• 0 Posts
  • 57 Comments
Joined 1 year ago
cake
Cake day: June 12th, 2023

help-circle


















  • Understood. Any public-facing server will be bombarded by bots. You need to deploy measures to avoid being hacked:

    1. Firewall: lockdown everything, allow only the strict necessary
    2. Remote login/SSH: update default username and pasword, only allow remote login using Encryption Key authentification
    3. (Optional) configure fail2ban to slowdown the attacks
    4. Keep your server up-to-date: configure auto-update, unattended-update or similare
    5. Setup and keep regular backups: be ready to nuke your server at anytime, with the confidence you can restart fresh in a short time and low effort

    Obviously, there are many other security steps that can be put in place, but firewall and ssh hardening are absolutely mandatory