home.social

#maltrail — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #maltrail, aggregated by home.social.

  1. Ich habe das Plugin #Maltrail (Malicious Traffic Detection) unter #OPNsense getestet und fand es vielversprechend — leider lief es nur einen Tag. Danach wurden keine Sensordaten mehr aufgezeichnet. Ursache ist ein bekannter Bug: es werden zu viele Prozesse gestartet, was den RAM unnötig belastet und stehenbleibt. In der Konsole ist das Problem gut nachvollziehbar. So ist das Plugin aktuell nicht nutzbar. Deinstalliert.

    Interessante Seite dazu: andersgood.de/blog/oeffentlich

  2. Ich habe das Plugin #Maltrail (Malicious Traffic Detection) unter #OPNsense getestet und fand es vielversprechend — leider lief es nur einen Tag. Danach wurden keine Sensordaten mehr aufgezeichnet. Ursache ist ein bekannter Bug: es werden zu viele Prozesse gestartet, was den RAM unnötig belastet und stehenbleibt. In der Konsole ist das Problem gut nachvollziehbar. So ist das Plugin aktuell nicht nutzbar. Deinstalliert.

    Interessante Seite dazu: andersgood.de/blog/oeffentlich

  3. From this week's ADMIN Update newsletter: Holger Reibold examines Maltrail, a traffic analysis software that identifies malicious traffic on your network with the use of established sources
    admin-magazine.com/Archive/202
    #Maltrail #security #MISP #detection #traffic #monitoring

  4. From this week's ADMIN Update newsletter: Holger Reibold examines Maltrail, a traffic analysis software that identifies malicious traffic on your network with the use of established sources
    admin-magazine.com/Archive/202
    #Maltrail #security #MISP #detection #traffic #monitoring

  5. From this week's ADMIN Update newsletter: Holger Reibold examines Maltrail, a traffic analysis software that identifies malicious traffic on your network with the use of established sources
    admin-magazine.com/Archive/202

  6. From this week's ADMIN Update newsletter: Holger Reibold examines Maltrail, a traffic analysis software that identifies malicious traffic on your network with the use of established sources
    admin-magazine.com/Archive/202
    #Maltrail #security #MISP #detection #traffic #monitoring

  7. From this week's ADMIN Update newsletter: Holger Reibold examines Maltrail, a traffic analysis software that identifies malicious traffic on your network with the use of established sources
    admin-magazine.com/Archive/202
    #Maltrail #security #MISP #detection #traffic #monitoring

  8. Крепость под наблюдением: ставим Maltrail и ловим «шпионов» (Часть 2)

    Привет, Хабр! В первой части нашего путешествия мы превратили голый VPS в маленькую крепость. Мы создали пользователя с sudo, настроили вход по SSH-ключам, выставили на стражу файрвол UFW и наняли вышибалу Fail2ban. Теперь лобовые brute-force атаки и автоматические сканеры разбиваются о наши стены, не доставляя хлопот. Мы победили, верно? Не совсем. Наша крепость неприступна, но она слепа . Мы отбиваем тех, кто ломится в ворота, но совершенно не видим, что происходит на периметре. Что если уязвимость найдется в нашем веб-сервере? Что если одна из запущенных нами программ начнет слать странный трафик, став частью ботнета? Здесь нам нужна "сигнализация". Система, которая станет нашими глазами и ушами, и поднимет тревогу при малейшем подозрительном движении. Сегодня мы установим именно такую — Maltrail .

    habr.com/ru/articles/926414/

    #maltrail #ids #linux #infosec #vps #nginx #fail2ban #кибербезопасность #безопасность_linux #мониторинг_трафика

  9. Крепость под наблюдением: ставим Maltrail и ловим «шпионов» (Часть 2)

    Привет, Хабр! В первой части нашего путешествия мы превратили голый VPS в маленькую крепость. Мы создали пользователя с sudo, настроили вход по SSH-ключам, выставили на стражу файрвол UFW и наняли вышибалу Fail2ban. Теперь лобовые brute-force атаки и автоматические сканеры разбиваются о наши стены, не доставляя хлопот. Мы победили, верно? Не совсем. Наша крепость неприступна, но она слепа . Мы отбиваем тех, кто ломится в ворота, но совершенно не видим, что происходит на периметре. Что если уязвимость найдется в нашем веб-сервере? Что если одна из запущенных нами программ начнет слать странный трафик, став частью ботнета? Здесь нам нужна "сигнализация". Система, которая станет нашими глазами и ушами, и поднимет тревогу при малейшем подозрительном движении. Сегодня мы установим именно такую — Maltrail .

    habr.com/ru/articles/926414/

    #maltrail #ids #linux #infosec #vps #nginx #fail2ban #кибербезопасность #безопасность_linux #мониторинг_трафика

  10. Крепость под наблюдением: ставим Maltrail и ловим «шпионов» (Часть 2)

    Привет, Хабр! В первой части нашего путешествия мы превратили голый VPS в маленькую крепость. Мы создали пользователя с sudo, настроили вход по SSH-ключам, выставили на стражу файрвол UFW и наняли вышибалу Fail2ban. Теперь лобовые brute-force атаки и автоматические сканеры разбиваются о наши стены, не доставляя хлопот. Мы победили, верно? Не совсем. Наша крепость неприступна, но она слепа . Мы отбиваем тех, кто ломится в ворота, но совершенно не видим, что происходит на периметре. Что если уязвимость найдется в нашем веб-сервере? Что если одна из запущенных нами программ начнет слать странный трафик, став частью ботнета? Здесь нам нужна "сигнализация". Система, которая станет нашими глазами и ушами, и поднимет тревогу при малейшем подозрительном движении. Сегодня мы установим именно такую — Maltrail .

    habr.com/ru/articles/926414/

    #maltrail #ids #linux #infosec #vps #nginx #fail2ban #кибербезопасность #безопасность_linux #мониторинг_трафика

  11. 🚨 CRITICAL: CVE-2025-34073 in Maltrail ≤0.54 enables unauthenticated OS command injection via /login. Remote attackers can gain code execution! Restrict access, monitor logs, and patch ASAP. Details: radar.offseq.com/threat/cve-20 #OffSeq #Maltrail #Vulnerability #CVE202534073

  12. 🚨 CRITICAL: CVE-2025-34073 in Maltrail ≤0.54 enables unauthenticated OS command injection via /login. Remote attackers can gain code execution! Restrict access, monitor logs, and patch ASAP. Details: radar.offseq.com/threat/cve-20 #OffSeq #Maltrail #Vulnerability #CVE202534073

  13. Öffentliche IP-Adressen in OPNsense mit maltrail absichern (plus Workaround für sensor.py Problem)

    Mit #maltrail und #OPNsense deine öffentlichen IP-Adressen so absichern, dass Angriffe mittels Blocklists und Heuristik automatisch abgewehrt werden.

    andersgood.de/blog/oeffentlich

    #SWEETGOOD #andersGOOD #Tutorial #Security #DevSecOps

  14. Öffentliche IP-Adressen in OPNsense mit maltrail absichern (plus Workaround für sensor.py Problem)

    Mit #maltrail und #OPNsense deine öffentlichen IP-Adressen so absichern, dass Angriffe mittels Blocklists und Heuristik automatisch abgewehrt werden.

    andersgood.de/blog/oeffentlich

    #SWEETGOOD #andersGOOD #Tutorial #Security #DevSecOps

  15. Öffentliche IP-Adressen in OPNsense mit maltrail absichern (plus Workaround für sensor.py Problem)

    Mit #maltrail und #OPNsense deine öffentlichen IP-Adressen so absichern, dass Angriffe mittels Blocklists und Heuristik automatisch abgewehrt werden.

    andersgood.de/blog/oeffentlich

    #SWEETGOOD #andersGOOD #Tutorial #Security #DevSecOps

  16. Öffentliche IP-Adressen in OPNsense mit maltrail absichern (plus Workaround für sensor.py Problem)

    Mit #maltrail und #OPNsense deine öffentlichen IP-Adressen so absichern, dass Angriffe mittels Blocklists und Heuristik automatisch abgewehrt werden.

    andersgood.de/blog/oeffentlich

    #SWEETGOOD #andersGOOD #Tutorial #Security #DevSecOps

  17. I'm looking for #OSSec guidance, I remember when #tripwire was suggested for detecting #rootkits, but there's so many options, with #Zeek and #Maltrail. #HIDS #IntrusionDetection

    I thought OSSEC with the GUI looked nice, especially if there was a central monitoring server that agents could report to. Zeek looks more like that but looks like it may have to sit at the router, which is annoying, and doesn't detect rootkits at all. My end goal is preventing SIP phone fraud.

    linuxsecurity.expert/tools/sam

  18. I'm looking for #OSSec guidance, I remember when #tripwire was suggested for detecting #rootkits, but there's so many options, with #Zeek and #Maltrail. #HIDS #IntrusionDetection

    I thought OSSEC with the GUI looked nice, especially if there was a central monitoring server that agents could report to. Zeek looks more like that but looks like it may have to sit at the router, which is annoying, and doesn't detect rootkits at all. My end goal is preventing SIP phone fraud.

    linuxsecurity.expert/tools/sam