754

Background: 15 years of experience in software and apparently spoiled because it was already set up correctly.

Been practicing doing my own servers, published a test site and 24 hours later, root was compromised.

Rolled back to the backup before I made it public and now I have a security checklist.

(page 2) 50 comments
sorted by: hot top controversial new old
[-] possiblylinux127@lemmy.zip 8 points 1 week ago

I like to spin up a public facing server and run tcpdump

Lol! Honeypot or just bored?

[-] possiblylinux127@lemmy.zip 4 points 1 week ago

Actually I was troubleshooting a Firewall issue on site. I just forgot to use the filter arguments to reduce the output.

load more comments (1 replies)
[-] Thcdenton@lemmy.world 7 points 1 week ago

I usually just follow this

[-] Rentlar@lemmy.ca 7 points 1 week ago

I do worry about putting up public servers that other people might rely on because there's something I might not realize making it vulnerable.

So far I have pubkey root login only on the VPSs I'm messing around with, but my ol' reliable private key from 6 years ago might be beginning to fall behind on encryption standards.

load more comments (1 replies)
[-] AngryCommieKender@lemmy.world 6 points 1 week ago

Use gnome powder to shrink, go behind the counter, kick his ass and get your money back.

[-] MNByChoice@midwest.social 5 points 1 week ago

Good on you learning new skills.

This is why other sysadmins and cybetsecurity exist. Be nice to them.

[-] ikidd@lemmy.world 5 points 1 week ago

This is like browsing /c/selfhosted as everyone portforwards every experimental piece of garbage across their router...

[-] Irelephant@lemm.ee 6 points 1 week ago

hey, thats me!

load more comments (4 replies)
[-] potentiallynotfelix@lemmy.fish 5 points 1 week ago

Weird. My last setup had a NAT with a few VMs hosting a few different services. For example, Jellyfin, a web server, and novnc/vm. That turned out perfectly fine and it was exposed to the web. You must have had a vulnerable version of whatever web host you were using, or maybe if you had SSH open without rate limits.

load more comments (1 replies)
[-] MonkderVierte@lemmy.ml 4 points 1 week ago

Yeah, about this; any ssh server that can be run as user and doesn't do shenanigans like switching user?

[-] gerryflap@feddit.nl 4 points 1 week ago

I've been quite stupid with this but never really had issues. Ever since I changed the open ssh port from 22 to something else, my server is basically ignored by botnets. These days I obviously also have some other tricks like fail2ban, but it was funny how effective that was.

load more comments (1 replies)
load more comments
view more: โ€น prev next โ€บ
this post was submitted on 10 Feb 2025
754 points (99.3% liked)

linuxmemes

22622 readers
687 users here now

Hint: :q!


Sister communities:


Community rules (click to expand)

1. Follow the site-wide rules

2. Be civil
  • Understand the difference between a joke and an insult.
  • Do not harrass or attack users for any reason. This includes using blanket terms, like "every user of thing".
  • Don't get baited into back-and-forth insults. We are not animals.
  • Leave remarks of "peasantry" to the PCMR community. If you dislike an OS/service/application, attack the thing you dislike, not the individuals who use it. Some people may not have a choice.
  • Bigotry will not be tolerated.
  • These rules are somewhat loosened when the subject is a public figure. Still, do not attack their person or incite harrassment.
  • 3. Post Linux-related content
  • Including Unix and BSD.
  • Non-Linux content is acceptable as long as it makes a reference to Linux. For example, the poorly made mockery of sudo in Windows.
  • No porn. Even if you watch it on a Linux machine.
  • 4. No recent reposts
  • Everybody uses Arch btw, can't quit Vim, <loves/tolerates/hates> systemd, and wants to interject for a moment. You can stop now.
  • 5. ๐Ÿ‡ฌ๐Ÿ‡ง Language/ัะทั‹ะบ/Sprache
  • This is primarily an English-speaking community. ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ฆ๐Ÿ‡บ๐Ÿ‡บ๐Ÿ‡ธ
  • Comments written in other languages are allowed.
  • The substance of a post should be comprehensible for people who only speak English.
  • Titles and post bodies written in other languages will be allowed, but only as long as the above rule is observed.
  • ย 

    Please report posts and comments that break these rules!


    Important: never execute code or follow advice that you don't understand or can't verify, especially here. The word of the day is credibility. This is a meme community -- even the most helpful comments might just be shitposts that can damage your system. Be aware, be smart, don't remove France.

    founded 2 years ago
    MODERATORS