CrowdSec

Açıklama

Note: You must first have CrowdSec installed on your server. The installation is very simple.

CrowdSec is composed of a behavior detection engine, able to block classical attacks like credential bruteforce, port scans, web scans, etc.

Based on the type and number of blocked attacks, and after curation of those signals to avoid false positives and poisoning, a global IP reputation DB is maintained and shared with all network members.

This WordPress plugin is a “bouncer”, which purpose is to block detected attacks with two remediation systems: ban or challenge detected attackers with a Captcha.

CrowdSec

You can:

  1. Block aggressive IPs
  2. Display a captcha for less aggressive IPs

Get more info on the CrowdSec official website.

Ekran Görüntüleri

  • The general configuration page
  • Customize the wall pages - Adapt the "captcha wall" page text content with your own
  • Customize the wall pages - Adapt the "ban wall" page text content with your own
  • Customize the wall pages - Adapt the pages with your colors. You can also add custom CSS rules.
  • Advanced settings - Select the live or the stream mode. Select a cache engine (Classical file system, Redis or Memcached). Adjust the cache durations.
  • Advanced settings - Set the CDN or Reverse Proxies to trust.
  • The standard Captcha page
  • The standard Ban page
  • A Captcha wall page customization (text and colors)
  • A Ban wall page customization (text and colors)

SSS

What do I need to make CrowdSec work?

  • You have to install a CrowdSec instance on this server.
  • You have to generate a bouncer key on the server on which CrowdSec is running.

İncelemeler

16 Temmuz 2022
My WordPress server & installation (including PHP version) met or exceeded all requirements. I was running WordPress 6.01 which apparently hasn't been tested. After downloading and activating the plugin, my site experienced a "Critical Error 503" error and I was unable to access the Admin Dashboard. I was able to overcome this restriction after 2 hours and 15 minutes and deactivating and deleting the CrowdSec plugin allowed me to regain control of my Admin Dashboard and the website was back online.
3 incelemeyi oku

Katkıda Bulunanlar ve Geliştiriciler

“CrowdSec” açık kaynaklı yazılımdır. Aşağıdaki kişiler bu eklentiye katkıda bulunmuşlardır.

Katkıda bulunanlar

Değişiklik Kaydı

1.9 (2022-09-15)

  • Add TLS authentication option

1.8 (2022-08-04)

  • Add use_curl configuration: should be used if allow_url_fopen is disabled and curl is available
  • Add disable_prod_log configuration
  • Change log path to wp-content/plugins/crowdsec/logs
  • By default, the bouncing_level setting is now bouncing_disabled (instead of normal_bouncing)

1.7 (2022-07-20)

  • Add geolocation feature

1.6 (2022-06-30)

  • Add “Test bouncing” action in settings view

1.5 (2022-06-09)

  • Use cache instead of session to store some values

1.4 (2022-04-07)

  • Do not bounce PHP CLI

1.3 (2022-02-03)

  • Use static settings only in standalone mode

1.2 (2021-12-09)

  • Fix issue that cause warning message error on front in standalone mode
  • Fix behavior : bounce should not be done twice in standalone mode
  • Remove useless configuration to enable standalone mode

1.1 (2021-12-02)

  • Use 0.14.0 version of crowdsec php lib
  • Handle typo fixing for retro compatibility (flex_boucing=>flex_bouncing and normal_boucing=>normal_bouncing)
  • Split of debug in 2 configurations : debug and display_errors

1.0 (2021-06-24)

  • Add Standalone mode: an option allowing the PHP engine to no longer have to load the WordPress core during the
    bouncing stage. To be able to apply this mode, the webmaster has to set the auto_prepend_file PHP flag to the
    script we provide.
  • Add debug mode: user can enable the debug mode directly from the CrowdSec advanced settings panel. A more verbose log
    will be written when this flag is enabled.
  • Add WordPress 5.7 support
  • Add PHP 8.0 support

Read the full Changelog