AlteredCoder

42 posts

AlteredCoder

AlteredCoder

@kkado_sh

DevSecOps at @Crowd_Security

Katılım Şubat 2013
336 Takip Edilen24 Takipçiler
Mattia
Mattia@mattiapomelli·
We built the fastest way to vibe design mobile apps. From idea to screen designs in under 2 minutes. Export to code or @figma. Comment "sleek" for early access.
English
2.9K
432
6.5K
885K
AlteredCoder retweetledi
CrowdSec
CrowdSec@Crowd_Security·
🚨 CVE-2024-27292 exploitation campaign detected! (thread) What is the CVE-2024-27292 vulnerability? CVE-2024-27292 is a path traversal vulnerability in Docassemble. It allows unauthenticated attackers to access arbitrary files, such as /etc/passwd via specially crafted URL parameters. The root cause is improper sanitization of user-supplied inputs, making it possible for attackers to probe system-level files. Over the past few days, CrowdSec telemetry has identified a significant and accelerating wave of exploit attempts targeting the URI pattern: /interview?i=/etc/passwd. Docassembe is a free, open source expert system for guided interviews and document assembly, based on Python, YAML, and Markdown. This pattern aligns with an exploit attempt for CVE-2024-27292, a vulnerability disclosed in late 2024 affecting Docassemble (v1.4.53 to v1.4.96).
CrowdSec tweet media
English
1
3
5
411
AlteredCoder
AlteredCoder@kkado_sh·
One week ago, I added three CrowdSec Blocklists on a VPS running WordPress and NGINX. With the CrowdSec NGINX RC's stats feature, I was able to see how effective CrowdSec Blocklists are! In just a week, they blocked 70% of HTTP requests coming from malicious IPs. #crowdsec
AlteredCoder tweet media
English
0
2
5
183
AlteredCoder retweetledi
CrowdSec
CrowdSec@Crowd_Security·
Jumping from New York to Milan for some shopping? Within … 30 minutes? 🧐 That seems a bit sus, wouldn’t you agree? Follow this tutorial and learn how to use the new conditional feature to detect impossible travel 🌍 and other suspicious IP behaviors. hubs.ly/Q023bNWQ0
English
0
5
7
734
AlteredCoder
AlteredCoder@kkado_sh·
@THESMASHY Hello, what issues or errors did you face while upgrading crowdsec ? We are available on Discord if you need help debugging your crowdsec :) discord.gg/crowdsec
English
1
0
1
6
ᴍʀ.ꜱᴍᴀꜱʜʏ
ᴍʀ.ꜱᴍᴀꜱʜʏ@THESMASHY·
I had a bit of a hard time getting Crowdsec to run properly after I upgraded to Bullseye. I had to uninstall and reinstall basically everything, change a port for the local API. Now it runs though, I am not seeing IPs attacking my server in Logwatch emails. Proc is a bit higher.
English
1
0
0
58
AlteredCoder retweetledi
CrowdSec
CrowdSec@Crowd_Security·
🚨Pesky Forti auth bypass (CVE-2022-40684) is no match for CrowdSec! We just released a scenario to aid in detecting these attacks which you will find here 👉 hub.crowdsec.net/author/crowdse…
CrowdSec tweet media
English
1
6
9
0
AlteredCoder retweetledi
Loz
Loz@iiAmLoz·
@Crowd_Security The top 5 IP's are already blocked by @Crowd_Security community blocklist another is also stated but coverage of 6/10 based on IP reputation is great start to protecting your websites!
Loz tweet media
English
2
1
5
0
AlteredCoder retweetledi
CrowdSec
CrowdSec@Crowd_Security·
We are still looking for alpha testers of our Windows agent and bouncer, would love to hear your feedback! docs.crowdsec.net/docs/next/gett…
CrowdSec@Crowd_Security

🚨🪟 We’ve released an ALPHA version of our Windows port! It comes with a few #Windows-specific collections and a Windows Firewall bouncer. Check out the documentation on how to get started: docs.crowdsec.net/docs/next/gett… Feel free to share your feedback on Discord or in GitHub Issues.

English
0
7
12
0
AlteredCoder retweetledi
CrowdSec
CrowdSec@Crowd_Security·
The new version of the CrowdSec @nginx bouncer is out! It comes with stream mode support, reCAPTCHA v2, and more. Read our latest blog post for the full list of new features and how-to install tutorial 👇👇👇 crowdsec.net/blog/nginx-bou…
English
0
11
24
0
AlteredCoder retweetledi
CrowdSec
CrowdSec@Crowd_Security·
🎉 Yesterday, our community shared 1+ MILLION signals! 🎉 On one single day! The detection capabilities of CrowdSec are now growing exponentially. Our users exchange threat signal data with each other daily, generating the greatest CTI network. 🚀🚀🚀 Join Us! #CyberSecurity
CrowdSec tweet media
English
2
23
54
0
AlteredCoder retweetledi
CrowdSec
CrowdSec@Crowd_Security·
🚀Over this year, CrowdSec blocked 1+ MILLION malicious IPs. And is now used in 120+ countries and 2K+ locations.🥳 We thank our community of #opensource enthusiasts and inspired #CyberSecurity professionals for being here with us, outnumbering cybercriminals together!💪
CrowdSec tweet media
English
0
20
22
0
AlteredCoder retweetledi
CrowdSec
CrowdSec@Crowd_Security·
List of IP addresses exploiting the #log4j #CVE-2021-44228 vulnerability, as reported by our network. (Updated several time/day). Courtesy of the CrowdSec community. gist.github.com/blotus/f87ed46… Stay safe.
English
5
341
1.1K
0