Background: 15 years of experience in software and apparently spoiled because it was already set up correctly.

Been practicing doing my own servers, published a test site and 24 hours later, root was compromised.

Rolled back to the backup before I made it public and now I have a security checklist.

  • kernelleA
    link
    fedilink
    arrow-up
    19
    ·
    19 hours ago

    Also does anyone still port knock these days?

    Enter Masscan, probably a net negative for the internet, so use with care.

    • davidgro@lemmy.world
      link
      fedilink
      arrow-up
      7
      ·
      17 hours ago

      I didn’t see anything about port knocking there, it rather looks like it has the opposite focus - a quote from that page is “features that support widespread scanning of many machines are supported, while in-depth scanning of single machines aren’t.”

      • kernelleA
        link
        fedilink
        arrow-up
        4
        ·
        16 hours ago

        Sure yeah it’s a discovery tool OOTB, but I’ve used it to perform specific packet sequences as well.