Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Discuss
  3. Security Recommendations...

Security Recommendations...

Scheduled Pinned Locked Moved Discuss
12 Posts 9 Posters 1.7k Views 9 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • R Offline
    R Offline
    roofboard
    wrote on last edited by roofboard
    #1

    Just had my first brush up on security... a wordpress site got hacked... what a headache!

    Moving on, I am happy that Cloudron is holding up against the subsequent DDOS attack I seem to be getting pinged now over 200mm times a day, but now I need to start thinking security. Any recommendations from the community on how to beef up server security while running Cloudron?

    There are many subdomains etc to think about... Maybe this security layer would need to be installed directly on the server side by side of cloudron?

    murgeroM robiR humptydumptyH 3 Replies Last reply
    0
    • R roofboard

      Just had my first brush up on security... a wordpress site got hacked... what a headache!

      Moving on, I am happy that Cloudron is holding up against the subsequent DDOS attack I seem to be getting pinged now over 200mm times a day, but now I need to start thinking security. Any recommendations from the community on how to beef up server security while running Cloudron?

      There are many subdomains etc to think about... Maybe this security layer would need to be installed directly on the server side by side of cloudron?

      murgeroM Offline
      murgeroM Offline
      murgero
      App Dev
      wrote on last edited by
      #2

      @roofboard Cloudron security is pretty reasonable, but if you're just getting DDOS'd you can block that with a simple script.

      I've never used this, but it has a lot of stars and seems to be kept up to date when needed.

      https://github.com/anti-ddos/Anti-DDOS

      --
      https://urgero.org
      ~ Professional Nerd. Freelance Programmer. ~

      A 1 Reply Last reply
      1
      • murgeroM murgero

        @roofboard Cloudron security is pretty reasonable, but if you're just getting DDOS'd you can block that with a simple script.

        I've never used this, but it has a lot of stars and seems to be kept up to date when needed.

        https://github.com/anti-ddos/Anti-DDOS

        A Offline
        A Offline
        ApplegateR
        wrote on last edited by
        #3

        @murgero sadly owner of this bash script had left. You can check his profile link now is 404 error 😕

        Richard Applegate
        Anthem Coffee and Tea
        Joe Coffee
        IT/Administrator Server/Network

        murgeroM 1 Reply Last reply
        0
        • A ApplegateR

          @murgero sadly owner of this bash script had left. You can check his profile link now is 404 error 😕

          murgeroM Offline
          murgeroM Offline
          murgero
          App Dev
          wrote on last edited by
          #4

          @ApplegateR Looks like his profile is private cause his profile pic and description still load for me. Weird it shows a 404 instead.

          --
          https://urgero.org
          ~ Professional Nerd. Freelance Programmer. ~

          1 Reply Last reply
          0
          • R roofboard

            Just had my first brush up on security... a wordpress site got hacked... what a headache!

            Moving on, I am happy that Cloudron is holding up against the subsequent DDOS attack I seem to be getting pinged now over 200mm times a day, but now I need to start thinking security. Any recommendations from the community on how to beef up server security while running Cloudron?

            There are many subdomains etc to think about... Maybe this security layer would need to be installed directly on the server side by side of cloudron?

            robiR Offline
            robiR Offline
            robi
            wrote on last edited by
            #5

            @roofboard said in Security Recommendations...:

            a wordpress site got hacked...

            A few questions:

            Who did you piss off? 😆

            Which WP Cloudron App were you using?

            Were updates enabled? For the plugins too?

            What was changed during the hack?

            Why is it a headache? (Other than it happening)

            Have backups pre-hack to restore? Easy-peasy?

            As @murgero said, Cloudron was designed to mitigate these types of things in many ways, and getting back online is much easier thanks to that.

            Conscious tech

            1 Reply Last reply
            0
            • R roofboard

              Just had my first brush up on security... a wordpress site got hacked... what a headache!

              Moving on, I am happy that Cloudron is holding up against the subsequent DDOS attack I seem to be getting pinged now over 200mm times a day, but now I need to start thinking security. Any recommendations from the community on how to beef up server security while running Cloudron?

              There are many subdomains etc to think about... Maybe this security layer would need to be installed directly on the server side by side of cloudron?

              humptydumptyH Offline
              humptydumptyH Offline
              humptydumpty
              wrote on last edited by humptydumpty
              #6

              @roofboard Are you using Sucuri or Wordfence for that site? You might want to consider their premium offerings for DDOS protection and post-hack services.

              Either way, you need to figure out how they got in. Most likely it's a corrupt plugin.

              jdaviescoatesJ R 2 Replies Last reply
              2
              • humptydumptyH humptydumpty

                @roofboard Are you using Sucuri or Wordfence for that site? You might want to consider their premium offerings for DDOS protection and post-hack services.

                Either way, you need to figure out how they got in. Most likely it's a corrupt plugin.

                jdaviescoatesJ Online
                jdaviescoatesJ Online
                jdaviescoates
                wrote on last edited by
                #7

                @humptydumpty said in Security Recommendations...:

                Wordfence

                +1

                The first I do with any new WordPress site is to install WordFence

                I use Cloudron with Gandi & Hetzner

                1 Reply Last reply
                1
                • humptydumptyH humptydumpty

                  @roofboard Are you using Sucuri or Wordfence for that site? You might want to consider their premium offerings for DDOS protection and post-hack services.

                  Either way, you need to figure out how they got in. Most likely it's a corrupt plugin.

                  R Offline
                  R Offline
                  roofboard
                  wrote on last edited by
                  #8

                  @humptydumpty said in Security Recommendations...:

                  for that site?

                  Thanks for all the replies, yes I am using wordfence. The whole story is that I had just spinned up and was working on a new website and (the big admit) Never changed the default password.

                  So @robi I think I just got picked up by a crawler. I caught the hack in a matter of hours, rolled to a backup and rolled passwords pretty quickly. Then I installed wordfence....

                  In the mean time it got me thinking... If I was a hacker and was able to get into xxx.aaa.bbb.ccc then I would try again on every port. So while it is easy to install a firewall and get monitoring on wordpress....

                  How do I get that monitoring for the whole server? It is a rude awakening when your VPS provider wakes you up with an unusual traffic notice....

                  subvenS scookeS robiR 3 Replies Last reply
                  0
                  • R roofboard

                    @humptydumpty said in Security Recommendations...:

                    for that site?

                    Thanks for all the replies, yes I am using wordfence. The whole story is that I had just spinned up and was working on a new website and (the big admit) Never changed the default password.

                    So @robi I think I just got picked up by a crawler. I caught the hack in a matter of hours, rolled to a backup and rolled passwords pretty quickly. Then I installed wordfence....

                    In the mean time it got me thinking... If I was a hacker and was able to get into xxx.aaa.bbb.ccc then I would try again on every port. So while it is easy to install a firewall and get monitoring on wordpress....

                    How do I get that monitoring for the whole server? It is a rude awakening when your VPS provider wakes you up with an unusual traffic notice....

                    subvenS Offline
                    subvenS Offline
                    subven
                    wrote on last edited by subven
                    #9

                    Another case that would have benefited from Custom Default Password ^^ Hope you learned from your mistake @roofboard :<

                    1 Reply Last reply
                    1
                    • R roofboard

                      @humptydumpty said in Security Recommendations...:

                      for that site?

                      Thanks for all the replies, yes I am using wordfence. The whole story is that I had just spinned up and was working on a new website and (the big admit) Never changed the default password.

                      So @robi I think I just got picked up by a crawler. I caught the hack in a matter of hours, rolled to a backup and rolled passwords pretty quickly. Then I installed wordfence....

                      In the mean time it got me thinking... If I was a hacker and was able to get into xxx.aaa.bbb.ccc then I would try again on every port. So while it is easy to install a firewall and get monitoring on wordpress....

                      How do I get that monitoring for the whole server? It is a rude awakening when your VPS provider wakes you up with an unusual traffic notice....

                      scookeS Offline
                      scookeS Offline
                      scooke
                      wrote on last edited by
                      #10

                      @roofboard afaik, Cloudron has built-in security for all the various ports that might be open. I don't think you need to install anything else as Cloudron does it all. I know I automatically set ssh to allow only a non-root sudo user to login with only a key, but Cloudron has had no problem installing with around that.

                      A life lived in fear is a life half-lived

                      1 Reply Last reply
                      0
                      • R roofboard

                        @humptydumpty said in Security Recommendations...:

                        for that site?

                        Thanks for all the replies, yes I am using wordfence. The whole story is that I had just spinned up and was working on a new website and (the big admit) Never changed the default password.

                        So @robi I think I just got picked up by a crawler. I caught the hack in a matter of hours, rolled to a backup and rolled passwords pretty quickly. Then I installed wordfence....

                        In the mean time it got me thinking... If I was a hacker and was able to get into xxx.aaa.bbb.ccc then I would try again on every port. So while it is easy to install a firewall and get monitoring on wordpress....

                        How do I get that monitoring for the whole server? It is a rude awakening when your VPS provider wakes you up with an unusual traffic notice....

                        robiR Offline
                        robiR Offline
                        robi
                        wrote on last edited by robi
                        #11

                        @roofboard said in Security Recommendations...:

                        So @robi I think I just got picked up by a crawler. I caught the hack in a matter of hours,

                        Yep, can't be lazy, as botnets are scanning the entire IP space for targets constantly.

                        And yes, many revisit previous active targets for more interesting exploits for a short time before moving on.

                        So order of operations and not skipping crucial initial steps is important 😇

                        It happens. 🤷 Lesson learned.

                        Could have been worse if you were not on Cloudron.

                        Conscious tech

                        1 Reply Last reply
                        2
                        • L Offline
                          L Offline
                          LoudLemur
                          wrote on last edited by
                          #12

                          https://attack.mitre.org/

                          1 Reply Last reply
                          0
                          Reply
                          • Reply as topic
                          Log in to reply
                          • Oldest to Newest
                          • Newest to Oldest
                          • Most Votes


                          • Login

                          • Don't have an account? Register

                          • Login or register to search.
                          • First post
                            Last post
                          0
                          • Categories
                          • Recent
                          • Tags
                          • Popular
                          • Bookmarks
                          • Search