Code Monkey home page Code Monkey logo

Comments (8)

LaurenceJJones avatar LaurenceJJones commented on May 20, 2024 4

Hey, we @crowdsecurity also would like to add log parser / scenario support. The remediation, however, would purely up to you if you would like to implement we do have golang libraries if not user can use the firewall remediation but would not be effective if they use something like CF.

from zoraxy.

ahmedabokandil avatar ahmedabokandil commented on May 20, 2024 1

Hi @tobychui , thanks for your reply , but i will tell you why this important
when we enable basic authentication to protect an backend servers , if someone tried brute force attack to get password
we can block it using fail2ban , what do you think ?

from zoraxy.

ahmedabokandil avatar ahmedabokandil commented on May 20, 2024

yes totally agreed we need to integrate with fail2ban

from zoraxy.

tobychui avatar tobychui commented on May 20, 2024

Hi @ahmedabokandil, I am just wondering, why you need fail2ban in the first place?
It doesn't seems like it can stop DDOS, or improve security in web serving.
If you need further security features regarding access to the management panel (e.g. 2FA or password-less login), you should be using another business grade reverse proxy before Zoraxy for managing authentication to the management panel.

from zoraxy.

tobychui avatar tobychui commented on May 20, 2024

@ahmedabokandil thanks for your explanation.
Fail2ban is an existing project that would alter the firewall rules of the host OS, which is way out of the scope of Zoraxy (as a reverse proxy server). Integrating another huge project into Zoraxy just doesn't make sense on its own.

But if what you mean is something like a maximum retry per preset time period (and the IP get banned if over that retry counts) in the basic auth mechanism, I think it is a valid enhancement request.

from zoraxy.

ahmedabokandil avatar ahmedabokandil commented on May 20, 2024

@tobychui
thanks for reply , totally agree , its very great idea to get dynamic ip banned if over retry counts

But if what you mean is something like a maximum retry per preset time period (and the IP get banned if over that retry counts) in the basic auth mechanism, I think it is a valid enhancement request

from zoraxy.

barto95100 avatar barto95100 commented on May 20, 2024

YEs great feature is implemented Crowdsec ;)

from zoraxy.

Aerics84 avatar Aerics84 commented on May 20, 2024

Support for crowdsec would be nice.

from zoraxy.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.