troduction: I'm Arber — 17 years running infrastructure that can't afford to be down (ISP backbones, national broadcasters, government systems), based in Tirana, Albania.
For the past year I watched fail2ban block tens of thousands of attacks… and nothing ever happened to the attacker. Almost every source is someone's hijacked VPS, and the provider never hears about it. That silence started to feel like the real vulnerability. So I built something about it.
RIPOSTE turns every firewall ban into an automated, evidence-backed abuse report:
→ fail2ban / QNAP QuFirewall push events to a local FastAPI collector (no log scraping)
→ attribution via Abusix abuse-contact DNS with RDAP fallback, cached per CIDR
→ one aggregated X-ARF report per responsible network per day, full timestamped evidence
→ delivery tracked end-to-end: sent / bounced / acked / human reply / takedown
Month one on my own infra: 2,847 blocked attacks → 214 responsible networks → 31 reports → 4 compromised hosts confirmed offline. The per-provider spread is the interesting part — some suspend within 48h, some abuse mailboxes literally hard-bounce. A public per-provider accountability dashboard is next.
No hack-back — it never sends a packet at the attacker. Only professional reports to registered abuse contacts.
Docs & architecture:
https://github.com/arberormeni2022/riposte
Beta access for operators:
https://buymeacoffee.com/securitysystem
Which firewall should get an adapter next? Happy to talk WHOIS/RDAP swamp-draining.
#infosec #fail2ban #selfhosted #sysadmin #abusedesktroduction: I'm Arber — 17 years running infrastructure that can't afford to be down (ISP backbones, national broadcasters, government systems), based in Tirana, Albania.
For the past year I watched fail2ban block tens of thousands of attacks… and nothing ever happened to the attacker. Almost every source is someone's hijacked VPS, and the provider never hears about it. That silence started to feel like the real vulnerability. So I built something about it.
RIPOSTE turns every firewall ban into an automated, evidence-backed abuse report:
→ fail2ban / QNAP QuFirewall push events to a local FastAPI collector (no log scraping)
→ attribution via Abusix abuse-contact DNS with RDAP fallback, cached per CIDR
→ one aggregated X-ARF report per responsible network per day, full timestamped evidence
→ delivery tracked end-to-end: sent / bounced / acked / human reply / takedown
Month one on my own infra: 2,847 blocked attacks → 214 responsible networks → 31 reports → 4 compromised hosts confirmed offline. The per-provider spread is the interesting part — some suspend within 48h, some abuse mailboxes literally hard-bounce. A public per-provider accountability dashboard is next.
No hack-back — it never sends a packet at the attacker. Only professional reports to registered abuse contacts.
Docs & architecture:
https://github.com/arberormeni2022/riposte
Beta access for operators:
https://buymeacoffee.com/securitysystem
Which firewall should get an adapter next? Happy to talk WHOIS/RDAP swamp-draining.
#infosec #fail2ban #selfhosted #sysadmin #abusedesktroduction: I'm Arber — 17 years running infrastructure that can't afford to be down (ISP backbones, national broadcasters, government systems), based in Tirana, Albania.
For the past year I watched fail2ban block tens of thousands of attacks… and nothing ever happened to the attacker. Almost every source is someone's hijacked VPS, and the provider never hears about it. That silence started to feel like the real vulnerability. So I built something about it.
RIPOSTE turns every firewall ban into an automated, evidence-backed abuse report:
→ fail2ban / QNAP QuFirewall push events to a local FastAPI collector (no log scraping)
→ attribution via Abusix abuse-contact DNS with RDAP fallback, cached per CIDR
→ one aggregated X-ARF report per responsible network per day, full timestamped evidence
→ delivery tracked end-to-end: sent / bounced / acked / human reply / takedown
Month one on my own infra: 2,847 blocked attacks → 214 responsible networks → 31 reports → 4 compromised hosts confirmed offline. The per-provider spread is the interesting part — some suspend within 48h, some abuse mailboxes literally hard-bounce. A public per-provider accountability dashboard is next.
No hack-back — it never sends a packet at the attacker. Only professional reports to registered abuse contacts.
Docs & architecture:
https://github.com/arberormeni2022/riposte
Beta access for operators:
https://buymeacoffee.com/securitysystem
Which firewall should get an adapter next? Happy to talk WHOIS/RDAP swamp-draining.
#infosec #fail2ban #selfhosted #sysadmin #abusedeskHi,
#introduction: I'm Arber — 17 years running infrastructure that can't afford to be down (ISP backbones, national broadcasters, government systems), based in Tirana, Albania.
For the past year I watched fail2ban block tens of thousands of attacks… and nothing ever happened to the attacker. Almost every source is someone's hijacked VPS, and the provider never hears about it. That silence started to feel like the real vulnerability. So I built something about it.
RIPOSTE turns every firewall ban into an automated, evidence-backed abuse report:
→ fail2ban / QNAP QuFirewall push events to a local FastAPI collector (no log scraping)
→ attribution via Abusix abuse-contact DNS with RDAP fallback, cached per CIDR
→ one aggregated X-ARF report per responsible network per day, full timestamped evidence
→ delivery tracked end-to-end: sent / bounced / acked / human reply / takedown
Month one on my own infra: 2,847 blocked attacks → 214 responsible networks → 31 reports → 4 compromised hosts confirmed offline. The per-provider spread is the interesting part — some suspend within 48h, some abuse mailboxes literally hard-bounce. A public per-provider accountability dashboard is next.
No hack-back — it never sends a packet at the attacker. Only professional reports to registered abuse contacts.
Docs & architecture:
https://github.com/arberormeni2022/riposte
Beta access for operators:
https://buymeacoffee.com/securitysystem
Which firewall should get an adapter next? Happy to talk WHOIS/RDAP swamp-draining.
#infosec #fail2ban #selfhosted #sysadmin #abusedesk