Habr•September 16, 2026•🇷🇺Translated from Russian

Developer Builds Custom Bouncer Tool to Automatically Block .env and SSH Probing on VPS

A system administrator managing a modest VPS hosting static sites behind Caddy decided to stop manually watching logs filled with brute-force attempts against SSH and automated scans for common sensitive files.

The server regularly received requests for wp-admin, .env, phpmyadmin, and backup configuration files even though no WordPress instance was present. At the same time, systemd-journal recorded repeated OpenSSH messages such as “Invalid user admin” and “Invalid user oracle”.

Although Fail2ban is widely used, the administrator found its configuration of jails, filters, and actions too cumbersome for web-related blocking and preferred a single binary with minimal dependencies.

How the custom solution works

The resulting tool, called Bouncer, first performs a controlled crawl of the site using a breadth-first queue limited by depth and total page count. It extracts internal links from HTML, records all discovered paths, and allows additional routes such as API endpoints to be added manually in the configuration.

When new entries appear in the Caddy access log showing a 404 response, the path is checked against the discovered list. Five unknown paths within a sliding time window trigger addition of the source IP to an nftables set that drops traffic before it reaches listening ports. Direct requests to files such as /.env result in immediate blocking without waiting for the threshold.

For SSH, the program parses journal entries and treats an “Invalid user” message as an immediate ban because legitimate users do not attempt non-existent accounts. Failed password attempts for existing users are counted within a time window instead.

  • The tool never replays old log files on startup, processing only new lines from the moment it begins.
  • Each site maintains its own path list and log source, allowing multiple Caddy virtual hosts to be protected by one process.
  • An installation script places the binary, generates a systemd unit, populates a whitelist with the administrator’s current IP, and inserts the required nftables drop rule in the correct chain order.

After switching from a previous prototype named CaddyBan, the administrator reported significantly cleaner logs and fewer manual reviews of connection attempts.

Related articles

Habr•Other

PKI Storm: Managing 100,000 Simultaneous Certificate Requests in Kubernetes Recovery Scenarios

A large organization's PKI infrastructure faced a critical bottleneck when a data center outage triggered simultaneous startup of tens of thousands of Kubernetes pods, each requiring mTLS certificates. The existing setup using ESAUS and Citadel routed all requests through external certificate authorities that could only sustain 50-70 RPS against an incoming burst of 100,000 requests. Average daily load of 10-11 RPS had masked the thundering herd risk during mass recovery. Scaling the CA 15x was rejected due to cost and the fundamental dependency on real-time signing. The team introduced pre-issuance of certificates stored in a dedicated Unified Secret Storage (ЕХС) layer that supports 14,000 RPS reads while the CA continues normal operation. This architectural separation of issuance and consumption reduced recovery time from nearly 24 minutes to seconds while shifting focus to secure secret lifecycle management including KRA key protection.

AntiMalware•Other

MinTsifry Considers Annual 10 Billion Rubles Support Package for Russian AI Development

Russia's Ministry of Digital Development is discussing a state support package worth up to 10 billion rubles per year aimed at local AI developers. The proposed funding would cover technology development, pilot launches, and compensation for computing resources. According to Kommersant, 8 billion rubles are planned for development and implementation while 2 billion would offset computational costs. Mechanisms under consideration include subsidized loans through authorized banks and grants covering up to 80 percent of pilot project costs in priority sectors. The initiative remains in discussion with no final parameters or launch timelines confirmed yet. Industry experts note that clear selection criteria and transparent reporting will be essential to prevent intermediaries and ensure fair access for independent teams.

AntiMalware•Other

Indid Reports Russian Identity Security Market Reaches 17 Billion Rubles Amid High Incident Rates

According to Indid, the Russian Identity Security market reached 17 billion rubles by the end of 2025. The assessment highlights that organizations continue to allocate significant budgets to access protection while account-related problems persist. Survey data shows that 87.5 percent of companies experienced incidents involving user accounts and access rights during the period. Identity Security solutions focus on managing digital identities, controlling permissions, and preventing unauthorized access across corporate systems. The findings indicate ongoing challenges in maintaining secure access despite growing investments in specialized tools and platforms.

Habr•Other

How a Node.js Bridge Connects MAX and VK Messengers to Chatwoot with Secure Bidirectional Sync

A detailed technical case study describes building a lightweight Node.js service that links the MAX messenger and VK communities to Chatwoot without scraping or using personal accounts. The bridge uses official bot APIs and community callbacks, separate API inboxes, and persistent state stored in a Docker volume to maintain conversation mappings across restarts. Security measures include webhook secret validation, deduplication of events using ring buffers, SSRF protections when handling images, and strict filtering to prevent loops or private notes from leaking externally. The implementation covers contact and conversation creation via Chatwoot Application API, image transfer for VK, and graceful recovery after partial failures. Limitations such as lack of exactly-once delivery and absence of a durable queue are acknowledged, with recommendations for production use including SQLite, retries, and structured logging. The author provides configuration examples, health checks, and a capability matrix showing current support for text and media in each direction.