The moment you start a new server, bots can (and will) discover and scan it. Most of the attacks are lazy: the bots are looking for password logins and default admin accounts.
Do these two things to protect yourself:
→ SSH keys instead of passwords. A bot can guess a password. It cannot brute-force a key.
→ A normal user with sudo instead of root for everything. One compromised session shouldn't hand over the whole machine.
Keep your system up to date to prevent bugs from being exploited, run a firewall, and let fail2ban ban the repeat knockers.
Full 6-step walkthrough with every command: https://www.doprax.com/tutorial/how-to-secure-a-new-linux-server-in-6-steps
Post #66
1.56K
