Background: 15 years of experience in software and apparently spoiled because it was already set up correctly.

Been practicing doing my own servers, published a test site and 24 hours later, root was compromised.

Rolled back to the backup before I made it public and now I have a security checklist.

  • smiletolerantly@awful.systems
    link
    fedilink
    arrow-up
    9
    ·
    2 days ago

    Meh. Each service in its isolated VM and subnet. Plus just generally a good firewall setup. Currently hosting ~10 services plubicly, never had any issue.

    • ikidd@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      1 day ago

      Well, if you actually do that, bully for you, that’s how that should be done if you have to expose services.

      Everyone else there is probably DMZing their desktop from what I can tell.