Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Discuss
  3. Security Recommendations...

Security Recommendations...

Scheduled Pinned Locked Moved Discuss
12 Posts 9 Posters 1.6k Views 9 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R Offline
      R Offline
      roofboard
      wrote on last edited by roofboard
      #1

      Just had my first brush up on security... a wordpress site got hacked... what a headache!

      Moving on, I am happy that Cloudron is holding up against the subsequent DDOS attack I seem to be getting pinged now over 200mm times a day, but now I need to start thinking security. Any recommendations from the community on how to beef up server security while running Cloudron?

      There are many subdomains etc to think about... Maybe this security layer would need to be installed directly on the server side by side of cloudron?

      murgeroM robiR humptydumptyH 3 Replies Last reply
      0
      • R roofboard

        Just had my first brush up on security... a wordpress site got hacked... what a headache!

        Moving on, I am happy that Cloudron is holding up against the subsequent DDOS attack I seem to be getting pinged now over 200mm times a day, but now I need to start thinking security. Any recommendations from the community on how to beef up server security while running Cloudron?

        There are many subdomains etc to think about... Maybe this security layer would need to be installed directly on the server side by side of cloudron?

        murgeroM Offline
        murgeroM Offline
        murgero
        App Dev
        wrote on last edited by
        #2

        @roofboard Cloudron security is pretty reasonable, but if you're just getting DDOS'd you can block that with a simple script.

        I've never used this, but it has a lot of stars and seems to be kept up to date when needed.

        https://github.com/anti-ddos/Anti-DDOS

        --
        https://urgero.org
        ~ Professional Nerd. Freelance Programmer. ~

        A 1 Reply Last reply
        1
        • murgeroM murgero

          @roofboard Cloudron security is pretty reasonable, but if you're just getting DDOS'd you can block that with a simple script.

          I've never used this, but it has a lot of stars and seems to be kept up to date when needed.

          https://github.com/anti-ddos/Anti-DDOS

          A Offline
          A Offline
          ApplegateR
          wrote on last edited by
          #3

          @murgero sadly owner of this bash script had left. You can check his profile link now is 404 error 😕

          Richard Applegate
          Anthem Coffee and Tea
          Joe Coffee
          IT/Administrator Server/Network

          murgeroM 1 Reply Last reply
          0
          • A ApplegateR

            @murgero sadly owner of this bash script had left. You can check his profile link now is 404 error 😕

            murgeroM Offline
            murgeroM Offline
            murgero
            App Dev
            wrote on last edited by
            #4

            @ApplegateR Looks like his profile is private cause his profile pic and description still load for me. Weird it shows a 404 instead.

            --
            https://urgero.org
            ~ Professional Nerd. Freelance Programmer. ~

            1 Reply Last reply
            0
            • R roofboard

              Just had my first brush up on security... a wordpress site got hacked... what a headache!

              Moving on, I am happy that Cloudron is holding up against the subsequent DDOS attack I seem to be getting pinged now over 200mm times a day, but now I need to start thinking security. Any recommendations from the community on how to beef up server security while running Cloudron?

              There are many subdomains etc to think about... Maybe this security layer would need to be installed directly on the server side by side of cloudron?

              robiR Offline
              robiR Offline
              robi
              wrote on last edited by
              #5

              @roofboard said in Security Recommendations...:

              a wordpress site got hacked...

              A few questions:

              Who did you piss off? 😆

              Which WP Cloudron App were you using?

              Were updates enabled? For the plugins too?

              What was changed during the hack?

              Why is it a headache? (Other than it happening)

              Have backups pre-hack to restore? Easy-peasy?

              As @murgero said, Cloudron was designed to mitigate these types of things in many ways, and getting back online is much easier thanks to that.

              Conscious tech

              1 Reply Last reply
              0
              • R roofboard

                Just had my first brush up on security... a wordpress site got hacked... what a headache!

                Moving on, I am happy that Cloudron is holding up against the subsequent DDOS attack I seem to be getting pinged now over 200mm times a day, but now I need to start thinking security. Any recommendations from the community on how to beef up server security while running Cloudron?

                There are many subdomains etc to think about... Maybe this security layer would need to be installed directly on the server side by side of cloudron?

                humptydumptyH Offline
                humptydumptyH Offline
                humptydumpty
                wrote on last edited by humptydumpty
                #6

                @roofboard Are you using Sucuri or Wordfence for that site? You might want to consider their premium offerings for DDOS protection and post-hack services.

                Either way, you need to figure out how they got in. Most likely it's a corrupt plugin.

                jdaviescoatesJ R 2 Replies Last reply
                2
                • humptydumptyH humptydumpty

                  @roofboard Are you using Sucuri or Wordfence for that site? You might want to consider their premium offerings for DDOS protection and post-hack services.

                  Either way, you need to figure out how they got in. Most likely it's a corrupt plugin.

                  jdaviescoatesJ Offline
                  jdaviescoatesJ Offline
                  jdaviescoates
                  wrote on last edited by
                  #7

                  @humptydumpty said in Security Recommendations...:

                  Wordfence

                  +1

                  The first I do with any new WordPress site is to install WordFence

                  I use Cloudron with Gandi & Hetzner

                  1 Reply Last reply
                  1
                  • humptydumptyH humptydumpty

                    @roofboard Are you using Sucuri or Wordfence for that site? You might want to consider their premium offerings for DDOS protection and post-hack services.

                    Either way, you need to figure out how they got in. Most likely it's a corrupt plugin.

                    R Offline
                    R Offline
                    roofboard
                    wrote on last edited by
                    #8

                    @humptydumpty said in Security Recommendations...:

                    for that site?

                    Thanks for all the replies, yes I am using wordfence. The whole story is that I had just spinned up and was working on a new website and (the big admit) Never changed the default password.

                    So @robi I think I just got picked up by a crawler. I caught the hack in a matter of hours, rolled to a backup and rolled passwords pretty quickly. Then I installed wordfence....

                    In the mean time it got me thinking... If I was a hacker and was able to get into xxx.aaa.bbb.ccc then I would try again on every port. So while it is easy to install a firewall and get monitoring on wordpress....

                    How do I get that monitoring for the whole server? It is a rude awakening when your VPS provider wakes you up with an unusual traffic notice....

                    subvenS scookeS robiR 3 Replies Last reply
                    0
                    • R roofboard

                      @humptydumpty said in Security Recommendations...:

                      for that site?

                      Thanks for all the replies, yes I am using wordfence. The whole story is that I had just spinned up and was working on a new website and (the big admit) Never changed the default password.

                      So @robi I think I just got picked up by a crawler. I caught the hack in a matter of hours, rolled to a backup and rolled passwords pretty quickly. Then I installed wordfence....

                      In the mean time it got me thinking... If I was a hacker and was able to get into xxx.aaa.bbb.ccc then I would try again on every port. So while it is easy to install a firewall and get monitoring on wordpress....

                      How do I get that monitoring for the whole server? It is a rude awakening when your VPS provider wakes you up with an unusual traffic notice....

                      subvenS Offline
                      subvenS Offline
                      subven
                      wrote on last edited by subven
                      #9

                      Another case that would have benefited from Custom Default Password ^^ Hope you learned from your mistake @roofboard :<

                      1 Reply Last reply
                      1
                      • R roofboard

                        @humptydumpty said in Security Recommendations...:

                        for that site?

                        Thanks for all the replies, yes I am using wordfence. The whole story is that I had just spinned up and was working on a new website and (the big admit) Never changed the default password.

                        So @robi I think I just got picked up by a crawler. I caught the hack in a matter of hours, rolled to a backup and rolled passwords pretty quickly. Then I installed wordfence....

                        In the mean time it got me thinking... If I was a hacker and was able to get into xxx.aaa.bbb.ccc then I would try again on every port. So while it is easy to install a firewall and get monitoring on wordpress....

                        How do I get that monitoring for the whole server? It is a rude awakening when your VPS provider wakes you up with an unusual traffic notice....

                        scookeS Offline
                        scookeS Offline
                        scooke
                        wrote on last edited by
                        #10

                        @roofboard afaik, Cloudron has built-in security for all the various ports that might be open. I don't think you need to install anything else as Cloudron does it all. I know I automatically set ssh to allow only a non-root sudo user to login with only a key, but Cloudron has had no problem installing with around that.

                        A life lived in fear is a life half-lived

                        1 Reply Last reply
                        0
                        • R roofboard

                          @humptydumpty said in Security Recommendations...:

                          for that site?

                          Thanks for all the replies, yes I am using wordfence. The whole story is that I had just spinned up and was working on a new website and (the big admit) Never changed the default password.

                          So @robi I think I just got picked up by a crawler. I caught the hack in a matter of hours, rolled to a backup and rolled passwords pretty quickly. Then I installed wordfence....

                          In the mean time it got me thinking... If I was a hacker and was able to get into xxx.aaa.bbb.ccc then I would try again on every port. So while it is easy to install a firewall and get monitoring on wordpress....

                          How do I get that monitoring for the whole server? It is a rude awakening when your VPS provider wakes you up with an unusual traffic notice....

                          robiR Offline
                          robiR Offline
                          robi
                          wrote on last edited by robi
                          #11

                          @roofboard said in Security Recommendations...:

                          So @robi I think I just got picked up by a crawler. I caught the hack in a matter of hours,

                          Yep, can't be lazy, as botnets are scanning the entire IP space for targets constantly.

                          And yes, many revisit previous active targets for more interesting exploits for a short time before moving on.

                          So order of operations and not skipping crucial initial steps is important 😇

                          It happens. 🤷 Lesson learned.

                          Could have been worse if you were not on Cloudron.

                          Conscious tech

                          1 Reply Last reply
                          2
                          • L Offline
                            L Offline
                            LoudLemur
                            wrote on last edited by
                            #12

                            https://attack.mitre.org/

                            1 Reply Last reply
                            0
                            Reply
                            • Reply as topic
                            Log in to reply
                            • Oldest to Newest
                            • Newest to Oldest
                            • Most Votes


                              • Login

                              • Don't have an account? Register

                              • Login or register to search.
                              • First post
                                Last post
                              0
                              • Categories
                              • Recent
                              • Tags
                              • Popular
                              • Bookmarks
                              • Search