.Parsed.request endsWith #})'
|
||||
groupby: "evt.Meta.source_ip"
|
||||
distinct: evt.Parsed.request
|
||||
data:
|
||||
- source_url: https://raw.githubusercontent.com/crowdsecurity/sec-lists/master/web/sensitive_data.txt
|
||||
dest_file: sensitive_data.txt
|
||||
type: string
|
||||
capacity: 4
|
||||
leakspeed: 5s
|
||||
blackhole: 5m
|
||||
labels:
|
||||
service: http
|
||||
type: discovery
|
||||
remediation: true
|
||||
@@ -0,0 +1,20 @@
|
||||
type: leaky
|
||||
#requires at least 2.0 because it's using the 'data' section and the 'Upper' expr helper
|
||||
format: 2.0
|
||||
name: crowdsecurity/http-sqli-probbing-detection
|
||||
data:
|
||||
- source_url: https://raw.githubusercontent.com/crowdsecurity/sec-lists/master/web/sqli_probe_patterns.txt
|
||||
dest_file: sqli_probe_patterns.txt
|
||||
type: string
|
||||
description: "A scenario that detects SQL injection probing with minimal false positives"
|
||||
filter: "evt.Meta.log_type in ['http_access-log', 'http_error-log'] && any(File('sqli_probe_patterns.txt'), {Upper(evt.Parsed.http_args) contains Upper(#)})"
|
||||
groupby: evt.Meta.source_ip
|
||||
capacity: 10
|
||||
leakspeed: 1s
|
||||
blackhole: 5m
|
||||
#low false positives approach : we require distinct payloads to avoid false positives
|
||||
distinct: evt.Parsed.http_args
|
||||
labels:
|
||||
service: http
|
||||
type: sqli_probing
|
||||
remediation: true
|
||||
@@ -0,0 +1,27 @@
|
||||
type: trigger
|
||||
name: crowdsecurity/http-technology-probing
|
||||
description: "Detect HTTP technology/vendor probing"
|
||||
filter: |
|
||||
if (evt.Meta.service == 'http' and
|
||||
evt.Meta.log_type in ['http_access-log', 'http_error-log'] and
|
||||
evt.Meta.http_status in ['404', '403'])
|
||||
{
|
||||
let target_technology = LookupFile(evt.Meta.http_path, "technology_probing.json");
|
||||
target_technology != "" ? evt.SetMeta("target_technology", target_technology) : false
|
||||
} else { false }
|
||||
groupby: evt.Meta.source_ip
|
||||
blackhole: 1m
|
||||
data:
|
||||
#
|
||||
- dest_file: technology_probing.json
|
||||
source_url: https://hub-data.crowdsec.net/web/technology_probing.json
|
||||
type: map
|
||||
labels:
|
||||
confidence: 3
|
||||
spoofable: 0
|
||||
classification:
|
||||
- attack.T1595
|
||||
behavior: "http:scan"
|
||||
label: "HTTP Technology Probing"
|
||||
service: http
|
||||
remediation: false
|
||||
@@ -0,0 +1,12 @@
|
||||
#contributed by ltsich
|
||||
type: trigger
|
||||
name: ltsich/http-w00tw00t
|
||||
description: "detect w00tw00t"
|
||||
debug: false
|
||||
filter: "evt.Meta.log_type == 'http_access-log' && evt.Parsed.file_name contains 'w00tw00t.at.ISC.SANS.DFind'"
|
||||
groupby: evt.Meta.source_ip
|
||||
blackhole: 5m
|
||||
labels:
|
||||
service: http
|
||||
type: scan
|
||||
remediation: true
|
||||
@@ -0,0 +1,22 @@
|
||||
type: leaky
|
||||
name: crowdsecurity/http-wordpress-scan
|
||||
description: "Detect exploitation attempts against common WordPress endpoints"
|
||||
filter: |
|
||||
evt.Meta.service == 'http' and
|
||||
evt.Meta.log_type in ['http_access-log', 'http_error-log'] and
|
||||
evt.Meta.http_status in ['404', '403'] and
|
||||
Lower(evt.Parsed.request) matches "(?i)(/wp-.*\\.php|/wp-content/plugins/.*\\.(txt|md))$"
|
||||
groupby: evt.Meta.source_ip
|
||||
distinct: evt.Parsed.request
|
||||
capacity: 3
|
||||
leakspeed: "10s"
|
||||
blackhole: 5m
|
||||
labels:
|
||||
remediation: true
|
||||
classification:
|
||||
- attack.T1595
|
||||
behavior: "http:scan"
|
||||
label: "WordPress Vuln Hunting"
|
||||
spoofable: 0
|
||||
service: wordpress
|
||||
confidence: 3
|
||||
@@ -0,0 +1,20 @@
|
||||
type: leaky
|
||||
#requires at least 2.0 because it's using the 'data' section and the 'Upper' expr helper
|
||||
format: 2.0
|
||||
name: crowdsecurity/http-xss-probbing
|
||||
data:
|
||||
- source_url: https://raw.githubusercontent.com/crowdsecurity/sec-lists/master/web/xss_probe_patterns.txt
|
||||
dest_file: xss_probe_patterns.txt
|
||||
type: string
|
||||
description: "A scenario that detects XSS probing with minimal false positives"
|
||||
filter: "evt.Meta.log_type in ['http_access-log', 'http_error-log'] && any(File('xss_probe_patterns.txt'), {Upper(evt.Parsed.http_args) contains Upper(#)})"
|
||||
groupby: evt.Meta.source_ip
|
||||
capacity: 5
|
||||
leakspeed: 1s
|
||||
blackhole: 5m
|
||||
#low false positives approach : we require distinct payloads to avoid false positives
|
||||
distinct: evt.Parsed.http_args
|
||||
labels:
|
||||
service: http
|
||||
type: xss_probing
|
||||
remediation: true
|
||||
@@ -0,0 +1,16 @@
|
||||
type: trigger
|
||||
format: 2.0
|
||||
#debug: true
|
||||
name: crowdsecurity/jira_cve-2021-26086
|
||||
description: "Detect Atlassian Jira CVE-2021-26086 exploitation attemps"
|
||||
filter: |
|
||||
evt.Meta.log_type in ["http_access-log", "http_error-log"] and any(File("jira_cve_2021-26086.txt"), {Upper(evt.Meta.http_path) contains Upper(#)})
|
||||
data:
|
||||
- source_url: https://raw.githubusercontent.com/crowdsecurity/sec-lists/master/web/jira_cve_2021-26086.txt
|
||||
dest_file: jira_cve_2021-26086.txt
|
||||
type: string
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 2m
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
@@ -0,0 +1,18 @@
|
||||
type: trigger
|
||||
#debug: true
|
||||
name: crowdsecurity/modsecurity
|
||||
description: "Web exploitation via modsecurity"
|
||||
#modsec for nginx only logs the numerical value of the severity
|
||||
filter: evt.Meta.log_type == 'modsecurity' && (evt.Parsed.ruleseverity == 'CRITICAL' || evt.Parsed.ruleseverity == '2')
|
||||
blackhole: 2m
|
||||
groupby: evt.Meta.source_ip
|
||||
labels:
|
||||
remediation: true
|
||||
classification:
|
||||
- attack.T1595
|
||||
- attack.T1190
|
||||
behavior: "http:exploit"
|
||||
label: "Modsecurity Alert"
|
||||
spoofable: 0
|
||||
confidence: 2
|
||||
service: http
|
||||
@@ -0,0 +1,21 @@
|
||||
type: trigger
|
||||
format: 2.0
|
||||
name: crowdsecurity/netgear_rce
|
||||
description: "Detect Netgear RCE DGN1000/DGN220 exploitation attempts"
|
||||
filter: |
|
||||
evt.Meta.log_type in ['http_access-log', 'http_error-log'] && Lower(QueryUnescape(evt.Meta.http_path)) startsWith Lower('/setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=')
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 2m
|
||||
references:
|
||||
- "https://www.exploit-db.com/exploits/25978"
|
||||
labels:
|
||||
confidence: 3
|
||||
spoofable: 0
|
||||
classification:
|
||||
- attack.T1595
|
||||
- attack.T1190
|
||||
- cve.CVE-2024-12847
|
||||
behavior: "http:exploit"
|
||||
label: "Netgear RCE"
|
||||
service: netgear
|
||||
remediation: true
|
||||
@@ -0,0 +1,13 @@
|
||||
type: leaky
|
||||
#debug: true
|
||||
name: crowdsecurity/nginx-req-limit-exceeded
|
||||
description: "Detects IPs which violate nginx's user set request limit."
|
||||
filter: evt.Meta.sub_type == 'req_limit_exceeded'
|
||||
leakspeed: "60s"
|
||||
capacity: 5
|
||||
groupby: evt.Meta.source_ip
|
||||
blackhole: 5m
|
||||
labels:
|
||||
service: nginx
|
||||
type: bruteforce
|
||||
remediation: true
|
||||
@@ -0,0 +1,14 @@
|
||||
type: trigger
|
||||
format: 2.0
|
||||
name: crowdsecurity/pulse-secure-sslvpn-cve-2019-11510
|
||||
description: "Detect cve-2019-11510 exploitation attemps"
|
||||
filter: |
|
||||
evt.Meta.log_type in ["http_access-log", "http_error-log"] and
|
||||
(Upper(evt.Meta.http_path) matches Upper('/dana-na/../dana/html5acc/guacamole/../../../../../../../[^?]+\\?/dana/html5acc/guacamole/')
|
||||
or
|
||||
Upper(evt.Meta.http_path) matches Upper('/dana-na/%2E%2E/dana/html5acc/guacamole/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/[^?]+\\?/dana/html5acc/guacamole/'))
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 2m
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
@@ -0,0 +1,12 @@
|
||||
type: trigger
|
||||
format: 2.0
|
||||
name: crowdsecurity/spring4shell_cve-2022-22965
|
||||
description: "Detect cve-2022-22965 probing"
|
||||
filter: |
|
||||
evt.Meta.log_type in ["http_access-log", "http_error-log"] and
|
||||
(Upper(evt.Meta.http_path) contains 'CLASS.MODULE.CLASSLOADER.')
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 2m
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
@@ -0,0 +1,32 @@
|
||||
# ssh bruteforce
|
||||
type: leaky
|
||||
name: crowdsecurity/ssh-bf
|
||||
description: "Detect ssh bruteforce"
|
||||
filter: "evt.Meta.log_type == 'ssh_failed-auth'"
|
||||
leakspeed: "10s"
|
||||
references:
|
||||
- http://wikipedia.com/ssh-bf-is-bad
|
||||
capacity: 5
|
||||
groupby: evt.Meta.source_ip
|
||||
blackhole: 1m
|
||||
reprocess: true
|
||||
labels:
|
||||
service: ssh
|
||||
type: bruteforce
|
||||
remediation: true
|
||||
---
|
||||
# ssh user-enum
|
||||
type: leaky
|
||||
name: crowdsecurity/ssh-bf_user-enum
|
||||
description: "Detect ssh user enum bruteforce"
|
||||
filter: evt.Meta.log_type == 'ssh_failed-auth'
|
||||
groupby: evt.Meta.source_ip
|
||||
distinct: evt.Meta.target_user
|
||||
leakspeed: 10s
|
||||
capacity: 5
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: ssh
|
||||
type: bruteforce
|
||||
remediation: true
|
||||
|
||||
@@ -0,0 +1,32 @@
|
||||
# ssh bruteforce
|
||||
type: leaky
|
||||
name: crowdsecurity/ssh-slow-bf
|
||||
description: "Detect slow ssh bruteforce"
|
||||
filter: "evt.Meta.log_type == 'ssh_failed-auth'"
|
||||
leakspeed: "60s"
|
||||
references:
|
||||
- http://wikipedia.com/ssh-bf-is-bad
|
||||
capacity: 10
|
||||
groupby: evt.Meta.source_ip
|
||||
blackhole: 1m
|
||||
reprocess: true
|
||||
labels:
|
||||
service: ssh
|
||||
type: bruteforce
|
||||
remediation: true
|
||||
---
|
||||
# ssh user-enum
|
||||
type: leaky
|
||||
name: crowdsecurity/ssh-slow-bf_user-enum
|
||||
description: "Detect slow ssh user enum bruteforce"
|
||||
filter: evt.Meta.log_type == 'ssh_failed-auth'
|
||||
groupby: evt.Meta.source_ip
|
||||
distinct: evt.Meta.target_user
|
||||
leakspeed: 60s
|
||||
capacity: 10
|
||||
blackhole: 1m
|
||||
labels:
|
||||
service: ssh
|
||||
type: bruteforce
|
||||
remediation: true
|
||||
|
||||
@@ -0,0 +1,16 @@
|
||||
type: trigger
|
||||
format: 2.0
|
||||
#debug: true
|
||||
name: crowdsecurity/thinkphp-cve-2018-20062
|
||||
description: "Detect ThinkPHP CVE-2018-20062 exploitation attemps"
|
||||
filter: |
|
||||
evt.Meta.log_type in ["http_access-log", "http_error-log"] and any(File("thinkphp_cve_2018-20062.txt"), {Upper(evt.Meta.http_path) matches Upper(#)})
|
||||
data:
|
||||
- source_url: https://raw.githubusercontent.com/crowdsecurity/sec-lists/master/web/thinkphp_cve_2018-20062.txt
|
||||
dest_file: thinkphp_cve_2018-20062.txt
|
||||
type: string
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 2m
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
@@ -0,0 +1,11 @@
|
||||
type: trigger
|
||||
format: 2.0
|
||||
name: crowdsecurity/vmware-cve-2022-22954
|
||||
description: "Detect Vmware CVE-2022-22954 exploitation attempts"
|
||||
filter: |
|
||||
evt.Meta.log_type in ['http_access-log', 'http_error-log'] && Upper(QueryUnescape(evt.Meta.http_path)) startsWith Upper('/catalog-portal/ui/oauth/verify?error=&deviceUdid=${"freemarker.template.utility.Execute"?new()(')
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 2m
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
@@ -0,0 +1,11 @@
|
||||
type: trigger
|
||||
format: 2.0
|
||||
name: crowdsecurity/vmware-vcenter-vmsa-2021-0027
|
||||
description: "Detect VMSA-2021-0027 exploitation attemps"
|
||||
filter: |
|
||||
evt.Meta.log_type in ['http_access-log', 'http_error-log'] && evt.Meta.http_path matches '/ui/vcav-bootstrap/rest/vcav-providers/provider-logo\\?url=(file|http)'
|
||||
groupby: "evt.Meta.source_ip"
|
||||
blackhole: 2m
|
||||
labels:
|
||||
type: exploit
|
||||
remediation: true
|
||||
@@ -0,0 +1,14 @@
|
||||
[coraza]
|
||||
spoe-agent coraza-agent
|
||||
messages coraza-req
|
||||
option var-prefix coraza
|
||||
option set-on-error error
|
||||
timeout hello 100ms
|
||||
timeout idle 2m
|
||||
timeout processing 500ms
|
||||
use-backend coraza-spoa
|
||||
|
||||
spoe-message coraza-req
|
||||
args app=var(txn.coraza.app) src-ip=src src-port=src_port dst-ip=dst dst-port=dst_port method=method path=path query=query version=req.ver headers=req.hdrs body=req.body
|
||||
event on-frontend-http-request
|
||||
|
||||
Binary file not shown.
Binary file not shown.
|
After Width: | Height: | Size: 60 MiB |
Binary file not shown.
@@ -0,0 +1,362 @@
|
||||
global
|
||||
log /dev/log local0
|
||||
log /dev/log local1 notice
|
||||
|
||||
# песочница
|
||||
# chroot /var/lib/haproxy
|
||||
|
||||
stats socket /run/haproxy/admin.sock mode 660 level admin
|
||||
stats timeout 30s
|
||||
|
||||
user haproxy
|
||||
group haproxy
|
||||
daemon
|
||||
|
||||
# Пути к сертификатам по умолчанию
|
||||
ca-base /etc/ssl/certs
|
||||
crt-base /etc/ssl/private
|
||||
|
||||
# See: https://ssl-config.mozilla.org/#server=haproxy&server-version=2.0.3&config=intermediate
|
||||
ssl-default-bind-ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384
|
||||
ssl-default-bind-ciphersuites TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256
|
||||
ssl-default-bind-options ssl-min-ver TLSv1.2 no-tls-tickets
|
||||
|
||||
# ВАЖНО: сохраняем TLS ClientHello для вычисления JA3/JA4/GREASE
|
||||
tune.ssl.capture-buffer-size 16384
|
||||
|
||||
# Корректная передача boolean-значений из HAProxy в Lua
|
||||
tune.lua.bool-sample-conversion normal
|
||||
|
||||
# Скрипты
|
||||
|
||||
# База по странам
|
||||
lua-load /etc/haproxy/lua/geoip_new2.lua
|
||||
|
||||
# База по ASN
|
||||
lua-load /etc/haproxy/lua/asn.lua
|
||||
|
||||
lua-load /etc/haproxy/lua/ja3n.lua
|
||||
lua-load /etc/haproxy/lua/ja4.lua
|
||||
lua-load /etc/haproxy/lua/grease_detect.lua
|
||||
|
||||
defaults
|
||||
log global
|
||||
|
||||
mode http
|
||||
option httplog
|
||||
option dontlognull
|
||||
|
||||
timeout http-request 10s
|
||||
timeout connect 5s
|
||||
timeout client 50s
|
||||
timeout server 50s
|
||||
|
||||
errorfile 400 /etc/haproxy/errors/400.http
|
||||
errorfile 403 /etc/haproxy/errors/403.http
|
||||
errorfile 408 /etc/haproxy/errors/408.http
|
||||
errorfile 500 /etc/haproxy/errors/500.http
|
||||
errorfile 502 /etc/haproxy/errors/502.http
|
||||
errorfile 503 /etc/haproxy/errors/503.http
|
||||
errorfile 504 /etc/haproxy/errors/504.http
|
||||
|
||||
backend coraza-spoa
|
||||
mode tcp
|
||||
server s1 127.0.0.1:9000
|
||||
|
||||
# --- ФРОНТЕНД (Прием трафика) ---
|
||||
frontend my_frontend
|
||||
mode http
|
||||
|
||||
# Слушаем обычный HTTP
|
||||
bind 185.137.233.123:80
|
||||
|
||||
# Слушаем HTTPS и указываем правильный путь к склеенному сертификату
|
||||
# Достаточно положить в папку crt /var/www/httpd-cert/haproxy/ .pem - слитый .crt и key
|
||||
bind 185.137.233.123:443 ssl crt /var/www/httpd-cert/haproxy/ alpn h2,http/1.1
|
||||
|
||||
# Исключаем Let's Encrypt. Чтобы было можно создавать SSL сертификаты
|
||||
acl is_letsencrypt path_beg /.well-known/acme-challenge/
|
||||
|
||||
# Перенаправление HTTP на HTTPS
|
||||
# Перенаправляем на https всех, кто пришел НЕ по защищенному соединению
|
||||
# http-request redirect scheme https unless { ssl_fc }
|
||||
http-request redirect scheme https if !{ ssl_fc } !is_letsencrypt
|
||||
|
||||
# Разрешаем доступ только если запросили именно наш домен
|
||||
acl is_valid_domain hdr(host) -i test.bratstvopera.ru kupidonia.ru www.kupidonia.ru passs.kupidonia.ru loba.kupidonia.ru nobobo.kupidonia.ru tishka.kupidonia.ru
|
||||
#acl is_valid_domain hdr(host) -i kupidonia.ru passs.kupidonia.ru loba.kupidonia.ru nobobo.kupidonia.ru
|
||||
|
||||
# Если домен чужой (или обращение по IP) - обрываем соединение без ответа
|
||||
http-request silent-drop if !is_valid_domain
|
||||
|
||||
# === ДОБАВЛЯЕМ РЕДИРЕКТ С WWW НА БЕЗ-WWW ===
|
||||
acl is_www hdr(host) -i www.kupidonia.ru
|
||||
http-request redirect prefix https://kupidonia.ru code 301 if is_www
|
||||
|
||||
# Разрешаем только стандартные методы
|
||||
acl allowed_methods method GET POST HEAD OPTIONS PUT DELETE
|
||||
http-request deny if !allowed_methods
|
||||
|
||||
# Или можно сделать точечный запрет на CONNECT и TRACE (используется для дебага)
|
||||
#http-request deny if { method CONNECT }
|
||||
#http-request deny if { method TRACE }
|
||||
|
||||
# Удаляем потенциально поддельные заголовки от клиента
|
||||
http-request del-header X-Forwarded-Proto
|
||||
|
||||
# Говорим Nginx'у, что клиент пришел по HTTPS (чтобы Nginx не делал лишних редиректов)
|
||||
http-request add-header X-Forwarded-Proto https if { ssl_fc }
|
||||
|
||||
# --- БЕЛЫЙ СПИСОК НАШИХ IP ---
|
||||
|
||||
# Загружаем список доверенных IP
|
||||
acl is_whitelisted_ip src -f /etc/haproxy/whitelists/whitelist-our-ips.txt
|
||||
|
||||
# Если IP в белом списке — пропускаем все проверки
|
||||
# Команда allow немедленно прекращает обработку правил для этого запроса и отправляет его дальше в бэкенд.
|
||||
http-request allow if is_whitelisted_ip
|
||||
|
||||
# --- БЛОКИРОВКА ПО СТРАНЕ ---
|
||||
|
||||
# 1. Вызываем lua-скрипт и сохраняем код страны посетителя
|
||||
http-request set-var(txn.country) lua.geoip_country
|
||||
|
||||
# 2. Создаем список стран для блокировки (через пробел)
|
||||
acl is_blocked_country var(txn.country) -m str -i CN IN VN SG KR ID HK TW TH MY PH PK TW BR NG EG MX AR SG ZA IR UY CL
|
||||
|
||||
# 3. Блокируем, если страна совпала со списком
|
||||
http-request deny if is_blocked_country !is_letsencrypt
|
||||
|
||||
# 4. Передаем эту переменную в заголовок X-Country для PHP
|
||||
http-request set-header X-Country %[var(txn.country)]
|
||||
|
||||
# --- БЛОКИРОВКА ПО ASN ---
|
||||
|
||||
# 1. Получаем номер ASN
|
||||
http-request set-var(txn.asn) lua.geoip_asn
|
||||
|
||||
# 2. Список плохих русских ASN (точное совпадение строк)
|
||||
acl is_blocked_asn var(txn.asn) -m str 9123 12555 50214 61178 214574 208969 35048 205090 213220
|
||||
# 2. Список плохих зарубежных ASN (точное совпадение строк)
|
||||
#acl is_blocked_asn var(txn.asn) -m str 9123 12555 50214 61178 214574 208969 35048 205090 213220
|
||||
|
||||
# 3. Блокируем, если совпало
|
||||
http-request deny if is_blocked_asn !is_letsencrypt
|
||||
|
||||
# 4. Передаем в PHP для проверки и статистики
|
||||
http-request set-header X-ASN %[var(txn.asn)]
|
||||
|
||||
# --- БЛОКИРОВКА ПО ИМЕНИ ПРОВАЙДЕРА (Хостинги и Дата-центры) ---
|
||||
|
||||
# 1. Получаем имя провайдера из базы
|
||||
http-request set-var(txn.asn_name) lua.geoip_asn_name
|
||||
|
||||
# 2. Проверяем имя на вхождение нежелательных подстрок (без учета регистра)
|
||||
# Флаг -m sub -i ищет подстроку, поэтому поймает "Amazon.com", "Hetzner Online GmbH" и т.д.
|
||||
acl is_blocked_provider var(txn.asn_name) -m sub -i Biterika WINDSTREAM HOSTING DigitalOcean Hetzner Amazon Linode Contabo EGIHOSTING
|
||||
|
||||
# 3. Блокируем, если провайдер из черного списка
|
||||
http-request deny if is_blocked_provider !is_letsencrypt
|
||||
|
||||
# 4. Передаем имя провайдера в PHP (для логов и проверки)
|
||||
http-request set-header X-ASN-Name %[var(txn.asn_name)]
|
||||
|
||||
# --- ПЕРЕДАЧА URL КУДА ИДЕТ ЧЕЛОВЕК --------------------
|
||||
|
||||
# Удаляем возможный поддельный заголовок, который мог прислать сам клиент
|
||||
http-request del-header X-Original-URL
|
||||
|
||||
# Кладём в заголовок реальный URL, по которому обратился пользователь
|
||||
http-request set-header X-Original-URL %[url]
|
||||
|
||||
# == ОТПРАВКА НА КАПЧУ ПО СТРАНЕ, REFERER И USER-AGENT ====================
|
||||
|
||||
# 1. Указываем, что правило работает ТОЛЬКО для kupidonia.ru (с www и без)
|
||||
acl is_main_kupidonia hdr(host) -i kupidonia.ru www.kupidonia.ru
|
||||
|
||||
# 2. Проверяем наличие заголовка Referer (true, если он есть)
|
||||
acl has_referer req.hdr(referer) -m found
|
||||
|
||||
# 3. Указываем саму страницу капчи, чтобы исключить её из правила (иначе будет цикл!)
|
||||
acl is_captcha_page path_beg /sorry
|
||||
|
||||
# 4. Исключаем статические файлы (картинки, стили, скрипты)
|
||||
acl is_static path_end -i .css .js .jpg .jpeg .png .gif .svg .ico .woff2 .webp .pdf
|
||||
|
||||
# 5. Ищем старые маки (Mac OS X 10.15 или 10_15)
|
||||
acl is_old_mac req.hdr(user-agent) -m sub -i "Mac OS X 10"
|
||||
|
||||
# 5. Ищем старые Android
|
||||
acl is_old_android req.hdr(user-agent) -m sub -i "Android 10"
|
||||
|
||||
# 6 Проверяем, что это Россия, Казахстан или Беларусь
|
||||
acl is_cis_country var(txn.country) -m str -i RU BY KZ
|
||||
|
||||
# 7. Исключаем запросы с параметром ysclid (метка Яндекса)
|
||||
# Проверяем, что ysclid= имеет непустое значение (хотя бы 1 символ после =)
|
||||
acl has_ysclid url -m reg -i "ysclid=[^&]+"
|
||||
|
||||
# 8. Исключаем поисковых роботов по белому списку
|
||||
acl is_whitelisted_bot src -f /etc/haproxy/whitelists/whitelist-bots.txt
|
||||
|
||||
# 9 ДЕЛАЕМ РЕДИРЕКТ (302 Временное перенаправление)
|
||||
# Правило 1: Старые Mac (всегда отправляем на капчу, кроме тех, у кого есть ysclid)
|
||||
http-request redirect location https://kupidonia.ru/sorry/pardon if is_main_kupidonia !has_referer !is_captcha_page !is_static !is_whitelisted_bot !has_ysclid is_old_mac
|
||||
|
||||
# Правило 2: Старые Android ТОЛЬКО если это НЕ Россия/Казахстан/Беларусь и НЕТ ysclid
|
||||
http-request redirect location https://kupidonia.ru/sorry/pardon if is_main_kupidonia !has_referer !is_captcha_page !is_static !is_whitelisted_bot !has_ysclid is_old_android !is_cis_country
|
||||
|
||||
# ------------------------------------------------------
|
||||
|
||||
# Удаляем информацию о веб-сервере и языке программирования
|
||||
http-response del-header Server
|
||||
http-response del-header X-Powered-By
|
||||
http-response del-header X-AspNet-Version
|
||||
|
||||
# Запрещаем встраивать сайт во фреймы на чужих доменах (защита от Clickjacking)
|
||||
#http-response set-header X-Frame-Options SAMEORIGIN
|
||||
|
||||
# Запрещаем браузеру пытаться "угадывать" тип файлов (защита от XSS через картинки)
|
||||
http-response set-header X-Content-Type-Options nosniff
|
||||
|
||||
# Принудительно заставляем браузеры всегда использовать HTTPS (HSTS), для поддоменов тоже
|
||||
#http-response set-header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
|
||||
# или строгий HTTPS только на основном домене (без поддоменов)
|
||||
#http-response set-header Strict-Transport-Security "max-age=86400"
|
||||
|
||||
# Жесткий контроль синтаксиса заголовков
|
||||
#option http-restrict-req-hdr-names preserve
|
||||
|
||||
# Вычисляем JA3N, JA4 и GREASE.
|
||||
# Данные ClientHello доступны благодаря
|
||||
# tune.ssl.capture-buffer-size в секции global.
|
||||
http-request lua.fingerprint_ja3n if { ssl_fc }
|
||||
http-request lua.ja4 if { ssl_fc }
|
||||
http-request set-var(txn.has_grease) lua.has_grease if { ssl_fc }
|
||||
|
||||
# Удаляем потенциально поддельные заголовки от клиента
|
||||
http-request del-header X-JA3-Hash
|
||||
http-request del-header X-JA3-String
|
||||
http-request del-header X-JA4-Fingerprint
|
||||
http-request del-header X-Has-Grease
|
||||
|
||||
# == ПРОВЕРКА REFERER И РЕДИРЕКТ НА КАПЧУ ====================
|
||||
|
||||
# 1. Указываем, что правило работает ТОЛЬКО для kupidonia.ru (с www и без)
|
||||
#acl is_main_kupidonia hdr(host) -i kupidonia.ru www.kupidonia.ru
|
||||
|
||||
# 2. Проверяем наличие заголовка Referer (true, если он есть)
|
||||
#acl has_referer req.hdr(referer) -m found
|
||||
|
||||
# 3. Указываем саму страницу капчи, чтобы исключить её из правила
|
||||
#acl is_captcha_page path_beg /sorry
|
||||
|
||||
# 4. Исключаем статические файлы
|
||||
#acl is_static path_end -i .css .js .jpg .jpeg .png .gif .svg .ico .woff2 .webp .pdf
|
||||
|
||||
# 5. ДЕЛАЕМ РЕДИРЕКТ (302 Временное перенаправление)
|
||||
#http-request redirect location /sorry if is_main_kupidonia !has_referer !is_captcha_page !is_static
|
||||
|
||||
# == ЗАЩИТА ГИТА =============================
|
||||
|
||||
# Ищем попытки скачать файл конфигурации .env (например: /.env или /api/.env)
|
||||
acl is_env_scan path_end .env
|
||||
|
||||
# Ищем директорию .git в любом месте пути (например: /.git/config или /assets/.git/)
|
||||
acl is_git_scan path_dir .git
|
||||
|
||||
# Молча сбрасываем (рвём TCP-соединение), если сработало хоть одно из условий
|
||||
http-request silent-drop if is_git_scan
|
||||
http-request silent-drop if is_env_scan
|
||||
|
||||
# ===============================
|
||||
|
||||
# Передаем вычисленные отпечатки
|
||||
http-request set-header X-JA3-Hash %[var(txn.fingerprint_ja3n)] if { ssl_fc }
|
||||
http-request set-header X-JA3-String %[var(txn.fingerprint_ja3n_raw)] if { ssl_fc }
|
||||
http-request set-header X-JA4-Fingerprint %[var(txn.ja4)] if { ssl_fc }
|
||||
http-request set-header X-Has-Grease %[var(txn.has_grease)] if { ssl_fc }
|
||||
|
||||
# Временный захват значений для журнала HAProxy.
|
||||
# После проверки эти четыре строки можно удалить.
|
||||
#http-request capture var(txn.fingerprint_ja3n) len 32 if { ssl_fc }
|
||||
#http-request capture var(txn.fingerprint_ja3n_raw) len 512 if { ssl_fc }
|
||||
#http-request capture var(txn.ja4) len 64 if { ssl_fc }
|
||||
#http-request capture var(txn.has_grease) len 1 if { ssl_fc }
|
||||
|
||||
# Подключение Coraza
|
||||
# Указываем имя приложения (как в name в config.yaml)
|
||||
http-request set-var(txn.coraza.app) str(sample_app)
|
||||
|
||||
# Отправляем запрос на проверку в SPOA
|
||||
filter spoe engine coraza config /etc/haproxy/coraza.cfg
|
||||
|
||||
# Блокируем запрос (выдаем 403), если Coraza обнаружила атаку
|
||||
http-request deny deny_status 403 if { var(txn.coraza.action) -m str deny } !is_letsencrypt
|
||||
|
||||
# == CAP ====================
|
||||
|
||||
# Ловим домен
|
||||
acl is_cap_host hdr(host) -i passs.kupidonia.ru kupidonia.ru nobobo.kupidonia.ru
|
||||
|
||||
# Ловим путь
|
||||
acl is_cap_path path_beg /cap/
|
||||
|
||||
# Если совпало и то, и другое — шлем в бэкенд капчи
|
||||
use_backend captcha_backend if is_cap_host is_cap_path
|
||||
|
||||
# == gitea ====================
|
||||
|
||||
# Ловим домен Gitea
|
||||
acl is_tishka_host hdr(host) -i tishka.kupidonia.ru
|
||||
|
||||
# Если это Let's Encrypt — отправляем в Nginx (где FastPanel создает проверочный файл)
|
||||
use_backend nginx_backend if is_tishka_host is_letsencrypt
|
||||
|
||||
# Весь остальной трафик Gitea отправляем в её бэкенд
|
||||
use_backend tishka_backend if is_tishka_host !is_letsencrypt
|
||||
|
||||
# ============================
|
||||
|
||||
# Отправляем в Nginx
|
||||
default_backend nginx_backend
|
||||
|
||||
# --- (Передача в Nginx) ---
|
||||
backend nginx_backend
|
||||
|
||||
# Если в очереди люди ждут дольше 10 секунд — отдаем им ошибку 503 (Сервер перегружен), чтобы не висели вечно
|
||||
timeout queue 60s
|
||||
|
||||
# Добавляем заголовок X-Forwarded-For с реальным IP клиента
|
||||
option forwardfor
|
||||
|
||||
# Указываем адрес Nginx (вы выбрали порт 8081) Пускаем на сайт не больше 400 одновременных активных запросов
|
||||
server nginx1 127.0.0.1:8081 check maxconn 400
|
||||
|
||||
# --- (Передача в Cap) ---
|
||||
|
||||
backend captcha_backend
|
||||
mode http
|
||||
|
||||
# Отрезаем /cap/ из пути, чтобы на порт 3000 ушел чистый запрос
|
||||
http-request replace-path /cap/(.*) /\1
|
||||
|
||||
# Передаем реальный IP
|
||||
option forwardfor
|
||||
http-request set-header X-Real-IP %[src]
|
||||
|
||||
# Отправляем на сервер с капчей
|
||||
server cap_node 127.0.0.1:3000 check
|
||||
|
||||
# --- (Передача в gitea) ---
|
||||
backend tishka_backend
|
||||
|
||||
mode http
|
||||
|
||||
# Передаем реальный IP
|
||||
option forwardfor
|
||||
http-request set-header X-Real-IP %[src]
|
||||
|
||||
# Отправляем на сервер с капчей
|
||||
server cap_node 127.0.0.1:3001 check
|
||||
|
||||
@@ -0,0 +1,26 @@
|
||||
local maxminddb = require("maxminddb")
|
||||
local db = maxminddb.open("/etc/haproxy/geo/GeoLite2-ASN.mmdb")
|
||||
|
||||
-- 1. Получаем номер ASN
|
||||
core.register_fetches("geoip_asn", function(txn)
|
||||
local client_ip = tostring(txn.f:src())
|
||||
if not client_ip then return "NO_IP" end
|
||||
local res = db:lookup(client_ip)
|
||||
if res then
|
||||
local asn = res:get("autonomous_system_number")
|
||||
if asn then return tostring(asn) end
|
||||
end
|
||||
return "UNKNOWN"
|
||||
end)
|
||||
|
||||
-- 2. Получаем имя провайдера (Organization)
|
||||
core.register_fetches("geoip_asn_name", function(txn)
|
||||
local client_ip = tostring(txn.f:src())
|
||||
if not client_ip then return "NO_IP" end
|
||||
local res = db:lookup(client_ip)
|
||||
if res then
|
||||
local org = res:get("autonomous_system_organization")
|
||||
if org then return tostring(org) end
|
||||
end
|
||||
return "UNKNOWN"
|
||||
end)
|
||||
@@ -0,0 +1,30 @@
|
||||
local maxminddb = require("maxminddb")
|
||||
local db = maxminddb.open("/etc/haproxy/geo/GeoLite2-City.mmdb")
|
||||
|
||||
core.register_fetches("geoip_country", function(txn)
|
||||
local client_ip = tostring(txn.f:src())
|
||||
if not client_ip then return "NO_IP" end
|
||||
|
||||
-- Получаем тот самый Си-объект (MMDB_lookup_result_s)
|
||||
local res, err = db:lookup(client_ip)
|
||||
|
||||
if err then return "ERR_" .. tostring(err) end
|
||||
|
||||
if res then
|
||||
-- ДОСТАЕМ КОД СТРАНЫ ИЗ СИ-ОБЪЕКТА
|
||||
-- Используем метод :get() с путем к нужному полю
|
||||
local iso_code, err2 = res:get("country", "iso_code")
|
||||
|
||||
if iso_code then
|
||||
return tostring(iso_code)
|
||||
end
|
||||
|
||||
-- Запасной вариант, если страна лежит в registered_country
|
||||
local reg_iso, err3 = res:get("registered_country", "iso_code")
|
||||
if reg_iso then
|
||||
return tostring(reg_iso)
|
||||
end
|
||||
end
|
||||
|
||||
return "UNKNOWN"
|
||||
end)
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user