I put up a vps with nginx and the logs show dodgy requests within minutes, how do you guys deal with these?
Edit: Thanks for the tips everyone!
Ok, so I spent way too much time tonight trying to figure this out, made a mess of my npm, and fixed it.
It is very well documented.
Official documentation on using crowdsec with NPM is out of date and relies on a fork thatโs no longer maintained. Iโm trying to find any documentation on how to integrate the bouncer into the official NPM project and am really coming up empty.
You only need the unmaintaind version (official PR is in the works: https://github.com/NginxProxyManager/nginx-proxy-manager/pull/2677 ) if you want to bounce at the NPM level (aka: with a captcha). At the moment I am using crowdsec to parse the NPM logs (and some other logs) and bounce at the IP tables level on my VPS ( block only) and at the opnsense firewall level (also block only) at home.
Iโm not sure if itโs the fact that I was up at 1am trying to figure this all out or what but it wasnโt clicking last night. So the NPM (nginx) integration would strictly be the captcha and I would need to bounce at the firewall to block? That makes way more sense to me now. Thanks.