Urgent.News

What's breaking now, across thousands of outlets.

Tech

Homelab security on 512 MB: warden scores my logs and asks before it bans anything

I wanted one place that tells me what is going on in my homelab: who is poking at it from outside, which boxes have known-exploited CVEs, what needs patching, and whether anything new turned up on the network. And I wanted it on a small box, without putting an agent on every machine. The obvious tools are good, and I'll say that up front. Wazuh does far more than this, but it wants an agent per…

I wanted a single place to monitor my homelab: who is accessing it from outside, which machines have known security vulnerabilities, what needs patching, and whether any new threats have appeared on the network. I wanted this all on a small box without installing an agent on every machine. The most obvious tools, such as Wazuh and CrowdSec, either require an agent or ban automatically without asking first.

So, I created a smaller solution called "warden" that combines existing scanners and adds its own logic. Warden is plain Python and uses an SQLite database to store data. It collects logs from the reverse proxy, authentication system, and Cloudflare tunnel, then scores potential issues like suspicious file paths, SQL injection attempts, scanner user agents, and login failures.

It also checks for vulnerabilities using trivy, patches systems over SSH, and monitors the network for threats using Suricata. Warden communicates with a Discord channel for user approval before taking any action. This approach allows it to run on minimal resources (1 vCPU and 512 MB RAM) while providing comprehensive monitoring and security for a small homelab environment.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

How to Monitor Public Telegram Channels for Free (No API Key, No Bot)

You can monitor public Telegram channels for free. No API key, no bot, no server bill. The trick is that Telegram exposes a web preview at t.me/s/<channel> that returns the last ~20 posts as plain…

  • Telegram offers free web preview at t.me/s/channel for last ~20 posts
  • Python script polls URL every 5 minutes to find new message IDs
  • Persist seen IDs to disk for deduplication across restarts

Turning code-review comments into useful Cursor rules

I asked my agent to build pr-rulebook from an idea that came up in conversation. When I wrote about the result, I included the candidate rule that failed review.

  • Code-review comments analyzed to identify frequently mentioned clues, not established policies.
  • Transforming feedback into Cursor rules requires gathering evidence, not reusing wording.
  • A useful rule specifies what to check, when it applies, and provides a correct example.

4 issues against password reset flow. Here's what I found.

Password reset looks like a 20-line feature. Until it has an email leak, a half-finished transaction, and more than one valid token at a time. I was building a task manager API for a skill assessment.

  • Forgot-password feature exposed others' accounts to unauthorized parties
  • Login process vulnerable to timing attacks
  • Reset password procedure involved three database steps, risking race conditions

Retry with Exponential Backoff in Python, Done Properly

A script that creates invoices runs at 2 a.m. and calls an API. For about thirty seconds, the API returns errors. Without retries, tonight's invoices never go out.

  • Implements exponential backoff strategy for retries
  • Focuses on temporary HTTP errors like timeouts and server issues
  • Adds randomness to prevent simultaneous retries

More from Saturday 10 October →