Add etc/crowdsec/config.yaml

Add        etc/crowdsec/parsers/s02-enrich/bing-whitelist.yaml
Add        etc/crowdsec/parsers/s02-enrich/google-whitelist.yaml
Add        etc/crowdsec/parsers/s02-enrich/whitelist-our-ips.yaml
Add        etc/crowdsec/parsers/s02-enrich/whitelist-social.yaml
Add        etc/crowdsec/parsers/s02-enrich/yandex-whitelist.yaml
Add        etc/crowdsec/scenarios/0-ban-many-sorry.yaml
Add        etc/crowdsec/scenarios/0-ban-multiple-referers.disabled
Add        etc/crowdsec/scenarios/0-ban-smart-bot.disabled
Add        etc/crowdsec/scenarios/0-ban-sorry-from-search.disabled
Add        etc/crowdsec/scenarios/0-cap-all-clouds.yaml
Add        etc/crowdsec/scenarios/0-cap-asn-selectel.yaml
Add        etc/crowdsec/scenarios/0-cap-bad-asn.yaml
Add        etc/crowdsec/scenarios/0-cap-bad-other-asn-2.yaml
Add        etc/crowdsec/scenarios/0-cap-brousers.yaml
Add        etc/crowdsec/scenarios/0-cap-bukva.disabled
Add        etc/crowdsec/scenarios/0-cap-crossword-word.disabled
Add        etc/crowdsec/scenarios/0-cap-empty-asn.yaml
Add        etc/crowdsec/scenarios/0-cap-empty-referer.yaml
Add        etc/crowdsec/scenarios/0-cap-honeypot.yaml
Add        etc/crowdsec/scenarios/0-cap-http11.des
Add        etc/crowdsec/scenarios/0-cap-index-mobile.yaml
Add        etc/crowdsec/scenarios/0-cap-many-bukva.yaml
Add        etc/crowdsec/scenarios/0-cap-many-crossword-word.yaml
Add        etc/crowdsec/scenarios/0-cap-many-spisok.yaml
Add        etc/crowdsec/scenarios/0-cap-many-viktoriny.disabled
Add        etc/crowdsec/scenarios/0-cap-other-countries-asn.yaml
Add        etc/crowdsec/scenarios/0-cap-pikabu.ru.yaml
Add        etc/crowdsec/scenarios/0-cap-ru-asn.yaml
Add        etc/crowdsec/scenarios/0-cap-site-scan-30-10m.yaml
Add        etc/crowdsec/scenarios/0-cap-spisok.disabled
Add        etc/crowdsec/scenarios/0-cap-ukr-asn.yaml
Add        etc/crowdsec/scenarios/0-cap-unknown-country.yaml
Add        etc/crowdsec/scenarios/0-cap-ya-vk-clouds.yaml
Add        etc/crowdsec/scenarios/0-coraza-waf.yaml
Add        etc/crowdsec/scenarios/CVE-2017-9841.yaml
Add        etc/crowdsec/scenarios/CVE-2019-18935.yaml
Add        etc/crowdsec/scenarios/CVE-2022-26134.yaml
Add        etc/crowdsec/scenarios/CVE-2022-35914.yaml
Add        etc/crowdsec/scenarios/CVE-2022-37042.yaml
Add        etc/crowdsec/scenarios/CVE-2022-40684.yaml
Add        etc/crowdsec/scenarios/CVE-2022-41082.yaml
Add        etc/crowdsec/scenarios/CVE-2022-41697.yaml
Add        etc/crowdsec/scenarios/CVE-2022-42889.yaml
Add        etc/crowdsec/scenarios/CVE-2022-44877.yaml
Add        etc/crowdsec/scenarios/CVE-2022-46169.yaml
Add        etc/crowdsec/scenarios/CVE-2023-22515.yaml
Add        etc/crowdsec/scenarios/CVE-2023-22518.yaml
Add        etc/crowdsec/scenarios/CVE-2023-49103.yaml
Add        etc/crowdsec/scenarios/CVE-2024-0012.yaml
Add        etc/crowdsec/scenarios/CVE-2024-38475.yaml
Add        etc/crowdsec/scenarios/CVE-2024-9474.yaml
Add        etc/crowdsec/scenarios/apache_log4j2_cve-2021-44228.yaml
Add        etc/crowdsec/scenarios/disabled/0-ban-bad-ru-asn.disabled
Add        etc/crowdsec/scenarios/disabled/0-ban-countries.disabled
Add        etc/crowdsec/scenarios/disabled/0-ban-datacenters-by-name.disabled
Add        etc/crowdsec/scenarios/disabled/0-ban-dzen.disabled
Add        etc/crowdsec/scenarios/disabled/0-ban-saelmon-bot.disabled
Add        etc/crowdsec/scenarios/disabled/0-cap-countries.disabled
Add        etc/crowdsec/scenarios/disabled/0-cap-mailru.disabled
Add        etc/crowdsec/scenarios/f5-big-ip-cve-2020-5902.yaml
Add        etc/crowdsec/scenarios/fortinet-cve-2018-13379.yaml
Add        etc/crowdsec/scenarios/grafana-cve-2021-43798.yaml
Add        etc/crowdsec/scenarios/http-admin-interface-probing.yaml
Add        etc/crowdsec/scenarios/http-backdoors-attempts.yaml
Add        etc/crowdsec/scenarios/http-bad-user-agent.yaml
Add        etc/crowdsec/scenarios/http-crawl-non_statics.yaml
Add        etc/crowdsec/scenarios/http-cve-2021-41773.yaml
Add        etc/crowdsec/scenarios/http-cve-2021-42013.yaml
Add        etc/crowdsec/scenarios/http-cve-probing.yaml
Add        etc/crowdsec/scenarios/http-generic-bf.yaml
Add        etc/crowdsec/scenarios/http-generic-test.yaml
Add        etc/crowdsec/scenarios/http-open-proxy.yaml
Add        etc/crowdsec/scenarios/http-path-traversal-probing.yaml
Add        etc/crowdsec/scenarios/http-probing.yaml
Add        etc/crowdsec/scenarios/http-sap-interface-probing.yaml
Add        etc/crowdsec/scenarios/http-sensitive-files.yaml
Add        etc/crowdsec/scenarios/http-sqli-probing.yaml
Add        etc/crowdsec/scenarios/http-technology-probing.yaml
Add        etc/crowdsec/scenarios/http-w00tw00t.yaml
Add        etc/crowdsec/scenarios/http-wordpress-scan.yaml
Add        etc/crowdsec/scenarios/http-xss-probing.yaml
Add        etc/crowdsec/scenarios/jira_cve-2021-26086.yaml
Add        etc/crowdsec/scenarios/modsecurity.yaml
Add        etc/crowdsec/scenarios/netgear_rce.yaml
Add        etc/crowdsec/scenarios/nginx-req-limit-exceeded.yaml
Add        etc/crowdsec/scenarios/pulse-secure-sslvpn-cve-2019-11510.yaml
Add        etc/crowdsec/scenarios/spring4shell_cve-2022-22965.yaml
Add        etc/crowdsec/scenarios/ssh-bf.yaml
Add        etc/crowdsec/scenarios/ssh-slow-bf.yaml
Add        etc/crowdsec/scenarios/thinkphp-cve-2018-20062.yaml
Add        etc/crowdsec/scenarios/vmware-cve-2022-22954.yaml
Add        etc/crowdsec/scenarios/vmware-vcenter-vmsa-2021-0027.yaml
Add        etc/haproxy/coraza.cfg
Add        etc/haproxy/geo/GeoLite2-ASN.mmdb
Add        etc/haproxy/geo/GeoLite2-City.mmdb
Add        etc/haproxy/geo/GeoLite2-Country.mmdb
Add        etc/haproxy/haproxy.cfg
Add        etc/haproxy/lua/asn.lua
Add        etc/haproxy/lua/geoip_new2.lua
Add        etc/haproxy/lua/grease_detect.lua
Add        etc/haproxy/lua/ja3n.lua
Add        etc/haproxy/lua/ja4.lua
Add        etc/haproxy/update-whitelist.sh
Add        etc/haproxy/whitelists/whitelist-bots.txt
Add        etc/haproxy/whitelists/whitelist-manual.txt
Add        etc/haproxy/whitelists/whitelist-our-ips.txt
Add        etc/mysql/mysql.cnf
Add        etc/nginx/conf.d/99-fastpanel.conf
Add        etc/nginx/conf.d/block-bots.conf
Add        etc/nginx/conf.d/cloudflare.conf
Add        etc/nginx/conf.d/default.conf
Add        etc/nginx/conf.d/fastcgi-cache.conf
Add        etc/nginx/conf.d/parking.conf.disabled
Add        etc/nginx/conf.d/reuseport.conf.disabled
Add        etc/nginx/conf.d/searchbots.conf.disabled
Add        etc/nginx/conf.d/ssl.conf
Add        etc/nginx/conf.d/trust_haproxy.conf
Add        etc/nginx/fastpanel2-available/artegos/artegos.art.conf
Add        etc/nginx/fastpanel2-available/bratstvopera/test.bratstvopera.ru.conf
Add        etc/nginx/fastpanel2-available/kupidonia/kupidonia.ru.conf
Add        etc/nginx/fastpanel2-available/kupidonia/loba.kupidonia.ru.conf
Add        etc/nginx/fastpanel2-available/kupidonia/nobobo.kupidonia.ru.conf
Add        etc/nginx/fastpanel2-available/kupidonia/passs.kupidonia.ru.conf
Add        etc/nginx/fastpanel2-available/tishka/tishka.kupidonia.ru.conf
Add        etc/nginx/fastpanel2-includes/letsencrypt.conf
Add        etc/nginx/fastpanel2-sites/artegos/artegos.art.conf
Add        etc/nginx/fastpanel2-sites/artegos/artegos.art.includes
Add        etc/nginx/fastpanel2-sites/bratstvopera/test.bratstvopera.ru.conf
Add        etc/nginx/fastpanel2-sites/bratstvopera/test.bratstvopera.ru.includes
Add        etc/nginx/fastpanel2-sites/kupidonia/kupidonia.ru.conf
Add        etc/nginx/fastpanel2-sites/kupidonia/kupidonia.ru.includes
Add        etc/nginx/fastpanel2-sites/kupidonia/loba.kupidonia.ru.conf
Add        etc/nginx/fastpanel2-sites/kupidonia/loba.kupidonia.ru.includes
Add        etc/nginx/fastpanel2-sites/kupidonia/nobobo.kupidonia.ru.conf
Add        etc/nginx/fastpanel2-sites/kupidonia/nobobo.kupidonia.ru.includes
Add        etc/nginx/fastpanel2-sites/kupidonia/passs.kupidonia.ru.conf
Add        etc/nginx/fastpanel2-sites/kupidonia/passs.kupidonia.ru.includes
Add        etc/nginx/fastpanel2-sites/tishka/tishka.kupidonia.ru.conf
Add        etc/nginx/fastpanel2-sites/tishka/tishka.kupidonia.ru.includes
Add        etc/nginx/nginx.conf
This commit is contained in:
2026-08-18 17:45:28 +03:00
commit ce539ef0bc
141 changed files with 4591 additions and 0 deletions
+62
View File
@@ -0,0 +1,62 @@
common:
daemonize: true
log_media: file
log_level: info
log_dir: /var/log/
log_max_size: 20
compress_logs: true
log_max_files: 10
config_paths:
config_dir: /etc/crowdsec/
data_dir: /var/lib/crowdsec/data/
simulation_path: /etc/crowdsec/simulation.yaml
hub_dir: /etc/crowdsec/hub/
index_path: /etc/crowdsec/hub/.index.json
notification_dir: /etc/crowdsec/notifications/
plugin_dir: /usr/lib/crowdsec/plugins/
crowdsec_service:
#console_context_path: /etc/crowdsec/console/context.yaml
acquisition_path: /etc/crowdsec/acquis.yaml
acquisition_dir: /etc/crowdsec/acquis.d
parser_routines: 1
cscli:
output: human
color: auto
db_config:
log_level: info
type: sqlite
db_path: /var/lib/crowdsec/data/crowdsec.db
#max_open_conns: 100
#user:
#password:
#db_name:
#host:
#port:
flush:
max_items: 5000
max_age: 7d
plugin_config:
user: nobody # plugin process would be ran on behalf of this user
group: nogroup # plugin process would be ran on behalf of this group
api:
client:
insecure_skip_verify: false
credentials_path: /etc/crowdsec/local_api_credentials.yaml
server:
log_level: info
listen_uri: 127.0.0.1:8080
profiles_path: /etc/crowdsec/profiles.yaml
console_path: /etc/crowdsec/console.yaml
online_client: # Central API credentials (to push signals and receive bad IPs)
credentials_path: /etc/crowdsec/online_api_credentials.yaml
trusted_ips: # IP ranges, or IPs which can have admin API access
- 127.0.0.1
- ::1
# tls:
# cert_file: /etc/crowdsec/ssl/cert.pem
# key_file: /etc/crowdsec/ssl/key.pem
prometheus:
enabled: true
level: full
listen_addr: 127.0.0.1
listen_port: 6060
@@ -0,0 +1,33 @@
name: custom/bing-whitelist
description: "Strict Whitelist for Bingbot (Official API)"
whitelist:
reason: "Bingbot Official IP Ranges"
cidr:
- "157.55.39.0/24"
- "207.46.13.0/24"
- "40.77.167.0/24"
- "13.66.139.0/24"
- "13.66.144.0/24"
- "52.167.144.0/24"
- "13.67.10.16/28"
- "13.69.66.240/28"
- "13.71.172.224/28"
- "139.217.52.0/28"
- "191.233.204.224/28"
- "20.36.108.32/28"
- "20.43.120.16/28"
- "40.79.131.208/28"
- "40.79.186.176/28"
- "52.231.148.0/28"
- "20.79.107.240/28"
- "51.105.67.0/28"
- "20.125.163.80/28"
- "40.77.188.0/22"
- "65.55.210.0/24"
- "199.30.24.0/23"
- "40.77.202.0/24"
- "40.77.139.0/25"
- "20.74.197.0/28"
- "20.15.133.160/27"
- "40.77.177.0/24"
- "40.77.178.0/23"
@@ -0,0 +1,62 @@
name: custom/google-whitelist
description: "Strict Whitelist for Google Common Crawlers (Official API)"
whitelist:
reason: "Googlebot Official IP Ranges"
cidr:
# --- IPv4 подсети ---
- "192.178.4.0/27"
- "192.178.4.128/27"
- "192.178.4.160/27"
- "192.178.4.192/27"
- "192.178.4.224/27"
- "192.178.4.32/27"
- "192.178.4.64/27"
- "192.178.4.96/27"
- "192.178.5.0/27"
- "192.178.6.0/27"
- "192.178.6.128/27"
- "192.178.6.160/27"
- "192.178.6.192/27"
- "192.178.6.224/27"
- "192.178.6.32/27"
- "192.178.6.64/27"
- "192.178.6.96/27"
- "192.178.7.0/27"
- "192.178.7.128/27"
- "192.178.7.160/27"
- "192.178.7.192/27"
- "192.178.7.224/27"
- "192.178.7.32/27"
- "192.178.7.64/27"
- "192.178.7.96/27"
- "34.100.182.96/28"
- "34.101.50.144/28"
- "34.118.254.0/28"
- "34.118.66.0/28"
- "34.126.178.96/28"
- "34.146.150.144/28"
- "34.147.110.144/28"
- "34.151.74.144/28"
- "34.152.50.64/28"
- "34.154.114.144/28"
- "34.155.98.32/28"
- "34.165.18.176/28"
- "34.175.160.64/28"
- "34.176.130.16/28"
- "34.22.85.0/27"
- "34.64.82.64/28"
- "34.65.242.112/28"
- "34.80.50.80/28"
- "34.88.194.0/28"
- "34.89.10.80/28"
- "34.89.198.80/28"
- "34.96.162.48/28"
- "35.247.243.240/28"
- "66.249.64.0/19"
- "66.102.0.0/20"
- "74.125.0.0/16"
- "66.102.6.0/20"
- "66.249.64.0/20" # Я объединил все ваши мелкие 66.249.x.x в одну для скорости работы фаервола
# --- IPv6 подсети ---
- "2001:4860:4801::/48" # Я объединил все ваши мелкие IPv6 в одну официальную крупную подсеть
- "66.102.0.0/20" # <-- Добавлено для Google-Read-Aloud и других сервисов Google
@@ -0,0 +1,9 @@
name: kupidonia/whitelist_our_ips
description: "Our personal whitelist"
whitelist:
reason: "Admin IP addresses"
ip:
- "185.137.233.123"
- "91.206.14.87"
- "188.187.103.53" #odina
- "178.67.245.39" #allegory
@@ -0,0 +1,7 @@
name: kupidonia/whitelist_social
description: "My personal whitelist"
whitelist:
reason: "IP addresses of social networks"
ip:
- "95.142.199.181" #VK автопубликации
#- "54.236.1.1" #Пинтерест
@@ -0,0 +1,22 @@
name: custom/yandex-whitelist
description: "Whitelist for Yandex search engine bots"
whitelist:
reason: "Yandex bot IP"
cidr:
- "5.45.192.0/18"
- "5.255.192.0/18"
- "37.9.64.0/18"
- "37.140.128.0/18"
- "77.88.0.0/18"
- "84.252.160.0/19"
- "87.250.224.0/19"
- "90.156.176.0/20"
- "92.255.112.0/20"
- "93.158.128.0/18"
- "95.108.128.0/17"
- "141.8.128.0/18"
- "178.154.128.0/18"
- "185.32.187.0/24"
- "213.180.192.0/19"
- "2a02:6b8::/29"
- "45.138.0.0/24"
@@ -0,0 +1,38 @@
type: leaky
name: kupidonia/ban-many-sorry
description: "Detects bots stuck in a loop or aggressively scraping the /sorry page"
filter: "evt.Meta.log_type in ['http_access-log', 'http_error-log'] and evt.Parsed.request contains '/sorry'"
groupby: "evt.Meta.source_ip"
capacity: 6
leakspeed: "2s"
blackhole: 1m
labels:
service: http
type: scan
remediation: true
---
type: leaky
name: kupidonia/ban-many-sorry-8
description: "Ban bots stuck in a loop and blindly hitting the /sorry page"
filter: "evt.Meta.log_type == 'http_access-log' && evt.Meta.http_path contains '/sorry'"
groupby: "evt.Meta.source_ip"
capacity: 8
leakspeed: "1m"
blackhole: 5m
labels:
service: http
type: abuse
remediation: true
---
type: leaky
name: kupidonia/ban-slow-sorry
description: "Catch low and slow bots hitting /sorry over a long period"
filter: "evt.Meta.log_type in ['http_access-log', 'http_error-log'] and evt.Parsed.request contains '/sorry'"
groupby: "evt.Meta.source_ip"
capacity: 10
leakspeed: "30m"
blackhole: 15m
labels:
service: http
type: crawler
remediation: true
@@ -0,0 +1,103 @@
#cscli decisions list | grep "kupidonia/ban-smart-bot-"
#cscli decisions list | grep -E "ID|kupidonia/ban-smart-bot-"
type: leaky
name: kupidonia/ban-smart-bot-many-page-1
description: "Detects aggressive scraping through deep pagination"
filter: "evt.Meta.log_type == 'http_access-log' && evt.Parsed.request contains '/s/'"
groupby: "evt.Meta.source_ip"
capacity: 15
leakspeed: "30s"
blackhole: 10m
labels:
service: http
type: scan
remediation: true
---
type: leaky
name: kupidonia/ban-smart-bot-many-page-2
description: "Detects aggressive scraping through deep pagination"
filter: "evt.Meta.log_type == 'http_access-log' && evt.Parsed.request contains '/s/'"
groupby: "evt.Meta.source_ip"
capacity: 20
leakspeed: "1m"
blackhole: 10m
labels:
service: http
type: scan
remediation: true
---
type: leaky
name: kupidonia/ban-smart-bot-many-page-3
description: "Detects aggressive scraping through deep pagination"
filter: "evt.Meta.log_type == 'http_access-log' && evt.Parsed.request contains '/s/'"
groupby: "evt.Meta.source_ip"
capacity: 40
leakspeed: "160s"
blackhole: 10m
labels:
service: http
type: scan
remediation: true
---
type: leaky
name: kupidonia/ban-smart-bot-rotator-user-agent
description: "Detects IPs rotating multiple different User-Agents"
filter: "evt.Meta.log_type == 'http_access-log' && evt.Parsed.http_user_agent != ''"
groupby: "evt.Meta.source_ip"
distinct: "evt.Parsed.http_user_agent"
capacity: 6
leakspeed: "24h"
blackhole: "1h"
labels:
service: http
type: scraper
remediation: captcha
---
type: trigger
name: kupidonia/ban-smart-bot-wordpress-scanner
description: "Instantly bans IPs looking for WordPress specific files/paths"
# Ищем совпадения: в URL есть куски wp-admin, wp-login и т.д., или xmlrpc.php
filter: "evt.Meta.log_type == 'http_access-log' && (evt.Parsed.request matches '(?i).*wp-(admin|login|content|includes|config).*' || evt.Parsed.request contains 'xmlrpc.php')"
groupby: "evt.Meta.source_ip"
blackhole: "1h"
labels:
service: http
type: exploit
remediation: ban
---
type: leaky
name: kupidonia/ban-smart-bot-many-404
description: "Detects IPs generating too many 404 Not Found errors"
filter: 'evt.Meta.log_type == "http_access-log" && evt.Parsed.status == "404" && not (evt.Parsed.request matches "(?i)\\.(jpg|jpeg|png|gif|css|js|ico|webp|svg|woff2?)(\\?.*)?$")'
groupby: "evt.Meta.source_ip"
capacity: 20
leakspeed: "10s"
blackhole: "1h"
labels:
service: http
type: scan
remediation: ban
---
type: trigger
name: kupidonia/cap-mac-chrome146
description: "Send fake Mac OS + Chrome 146 bots to CAPTCHA"
filter: evt.Meta.service == 'http' and evt.Parsed.http_user_agent contains 'Mac OS X 10_15_7' and (evt.Parsed.http_user_agent contains 'Chrome/146.0.0.0' or evt.Parsed.http_user_agent contains 'Chrome/148.0.0.0')
groupby: evt.Meta.source_ip
blackhole: 2m
labels:
service: http
type: antispam
remediation: captcha
---
type: trigger
name: custom/captcha-all-mac10-15-7
description: "Send ALL Mac OS X 10_15_7 traffic to CAPTCHA"
filter: >
evt.Meta.service == 'http' and
evt.Parsed.http_user_agent contains 'Mac OS X 10_15_7'
groupby: evt.Meta.source_ip
blackhole: 2m
labels:
service: http
type: antispam
remediation: captcha
@@ -0,0 +1,16 @@
type: trigger
name: kupidonia/ban-sorry-from-search
description: "/sorry from search"
filter: >
evt.Meta.log_type == 'http_access-log' and
evt.Parsed.request startsWith '/sorry' and
(evt.Parsed.http_referer contains 'yandex.ru' or
evt.Parsed.http_referer contains 'google.ru' or
evt.Parsed.http_referer contains 'google.com' or
evt.Parsed.http_referer contains 'bing.ru' or
evt.Parsed.http_referer contains 'bing.com' or
evt.Parsed.http_referer contains 'dzen.ru')
labels:
service: http
type: bot
remediation: true
@@ -0,0 +1,10 @@
type: trigger
name: kupidonia/cap-all-clouds
description: "Instant captcha for ANY provider with Cloud in ASOrg name"
filter: "evt.Meta.log_type == 'http_access-log' && evt.Enriched.ASOrg matches '(?i)cloud'"
groupby: "evt.Meta.source_ip"
blackhole: 1m
labels:
service: http
type: captcha
remediation: true
@@ -0,0 +1,10 @@
type: trigger
name: kupidonia/cap-asn-selectel
description: "Instant captcha for datacenter ASNs of Selectel"
filter: "evt.Meta.log_type == 'http_access-log' && evt.Enriched.ASNNumber in ['49505', '50340', '61976', '60084', '50149']"
groupby: "evt.Meta.source_ip"
blackhole: 1m
labels:
service: http
type: captcha
remediation: true
+10
View File
@@ -0,0 +1,10 @@
type: trigger
name: kupidonia/cap-bad-asn
description: "Instant captcha for datacenter ASNs"
filter: "evt.Meta.log_type == 'http_access-log' && evt.Enriched.ASNNumber in ['3209','200373','44964','16509', '213220', '396982', '19318', '51167', '47583', '14061', '394380', '393406', '202018', '24940', '213230', '2119', '197540', '24961', '16276', '137539', '35540', '63949', '20473', '45102', '37963', '132203', '45090', '8075', '205090', '12695', '50867', '48614', '44559', '9123', '44112', '197695', '197397', '41668', '48287', '197327', '44133', '50952', '49981', '50465', '39798', '42722', '17727', '138950', '214574', '9318', '55967', '36907', '36907', '150436', '55990', '136907', '45899', '17754', '55862', '4837', '209641', '26548', '7552', '9658', '28169', '4787', '4787', '263553', '208137', '212238', '23724', '271240', '270832', '268418', '52871', '8452', '8167', '28202', '61668']"
groupby: "evt.Meta.source_ip"
blackhole: 1m
labels:
service: http
type: captcha
remediation: true
@@ -0,0 +1,10 @@
type: trigger
name: kupidonia/cap-bad-other-asn-2
description: "Instant captcha for datacenter ASNs"
filter: "evt.Enriched.ASNNumber in ['11556', '202991', '48614', '21001', '264750', '62240', '5384', '24691', '35916', '55933', '24691', '262638', '15169', '45090', '132203', '209854', '39238', '4249', '16276', '26548', '24940', '398781', '200373', '36924', '15169', '14061', '396982', '9808', '4134', '54994', '7029']"
groupby: "evt.Meta.source_ip"
blackhole: 1m
labels:
service: http
type: ban
remediation: true
@@ -0,0 +1,56 @@
type: trigger
name: kupidonia/cap-bot-android10-chrome
description: "Instant captcha for bots using Android 10 with Mobile Chrome 149/150/151"
filter: "evt.Meta.service == 'http' and evt.Parsed.http_user_agent contains 'Android 10' and evt.Parsed.http_user_agent contains 'Mobile' and (evt.Parsed.http_user_agent contains 'Chrome/148' or evt.Parsed.http_user_agent contains 'Chrome/149' or evt.Parsed.http_user_agent contains 'Chrome/150' or evt.Parsed.http_user_agent contains 'Chrome/151')"
groupby: evt.Meta.source_ip
blackhole: 1m
labels:
service: http
type: bot
remediation: captcha
---
type: leaky
name: kupidonia/ban-fast-quiz-solver
description: "Ban bots that submit quiz results too fast or too many times"
filter: "evt.Meta.service == 'http' and evt.Parsed.request contains '/viktoriny-result/' and evt.Parsed.verb == 'POST'"
groupby: evt.Meta.source_ip
leakspeed: 3m
capacity: 10
blackhole: 30m
labels:
service: http
type: bot
remediation: ban
---
type: trigger
name: kupidonia/ban-smart-bot-android10
description: "Instant ban for bot using Android 10 submitting quiz results"
filter: "evt.Meta.service == 'http' and evt.Parsed.request contains '/viktoriny-result/' and evt.Parsed.verb == 'POST' and evt.Parsed.http_user_agent contains 'Android 10' and evt.Parsed.http_user_agent contains 'Mobile' and (evt.Parsed.http_user_agent contains 'Chrome/148' or evt.Parsed.http_user_agent contains 'Chrome/149' or evt.Parsed.http_user_agent contains 'Chrome/150')"
groupby: evt.Meta.source_ip
blackhole: 15m
labels:
service: http
type: bot
remediation: ban
---
type: trigger
name: kupidonia/cap-old-os
description: "Send ancient OS (Old Android, Win 7/8, Headless) to captcha"
filter: >
evt.Meta.service == 'http' and (
evt.Parsed.http_user_agent contains 'Android 7' or
evt.Parsed.http_user_agent contains 'Android 8' or
evt.Parsed.http_user_agent contains 'Android 9' or
evt.Parsed.http_user_agent contains 'Android 10' or
evt.Parsed.http_user_agent contains 'Android 11' or
evt.Parsed.http_user_agent contains 'Windows NT 6.1' or
evt.Parsed.http_user_agent contains 'Windows NT 6.2' or
evt.Parsed.http_user_agent contains 'Windows NT 6.3' or
evt.Parsed.http_user_agent contains 'HeadlessChrome'
)
groupby: evt.Meta.source_ip
blackhole: 2m
labels:
service: http
type: bot
remediation: captcha
@@ -0,0 +1,8 @@
type: trigger
name: kupidonia/cap-bukva
description: "Send users requesting /bukva/ to CAPTCHA"
filter: "evt.Meta.log_type == 'http_access-log' && evt.Meta.http_path contains '/bukva/'"
labels:
service: http
type: custom
remediation: true
@@ -0,0 +1,8 @@
type: trigger
name: kupidonia/cap-crossword-word
description: "Send users requesting /crossword-word/ to CAPTCHA"
filter: "evt.Meta.log_type == 'http_access-log' && evt.Meta.http_path contains '/crossword-word/'"
labels:
service: http
type: custom
remediation: true
@@ -0,0 +1,11 @@
type: trigger
name: kupidonia/cap-empty-asn
description: "Instant captcha for IPs with missing ASN"
# Проверяем, что это HTTP и поле ASN пустое (или равно нулю)
filter: "evt.Meta.service == 'http' and (evt.Enriched.ASNNumber == '' or evt.Enriched.ASNNumber == '0')"
groupby: evt.Meta.source_ip
blackhole: 1m
labels:
service: http
type: antispam
remediation: captcha
@@ -0,0 +1,10 @@
type: trigger
name: kupidonia/cap-empty-referer
description: "Instant captcha for empty referer"
filter: "evt.Meta.service == 'http' and (evt.Parsed.http_referer == '' or evt.Parsed.http_referer == '-')"
groupby: evt.Meta.source_ip
blackhole: 1m
labels:
service: http
type: antispam
remediation: captcha
@@ -0,0 +1,10 @@
type: trigger
name: kupidonia/cap-honeypot
description: "Detects dumb bots appending /indev to random URLs"
filter: "evt.Meta.log_type in ['http_access-log', 'http_error-log'] && evt.Parsed.request matches '^/.+/indev([/?].*)?$'"
groupby: evt.Meta.source_ip
blackhole: 1m
labels:
service: http
type: capcha
remediation: true
+8
View File
@@ -0,0 +1,8 @@
type: trigger
name: kupidonia/cap-http11
description: "Catches bots on HTTP/1.1 with fake modern User-Agent"
filter: "evt.Meta.log_type == 'http_access-log' and evt.Parsed.http_version in ['1.1', '1.0'] and evt.Parsed.http_user_agent matches 'Chrome/1[1-9][0-9]|Firefox/1[1-9][0-9]|OS 1[6-9]_|OS [2-9][0-9]_|Version/1[6-9]|Version/[2-9][0-9]'"
labels:
service: http
type: bot
remediation: captcha
@@ -0,0 +1,10 @@
type: trigger
name: kupidonia/cap-index-mobile
description: "Instant captcha for Android Chrome 149/150 coming from search to index"
filter: "evt.Meta.log_type == 'http_access-log' && evt.Parsed.request in ['/', '/index.php'] && evt.Parsed.http_referer matches '(?i)(google|yandex)' && evt.Parsed.http_user_agent matches '(?i)Android.*Chrome/(149|150).*Mobile'"
groupby: "evt.Meta.source_ip"
blackhole: 1m
labels:
service: http
type: captcha
remediation: true
@@ -0,0 +1,12 @@
type: leaky
name: kupidonia/cap-many-bukva
description: "Rate limit for /bukva/ and /bukv/ (catch slow scrapers)"
filter: "evt.Meta.log_type == 'http_access-log' and (evt.Parsed.request contains '/bukva/' or evt.Parsed.request contains '/bukv/')"
groupby: "evt.Meta.source_ip"
capacity: 15
leakspeed: "1m"
blackhole: "5m"
labels:
service: http
type: bruteforce
remediation: capcha
@@ -0,0 +1,12 @@
type: leaky
name: kupidonia/cap-many-crossword-word
description: "/crossword-word/ in url"
filter: "evt.Meta.log_type == 'http_access-log' and evt.Parsed.request contains '/crossword-word/'"
groupby: "evt.Meta.source_ip"
capacity: 15
leakspeed: "1m"
blackhole: "5m"
labels:
service: http
type: bruteforce
remediation: capcha
@@ -0,0 +1,25 @@
type: leaky
name: kupidonia/cap-many-spisok
description: "Rate limit for /spisok/ and /spiski/ (catch slow scrapers)"
filter: "evt.Meta.log_type == 'http_access-log' and (evt.Parsed.request contains '/spisok/' or evt.Parsed.request contains '/spiski/')"
groupby: "evt.Meta.source_ip"
capacity: 15
leakspeed: "1m"
blackhole: "5m"
labels:
service: http
type: bruteforce
remediation: capcha
---
type: leaky
name: kupidonia/cap-many-spisok-20
description: "Detects slow scrapers reading more than 20 /spisok/ pages per hour"
filter: "evt.Meta.log_type in ['http_access-log', 'http_error-log'] and evt.Parsed.request contains '/spisok/'"
groupby: "evt.Meta.source_ip"
capacity: 20
leakspeed: "3m"
blackhole: 15m
labels:
service: http
type: scraper
remediation: true
@@ -0,0 +1,12 @@
type: leaky
name: kupidonia/cap-many-viktoriny
description: "/viktoriny/"
filter: "evt.Meta.log_type == 'http_access-log' and evt.Parsed.request contains '/viktoriny/'"
groupby: "evt.Meta.source_ip"
capacity: 7
leakspeed: "7s"
blackhole: "1m"
labels:
service: http
type: bruteforce
remediation: capcha
@@ -0,0 +1,10 @@
type: trigger
name: kupidonia/cap-other-countries-asn
description: "Instant captcha for datacenter ASNs of other Countries"
filter: "evt.Meta.log_type == 'http_access-log' && evt.Enriched.ASNNumber in ['24940', '55286', '203020', '5503', '43395', '3257', '134450', '212238', '8452', '12312', '212283', '3209', '132203', '200373']"
groupby: "evt.Meta.source_ip"
blackhole: 1m
labels:
service: http
type: captcha
remediation: true
@@ -0,0 +1,13 @@
type: trigger
name: kupidonia/cap-pikabu
description: "Instant captcha for pikabu.ru links"
filter: |
evt.Meta.log_type == 'http_access-log' and
evt.Parsed.http_referer contains 'pikabu.ru' and
not (evt.Parsed.request matches '(?i).*\\.(css|js|jpg|jpeg|png|gif|webp|svg|ico|woff|woff2).*')
groupby: evt.Meta.source_ip
blackhole: 1m
labels:
service: http
type: antispam
remediation: captcha
+10
View File
@@ -0,0 +1,10 @@
type: trigger
name: kupidonia/cap-ru-asn
description: "Instant captcha for datacenter ASNs "
filter: "evt.Meta.log_type == 'http_access-log' && evt.Enriched.ASNNumber in ['13335', '199136', '213220', '208677', '60245', '207967', '41722', '43152', '61178', '48030', '29182', '35751','21051', '47764', '9123', '25532', '50867', '197695', '44112', '47385', '47595', '62082']"
groupby: "evt.Meta.source_ip"
blackhole: 1m
labels:
service: http
type: captcha
remediation: true
@@ -0,0 +1,12 @@
type: leaky
name: kupidonia/cap-site-scan-30-10m
description: "Crawling more than 30 pages in 10 minutes"
filter: "evt.Meta.log_type == 'http_access-log' and evt.Parsed.static_resource == 'false'"
groupby: "evt.Meta.source_ip"
capacity: 30
leakspeed: "20s"
blackhole: "1m"
labels:
service: http
type: scan
remediation: ban
@@ -0,0 +1,8 @@
type: trigger
name: kupidonia/cap-spisok
description: "Send users requesting /spisok/ to CAPTCHA"
filter: "evt.Meta.log_type == 'http_access-log' && evt.Meta.http_path contains '/spisok/'"
labels:
service: http
type: custom
remediation: true
+10
View File
@@ -0,0 +1,10 @@
type: trigger
name: kupidonia/cap-ukr-asn
description: "Instant captcha for datacenter ASNs of Ukraine"
filter: "evt.Meta.log_type == 'http_access-log' && evt.Enriched.ASNNumber in ['35381', '197327', '48031']"
groupby: "evt.Meta.source_ip"
blackhole: 1m
labels:
service: http
type: captcha
remediation: true
@@ -0,0 +1,10 @@
type: trigger
name: kupidonia/cap-unknown-country
description: "Send unknown countries to Captcha"
filter: "evt.Meta.source_ip != '' && evt.Meta.source_ip not in ['127.0.0.1', '::1'] && evt.Enriched.IsoCode == ''"
groupby: evt.Meta.source_ip
blackhole: 1m
labels:
service: http
type: geo-block
remediation: true
@@ -0,0 +1,10 @@
type: trigger
name: kupidonia/cap-ya-vk-clouds
description: "Instant captcha for Yandex.Cloud and VK Cloud by ASOrg name"
filter: "evt.Meta.log_type == 'http_access-log' && evt.Enriched.ASOrg matches '(?i)(yandex.*cloud|vk.*cloud|vk-as)'"
groupby: "evt.Meta.source_ip"
blackhole: 1m
labels:
service: http
type: captcha
remediation: true
+12
View File
@@ -0,0 +1,12 @@
#Block all from Coraza
type: trigger
name: custom/coraza-waf
description: "Ban immediately on Coraza WAF hits"
filter: "evt.Meta.log_type == 'modsecurity'"
groupby: "evt.Meta.source_ip"
blackhole: 1m
labels:
service: http
type: exploit
remediation: true
+21
View File
@@ -0,0 +1,21 @@
type: trigger
#debug: true
name: crowdsecurity/CVE-2017-9841
description: "Detect CVE-2017-9841 exploits"
filter: |
evt.Meta.log_type == 'http_access-log' &&
Lower(evt.Meta.http_path) endsWith 'util/php/eval-stdin.php'
blackhole: 1m
groupby: "evt.Meta.source_ip"
labels:
type: exploit
remediation: true
classification:
- attack.T1595
- attack.T1190
- cve.CVE-2017-9841
spoofable: 0
confidence: 3
behavior: "http:exploit"
label: "PHP Unit Test Framework CVE-2017-9841"
service: PHP
@@ -0,0 +1,20 @@
type: trigger
format: 2.0
name: crowdsecurity/CVE-2019-18935
description: "Detect Telerik CVE-2019-18935 exploitation attempts"
filter: |
evt.Meta.log_type in ['http_access-log', 'http_error-log'] && Upper(QueryUnescape(evt.Meta.http_path)) startsWith Upper('/Telerik.Web.UI.WebResource.axd?type=rau')
groupby: "evt.Meta.source_ip"
blackhole: 2m
labels:
type: exploit
remediation: true
classification:
- attack.T1595
- attack.T1190
- cve.CVE-2019-18935
spoofable: 0
confidence: 3
behavior: "http:exploit"
label: "Telerik CVE-2019-18935"
service: telerik
@@ -0,0 +1,10 @@
type: trigger
#debug: true
name: crowdsecurity/CVE-2022-26134
description: "Detect CVE-2022-26134 exploits"
filter: "Upper(PathUnescape(evt.Meta.http_path)) contains Upper('@java.lang.Runtime@getRuntime().exec(')"
blackhole: 1m
groupby: "evt.Meta.source_ip"
labels:
type: exploit
remediation: true
@@ -0,0 +1,10 @@
type: trigger
#debug: true
name: crowdsecurity/CVE-2022-35914
description: "Detect CVE-2022-35914 exploits"
filter: "Upper(evt.Meta.http_path) contains Upper('/vendor/htmlawed/htmlawed/htmLawedTest.php')"
blackhole: 1m
groupby: "evt.Meta.source_ip"
labels:
type: exploit
remediation: true
@@ -0,0 +1,18 @@
type: trigger
#debug: true
name: crowdsecurity/CVE-2022-37042
description: "Detect CVE-2022-37042 exploits"
filter: |
(
Upper(evt.Meta.http_path) contains Upper('/service/extension/backup/mboximport?account-name=admin&ow=2&no-switch=1&append=1') ||
Upper(evt.Meta.http_path) contains Upper('/service/extension/backup/mboximport?account-name=admin&account-status=1&ow=cmd')
)
and evt.Meta.http_status startsWith ('40') and
Upper(evt.Meta.http_verb) == 'POST'
blackhole: 2m
groupby: "evt.Meta.source_ip"
labels:
type: exploit
remediation: true
@@ -0,0 +1,11 @@
type: trigger
name: crowdsecurity/fortinet-cve-2022-40684
description: "Detect cve-2022-40684 exploitation attempts"
filter: |
evt.Meta.log_type in ["http_access-log", "http_error-log"] and
Upper(evt.Meta.http_path) startsWith Upper('/api/v2/cmdb/system/admin/') and Lower(evt.Parsed.http_user_agent) == 'report runner'
groupby: "evt.Meta.source_ip"
blackhole: 2m
labels:
type: exploit
remediation: true
@@ -0,0 +1,13 @@
type: trigger
#debug: true
name: crowdsecurity/CVE-2022-41082
description: "Detect CVE-2022-41082 exploits"
filter: |
Upper(evt.Meta.http_path) contains Upper('/autodiscover/autodiscover.json') &&
Upper(evt.Parsed.http_args) contains Upper('powershell')
blackhole: 1m
groupby: "evt.Meta.source_ip"
labels:
type: exploit
remediation: true
@@ -0,0 +1,14 @@
type: leaky
name: crowdsecurity/CVE-2022-41697
description: "Detect CVE-2022-41697 enumeration"
filter: |
Upper(evt.Meta.http_path) contains Upper('/ghost/api/admin/session') &&
Upper(evt.Parsed.verb) == 'POST' &&
evt.Meta.http_status == '404'
leakspeed: "10s"
capacity: 5
blackhole: 1m
groupby: "evt.Meta.source_ip"
labels:
type: exploit
remediation: true
@@ -0,0 +1,17 @@
type: trigger
#debug: true
name: crowdsecurity/CVE-2022-42889
description: "Detect CVE-2022-42889 exploits (Text4Shell)"
filter: |
Upper(PathUnescape(evt.Meta.http_path)) contains Upper('${script:javascript:java.lang.Runtime.getRuntime().exec(')
or
Upper(PathUnescape(evt.Meta.http_path)) contains Upper('${script:js:java.lang.Runtime.getRuntime().exec(')
or
Upper(PathUnescape(evt.Meta.http_path)) contains Upper('${url:UTF-8:')
or
Upper(PathUnescape(evt.Meta.http_path)) contains Upper('${dns:address|')
blackhole: 1m
groupby: "evt.Meta.source_ip"
labels:
type: exploit
remediation: true
@@ -0,0 +1,15 @@
type: trigger
#debug: true
name: crowdsecurity/CVE-2022-44877
description: "Detect CVE-2022-44877 exploits"
filter: |
Lower(evt.Meta.http_path) contains '/index.php' &&
Upper(evt.Parsed.verb) == 'POST' &&
evt.Meta.http_status == '302' &&
Lower(evt.Parsed.http_args) matches 'login=.*[$|%24][\\(|%28].*[\\)|%29]'
blackhole: 1m
groupby: "evt.Meta.source_ip"
labels:
type: exploit
remediation: true
@@ -0,0 +1,29 @@
type: leaky
name: crowdsecurity/CVE-2022-46169-bf
description: "Detect CVE-2022-46169 brute forcing"
filter: |
Upper(evt.Meta.http_path) contains Upper('/remote_agent.php') &&
Upper(evt.Parsed.verb) == 'GET' &&
Lower(evt.Parsed.http_args) contains 'host_id' &&
Lower(evt.Parsed.http_args) contains 'local_data_ids'
leakspeed: "10s"
capacity: 5
blackhole: 1m
groupby: "evt.Meta.source_ip"
labels:
type: exploit
remediation: true
---
type: trigger
name: crowdsecurity/CVE-2022-46169-cmd
description: "Detect CVE-2022-46169 cmd injection"
filter: |
Upper(evt.Meta.http_path) contains Upper('/remote_agent.php') &&
Upper(evt.Parsed.verb) == 'GET' &&
Lower(evt.Parsed.http_args) contains 'action=polldata' &&
Lower(evt.Parsed.http_args) matches 'poller_id=.*(;|%3b)'
blackhole: 1m
groupby: "evt.Meta.source_ip"
labels:
type: exploit
remediation: true
@@ -0,0 +1,22 @@
## CVE-2023-22515
type: trigger
name: crowdsecurity/CVE-2023-22515
description: "Detect CVE-2023-22515 exploitation"
filter: |
Lower(evt.Parsed.file_ext) == '.action' &&
(Lower(evt.Parsed.file_dir) contains '/setup' || Lower(evt.Parsed.file_frag) == 'server-info') &&
evt.Parsed.file_frag != nil
blackhole: 1m
groupby: "evt.Meta.source_ip"
labels:
type: exploit
remediation: true
classification:
- attack.T1595
- attack.T1190
- cve.CVE-2023-22515
spoofable: 0
confidence: 1
behavior: "http:exploit"
label: "Confluence CVE-2023-22515"
service: confluence
@@ -0,0 +1,21 @@
type: trigger
#debug: true
name: crowdsecurity/CVE-2023-22518
description: "Detect CVE-2023-22518 exploits"
filter: |
Upper(evt.Meta.http_path) contains Upper('/json/setup-restore.action') &&
Upper(evt.Parsed.verb) == 'POST'
blackhole: 1m
groupby: "evt.Meta.source_ip"
labels:
type: exploit
remediation: true
classification:
- attack.T1595
- attack.T1190
- cve.CVE-2023-22518
spoofable: 0
confidence: 1
behavior: "http:exploit"
label: "Atlassian Confluence Server CVE-2023-22518"
service: confluence
@@ -0,0 +1,20 @@
type: trigger
format: 2.0
name: crowdsecurity/CVE-2023-49103
description: "Detect owncloud CVE-2023-49103 exploitation attempts"
filter: |
evt.Meta.log_type in ['http_access-log', 'http_error-log'] && Lower(evt.Meta.http_path) contains '/owncloud/apps/graphapi/vendor/microsoft/microsoft-graph/tests/getphpinfo.php'
groupby: "evt.Meta.source_ip"
blackhole: 2m
labels:
type: exploit
remediation: true
classification:
- attack.T1595
- attack.T1190
- cve.CVE-2023-49103
spoofable: 1
confidence: 2
behavior: "http:exploit"
label: "ownCloud CVE-2023-49103"
service: owncloud
+23
View File
@@ -0,0 +1,23 @@
type: trigger
format: 2.0
name: crowdsecurity/CVE-2024-0012
description: "Detect CVE-2024-0012 exploitation attempts"
filter: |
let request = Lower(evt.Parsed.request);
evt.Meta.log_type in ['http_access-log', 'http_error-log'] &&
evt.Meta.http_status in ['404', '403'] &&
(request matches '/php/.*/\\.js\\.map' || request matches '/index.php/.*\\.js\\.map')
groupby: "evt.Meta.source_ip"
blackhole: 2m
labels:
type: exploit
remediation: true
classification:
- attack.T1595
- attack.T1190
- cve.CVE-2024-0012
confidence: 3
spoofable: 0
behavior: "http:exploit"
label: "CVE-2024-0012"
service: panos
@@ -0,0 +1,25 @@
type: leaky
format: 2.0
name: crowdsecurity/CVE-2024-38475
description: "Detect CVE-2024-38475 exploitation attempts"
filter: |
evt.Meta.log_type in ['http_access-log', 'http_error-log'] &&
evt.Meta.http_status in ['404', '403'] &&
Lower(evt.Parsed.request) endsWith '%3f'
groupby: "evt.Meta.source_ip"
distinct: "evt.Parsed.request"
capacity: 3
blackhole: 2m
leakspeed: 10s
labels:
type: exploit
remediation: true
classification:
- attack.T1595
- attack.T1190
- cve.CVE-2024-38475
confidence: 3
spoofable: 0
behavior: "http:exploit"
label: "CVE-2024-38475"
service: apache
+24
View File
@@ -0,0 +1,24 @@
type: trigger
format: 2.0
name: crowdsecurity/CVE-2024-9474
description: "Detect CVE-2024-9474 exploitation attempts"
filter: |
let request = Lower(evt.Parsed.request);
evt.Meta.log_type in ['http_access-log', 'http_error-log'] &&
evt.Meta.http_status in ['404', '403'] &&
evt.Meta.http_verb == 'POST' &&
request contains '/php/utils/createremoteappwebsession.php/watchtowr.js.map'
groupby: "evt.Meta.source_ip"
blackhole: 2m
labels:
type: exploit
remediation: true
classification:
- attack.T1595
- attack.T1190
- cve.CVE-2024-9474
confidence: 3
spoofable: 0
behavior: "http:exploit"
label: "CVE-2024-9474"
service: panos
@@ -0,0 +1,23 @@
type: trigger
format: 2.0
#debug: true
name: crowdsecurity/apache_log4j2_cve-2021-44228
description: "Detect cve-2021-44228 exploitation attemps"
filter: |
evt.Meta.log_type in ["http_access-log", "http_error-log"] and
(
any(File("log4j2_cve_2021_44228.txt"), { Upper(evt.Meta.http_path) contains Upper(#)})
or
any(File("log4j2_cve_2021_44228.txt"), { Upper(evt.Parsed.http_user_agent) contains Upper(#)})
or
any(File("log4j2_cve_2021_44228.txt"), { Upper(evt.Parsed.http_referer) contains Upper(#)})
)
data:
- source_url: https://raw.githubusercontent.com/crowdsecurity/sec-lists/master/web/log4j2_cve_2021_44228.txt
dest_file: log4j2_cve_2021_44228.txt
type: string
groupby: "evt.Meta.source_ip"
blackhole: 2m
labels:
type: exploit
remediation: true
@@ -0,0 +1,10 @@
type: trigger
name: kupidonia/ban-bad-ru-asn
description: "Instant ban for datacenter ASNs "
filter: "evt.Meta.log_type == 'http_access-log' && evt.Enriched.ASNNumber in ['9123', '12555', '50214', '61178', '214574', '208969', '35048', '205090', '213220']"
groupby: "evt.Meta.source_ip"
blackhole: 1m
labels:
service: http
type: ban
remediation: true
@@ -0,0 +1,9 @@
type: trigger
name: kupidonia/ban-countries
description: "Block traffic from countries"
filter: "evt.Enriched.IsoCode in ['CN', 'IN', 'VN', 'SG', 'KR', 'ID', 'HK', 'TW', 'TH', 'MY', 'PH', 'PK', 'TW', 'BR', 'NG', 'EG']"
groupby: evt.Meta.source_ip
blackhole: 1m
labels:
type: geo-block
remediation: true
@@ -0,0 +1,10 @@
type: trigger
name: kupidonia/ban-datacenters-by-name
description: "Instant ban for hosting and cloud providers"
filter: "'ASNOrg' in evt.Enriched and evt.Enriched.ASNOrg matches '(?i).*(Biterika|WINDSTREAM|HOSTING|DigitalOcean|Hetzner|Amazon|AMAZON|Linode|Contabo|EGIHOSTING).*'"
groupby: "evt.Meta.source_ip"
blackhole: 1m
labels:
service: http
type: ban
remediation: true
@@ -0,0 +1,14 @@
type: trigger
name: kupidonia/ban-dzen
description: "Block Dzen immediately except allowed URLs"
filter: |
evt.Meta.log_type == 'http_access-log' and
evt.Parsed.http_referer contains 'dzen.ru' and
!(evt.Parsed.request contains '/otvety-' or evt.Parsed.request contains '/ezhednevnyj-test' or evt.Parsed.request contains 'for-dzen') and
!(evt.Parsed.request matches '(?i).*\\.(css|js|jpg|jpeg|png|gif|webp|svg|ico|woff|woff2).*')
groupby: evt.Meta.source_ip
blackhole: 1m
labels:
service: http
type: ban
remediation: true
@@ -0,0 +1,10 @@
type: trigger
name: kupidonia/ban-saelmon-bot
description: "Мгновенный бан для бота saelmon"
filter: "evt.Meta.log_type == 'http_access-log' and evt.Parsed.http_user_agent contains 'saelmon'"
groupby: "evt.Meta.source_ip"
blackhole: "1m"
labels:
service: http
type: bot
remediation: true
@@ -0,0 +1,10 @@
type: trigger
name: kupidonia/cap-countries
description: "Send Germany traffic to Captcha"
filter: "evt.Enriched.IsoCode in ['JP', 'AD', 'AG', 'AI', 'AL', 'AT', 'AW', 'BA', 'BB', 'BE', 'BG', 'BL', 'BM', 'BS', 'BY', 'BZ', 'CA', 'CH', 'CL', 'CR', 'CU', 'CW', 'CY', 'CZ', 'DE', 'DK', 'DM', 'DO', 'EE', 'ES', 'FI', 'FR', 'GB', 'GD', 'GL', 'GP', 'GR', 'GT', 'HN', 'HR', 'HT', 'HU', 'IE', 'IS', 'IT', 'JM', 'KN', 'KY', 'LC', 'LI', 'LT', 'LU', 'LV', 'MC', 'MD', 'ME', 'MF', 'MK', 'MQ', 'MS', 'MT', 'MX', 'MY', 'NI', 'NL', 'NO', 'PA', 'PL', 'PM', 'PR', 'PT', 'RO', 'RS', 'SE', 'SI', 'SK', 'SM', 'SV', 'SX', 'TC', 'TT', 'UA', 'US', 'VA', 'VC', 'VG', 'VI']"
groupby: evt.Meta.source_ip
blackhole: 1m
labels:
service: http
type: geo-block
remediation: true
@@ -0,0 +1,13 @@
type: trigger
name: kupidonia/cap-mailru
description: "Instant captcha for mailru links"
filter: |
evt.Meta.log_type == 'http_access-log' and
evt.Parsed.http_referer contains 'mail.ru' and
not (evt.Parsed.request matches '(?i).*\\.(css|js|jpg|jpeg|png|gif|webp|svg|ico|woff|woff2).*')
groupby: evt.Meta.source_ip
blackhole: 1m
labels:
service: http
type: antispam
remediation: captcha
@@ -0,0 +1,16 @@
type: trigger
format: 2.0
name: crowdsecurity/f5-big-ip-cve-2020-5902
description: "Detect cve-2020-5902 exploitation attemps"
filter: |
evt.Meta.log_type in ["http_access-log", "http_error-log"] and
(
Upper(evt.Meta.http_path) matches Upper('/tmui/login.jsp/..;/tmui/[^.]+.jsp\\?(fileName|command|directoryPath|tabId)=')
or
Upper(evt.Meta.http_path) matches Upper('/tmui/login.jsp/%2E%2E;/tmui/[^.]+.jsp\\?(fileName|command|directoryPath|tabId)=')
)
groupby: "evt.Meta.source_ip"
blackhole: 2m
labels:
type: exploit
remediation: true
@@ -0,0 +1,12 @@
type: trigger
format: 2.0
name: crowdsecurity/fortinet-cve-2018-13379
description: "Detect cve-2018-13379 exploitation attemps"
filter: |
evt.Meta.log_type in ["http_access-log", "http_error-log"] and
Upper(evt.Meta.http_path) contains Upper('/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession')
groupby: "evt.Meta.source_ip"
blackhole: 2m
labels:
type: exploit
remediation: true
@@ -0,0 +1,14 @@
type: trigger
format: 2.0
name: crowdsecurity/grafana-cve-2021-43798
description: "Detect cve-2021-43798 exploitation attemps"
filter: |
evt.Meta.log_type in ["http_access-log", "http_error-log"] and
(Upper(evt.Meta.http_path) matches '/PUBLIC/PLUGINS/[^/]+/../[./]+/'
or
Upper(evt.Meta.http_path) matches '/PUBLIC/PLUGINS/[^/]+/%2E%2E/[%2E/]+/')
groupby: "evt.Meta.source_ip"
blackhole: 2m
labels:
type: exploit
remediation: true
@@ -0,0 +1,27 @@
type: leaky
#debug: true
name: crowdsecurity/http-admin-interface-probing
description: "Detect generic HTTP admin interface probing"
filter: |
evt.Meta.service == 'http' and
evt.Meta.log_type in ['http_access-log', 'http_error-log'] and
evt.Meta.http_status in ['404', '403'] and
any(File("admin_interfaces.txt"), { Lower(evt.Meta.http_path) contains #})
groupby: evt.Meta.source_ip
distinct: "evt.Meta.http_path"
data:
- source_url: https://hub-data.crowdsec.net/web/admin_interfaces.txt
dest_file: admin_interfaces.txt
type: string
capacity: 2
leakspeed: "10s"
blackhole: 1m
labels:
confidence: 3
spoofable: 0
classification:
- attack.T1595
behavior: "http:scan"
label: "HTTP Admin Interface Probing"
service: http
remediation: true
@@ -0,0 +1,18 @@
type: leaky
#debug: true
name: crowdsecurity/http-backdoors-attempts
description: "Detect attempt to common backdoors"
filter: 'evt.Meta.log_type in ["http_access-log", "http_error-log"] and any(File("backdoors.txt"), { evt.Parsed.file_name == #})'
groupby: "evt.Meta.source_ip"
distinct: evt.Parsed.file_name
data:
- source_url: https://raw.githubusercontent.com/crowdsecurity/sec-lists/master/web/backdoors.txt
dest_file: backdoors.txt
type: string
capacity: 1
leakspeed: 5s
blackhole: 5m
labels:
service: http
type: discovery
remediation: true
@@ -0,0 +1,17 @@
type: leaky
format: 2.0
#debug: true
name: crowdsecurity/http-bad-user-agent
description: "Detect bad user-agents"
filter: 'evt.Meta.log_type in ["http_access-log", "http_error-log"] && RegexpInFile(evt.Parsed.http_user_agent, "bad_user_agents.regex.txt")'
data:
- source_url: https://raw.githubusercontent.com/crowdsecurity/sec-lists/master/web/bad_user_agents.regex.txt
dest_file: bad_user_agents.regex.txt
type: regexp
capacity: 1
leakspeed: 1m
groupby: "evt.Meta.source_ip"
blackhole: 2m
labels:
type: scan
remediation: true
@@ -0,0 +1,16 @@
type: leaky
name: crowdsecurity/http-crawl-non_statics
description: "Detect aggressive crawl from single ip"
filter: "evt.Meta.log_type in ['http_access-log', 'http_error-log'] && evt.Parsed.static_ressource == 'false' && evt.Parsed.verb in ['GET', 'HEAD']"
distinct: "evt.Parsed.file_name"
leakspeed: 0.5s
capacity: 40
#debug: true
#this limits the memory cache (and event_sequences in output) to five events
cache_size: 5
groupby: "evt.Meta.source_ip + '/' + evt.Parsed.target_fqdn"
blackhole: 1m
labels:
service: http
type: crawl
remediation: true
@@ -0,0 +1,15 @@
type: trigger
format: 2.0
#debug: true
name: crowdsecurity/http-cve-2021-41773
description: "cve-2021-41773"
filter: |
evt.Meta.log_type in ["http_access-log", "http_error-log"] and
(Upper(evt.Meta.http_path) contains "/.%2E/.%2E/"
or
Upper(evt.Meta.http_path) contains "/%2E%2E/%2E%2E")
groupby: "evt.Meta.source_ip"
blackhole: 2m
labels:
type: scan
remediation: true
@@ -0,0 +1,14 @@
type: trigger
format: 2.0
#debug: true
#this is getting funny, it's the third patch on top of cve-2021-41773
name: crowdsecurity/http-cve-2021-42013
description: "cve-2021-42013"
filter: |
evt.Meta.log_type in ["http_access-log", "http_error-log"] and
Upper(evt.Meta.http_path) contains "/%%32%65%%32%65/"
groupby: "evt.Meta.source_ip"
blackhole: 2m
labels:
type: scan
remediation: true
@@ -0,0 +1,27 @@
type: trigger
name: crowdsecurity/http-cve-probing
description: "Detect generic HTTP cve probing"
filter: |
evt.Meta.service == 'http' and
evt.Meta.log_type in ['http_access-log', 'http_error-log'] and
evt.Meta.http_status in ['404', '403'] and
any(File("trendy_cves_uris.json"), {
evt.Meta.http_path contains JsonExtract(#, "uri") ? evt.SetMeta("cve", JsonExtract(#, "cve")) : false
})
groupby: evt.Meta.source_ip
distinct: "evt.Meta.http_path"
data:
#
- source_url: https://hub-data.crowdsec.net/web/trendy_cves_uris.json
dest_file: trendy_cves_uris.json
type: string
blackhole: 1m
labels:
confidence: 3
spoofable: 0
classification:
- attack.T1595
behavior: "http:scan"
label: "HTTP CVE Probing"
service: http
remediation: true
@@ -0,0 +1,44 @@
# 404 scan
type: leaky
#debug: true
name: crowdsecurity/http-generic-bf
description: "Detect generic http brute force"
filter: "evt.Meta.service == 'http' && evt.Meta.sub_type == 'auth_fail'"
groupby: evt.Meta.source_ip
capacity: 5
leakspeed: "10s"
blackhole: 1m
labels:
service: http
type: bf
remediation: true
---
# Generic 401 Authorization Errors
type: leaky
#debug: true
name: LePresidente/http-generic-401-bf
description: "Detect generic 401 Authorization error brute force"
filter: "evt.Meta.log_type == 'http_access-log' && evt.Parsed.verb == 'POST' && evt.Meta.http_status == '401'"
groupby: evt.Meta.source_ip
capacity: 5
leakspeed: "10s"
blackhole: 1m
labels:
service: http
type: bf
remediation: true
---
# Generic 403 Forbidden (Authorization) Errors
type: leaky
#debug: true
name: LePresidente/http-generic-403-bf
description: "Detect generic 403 Forbidden (Authorization) error brute force"
filter: "evt.Meta.log_type == 'http_access-log' && evt.Parsed.verb == 'POST' && evt.Meta.http_status == '403'"
groupby: evt.Meta.source_ip
capacity: 5
leakspeed: "10s"
blackhole: 1m
labels:
service: http
type: bf
remediation: true
@@ -0,0 +1,16 @@
# EICAR style scenario
# This scenario is used to test CrowdSec installation and configuration and doesn't generate any decisions.
type: trigger
name: crowdsecurity/http-generic-test
description: "Crowdsec Generic Test Scenario: basic HTTP trigger"
filter: evt.Meta.log_type in ["http_access-log", "http_error-log"] and
evt.Meta.http_path == "/crowdsec-test-NtktlJHV4TfBSK3wvlhiOBnl"
blackhole: 5m
groupby: "evt.Meta.source_ip"
labels:
confidence: 0
spoofable: 3
behavior: "http:test"
label: "CrowdSec Generic Test Scenario"
service: http
remediation: false
@@ -0,0 +1,10 @@
type: trigger
name: crowdsecurity/http-open-proxy
description: "Detect scan for open proxy"
#apache returns 405, nginx 400
filter: "evt.Meta.log_type == 'http_access-log' && evt.Meta.http_status in ['400','405'] && (evt.Parsed.verb == 'CONNECT' || evt.Parsed.request matches '^http[s]?://')"
blackhole: 2m
labels:
service: http
type: scan
remediation: true
@@ -0,0 +1,20 @@
# path traversal probing
type: leaky
#debug: true
name: crowdsecurity/http-path-traversal-probing
description: "Detect path traversal attempt"
filter: "evt.Meta.log_type in ['http_access-log', 'http_error-log'] && any(File('http_path_traversal.txt'),{evt.Meta.http_path contains #})"
data:
- source_url: https://raw.githubusercontent.com/crowdsecurity/sec-lists/master/web/path_traversal.txt
dest_file: http_path_traversal.txt
type: string
groupby: "evt.Meta.source_ip"
distinct: "evt.Meta.http_path"
capacity: 3
reprocess: true
leakspeed: 10s
blackhole: 2m
labels:
service: http
type: scan
remediation: true
+16
View File
@@ -0,0 +1,16 @@
# 404 scan
type: leaky
#debug: true
name: crowdsecurity/http-probing
description: "Detect site scanning/probing from a single ip"
filter: "evt.Meta.service == 'http' && evt.Meta.http_status in ['404', '403', '400'] && evt.Parsed.static_ressource == 'false'"
groupby: "evt.Meta.source_ip + '/' + evt.Parsed.target_fqdn"
distinct: "evt.Meta.http_path"
capacity: 10
reprocess: true
leakspeed: "10s"
blackhole: 5m
labels:
service: http
type: scan
remediation: true
@@ -0,0 +1,41 @@
type: leaky
#debug: true
name: crowdsecurity/http-sap-interface-probing
description: "Detect generic HTTP SAP interface probing"
filter: |
evt.Meta.service == 'http' and
evt.Meta.log_type in ['http_access-log', 'http_error-log'] and
evt.Meta.http_status in ['404', '403'] and (
let uri = Lower(evt.Meta.http_path);
uri contains "/sap/bc/gui/sap/its/webgui"
or uri contains "/irj/portal"
or uri contains "/sap/bc/"
or uri contains "/sap/bc/ui2/flp"
or uri contains "/sap/bc/ui5_ui5/"
or uri contains "/sap/opu/odata/"
or uri contains "/sap/bc/webdynpro/"
or uri contains "/sap/public/bc/"
or uri contains "/sap/public/info"
or uri contains "/sap/public/icf_info"
or uri contains "/sap/admin/publicicp/"
or uri contains "/sap/admin/public/"
or uri == "/nwa"
or uri contains "/webdynpro/dispatcher/sap.com/tc~sec~ume~wd~umeadmin/umeadminapp"
or uri contains "/sap/hana/xs/admin"
or uri contains "/sap/hana/xs/formlogin"
or uri contains "/irj/go/km/navigation"
)
groupby: evt.Meta.source_ip
leakspeed: "10s"
capacity: 1
distinct: evt.Meta.http_path
blackhole: 1m
labels:
confidence: 3
spoofable: 0
classification:
- attack.T1595
behavior: "http:scan"
label: "HTTP SAP Interface Probing"
service: http
remediation: true
@@ -0,0 +1,19 @@
type: leaky
format: 2.0
#debug: true
name: crowdsecurity/http-sensitive-files
description: "Detect attempt to access to sensitive files (.log, .db ..) or folders (.git)"
filter: 'evt.Meta.log_type in ["http_access-log", "http_error-log"] and any(File("sensitive_data.txt"), { evt.Parsed.request endsWith #})'
groupby: "evt.Meta.source_ip"
distinct: evt.Parsed.request
data:
- source_url: https://raw.githubusercontent.com/crowdsecurity/sec-lists/master/web/sensitive_data.txt
dest_file: sensitive_data.txt
type: string
capacity: 4
leakspeed: 5s
blackhole: 5m
labels:
service: http
type: discovery
remediation: true
@@ -0,0 +1,20 @@
type: leaky
#requires at least 2.0 because it's using the 'data' section and the 'Upper' expr helper
format: 2.0
name: crowdsecurity/http-sqli-probbing-detection
data:
- source_url: https://raw.githubusercontent.com/crowdsecurity/sec-lists/master/web/sqli_probe_patterns.txt
dest_file: sqli_probe_patterns.txt
type: string
description: "A scenario that detects SQL injection probing with minimal false positives"
filter: "evt.Meta.log_type in ['http_access-log', 'http_error-log'] && any(File('sqli_probe_patterns.txt'), {Upper(evt.Parsed.http_args) contains Upper(#)})"
groupby: evt.Meta.source_ip
capacity: 10
leakspeed: 1s
blackhole: 5m
#low false positives approach : we require distinct payloads to avoid false positives
distinct: evt.Parsed.http_args
labels:
service: http
type: sqli_probing
remediation: true
@@ -0,0 +1,27 @@
type: trigger
name: crowdsecurity/http-technology-probing
description: "Detect HTTP technology/vendor probing"
filter: |
if (evt.Meta.service == 'http' and
evt.Meta.log_type in ['http_access-log', 'http_error-log'] and
evt.Meta.http_status in ['404', '403'])
{
let target_technology = LookupFile(evt.Meta.http_path, "technology_probing.json");
target_technology != "" ? evt.SetMeta("target_technology", target_technology) : false
} else { false }
groupby: evt.Meta.source_ip
blackhole: 1m
data:
#
- dest_file: technology_probing.json
source_url: https://hub-data.crowdsec.net/web/technology_probing.json
type: map
labels:
confidence: 3
spoofable: 0
classification:
- attack.T1595
behavior: "http:scan"
label: "HTTP Technology Probing"
service: http
remediation: false
+12
View File
@@ -0,0 +1,12 @@
#contributed by ltsich
type: trigger
name: ltsich/http-w00tw00t
description: "detect w00tw00t"
debug: false
filter: "evt.Meta.log_type == 'http_access-log' && evt.Parsed.file_name contains 'w00tw00t.at.ISC.SANS.DFind'"
groupby: evt.Meta.source_ip
blackhole: 5m
labels:
service: http
type: scan
remediation: true
@@ -0,0 +1,22 @@
type: leaky
name: crowdsecurity/http-wordpress-scan
description: "Detect exploitation attempts against common WordPress endpoints"
filter: |
evt.Meta.service == 'http' and
evt.Meta.log_type in ['http_access-log', 'http_error-log'] and
evt.Meta.http_status in ['404', '403'] and
Lower(evt.Parsed.request) matches "(?i)(/wp-.*\\.php|/wp-content/plugins/.*\\.(txt|md))$"
groupby: evt.Meta.source_ip
distinct: evt.Parsed.request
capacity: 3
leakspeed: "10s"
blackhole: 5m
labels:
remediation: true
classification:
- attack.T1595
behavior: "http:scan"
label: "WordPress Vuln Hunting"
spoofable: 0
service: wordpress
confidence: 3
@@ -0,0 +1,20 @@
type: leaky
#requires at least 2.0 because it's using the 'data' section and the 'Upper' expr helper
format: 2.0
name: crowdsecurity/http-xss-probbing
data:
- source_url: https://raw.githubusercontent.com/crowdsecurity/sec-lists/master/web/xss_probe_patterns.txt
dest_file: xss_probe_patterns.txt
type: string
description: "A scenario that detects XSS probing with minimal false positives"
filter: "evt.Meta.log_type in ['http_access-log', 'http_error-log'] && any(File('xss_probe_patterns.txt'), {Upper(evt.Parsed.http_args) contains Upper(#)})"
groupby: evt.Meta.source_ip
capacity: 5
leakspeed: 1s
blackhole: 5m
#low false positives approach : we require distinct payloads to avoid false positives
distinct: evt.Parsed.http_args
labels:
service: http
type: xss_probing
remediation: true
@@ -0,0 +1,16 @@
type: trigger
format: 2.0
#debug: true
name: crowdsecurity/jira_cve-2021-26086
description: "Detect Atlassian Jira CVE-2021-26086 exploitation attemps"
filter: |
evt.Meta.log_type in ["http_access-log", "http_error-log"] and any(File("jira_cve_2021-26086.txt"), {Upper(evt.Meta.http_path) contains Upper(#)})
data:
- source_url: https://raw.githubusercontent.com/crowdsecurity/sec-lists/master/web/jira_cve_2021-26086.txt
dest_file: jira_cve_2021-26086.txt
type: string
groupby: "evt.Meta.source_ip"
blackhole: 2m
labels:
type: exploit
remediation: true
+18
View File
@@ -0,0 +1,18 @@
type: trigger
#debug: true
name: crowdsecurity/modsecurity
description: "Web exploitation via modsecurity"
#modsec for nginx only logs the numerical value of the severity
filter: evt.Meta.log_type == 'modsecurity' && (evt.Parsed.ruleseverity == 'CRITICAL' || evt.Parsed.ruleseverity == '2')
blackhole: 2m
groupby: evt.Meta.source_ip
labels:
remediation: true
classification:
- attack.T1595
- attack.T1190
behavior: "http:exploit"
label: "Modsecurity Alert"
spoofable: 0
confidence: 2
service: http
+21
View File
@@ -0,0 +1,21 @@
type: trigger
format: 2.0
name: crowdsecurity/netgear_rce
description: "Detect Netgear RCE DGN1000/DGN220 exploitation attempts"
filter: |
evt.Meta.log_type in ['http_access-log', 'http_error-log'] && Lower(QueryUnescape(evt.Meta.http_path)) startsWith Lower('/setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=')
groupby: "evt.Meta.source_ip"
blackhole: 2m
references:
- "https://www.exploit-db.com/exploits/25978"
labels:
confidence: 3
spoofable: 0
classification:
- attack.T1595
- attack.T1190
- cve.CVE-2024-12847
behavior: "http:exploit"
label: "Netgear RCE"
service: netgear
remediation: true
@@ -0,0 +1,13 @@
type: leaky
#debug: true
name: crowdsecurity/nginx-req-limit-exceeded
description: "Detects IPs which violate nginx's user set request limit."
filter: evt.Meta.sub_type == 'req_limit_exceeded'
leakspeed: "60s"
capacity: 5
groupby: evt.Meta.source_ip
blackhole: 5m
labels:
service: nginx
type: bruteforce
remediation: true
@@ -0,0 +1,14 @@
type: trigger
format: 2.0
name: crowdsecurity/pulse-secure-sslvpn-cve-2019-11510
description: "Detect cve-2019-11510 exploitation attemps"
filter: |
evt.Meta.log_type in ["http_access-log", "http_error-log"] and
(Upper(evt.Meta.http_path) matches Upper('/dana-na/../dana/html5acc/guacamole/../../../../../../../[^?]+\\?/dana/html5acc/guacamole/')
or
Upper(evt.Meta.http_path) matches Upper('/dana-na/%2E%2E/dana/html5acc/guacamole/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/[^?]+\\?/dana/html5acc/guacamole/'))
groupby: "evt.Meta.source_ip"
blackhole: 2m
labels:
type: exploit
remediation: true
@@ -0,0 +1,12 @@
type: trigger
format: 2.0
name: crowdsecurity/spring4shell_cve-2022-22965
description: "Detect cve-2022-22965 probing"
filter: |
evt.Meta.log_type in ["http_access-log", "http_error-log"] and
(Upper(evt.Meta.http_path) contains 'CLASS.MODULE.CLASSLOADER.')
groupby: "evt.Meta.source_ip"
blackhole: 2m
labels:
type: exploit
remediation: true
+32
View File
@@ -0,0 +1,32 @@
# ssh bruteforce
type: leaky
name: crowdsecurity/ssh-bf
description: "Detect ssh bruteforce"
filter: "evt.Meta.log_type == 'ssh_failed-auth'"
leakspeed: "10s"
references:
- http://wikipedia.com/ssh-bf-is-bad
capacity: 5
groupby: evt.Meta.source_ip
blackhole: 1m
reprocess: true
labels:
service: ssh
type: bruteforce
remediation: true
---
# ssh user-enum
type: leaky
name: crowdsecurity/ssh-bf_user-enum
description: "Detect ssh user enum bruteforce"
filter: evt.Meta.log_type == 'ssh_failed-auth'
groupby: evt.Meta.source_ip
distinct: evt.Meta.target_user
leakspeed: 10s
capacity: 5
blackhole: 1m
labels:
service: ssh
type: bruteforce
remediation: true
+32
View File
@@ -0,0 +1,32 @@
# ssh bruteforce
type: leaky
name: crowdsecurity/ssh-slow-bf
description: "Detect slow ssh bruteforce"
filter: "evt.Meta.log_type == 'ssh_failed-auth'"
leakspeed: "60s"
references:
- http://wikipedia.com/ssh-bf-is-bad
capacity: 10
groupby: evt.Meta.source_ip
blackhole: 1m
reprocess: true
labels:
service: ssh
type: bruteforce
remediation: true
---
# ssh user-enum
type: leaky
name: crowdsecurity/ssh-slow-bf_user-enum
description: "Detect slow ssh user enum bruteforce"
filter: evt.Meta.log_type == 'ssh_failed-auth'
groupby: evt.Meta.source_ip
distinct: evt.Meta.target_user
leakspeed: 60s
capacity: 10
blackhole: 1m
labels:
service: ssh
type: bruteforce
remediation: true
@@ -0,0 +1,16 @@
type: trigger
format: 2.0
#debug: true
name: crowdsecurity/thinkphp-cve-2018-20062
description: "Detect ThinkPHP CVE-2018-20062 exploitation attemps"
filter: |
evt.Meta.log_type in ["http_access-log", "http_error-log"] and any(File("thinkphp_cve_2018-20062.txt"), {Upper(evt.Meta.http_path) matches Upper(#)})
data:
- source_url: https://raw.githubusercontent.com/crowdsecurity/sec-lists/master/web/thinkphp_cve_2018-20062.txt
dest_file: thinkphp_cve_2018-20062.txt
type: string
groupby: "evt.Meta.source_ip"
blackhole: 2m
labels:
type: exploit
remediation: true
@@ -0,0 +1,11 @@
type: trigger
format: 2.0
name: crowdsecurity/vmware-cve-2022-22954
description: "Detect Vmware CVE-2022-22954 exploitation attempts"
filter: |
evt.Meta.log_type in ['http_access-log', 'http_error-log'] && Upper(QueryUnescape(evt.Meta.http_path)) startsWith Upper('/catalog-portal/ui/oauth/verify?error=&deviceUdid=${"freemarker.template.utility.Execute"?new()(')
groupby: "evt.Meta.source_ip"
blackhole: 2m
labels:
type: exploit
remediation: true
@@ -0,0 +1,11 @@
type: trigger
format: 2.0
name: crowdsecurity/vmware-vcenter-vmsa-2021-0027
description: "Detect VMSA-2021-0027 exploitation attemps"
filter: |
evt.Meta.log_type in ['http_access-log', 'http_error-log'] && evt.Meta.http_path matches '/ui/vcav-bootstrap/rest/vcav-providers/provider-logo\\?url=(file|http)'
groupby: "evt.Meta.source_ip"
blackhole: 2m
labels:
type: exploit
remediation: true
+14
View File
@@ -0,0 +1,14 @@
[coraza]
spoe-agent coraza-agent
messages coraza-req
option var-prefix coraza
option set-on-error error
timeout hello 100ms
timeout idle 2m
timeout processing 500ms
use-backend coraza-spoa
spoe-message coraza-req
args app=var(txn.coraza.app) src-ip=src src-port=src_port dst-ip=dst dst-port=dst_port method=method path=path query=query version=req.ver headers=req.hdrs body=req.body
event on-frontend-http-request
Binary file not shown.
Binary file not shown.

After

Width:  |  Height:  |  Size: 60 MiB

Binary file not shown.
+362
View File
@@ -0,0 +1,362 @@
global
log /dev/log local0
log /dev/log local1 notice
# песочница
# chroot /var/lib/haproxy
stats socket /run/haproxy/admin.sock mode 660 level admin
stats timeout 30s
user haproxy
group haproxy
daemon
# Пути к сертификатам по умолчанию
ca-base /etc/ssl/certs
crt-base /etc/ssl/private
# See: https://ssl-config.mozilla.org/#server=haproxy&server-version=2.0.3&config=intermediate
ssl-default-bind-ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384
ssl-default-bind-ciphersuites TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256
ssl-default-bind-options ssl-min-ver TLSv1.2 no-tls-tickets
# ВАЖНО: сохраняем TLS ClientHello для вычисления JA3/JA4/GREASE
tune.ssl.capture-buffer-size 16384
# Корректная передача boolean-значений из HAProxy в Lua
tune.lua.bool-sample-conversion normal
# Скрипты
# База по странам
lua-load /etc/haproxy/lua/geoip_new2.lua
# База по ASN
lua-load /etc/haproxy/lua/asn.lua
lua-load /etc/haproxy/lua/ja3n.lua
lua-load /etc/haproxy/lua/ja4.lua
lua-load /etc/haproxy/lua/grease_detect.lua
defaults
log global
mode http
option httplog
option dontlognull
timeout http-request 10s
timeout connect 5s
timeout client 50s
timeout server 50s
errorfile 400 /etc/haproxy/errors/400.http
errorfile 403 /etc/haproxy/errors/403.http
errorfile 408 /etc/haproxy/errors/408.http
errorfile 500 /etc/haproxy/errors/500.http
errorfile 502 /etc/haproxy/errors/502.http
errorfile 503 /etc/haproxy/errors/503.http
errorfile 504 /etc/haproxy/errors/504.http
backend coraza-spoa
mode tcp
server s1 127.0.0.1:9000
# --- ФРОНТЕНД (Прием трафика) ---
frontend my_frontend
mode http
# Слушаем обычный HTTP
bind 185.137.233.123:80
# Слушаем HTTPS и указываем правильный путь к склеенному сертификату
# Достаточно положить в папку crt /var/www/httpd-cert/haproxy/ .pem - слитый .crt и key
bind 185.137.233.123:443 ssl crt /var/www/httpd-cert/haproxy/ alpn h2,http/1.1
# Исключаем Let's Encrypt. Чтобы было можно создавать SSL сертификаты
acl is_letsencrypt path_beg /.well-known/acme-challenge/
# Перенаправление HTTP на HTTPS
# Перенаправляем на https всех, кто пришел НЕ по защищенному соединению
# http-request redirect scheme https unless { ssl_fc }
http-request redirect scheme https if !{ ssl_fc } !is_letsencrypt
# Разрешаем доступ только если запросили именно наш домен
acl is_valid_domain hdr(host) -i test.bratstvopera.ru kupidonia.ru www.kupidonia.ru passs.kupidonia.ru loba.kupidonia.ru nobobo.kupidonia.ru tishka.kupidonia.ru
#acl is_valid_domain hdr(host) -i kupidonia.ru passs.kupidonia.ru loba.kupidonia.ru nobobo.kupidonia.ru
# Если домен чужой (или обращение по IP) - обрываем соединение без ответа
http-request silent-drop if !is_valid_domain
# === ДОБАВЛЯЕМ РЕДИРЕКТ С WWW НА БЕЗ-WWW ===
acl is_www hdr(host) -i www.kupidonia.ru
http-request redirect prefix https://kupidonia.ru code 301 if is_www
# Разрешаем только стандартные методы
acl allowed_methods method GET POST HEAD OPTIONS PUT DELETE
http-request deny if !allowed_methods
# Или можно сделать точечный запрет на CONNECT и TRACE (используется для дебага)
#http-request deny if { method CONNECT }
#http-request deny if { method TRACE }
# Удаляем потенциально поддельные заголовки от клиента
http-request del-header X-Forwarded-Proto
# Говорим Nginx'у, что клиент пришел по HTTPS (чтобы Nginx не делал лишних редиректов)
http-request add-header X-Forwarded-Proto https if { ssl_fc }
# --- БЕЛЫЙ СПИСОК НАШИХ IP ---
# Загружаем список доверенных IP
acl is_whitelisted_ip src -f /etc/haproxy/whitelists/whitelist-our-ips.txt
# Если IP в белом списке — пропускаем все проверки
# Команда allow немедленно прекращает обработку правил для этого запроса и отправляет его дальше в бэкенд.
http-request allow if is_whitelisted_ip
# --- БЛОКИРОВКА ПО СТРАНЕ ---
# 1. Вызываем lua-скрипт и сохраняем код страны посетителя
http-request set-var(txn.country) lua.geoip_country
# 2. Создаем список стран для блокировки (через пробел)
acl is_blocked_country var(txn.country) -m str -i CN IN VN SG KR ID HK TW TH MY PH PK TW BR NG EG MX AR SG ZA IR UY CL
# 3. Блокируем, если страна совпала со списком
http-request deny if is_blocked_country !is_letsencrypt
# 4. Передаем эту переменную в заголовок X-Country для PHP
http-request set-header X-Country %[var(txn.country)]
# --- БЛОКИРОВКА ПО ASN ---
# 1. Получаем номер ASN
http-request set-var(txn.asn) lua.geoip_asn
# 2. Список плохих русских ASN (точное совпадение строк)
acl is_blocked_asn var(txn.asn) -m str 9123 12555 50214 61178 214574 208969 35048 205090 213220
# 2. Список плохих зарубежных ASN (точное совпадение строк)
#acl is_blocked_asn var(txn.asn) -m str 9123 12555 50214 61178 214574 208969 35048 205090 213220
# 3. Блокируем, если совпало
http-request deny if is_blocked_asn !is_letsencrypt
# 4. Передаем в PHP для проверки и статистики
http-request set-header X-ASN %[var(txn.asn)]
# --- БЛОКИРОВКА ПО ИМЕНИ ПРОВАЙДЕРА (Хостинги и Дата-центры) ---
# 1. Получаем имя провайдера из базы
http-request set-var(txn.asn_name) lua.geoip_asn_name
# 2. Проверяем имя на вхождение нежелательных подстрок (без учета регистра)
# Флаг -m sub -i ищет подстроку, поэтому поймает "Amazon.com", "Hetzner Online GmbH" и т.д.
acl is_blocked_provider var(txn.asn_name) -m sub -i Biterika WINDSTREAM HOSTING DigitalOcean Hetzner Amazon Linode Contabo EGIHOSTING
# 3. Блокируем, если провайдер из черного списка
http-request deny if is_blocked_provider !is_letsencrypt
# 4. Передаем имя провайдера в PHP (для логов и проверки)
http-request set-header X-ASN-Name %[var(txn.asn_name)]
# --- ПЕРЕДАЧА URL КУДА ИДЕТ ЧЕЛОВЕК --------------------
# Удаляем возможный поддельный заголовок, который мог прислать сам клиент
http-request del-header X-Original-URL
# Кладём в заголовок реальный URL, по которому обратился пользователь
http-request set-header X-Original-URL %[url]
# == ОТПРАВКА НА КАПЧУ ПО СТРАНЕ, REFERER И USER-AGENT ====================
# 1. Указываем, что правило работает ТОЛЬКО для kupidonia.ru (с www и без)
acl is_main_kupidonia hdr(host) -i kupidonia.ru www.kupidonia.ru
# 2. Проверяем наличие заголовка Referer (true, если он есть)
acl has_referer req.hdr(referer) -m found
# 3. Указываем саму страницу капчи, чтобы исключить её из правила (иначе будет цикл!)
acl is_captcha_page path_beg /sorry
# 4. Исключаем статические файлы (картинки, стили, скрипты)
acl is_static path_end -i .css .js .jpg .jpeg .png .gif .svg .ico .woff2 .webp .pdf
# 5. Ищем старые маки (Mac OS X 10.15 или 10_15)
acl is_old_mac req.hdr(user-agent) -m sub -i "Mac OS X 10"
# 5. Ищем старые Android
acl is_old_android req.hdr(user-agent) -m sub -i "Android 10"
# 6 Проверяем, что это Россия, Казахстан или Беларусь
acl is_cis_country var(txn.country) -m str -i RU BY KZ
# 7. Исключаем запросы с параметром ysclid (метка Яндекса)
# Проверяем, что ysclid= имеет непустое значение (хотя бы 1 символ после =)
acl has_ysclid url -m reg -i "ysclid=[^&]+"
# 8. Исключаем поисковых роботов по белому списку
acl is_whitelisted_bot src -f /etc/haproxy/whitelists/whitelist-bots.txt
# 9 ДЕЛАЕМ РЕДИРЕКТ (302 Временное перенаправление)
# Правило 1: Старые Mac (всегда отправляем на капчу, кроме тех, у кого есть ysclid)
http-request redirect location https://kupidonia.ru/sorry/pardon if is_main_kupidonia !has_referer !is_captcha_page !is_static !is_whitelisted_bot !has_ysclid is_old_mac
# Правило 2: Старые Android ТОЛЬКО если это НЕ Россия/Казахстан/Беларусь и НЕТ ysclid
http-request redirect location https://kupidonia.ru/sorry/pardon if is_main_kupidonia !has_referer !is_captcha_page !is_static !is_whitelisted_bot !has_ysclid is_old_android !is_cis_country
# ------------------------------------------------------
# Удаляем информацию о веб-сервере и языке программирования
http-response del-header Server
http-response del-header X-Powered-By
http-response del-header X-AspNet-Version
# Запрещаем встраивать сайт во фреймы на чужих доменах (защита от Clickjacking)
#http-response set-header X-Frame-Options SAMEORIGIN
# Запрещаем браузеру пытаться "угадывать" тип файлов (защита от XSS через картинки)
http-response set-header X-Content-Type-Options nosniff
# Принудительно заставляем браузеры всегда использовать HTTPS (HSTS), для поддоменов тоже
#http-response set-header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
# или строгий HTTPS только на основном домене (без поддоменов)
#http-response set-header Strict-Transport-Security "max-age=86400"
# Жесткий контроль синтаксиса заголовков
#option http-restrict-req-hdr-names preserve
# Вычисляем JA3N, JA4 и GREASE.
# Данные ClientHello доступны благодаря
# tune.ssl.capture-buffer-size в секции global.
http-request lua.fingerprint_ja3n if { ssl_fc }
http-request lua.ja4 if { ssl_fc }
http-request set-var(txn.has_grease) lua.has_grease if { ssl_fc }
# Удаляем потенциально поддельные заголовки от клиента
http-request del-header X-JA3-Hash
http-request del-header X-JA3-String
http-request del-header X-JA4-Fingerprint
http-request del-header X-Has-Grease
# == ПРОВЕРКА REFERER И РЕДИРЕКТ НА КАПЧУ ====================
# 1. Указываем, что правило работает ТОЛЬКО для kupidonia.ru (с www и без)
#acl is_main_kupidonia hdr(host) -i kupidonia.ru www.kupidonia.ru
# 2. Проверяем наличие заголовка Referer (true, если он есть)
#acl has_referer req.hdr(referer) -m found
# 3. Указываем саму страницу капчи, чтобы исключить её из правила
#acl is_captcha_page path_beg /sorry
# 4. Исключаем статические файлы
#acl is_static path_end -i .css .js .jpg .jpeg .png .gif .svg .ico .woff2 .webp .pdf
# 5. ДЕЛАЕМ РЕДИРЕКТ (302 Временное перенаправление)
#http-request redirect location /sorry if is_main_kupidonia !has_referer !is_captcha_page !is_static
# == ЗАЩИТА ГИТА =============================
# Ищем попытки скачать файл конфигурации .env (например: /.env или /api/.env)
acl is_env_scan path_end .env
# Ищем директорию .git в любом месте пути (например: /.git/config или /assets/.git/)
acl is_git_scan path_dir .git
# Молча сбрасываем (рвём TCP-соединение), если сработало хоть одно из условий
http-request silent-drop if is_git_scan
http-request silent-drop if is_env_scan
# ===============================
# Передаем вычисленные отпечатки
http-request set-header X-JA3-Hash %[var(txn.fingerprint_ja3n)] if { ssl_fc }
http-request set-header X-JA3-String %[var(txn.fingerprint_ja3n_raw)] if { ssl_fc }
http-request set-header X-JA4-Fingerprint %[var(txn.ja4)] if { ssl_fc }
http-request set-header X-Has-Grease %[var(txn.has_grease)] if { ssl_fc }
# Временный захват значений для журнала HAProxy.
# После проверки эти четыре строки можно удалить.
#http-request capture var(txn.fingerprint_ja3n) len 32 if { ssl_fc }
#http-request capture var(txn.fingerprint_ja3n_raw) len 512 if { ssl_fc }
#http-request capture var(txn.ja4) len 64 if { ssl_fc }
#http-request capture var(txn.has_grease) len 1 if { ssl_fc }
# Подключение Coraza
# Указываем имя приложения (как в name в config.yaml)
http-request set-var(txn.coraza.app) str(sample_app)
# Отправляем запрос на проверку в SPOA
filter spoe engine coraza config /etc/haproxy/coraza.cfg
# Блокируем запрос (выдаем 403), если Coraza обнаружила атаку
http-request deny deny_status 403 if { var(txn.coraza.action) -m str deny } !is_letsencrypt
# == CAP ====================
# Ловим домен
acl is_cap_host hdr(host) -i passs.kupidonia.ru kupidonia.ru nobobo.kupidonia.ru
# Ловим путь
acl is_cap_path path_beg /cap/
# Если совпало и то, и другое — шлем в бэкенд капчи
use_backend captcha_backend if is_cap_host is_cap_path
# == gitea ====================
# Ловим домен Gitea
acl is_tishka_host hdr(host) -i tishka.kupidonia.ru
# Если это Let's Encrypt — отправляем в Nginx (где FastPanel создает проверочный файл)
use_backend nginx_backend if is_tishka_host is_letsencrypt
# Весь остальной трафик Gitea отправляем в её бэкенд
use_backend tishka_backend if is_tishka_host !is_letsencrypt
# ============================
# Отправляем в Nginx
default_backend nginx_backend
# --- (Передача в Nginx) ---
backend nginx_backend
# Если в очереди люди ждут дольше 10 секунд — отдаем им ошибку 503 (Сервер перегружен), чтобы не висели вечно
timeout queue 60s
# Добавляем заголовок X-Forwarded-For с реальным IP клиента
option forwardfor
# Указываем адрес Nginx (вы выбрали порт 8081) Пускаем на сайт не больше 400 одновременных активных запросов
server nginx1 127.0.0.1:8081 check maxconn 400
# --- (Передача в Cap) ---
backend captcha_backend
mode http
# Отрезаем /cap/ из пути, чтобы на порт 3000 ушел чистый запрос
http-request replace-path /cap/(.*) /\1
# Передаем реальный IP
option forwardfor
http-request set-header X-Real-IP %[src]
# Отправляем на сервер с капчей
server cap_node 127.0.0.1:3000 check
# --- (Передача в gitea) ---
backend tishka_backend
mode http
# Передаем реальный IP
option forwardfor
http-request set-header X-Real-IP %[src]
# Отправляем на сервер с капчей
server cap_node 127.0.0.1:3001 check
+26
View File
@@ -0,0 +1,26 @@
local maxminddb = require("maxminddb")
local db = maxminddb.open("/etc/haproxy/geo/GeoLite2-ASN.mmdb")
-- 1. Получаем номер ASN
core.register_fetches("geoip_asn", function(txn)
local client_ip = tostring(txn.f:src())
if not client_ip then return "NO_IP" end
local res = db:lookup(client_ip)
if res then
local asn = res:get("autonomous_system_number")
if asn then return tostring(asn) end
end
return "UNKNOWN"
end)
-- 2. Получаем имя провайдера (Organization)
core.register_fetches("geoip_asn_name", function(txn)
local client_ip = tostring(txn.f:src())
if not client_ip then return "NO_IP" end
local res = db:lookup(client_ip)
if res then
local org = res:get("autonomous_system_organization")
if org then return tostring(org) end
end
return "UNKNOWN"
end)
+30
View File
@@ -0,0 +1,30 @@
local maxminddb = require("maxminddb")
local db = maxminddb.open("/etc/haproxy/geo/GeoLite2-City.mmdb")
core.register_fetches("geoip_country", function(txn)
local client_ip = tostring(txn.f:src())
if not client_ip then return "NO_IP" end
-- Получаем тот самый Си-объект (MMDB_lookup_result_s)
local res, err = db:lookup(client_ip)
if err then return "ERR_" .. tostring(err) end
if res then
-- ДОСТАЕМ КОД СТРАНЫ ИЗ СИ-ОБЪЕКТА
-- Используем метод :get() с путем к нужному полю
local iso_code, err2 = res:get("country", "iso_code")
if iso_code then
return tostring(iso_code)
end
-- Запасной вариант, если страна лежит в registered_country
local reg_iso, err3 = res:get("registered_country", "iso_code")
if reg_iso then
return tostring(reg_iso)
end
end
return "UNKNOWN"
end)

Some files were not shown because too many files have changed in this diff Show More