• 1 Post
  • 16 Comments
Joined 9 months ago
cake
Cake day: January 9th, 2025

help-circle



  • I think I have the same protectli as you and it is awesome. Need it for my 2.5gb uplink. I use openwrt on it… Didn’t really like opnsense. I am more used to linux than bsd.

    I host lots of services and get bombarded by scrapers, scanners, and skids both at home and on my VPSs.

    I use ipset for the usual blocklists which I download regularly. I also have tarpits on 22/tcp (endlessh). I pipe the IPs from the endlessh logs into fail2ban which feeds the ipsets. I have ipset blocks and fail2ban on my home firewall and all VPSs and coordinate over mqtt. So any fail2ban trigger > mqtt > every ipset block. Touch my 22/tcp anywhere and you get banned instantly everywhere. The program I use for this is called vallumd and it runs on openwrt.

    I also put maltrail everywhere but I’m not totally sure how to interpret and respond to the results. Probably will implement a pipe from maltrail to my mqtt > blocklist setup.

    I don’t do any network-level adblocking… Might be a future project.
















  • I like to think of global conflict as being world people vs world governments/elites. The govs and elites just frame global conflict as being country x vs country y to divide and conquer.

    Straight outta 1984, where the world is kept in perpetual world war and nobody remembers why they’re at war. Orwell writes that war is the best business (arms) because the product is destroyed instantly. War is just another way the elites suck wealth from the citizens, whose taxes involuntarily fund it.