Compare commits
3
Commits
0229406ad6
..
1.10.2
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
880857a70a | ||
|
|
70bf539546 | ||
|
|
5dd38b7e49 |
@@ -36,10 +36,15 @@
|
|||||||
ansible.builtin.set_fact:
|
ansible.builtin.set_fact:
|
||||||
acquisd_list:
|
acquisd_list:
|
||||||
fw:
|
fw:
|
||||||
collection: "crowdsecurity/suricata"
|
collection:
|
||||||
|
- "crowdsecurity/suricata"
|
||||||
|
parser: []
|
||||||
config: "suricata.yaml"
|
config: "suricata.yaml"
|
||||||
auth:
|
auth:
|
||||||
collection: "crowdsecurity/caddy"
|
collection:
|
||||||
|
- "crowdsecurity/caddy"
|
||||||
|
parser:
|
||||||
|
- "crowdsecurity/nextcloud-whitelist"
|
||||||
config: "caddy.yaml"
|
config: "caddy.yaml"
|
||||||
|
|
||||||
- name: Deploy crowdsec-update service files
|
- name: Deploy crowdsec-update service files
|
||||||
@@ -181,7 +186,8 @@
|
|||||||
block:
|
block:
|
||||||
- name: Install crowdsec collection
|
- name: Install crowdsec collection
|
||||||
ansible.builtin.command:
|
ansible.builtin.command:
|
||||||
cmd: "cscli collections install {{ acquisd_list[node['name']]['collection'] }}"
|
cmd: "cscli collections install {{ item }}"
|
||||||
|
loop: "{{ acquisd_list[node['name']]['collection'] }}"
|
||||||
become: true
|
become: true
|
||||||
changed_when: "'overwrite' not in is_collection_installed.stderr"
|
changed_when: "'overwrite' not in is_collection_installed.stderr"
|
||||||
failed_when:
|
failed_when:
|
||||||
@@ -189,6 +195,17 @@
|
|||||||
- "'already installed' not in is_collection_installed.stderr"
|
- "'already installed' not in is_collection_installed.stderr"
|
||||||
register: "is_collection_installed"
|
register: "is_collection_installed"
|
||||||
|
|
||||||
|
- name: Install crowdsec parser
|
||||||
|
ansible.builtin.command:
|
||||||
|
cmd: "cscli parsers install {{ item }}"
|
||||||
|
loop: "{{ acquisd_list[node['name']]['parser'] }}"
|
||||||
|
become: true
|
||||||
|
changed_when: "'overwrite' not in is_parser_installed.stderr"
|
||||||
|
failed_when:
|
||||||
|
- is_parser_installed.rc != 0
|
||||||
|
- "'already installed' not in is_parser_installed.stderr"
|
||||||
|
register: "is_parser_installed"
|
||||||
|
|
||||||
- name: Create crowdsec acquis.d directory
|
- name: Create crowdsec acquis.d directory
|
||||||
ansible.builtin.file:
|
ansible.builtin.file:
|
||||||
path: "/etc/crowdsec/acquis.d"
|
path: "/etc/crowdsec/acquis.d"
|
||||||
|
|||||||
@@ -18,6 +18,4 @@ whitelist:
|
|||||||
- "evt.Meta.target_fqdn == '{{ services['immich']['domain']['public'] }}.{{ domain['public'] }}' && evt.Meta.http_path contains '/api/assets/' && evt.Meta.http_path contains '/thumbnail'"
|
- "evt.Meta.target_fqdn == '{{ services['immich']['domain']['public'] }}.{{ domain['public'] }}' && evt.Meta.http_path contains '/api/assets/' && evt.Meta.http_path contains '/thumbnail'"
|
||||||
# opencloud chunk request false positive
|
# opencloud chunk request false positive
|
||||||
- "evt.Meta.target_fqdn == '{{ services['opencloud']['domain']['public'] }}.{{ domain['public'] }}' && evt.Meta.http_path contains '/js/chunks/'"
|
- "evt.Meta.target_fqdn == '{{ services['opencloud']['domain']['public'] }}.{{ domain['public'] }}' && evt.Meta.http_path contains '/js/chunks/'"
|
||||||
# nextcloud chunk request false positive
|
|
||||||
- evt.Meta.target_fqdn == '{{ services['opencloud']['domain']['public'] }}.{{ domain['public'] }}' && evt.Meta.http_path contains '/apps/viewer/js/'
|
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|||||||
@@ -26,7 +26,7 @@
|
|||||||
- Access to fw
|
- Access to fw
|
||||||
- Check the ban list with `sudo cscli alerts list`
|
- Check the ban list with `sudo cscli alerts list`
|
||||||
- Read the ban case with `sudo cscli alerts inspect $NUMBER`
|
- Read the ban case with `sudo cscli alerts inspect $NUMBER`
|
||||||
- Add regex on whitelist
|
- Add expressions on whitelist
|
||||||
- evt.Meta.target_fqdn == '{{ services['actualbudget']['domain']['public'] }}.{{ domain['public'] }}' && evt.Meta.http_path contains '/data/migrations/'
|
- evt.Meta.target_fqdn == '{{ services['actualbudget']['domain']['public'] }}.{{ domain['public'] }}' && evt.Meta.http_path contains '/data/migrations/'
|
||||||
- Delete false positive decision
|
- Delete false positive decision
|
||||||
- Check false positive decision with `sudo cscli decision list`
|
- Check false positive decision with `sudo cscli decision list`
|
||||||
|
|||||||
@@ -25,8 +25,8 @@
|
|||||||
- Access to fw
|
- Access to fw
|
||||||
- Check the ban list with `sudo cscli alerts list`
|
- Check the ban list with `sudo cscli alerts list`
|
||||||
- Read the ban case with `sudo cscli alerts inspect $NUMBER`
|
- Read the ban case with `sudo cscli alerts inspect $NUMBER`
|
||||||
- Add regex on whitelist
|
- Add expressions on whitelist
|
||||||
- evt.Meta.target_fqdn == 'Immich.ilnmors.com' && evt.Meta.http_path contains '/api/assets/' && evt.Meta.http_path contains '/thumbnail'
|
- evt.Meta.target_fqdn == '{{ services['immich']['domain']['public'] }}.{{ domain['public'] }}' && evt.Meta.http_path contains '/api/assets/' && evt.Meta.http_path contains '/thumbnail'
|
||||||
- Delete false positive decision
|
- Delete false positive decision
|
||||||
- Check false positive decision with `sudo cscli decision list`
|
- Check false positive decision with `sudo cscli decision list`
|
||||||
- Delete false positive decision with `sudo cscli decision delete --id $ID`
|
- Delete false positive decision with `sudo cscli decision delete --id $ID`
|
||||||
|
|||||||
@@ -25,7 +25,7 @@
|
|||||||
- Access to fw
|
- Access to fw
|
||||||
- Check the ban list with `sudo cscli alerts list`
|
- Check the ban list with `sudo cscli alerts list`
|
||||||
- Read the ban case with `sudo cscli alerts inspect $NUMBER`
|
- Read the ban case with `sudo cscli alerts inspect $NUMBER`
|
||||||
- Add regex on whitelist
|
- Add expressions on whitelist
|
||||||
- evt.Meta.target_fqdn == '{{ services['opencloud']['domain']['public'] }}.{{ domain['public'] }}' && evt.Meta.http_path contains '/js/chunks/'
|
- evt.Meta.target_fqdn == '{{ services['opencloud']['domain']['public'] }}.{{ domain['public'] }}' && evt.Meta.http_path contains '/js/chunks/'
|
||||||
- Delete false positive decision
|
- Delete false positive decision
|
||||||
- Check false positive decision with `sudo cscli decision list`
|
- Check false positive decision with `sudo cscli decision list`
|
||||||
|
|||||||
@@ -14,20 +14,25 @@
|
|||||||
- fw ban users' IP address.
|
- fw ban users' IP address.
|
||||||
|
|
||||||
## Reason
|
## Reason
|
||||||
- Nextcloud uses chunks when clients uploads or download files to it.
|
- Nextcloud has a lot of workflows which can be caught from crowdsec
|
||||||
- LAPI decides a ban when a lot of chunks file is uploaded or downloaded from external devices.
|
|
||||||
- `crowdsecurity/http-crawl-non_statics`
|
|
||||||
|
|
||||||
## Timeline
|
## Timeline
|
||||||
- 2026-05-02: Release OpenCloud
|
- 2026-05-02: Release nextcloud
|
||||||
- 2026-05-02: Find the false positive case, and add whitelist
|
- 2026-05-02: Find the false positive case, and add whitelist
|
||||||
|
- 2026-05-03: Install crowdsecurity/nextcloud-whitelist parser
|
||||||
|
- 2026-05-03: Make previous expressions annotation
|
||||||
|
|
||||||
## Solution
|
## Solution
|
||||||
|
- Install crowdsecurity/nextcloud-whitelist on auth node
|
||||||
|
|
||||||
|
### Deprecated solution
|
||||||
- Access to fw
|
- Access to fw
|
||||||
- Check the ban list with `sudo cscli alerts list`
|
- Check the ban list with `sudo cscli alerts list`
|
||||||
- Read the ban case with `sudo cscli alerts inspect $NUMBER`
|
- Read the ban case with `sudo cscli alerts inspect $NUMBER`
|
||||||
- Add regex on whitelist
|
- Add expressions on whitelist
|
||||||
- evt.Meta.target_fcqdn == '{{ services['opencloud']['domain']['public'] }}.{{ domain['public'] }}' && evt.Meta.http_path contains '/apps/viewer/js/'
|
- evt.Meta.target_fqdn == '{{ services['nextcloud']['domain']['public'] }}.{{ domain['public'] }}' && evt.Meta.http_path contains '/apps/viewer/js/'
|
||||||
|
- evt.Meta.target_fqdn == '{{ services['nextcloud']['domain']['public'] }}.{{ domain['public'] }}' && evt.Meta.http_path contains '/dist/'
|
||||||
|
- evt.Meta.target_fqdn == '{{ services['nextcloud']['domain']['public'] }}.{{ domain['public'] }}' && evt.Meta.http_path contains '/remote.php/dav/files/'
|
||||||
- Delete false positive decision
|
- Delete false positive decision
|
||||||
- Check false positive decision with `sudo cscli decision list`
|
- Check false positive decision with `sudo cscli decision list`
|
||||||
- Delete false positive decision with `sudo cscli decision delete --id $ID`
|
- Delete false positive decision with `sudo cscli decision delete --id $ID`
|
||||||
|
|||||||
Reference in New Issue
Block a user