Background: 15 years of experience in software and apparently spoiled because it was already set up correctly.

Been practicing doing my own servers, published a test site and 24 hours later, root was compromised.

Rolled back to the backup before I made it public and now I have a security checklist.

you are viewing a single comment's thread
view the rest of the comments

Did all that, minus the no ssh root login (only key, obviously) plus one failed attempt, fail2ban permaban.

Have not had any issues, ever

  • source
  • parent