From 70cd718acc16d6892f0643f0ee9b52bc3e0ccdbe Mon Sep 17 00:00:00 2001 From: CyberMind-FR Date: Fri, 5 Jun 2026 17:13:11 +0200 Subject: [PATCH] =?UTF-8?q?docs:=20Phase=207.A=20WAF=E2=86=92CrowdSec=20br?= =?UTF-8?q?idge=20shipped=20=E2=80=94=20HISTORY/WIP/TODO=20(ref=20#498)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit * HISTORY.md : 2026-06-05 entry for Phase 7.A (pipeline, files, discoveries) * WIP.md : section Phase 7.A done + 7.A.2/7.B/7.C next-ups * TODO.md : 7.A checked, 7.A.2 sub-tasks, roadmap doc referenced Live state on gk2 : secubox-cs-bridge.service active (socat 10.100.0.1:8080 → 127.0.0.1:8080) cscli machine 'secubox-waf' registered mitm WAF reading /etc/secubox/waf/crowdsec.toml + posting alerts on threshold Issue #498 stays open for Phase 7.B and 7.C. --- .claude/HISTORY.md | 48 ++++++++++++++++++++++++++++++++++++++++++++++ .claude/TODO.md | 20 +++++++++++++------ .claude/WIP.md | 30 +++++++++++++++++++++++++++++ 3 files changed, 92 insertions(+), 6 deletions(-) diff --git a/.claude/HISTORY.md b/.claude/HISTORY.md index 38cb8629..430e5a0f 100644 --- a/.claude/HISTORY.md +++ b/.claude/HISTORY.md @@ -3,6 +3,54 @@ --- +## 2026-06-05 — Phase 7.A WAF active enforcement SHIPPED (ref #498) + +Same-day landing right after Phase 6 closure. WAF detections now become real +nft drops within seconds. + +### Pipeline live-verified end-to-end on gk2 + +``` +mitm WAF (LXC) detects threat (count >= BAN_THRESHOLD) + → _ban_via_crowdsec() POST /v1/alerts + → socat bridge 10.100.0.1:8080 → 127.0.0.1:8080 + → CrowdSec LAPI insert decision + → crowdsec-firewall-bouncer poll + apply + → nft table ip crowdsec DROP + +login : 200 JWT 160 chars +alert : 201 ← decision id 13244 +cscli : Ip:192.0.2.99 ban origin=secubox-waf 1h +nft : 192.0.2.99 in table ip crowdsec (kernel drop) +``` + +Round-trip ~12s. Merged in `3eb5378e`. Issue #498 stays open for 7.B/7.C. + +### Files added + +- `packages/secubox-mitmproxy/addons/secubox_waf.py` — `_ban_via_crowdsec()`, + `_cs_jwt()` with 25-min cache, `_load_crowdsec_cfg()`, `ban_ip()` now + bridges via HTTP first (fallback to cscli subprocess) +- `packages/secubox-mitmproxy/bin/secubox-waf-cs-bridge-setup` — idempotent + setup : creates socat unit, registers machine via `cscli machines add -f -`, + writes config TOML +- `packages/secubox-mitmproxy/crowdsec/crowdsec.toml.example` — schema doc + +### Discoveries / decisions + +- LAPI POST /v1/alerts needs WATCHER (JWT) auth, NOT bouncer (X-Api-Key). + Bouncers only PULL via /v1/decisions/stream. +- `cscli machines list -o json` uses key `machineId` not `name`. +- `cscli machines add` writes to `/etc/crowdsec/local_api_credentials.yaml` + by default — conflicts with local agent. Use `-f -` to suppress. +- Alert envelope requires `leakspeed` (one word, not snake_case). +- urllib stdlib used instead of httpx (mitm venv lacks httpx, +1ms vs no dep). +- Socat bridge chosen over changing LAPI `listen_uri` : changing the bind + address breaks the local agent + existing bouncer (hard-coded 127.0.0.1 + in their credentials). + +--- + ## 2026-06-05 — Phase 6 R3 WIREGUARD : MAJOR RELEASE shipped (ref #496) + WAF leak FIXED Phase 6 (R3 mode = portable WireGuard tunnel + mitm interception from anywhere) diff --git a/.claude/TODO.md b/.claude/TODO.md index b3695543..23d7a8b8 100644 --- a/.claude/TODO.md +++ b/.claude/TODO.md @@ -28,14 +28,22 @@ ### 🛡 Phase 7 — WAF active enforcement (issue #498 filée 2026-06-05) -- [ ] **#498 Phase 7.A** quick win : bridge mitm WAF → CrowdSec `/v1/decisions` - → nft drop. Estim 2-3 jours. Acceptance : attacker dropped < 30s post-trigger, - threat_counts < 200 sous attaque. -- [ ] **#498 Phase 7.B** mid-term : nft rate-limit pre-mitm + WAF dashboard + - honeypot routes pour bot signatures (/wp-admin /.env etc). +- [x] **#498 Phase 7.A** SHIPPED 2026-06-05 same-day : bridge mitm WAF → + CrowdSec `/v1/alerts` (machine JWT auth) → nft drop via existing bouncer. + Live verified : login 200, alert 201, cscli decision, nft entry, + ~12s round-trip. Merged `3eb5378e`. +- [ ] **#498 Phase 7.A.2 followups** + - [ ] Backport into `packages/secubox-waf/mitmproxy/secubox_waf.py` (older copy) + - [ ] `debian/postinst` invokes `secubox-waf-cs-bridge-setup` + bind-mounts + config into LXC + - [ ] WAF dashboard tab in admin webui : `bans_pushed` counter + recent bans + - [ ] Tune `BAN_THRESHOLD` per category (XSS=2, SQLi=1, scanner=5) +- [ ] **#498 Phase 7.B** mid-term : nft rate-limit pre-mitm (catches TCP-only + scanners CrowdSec doesn't see), live attacker top-20 dashboard, honeypot + routes for `/wp-admin /.env /.git/config`. - [ ] **#498 Phase 7.C** long-term : eBPF/XDP kernel filter + ModSecurity remplacement mitm WAF + federation CrowdSec Hub/OTX/Spamhaus. -- [ ] Roadmap doc : `.claude/PHASE-7-WAF-ROADMAP.md` ✅ (référence ci-dessus) +- [x] Roadmap doc : `.claude/PHASE-7-WAF-ROADMAP.md` ✅ ### Release pipeline ✅ v2.13.4 APT GREEN + v2.13.12 rpi400 kiosk SALON-READY diff --git a/.claude/WIP.md b/.claude/WIP.md index 6bb9a19d..4260d316 100644 --- a/.claude/WIP.md +++ b/.claude/WIP.md @@ -3,6 +3,36 @@ --- +## 🔄 2026-06-05 : Phase 7.A WAF active enforcement SHIPPED (ref #498) + +### ✅ Done + +* Bridge mitm WAF (LXC) → CrowdSec LAPI (host) → nft drops, full chain E2E : + login 200 + alert 201 + cscli decision + nft entry, ~12s round-trip. +* `_ban_via_crowdsec()` in `secubox_waf.py` uses watcher JWT auth (POST + /v1/alerts), urllib stdlib (no httpx dep), 25-min JWT cache, auto-refresh + on 401. Stats : `bans_pushed`, `bans_failed`. +* `secubox-cs-bridge.service` (socat 10.100.0.1:8080 → 127.0.0.1:8080) so + the mitm LXC reaches host LAPI without invasive CrowdSec config change. +* `secubox-waf-cs-bridge-setup` script : idempotent, registers machine with + `cscli machines add -f -` (avoids touching local_api_credentials.yaml), + writes config TOML. +* `crowdsec.toml.example` documents schema (enabled/url/machine_id/password/duration). +* Merged to master in `3eb5378e`. Worktree 498 cleaned. + +### ⬜ Next up + +* **Phase 7.A.2 followups** : backport into `packages/secubox-waf/`, + wire `debian/postinst` to invoke setup script + bind-mount config into LXC, + WAF dashboard tab in admin webui showing `bans_pushed` counter. +* **Phase 7.B mid-term** : nft rate-limit pre-mitm (catches TCP-only scanners + like the 134.195.158.62 slowloris from earlier today), live attacker + top-20 dashboard, honeypot routes for `/wp-admin /.env /.git/config` etc. +* **Phase 7.C long-term** : eBPF/XDP kernel filter, ModSecurity replacement, + CrowdSec Hub + AlienVault OTX + Spamhaus federation. + +--- + ## 🔄 2026-06-05 : Phase 6 R3 WireGuard — MAJOR RELEASE shipped (ref #496) ### ✅ Done