What this box is blocking
A live view of CrowdSec on the server behind divyam.top. CrowdSec parses Caddy's access logs on this box and pulls the community blocklist; a Caddy bouncer answers 403 to banned addresses. Decisions expire on their own; the numbers here are what is active right now.
Top scenarios
| http:scan | 22427 | |
| http:exploit | 453 | |
| http:crawl | 44 | |
| crowdsecurity/http-probing | 2 | |
| crowdsecurity/CVE-2017-9841 | 1 | |
| crowdsecurity/http-admin-interface-probing | 1 | |
| crowdsecurity/http-bad-user-agent | 1 | |
| crowdsecurity/http-cve-probing | 1 |
By origin
| CAPI | 22924 |
| crowdsec | 7 |
crowdsec / cscli: decided here from this box's own logs. CAPI / lists: shared by the CrowdSec community.
Agent counters
| alerts_in_database | 121 |
| local_detections_since_start | 988 |
A sample of current decisions
Addresses are masked; local detections are listed first.
| address | scenario | origin | type | expires in |
|---|---|---|---|---|
| 54.246.242.x | crowdsecurity/http-bad-user-agent | crowdsec | ban | 2h49m45s |
| 80.94.92.x | crowdsecurity/http-probing | crowdsec | ban | 3h29m13s |
| 80.94.92.x | crowdsecurity/http-admin-interface-probing | crowdsec | ban | 3h29m19s |
| 80.94.92.x | crowdsecurity/http-sensitive-files | crowdsec | ban | 3h29m27s |
| 80.94.92.x | crowdsecurity/http-probing | crowdsec | ban | 3h34m20s |
| 107.170.54.x | crowdsecurity/CVE-2017-9841 | crowdsec | ban | 3h45m15s |
| 107.170.54.x | crowdsecurity/http-cve-probing | crowdsec | ban | 3h45m15s |
| 71.6.235.x | http:scan | CAPI | ban | 15m51s |
| 59.103.119.x | http:scan | CAPI | ban | 15m51s |
| 168.138.232.x | http:scan | CAPI | ban | 15m52s |
How it works
Caddy writes access logs; a CrowdSec agent on the same box parses them with the standard HTTP scenarios (probing, bad user agents, path traversal, brute force …) and subscribes to the community blocklist. When a decision is made, a CrowdSec bouncer inside Caddy answers 403 to that address until the decision expires. This page asks the local API for the active decisions and shows the shape of them. Nothing here identifies a visitor.
Snapshot at 11:14:11 UTC, cached 30s. curl https://security.divyam.top/ returns the same data as JSON.