<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Security issue when installing&#x2F;restore Cloudron on same VPS?]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I was thinking about the following scenario (i.e. whenever you want to have restore or a 'clean upgrade' to Ubuntu 20.04 on the <strong>same VPS/IP</strong>) but it might lead to a security issue?</p>
<ol>
<li>On a VPS you have a running Cloudron with traffic</li>
<li>You have a very recent external backup to use for restore</li>
<li>Wipe/format the SSD of your VPS and do a clean install of Ubuntu with or without Cloudron-image (if without, install Cloudron manually)</li>
<li><strong>After Cloudron install you have the situation that every visitor of every app (i.e. high traffic Wordpress sites) will end up in the Cloudron Domain Setup and can mess up whatever they want because DNS of all (sub-)domains are still present and resolves to IP</strong></li>
</ol>
<p dir="auto">What I would like to see is that after Cloudron install, the response on the IP-only is a decent "Coming soon" page (un-branded) and a special "hidden" URL (there is already the setupdns.html) where the admin can start configuring and restoring? It's also much nicer for "clean installs", it prevents "old" IP traffic or crawlers from running into setup?</p>
]]></description><link>https://forum.cloudron.io/topic/3993/security-issue-when-installing-restore-cloudron-on-same-vps</link><generator>RSS for Node</generator><lastBuildDate>Tue, 14 Apr 2026 06:53:24 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/3993.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 16 Dec 2020 13:54:45 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Security issue when installing&#x2F;restore Cloudron on same VPS? on Thu, 17 Dec 2020 21:43:15 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> thanks again for this!</p>
]]></description><link>https://forum.cloudron.io/post/21929</link><guid isPermaLink="true">https://forum.cloudron.io/post/21929</guid><dc:creator><![CDATA[imc67]]></dc:creator><pubDate>Thu, 17 Dec 2020 21:43:15 GMT</pubDate></item><item><title><![CDATA[Reply to Security issue when installing&#x2F;restore Cloudron on same VPS? on Thu, 17 Dec 2020 02:12:02 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/imc67" aria-label="Profile: imc67">@<bdi>imc67</bdi></a> The "coming soon" seems like a bug.</p>
<p dir="auto">I have opened <a href="https://git.cloudron.io/cloudron/box/-/issues/751" target="_blank" rel="noopener noreferrer nofollow ugc">https://git.cloudron.io/cloudron/box/-/issues/751</a> and <a href="https://git.cloudron.io/cloudron/box/-/issues/752" target="_blank" rel="noopener noreferrer nofollow ugc">https://git.cloudron.io/cloudron/box/-/issues/752</a> for next release.</p>
]]></description><link>https://forum.cloudron.io/post/21814</link><guid isPermaLink="true">https://forum.cloudron.io/post/21814</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Thu, 17 Dec 2020 02:12:02 GMT</pubDate></item><item><title><![CDATA[Reply to Security issue when installing&#x2F;restore Cloudron on same VPS? on Wed, 16 Dec 2020 21:20:22 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> that would be great, but even better in combination with on bare IP a "coming soon" page and setup on a specific URL.</p>
]]></description><link>https://forum.cloudron.io/post/21801</link><guid isPermaLink="true">https://forum.cloudron.io/post/21801</guid><dc:creator><![CDATA[imc67]]></dc:creator><pubDate>Wed, 16 Dec 2020 21:20:22 GMT</pubDate></item><item><title><![CDATA[Reply to Security issue when installing&#x2F;restore Cloudron on same VPS? on Wed, 16 Dec 2020 21:00:05 GMT]]></title><description><![CDATA[<p dir="auto">For the aws marketplace, we already implement this with asking for the ec2 instance id during setup.</p>
<p dir="auto">I guess for a start, we can have an option in the setup script to generate a passphrase and then maybe make this the default in a future release?</p>
]]></description><link>https://forum.cloudron.io/post/21800</link><guid isPermaLink="true">https://forum.cloudron.io/post/21800</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Wed, 16 Dec 2020 21:00:05 GMT</pubDate></item><item><title><![CDATA[Reply to Security issue when installing&#x2F;restore Cloudron on same VPS? on Wed, 16 Dec 2020 17:27:34 GMT]]></title><description><![CDATA[<p dir="auto">The cleanest solution, from a security standpoint, would be to display a random password in the terminal when installing Cloudron, that would be required by the server setup page.</p>
<p dir="auto">Pre-installed Cloudron images would need to have a set password, so be a bit less secure, but it still would be good.</p>
]]></description><link>https://forum.cloudron.io/post/21774</link><guid isPermaLink="true">https://forum.cloudron.io/post/21774</guid><dc:creator><![CDATA[mehdi]]></dc:creator><pubDate>Wed, 16 Dec 2020 17:27:34 GMT</pubDate></item><item><title><![CDATA[Reply to Security issue when installing&#x2F;restore Cloudron on same VPS? on Wed, 16 Dec 2020 14:57:52 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/imc67" aria-label="Profile: imc67">@<bdi>imc67</bdi></a> I just migrated a Cloudron server between cloud providers with a restore, and my solution was to serve downtime / maintenance pages from the edge of the Cloudflare network. Worked flawlessly. Without Cloudflare in the mix (I know folks have very mixed opinions), you could just pull a new IP for the box (DNS will be auto-updated to the new one upon restore) so that the old one just 404s, or you could use firewall rules at the provider or box level to restrict inbound traffic to your management network temporarily.</p>
<p dir="auto">This is mostly just to lay out the current options - there may well be merit to the obscure URL trick as well, and that's worth considering in <a href="https://forum.cloudron.io/category/97/feature-requests">Feature Requests</a> perhaps as well for further discussion.</p>
]]></description><link>https://forum.cloudron.io/post/21766</link><guid isPermaLink="true">https://forum.cloudron.io/post/21766</guid><dc:creator><![CDATA[jimcavoli]]></dc:creator><pubDate>Wed, 16 Dec 2020 14:57:52 GMT</pubDate></item></channel></rss>