{
  "id": 13360095,
  "title": "CrowdSec alert from my own IP: the 'attack' was my phone's photo app",
  "url": "https://urgent.news/2026/10/10/crowdsec-alert-from-my-own-ip-the-attack-was-my-phones-photo-app",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-10T08:00:16.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/iam-tech/crowdsec-alert-from-my-own-ip-the-attack-was-my-phones-photo-app-b41"
  },
  "original_language": "en",
  "account": "On 21 September, the author discovered that CrowdSec, an open-source threat intelligence platform, had flagged their own IP address for a series of suspicious activities. The source material revealed that the crowdsecurity/http-probing scenario, which flags 11 thumbnail requests returning 404 errors in 4 seconds, had triggered on their WAN address. The culprit turned out to be a photo-backup app on their own phone, which was requesting thumbnails of deleted photos. The author examined the situation using the cscli metrics command, which showed a large number of decisions made by CrowdSec's community blocklist and third-party sources. However, this metric does not represent actual attacks on their network. The author emphasized the importance of reviewing individual alerts instead of relying solely on metrics. They explained that local alerts, which indicate activity against their specific network, were the most critical metric to monitor. The article also discussed the limitations of blocking local attacks directly, as IP addresses behind a Cloudflare tunnel cannot be directly identified. Instead, the author configured warden, a detection-only tool they wrote, to push bans to Cloudflare's edge. The author highlighted several bugs they discovered while building warden, including incorrect event timestamps, double-counting events, and per-address scoring missed activity spread across subnets. They addressed these issues by adjusting the lookback period, adding a range ban check, and improving event timestamp handling. Finally, the author mentioned a URL-decoding bug in their Cloudflare Worker alerting system, which they fixed to ensure proper pattern matching. Overall, the author learned valuable lessons about CrowdSec's metrics, proper alert review, and the importance of maintaining a bug-free configuration for their detection tools.",
  "summary": "The worry was simple: CrowdSec was \"being hammered\". The numbers looked alarming, and I wanted to know who was attacking my homelab. The answer, after a proper look on 21 September, was me. This post covers how that happened, what the big numbers actually meant, and the bugs I found in my own detection while working it out. The only local alert in a week was my own address My setup: services sit…",
  "key_points": [
    "CrowdSec flagged author's IP for suspicious thumbnail requests",
    "Photo-backup app on author's phone triggered alerts",
    "Author built tool to push bans to Cloudflare's edge"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}