#abusedesk

2 posts · Last used Aug 26

troduction: I'm Arber — 17 years running infrastructure that can't afford to be down (ISP backbones, national broadcasters, government systems), based in Tirana, Albania. For the past year I watched fail2ban block tens of thousands of attacks… and nothing ever happened to the attacker. Almost every source is someone's hijacked VPS, and the provider never hears about it. That silence started to feel like the real vulnerability. So I built something about it. RIPOSTE turns every firewall ban into an automated, evidence-backed abuse report: → fail2ban / QNAP QuFirewall push events to a local FastAPI collector (no log scraping) → attribution via Abusix abuse-contact DNS with RDAP fallback, cached per CIDR → one aggregated X-ARF report per responsible network per day, full timestamped evidence → delivery tracked end-to-end: sent / bounced / acked / human reply / takedown Month one on my own infra: 2,847 blocked attacks → 214 responsible networks → 31 reports → 4 compromised hosts confirmed offline. The per-provider spread is the interesting part — some suspend within 48h, some abuse mailboxes literally hard-bounce. A public per-provider accountability dashboard is next. No hack-back — it never sends a packet at the attacker. Only professional reports to registered abuse contacts. Docs & architecture: https://github.com/arberormeni2022/riposte Beta access for operators: https://buymeacoffee.com/securitysystem Which firewall should get an adapter next? Happy to talk WHOIS/RDAP swamp-draining. #infosec #fail2ban #selfhosted #sysadmin #abusedesktroduction: I'm Arber — 17 years running infrastructure that can't afford to be down (ISP backbones, national broadcasters, government systems), based in Tirana, Albania. For the past year I watched fail2ban block tens of thousands of attacks… and nothing ever happened to the attacker. Almost every source is someone's hijacked VPS, and the provider never hears about it. That silence started to feel like the real vulnerability. So I built something about it. RIPOSTE turns every firewall ban into an automated, evidence-backed abuse report: → fail2ban / QNAP QuFirewall push events to a local FastAPI collector (no log scraping) → attribution via Abusix abuse-contact DNS with RDAP fallback, cached per CIDR → one aggregated X-ARF report per responsible network per day, full timestamped evidence → delivery tracked end-to-end: sent / bounced / acked / human reply / takedown Month one on my own infra: 2,847 blocked attacks → 214 responsible networks → 31 reports → 4 compromised hosts confirmed offline. The per-provider spread is the interesting part — some suspend within 48h, some abuse mailboxes literally hard-bounce. A public per-provider accountability dashboard is next. No hack-back — it never sends a packet at the attacker. Only professional reports to registered abuse contacts. Docs & architecture: https://github.com/arberormeni2022/riposte Beta access for operators: https://buymeacoffee.com/securitysystem Which firewall should get an adapter next? Happy to talk WHOIS/RDAP swamp-draining. #infosec #fail2ban #selfhosted #sysadmin #abusedesktroduction: I'm Arber — 17 years running infrastructure that can't afford to be down (ISP backbones, national broadcasters, government systems), based in Tirana, Albania. For the past year I watched fail2ban block tens of thousands of attacks… and nothing ever happened to the attacker. Almost every source is someone's hijacked VPS, and the provider never hears about it. That silence started to feel like the real vulnerability. So I built something about it. RIPOSTE turns every firewall ban into an automated, evidence-backed abuse report: → fail2ban / QNAP QuFirewall push events to a local FastAPI collector (no log scraping) → attribution via Abusix abuse-contact DNS with RDAP fallback, cached per CIDR → one aggregated X-ARF report per responsible network per day, full timestamped evidence → delivery tracked end-to-end: sent / bounced / acked / human reply / takedown Month one on my own infra: 2,847 blocked attacks → 214 responsible networks → 31 reports → 4 compromised hosts confirmed offline. The per-provider spread is the interesting part — some suspend within 48h, some abuse mailboxes literally hard-bounce. A public per-provider accountability dashboard is next. No hack-back — it never sends a packet at the attacker. Only professional reports to registered abuse contacts. Docs & architecture: https://github.com/arberormeni2022/riposte Beta access for operators: https://buymeacoffee.com/securitysystem Which firewall should get an adapter next? Happy to talk WHOIS/RDAP swamp-draining. #infosec #fail2ban #selfhosted #sysadmin #abusedeskHi, #introduction: I'm Arber — 17 years running infrastructure that can't afford to be down (ISP backbones, national broadcasters, government systems), based in Tirana, Albania. For the past year I watched fail2ban block tens of thousands of attacks… and nothing ever happened to the attacker. Almost every source is someone's hijacked VPS, and the provider never hears about it. That silence started to feel like the real vulnerability. So I built something about it. RIPOSTE turns every firewall ban into an automated, evidence-backed abuse report: → fail2ban / QNAP QuFirewall push events to a local FastAPI collector (no log scraping) → attribution via Abusix abuse-contact DNS with RDAP fallback, cached per CIDR → one aggregated X-ARF report per responsible network per day, full timestamped evidence → delivery tracked end-to-end: sent / bounced / acked / human reply / takedown Month one on my own infra: 2,847 blocked attacks → 214 responsible networks → 31 reports → 4 compromised hosts confirmed offline. The per-provider spread is the interesting part — some suspend within 48h, some abuse mailboxes literally hard-bounce. A public per-provider accountability dashboard is next. No hack-back — it never sends a packet at the attacker. Only professional reports to registered abuse contacts. Docs & architecture: https://github.com/arberormeni2022/riposte Beta access for operators: https://buymeacoffee.com/securitysystem Which firewall should get an adapter next? Happy to talk WHOIS/RDAP swamp-draining. #infosec #fail2ban #selfhosted #sysadmin #abusedesk
0
0
1
0
#Intro I am ZeroTrace, an independent, UK-based security researcher using passive #OSINT to track, map, and dismantle online drug trafficking infrastructure, and founder of http://www.drift-lock.co.uk My work focuses on Telegram-based marketplaces and the digital supply chains—domains, registrars, and hosting providers—that enable them. What I post here: Deep dives into infrastructure resilience (how networks relocate post-takedown) Aggregated threat intel on bulletproof hosts and complicit registrars Defanged IOCs and infrastructure mapping threads All findings are reported to relevant platform abuse teams and UK law enforcement. Transparent tracking log: https://drift-lock.co.uk #ThreatIntel #CTI #AbuseDesk #NetworkSecurity #CyberSecurity
2
0
0
0
You've seen all posts