#server-security — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #server-security, aggregated by home.social.
-
How to Stay Protected
XMRig Malware Campaigns Target Businesses
Cybersecurity threats continue to evolve, and one of the most persistent threats facing businesses today involves cybercriminals abusing the popular XMRig mining software. While XMRig is a legitimate, open-source cryptocurrency miner used by many enthusiasts to mine Monero (XMR), attackers frequently modify or secretly install it on corporate computers to generate profits without the owner’s knowledge.
In this article, we’ll explain how XMRig is being misused in corporate environments, the risks to businesses, how these attacks work, and the best practices to prevent them.
What Is XMRig?
XMRig is a free and open-source CPU and GPU miner designed primarily for mining Monero (XMR). It is widely respected within the cryptocurrency community because it is efficient, actively maintained, and available for Windows, Linux, and macOS.
By itself, XMRig is not malware. However, cybercriminals often bundle modified versions of XMRig with malicious software or deploy it after compromising a computer.
Why Are Businesses Being Targeted?
Corporate environments provide an attractive opportunity for attackers because they often contain:
- High-performance desktop computers
- Powerful servers
- Multiple workstations
- Cloud infrastructure
- Continuous internet connectivity
Instead of mining cryptocurrency on their own hardware, attackers infect company devices and secretly use the organisation’s computing power.
The result is free cryptocurrency mining at the company’s expense.
How XMRig Malware Gets Installed
Most unauthorised XMRig installations begin after another security weakness has already been exploited.
Common infection methods include:
- Phishing emails containing malicious attachments
- Fake software downloads
- Exploitation of unpatched vulnerabilities
- Weak Remote Desktop Protocol (RDP) passwords
- Stolen administrator credentials
- Trojan malware that downloads additional payloads
Once attackers gain access, they silently install XMRig and configure it to connect to their own mining pools.
Warning Signs of an XMRig Infection
Many organisations discover mining malware only after performance problems become noticeable.
Common symptoms include:
- Constantly high CPU usage
- Increased electricity consumption
- Slow computers
- Loud cooling fans
- Servers running hotter than normal
- Unknown scheduled tasks
- Unexpected outbound network traffic
- Security software being disabled
Some attackers even configure XMRig to stop mining whenever a user opens Task Manager, making detection more difficult.
Business Impact
Although cryptojacking usually does not encrypt files like ransomware, it can still cause significant operational issues.
Potential consequences include:
Reduced Productivity
Employees experience slower computers, affecting daily work.
Higher Operating Costs
Mining consumes CPU resources and electricity around the clock.
Hardware Wear
Continuous high CPU usage can shorten the lifespan of processors, cooling systems, and power supplies.
Security Risks
An XMRig infection often indicates that attackers already have unauthorised access to the network, meaning sensitive business data may also be at risk.
How Organisations Can Protect Themselves
Preventing cryptojacking requires multiple layers of security.
Keep Systems Updated
Install security updates for Windows, Linux, browsers, and all business software as soon as practical.
Use Endpoint Protection
Modern antivirus and endpoint detection solutions can identify suspicious mining behaviour before it becomes widespread.
Enable Multi-Factor Authentication
Protect administrator accounts and remote access services with MFA wherever possible.
Monitor CPU Usage
Investigate unexplained spikes in processor utilisation, especially outside business hours.
Restrict Administrative Privileges
Limit local administrator permissions to reduce the impact of compromised accounts.
Educate Employees
Regular cybersecurity awareness training helps staff recognise phishing emails and other social engineering attacks.
Is XMRig Dangerous?
The software itself is completely legitimate.
The danger comes from unauthorised installation and misuse by attackers.
Many security vendors detect unauthorised XMRig deployments because they are commonly associated with cryptojacking campaigns rather than because the software itself is malicious.
Best Practices for IT Teams
Organisations should adopt a proactive security strategy by:
- Regularly auditing endpoints
- Monitoring unusual network connections
- Reviewing scheduled tasks and startup entries
- Enforcing least-privilege access
- Conducting vulnerability scans
- Backing up critical business data
- Implementing continuous security monitoring
Early detection significantly reduces the financial and operational impact of mining malware.
Final Thoughts
Cryptocurrency mining software like XMRig serves legitimate purposes for individuals and organisations that choose to mine digital assets. However, when cybercriminals secretly deploy XMRig on corporate systems, it becomes part of a cryptojacking attack that wastes resources, increases costs, and may signal a broader security compromise.
Businesses should combine strong cybersecurity practices, employee awareness, regular patching, and continuous monitoring to minimise the risk of unauthorised mining software running within their networks.
By understanding how these attacks operate and responding quickly to suspicious activity, organisations can better protect their infrastructure, maintain productivity, and reduce the likelihood of future compromises.
Frequently Asked Questions
Is XMRig malware?
No. XMRig is legitimate open-source cryptocurrency mining software. It only becomes part of malicious activity when attackers install it without permission.
What cryptocurrency does XMRig mine?
It is primarily designed to mine Monero (XMR) using the RandomX algorithm.
Can antivirus detect XMRig?
Many security products detect unauthorised XMRig installations because they are commonly used in cryptojacking attacks.
How can I tell if my computer is mining cryptocurrency?
Persistent high CPU usage, overheating, increased fan noise, slow performance, and unexplained network connections can all indicate possible cryptojacking.
#Technology #ai #businessSecurity #corporateSecurity #cpuMining #cryptoMalware #cryptocurrencyMining #cryptojacking #cyberSecurity #cyberThreats #cyberSecurity #cybersecurity #dataProtection #endpointSecurity #enterpriseCybersecurity #ITSecurity #LinuxSecurity #malwareDetection #malwareProtection #miningMalware #Monero #MoneroMiner #MoneroMining #networkSecurity #phishingAttacks #RandomX #ransomware #security #securityAwareness #serverSecurity #WindowsSecurity #XMRig #XMRigMalware #XMRigMiner -
How to Stay Protected
XMRig Malware Campaigns Target Businesses
Cybersecurity threats continue to evolve, and one of the most persistent threats facing businesses today involves cybercriminals abusing the popular XMRig mining software. While XMRig is a legitimate, open-source cryptocurrency miner used by many enthusiasts to mine Monero (XMR), attackers frequently modify or secretly install it on corporate computers to generate profits without the owner’s knowledge.
In this article, we’ll explain how XMRig is being misused in corporate environments, the risks to businesses, how these attacks work, and the best practices to prevent them.
What Is XMRig?
XMRig is a free and open-source CPU and GPU miner designed primarily for mining Monero (XMR). It is widely respected within the cryptocurrency community because it is efficient, actively maintained, and available for Windows, Linux, and macOS.
By itself, XMRig is not malware. However, cybercriminals often bundle modified versions of XMRig with malicious software or deploy it after compromising a computer.
Why Are Businesses Being Targeted?
Corporate environments provide an attractive opportunity for attackers because they often contain:
- High-performance desktop computers
- Powerful servers
- Multiple workstations
- Cloud infrastructure
- Continuous internet connectivity
Instead of mining cryptocurrency on their own hardware, attackers infect company devices and secretly use the organisation’s computing power.
The result is free cryptocurrency mining at the company’s expense.
How XMRig Malware Gets Installed
Most unauthorised XMRig installations begin after another security weakness has already been exploited.
Common infection methods include:
- Phishing emails containing malicious attachments
- Fake software downloads
- Exploitation of unpatched vulnerabilities
- Weak Remote Desktop Protocol (RDP) passwords
- Stolen administrator credentials
- Trojan malware that downloads additional payloads
Once attackers gain access, they silently install XMRig and configure it to connect to their own mining pools.
Warning Signs of an XMRig Infection
Many organisations discover mining malware only after performance problems become noticeable.
Common symptoms include:
- Constantly high CPU usage
- Increased electricity consumption
- Slow computers
- Loud cooling fans
- Servers running hotter than normal
- Unknown scheduled tasks
- Unexpected outbound network traffic
- Security software being disabled
Some attackers even configure XMRig to stop mining whenever a user opens Task Manager, making detection more difficult.
Business Impact
Although cryptojacking usually does not encrypt files like ransomware, it can still cause significant operational issues.
Potential consequences include:
Reduced Productivity
Employees experience slower computers, affecting daily work.
Higher Operating Costs
Mining consumes CPU resources and electricity around the clock.
Hardware Wear
Continuous high CPU usage can shorten the lifespan of processors, cooling systems, and power supplies.
Security Risks
An XMRig infection often indicates that attackers already have unauthorised access to the network, meaning sensitive business data may also be at risk.
How Organisations Can Protect Themselves
Preventing cryptojacking requires multiple layers of security.
Keep Systems Updated
Install security updates for Windows, Linux, browsers, and all business software as soon as practical.
Use Endpoint Protection
Modern antivirus and endpoint detection solutions can identify suspicious mining behaviour before it becomes widespread.
Enable Multi-Factor Authentication
Protect administrator accounts and remote access services with MFA wherever possible.
Monitor CPU Usage
Investigate unexplained spikes in processor utilisation, especially outside business hours.
Restrict Administrative Privileges
Limit local administrator permissions to reduce the impact of compromised accounts.
Educate Employees
Regular cybersecurity awareness training helps staff recognise phishing emails and other social engineering attacks.
Is XMRig Dangerous?
The software itself is completely legitimate.
The danger comes from unauthorised installation and misuse by attackers.
Many security vendors detect unauthorised XMRig deployments because they are commonly associated with cryptojacking campaigns rather than because the software itself is malicious.
Best Practices for IT Teams
Organisations should adopt a proactive security strategy by:
- Regularly auditing endpoints
- Monitoring unusual network connections
- Reviewing scheduled tasks and startup entries
- Enforcing least-privilege access
- Conducting vulnerability scans
- Backing up critical business data
- Implementing continuous security monitoring
Early detection significantly reduces the financial and operational impact of mining malware.
Final Thoughts
Cryptocurrency mining software like XMRig serves legitimate purposes for individuals and organisations that choose to mine digital assets. However, when cybercriminals secretly deploy XMRig on corporate systems, it becomes part of a cryptojacking attack that wastes resources, increases costs, and may signal a broader security compromise.
Businesses should combine strong cybersecurity practices, employee awareness, regular patching, and continuous monitoring to minimise the risk of unauthorised mining software running within their networks.
By understanding how these attacks operate and responding quickly to suspicious activity, organisations can better protect their infrastructure, maintain productivity, and reduce the likelihood of future compromises.
Frequently Asked Questions
Is XMRig malware?
No. XMRig is legitimate open-source cryptocurrency mining software. It only becomes part of malicious activity when attackers install it without permission.
What cryptocurrency does XMRig mine?
It is primarily designed to mine Monero (XMR) using the RandomX algorithm.
Can antivirus detect XMRig?
Many security products detect unauthorised XMRig installations because they are commonly used in cryptojacking attacks.
How can I tell if my computer is mining cryptocurrency?
Persistent high CPU usage, overheating, increased fan noise, slow performance, and unexplained network connections can all indicate possible cryptojacking.
#Technology #ai #businessSecurity #corporateSecurity #cpuMining #cryptoMalware #cryptocurrencyMining #cryptojacking #cyberSecurity #cyberThreats #cyberSecurity #cybersecurity #dataProtection #endpointSecurity #enterpriseCybersecurity #ITSecurity #LinuxSecurity #malwareDetection #malwareProtection #miningMalware #Monero #MoneroMiner #MoneroMining #networkSecurity #phishingAttacks #RandomX #ransomware #security #securityAwareness #serverSecurity #WindowsSecurity #XMRig #XMRigMalware #XMRigMiner -
Unlocking Fully Encrypted Servers over Tor
Remote servers should not have to choose between security and availability.
For years, the common compromise has been to expose SSH to the public Internet or to rely on VPNs and provider-specific KVM consoles whenever a LUKS-encrypted server reboots.
I believe there is a better approach.
By combining LUKS, Tor Onion Services, and a lightweight SSH server running directly inside the initramfs, it is possible to build servers that remain fully encrypted at rest, yet can always be unlocked remotely without exposing any public management interface.
This article describes the concept and how it could evolve into a reusable feature for Infinito.Nexus.
The Problem
Full disk encryption protects data when a server is powered off.
However, after every reboot someone must enter the LUKS passphrase.
For remote dedicated servers this usually means one of the following:
- opening SSH to the Internet
- connecting through a VPN
- using a provider’s KVM/IPMI console
- booting into a rescue system
While remote unlocking via Dropbear inside the initramfs is already a well-known solution, it still typically relies on a publicly reachable IP address.
The Idea
Instead of exposing SSH publicly, start Tor directly inside the initramfs.
The boot sequence would look like this:
Server boots
│
▼
Kernel + initramfs
│
▼
Network initialization
│
▼
Tor starts
│
▼
Temporary Onion Service appears
unlock-xxxxxxxx.onion
│
▼
SSH via Tor
│
▼
cryptsetup luksOpen
│
▼
Root filesystem unlocked
│
▼
Operating system boots
│
▼
Temporary Onion Service disappearsThe administrator simply connects through Tor:
torsocks ssh [email protected]After entering the LUKS passphrase, the operating system continues booting normally.
Separate Identities for Boot and Runtime
One of the strongest aspects of this design is that boot-time and runtime use different Onion identities.
Boot environment
- dedicated Ed25519 key
- dedicated Onion address
- only SSH
- exists only during boot
Example:
unlock-xxxxxxxx.onionRuntime environment
Once the operating system has booted:
- the initramfs exits
- Tor inside initramfs stops
- a new Tor instance starts
- completely different Onion addresses become available
For example:
ssh-xxxxxxxx.onion
cloud-xxxxxxxx.onion
matrix-xxxxxxxx.onion
mail-xxxxxxxx.onionThe unlock address simply disappears.
This cleanly separates the trust boundaries between the bootloader environment and the running operating system.
Why Tor?
Using Tor instead of exposing SSH directly provides several advantages:
- no public IP address required
- no exposed SSH port
- no VPN infrastructure
- works behind NAT or Carrier-Grade NAT
- management interface is only reachable through the Tor network
- additional network privacy
- ideal for self-hosted infrastructure
This is particularly attractive for servers hosted in data centers where administrators rarely have physical access.
What Happens After a Crash?
Whenever the server reboots:
- the initramfs starts
- networking is initialized
- Tor publishes the temporary Onion Service
- you connect via SSH
- you unlock LUKS
- the server continues booting
No KVM console.
No VPN.
No public SSH endpoint.
Only Tor.
Of course, catastrophic failures such as a broken initramfs or missing network drivers still require traditional recovery methods such as a rescue system or KVM.
Existing Building Blocks
Most of the required components already exist today.
My repository hetzner-arch-luks demonstrates how to deploy Arch Linux with full disk encryption on Hetzner servers and configure remote unlocking via SSH during the initramfs stage.
Repository:
https://github.com/kevinveenbirkenbach/hetzner-arch-luks
Another project, linux-image-manager, automates the creation and customization of Linux images and could serve as the foundation for embedding Tor, Dropbear/TinySSH, and the required initramfs configuration into reusable images.
Repository:
https://github.com/kevinveenbirkenbach/linux-image-manager
Together, these repositories provide much of the groundwork required for a fully automated implementation.
Future Integration into Infinito.Nexus
I envision this becoming a native feature of Infinito.Nexus.
Provisioning a server could automatically:
- install Arch Linux
- configure LUKS full disk encryption
- generate an initramfs containing:
- Tor
- Dropbear or TinySSH
- cryptsetup
- create a dedicated boot-time Onion Service
- automatically switch to permanent runtime Onion Services after successful boot
From the administrator’s perspective, recovering a rebooted server would be as simple as:
torsocks ssh root@unlock-<hostname>.onionEnter the passphrase.
The server continues booting.
Nothing is ever exposed to the public Internet.
Looking Ahead
This concept combines three mature technologies:
- LUKS
- Tor Onion Services
- Remote initramfs unlocking
While each technology already exists independently, integrating them into a seamless provisioning workflow could significantly improve the security and usability of encrypted self-hosted infrastructure.
For projects focused on digital sovereignty and privacy, removing the need for publicly exposed management interfaces is a natural next step.
#ArchLinux #cryptsetup #Cybersecurity #DevOps #DigitalSovereignty #DiskEncryption #Dropbear #FullDiskEncryption #Hetzner #InfinitoNexus #InfrastructureAsCode #initramfs #Linux #LinuxSecurity #LUKS #OnionServices #OpenSource #Privacy #RemoteLUKSUnlock #RemoteServerManagement #RemoteUnlock #SecureBoot #SelfHostedInfrastructure #SelfHosting #ServerSecurity #SSHOverTor #TinySSH #Tor #TorHiddenServices -
A secure Linux hosting environment is rarely the result of one setting or one security tool.
Strong hardening comes from reducing attack surface, tightening access controls, keeping systems updated, securing the web stack, and maintaining visibility through monitoring and logs.
Read more: https://olvy.io/eoS4L
#Linux #LinuxHosting #ServerSecurity #WebsiteSecurity #ManagedHosting
-
CW: Human+AI
It is quite concerning to see how quickly the CVE 2026 48172 security flaw is being exploited. CISA has issued a very tight deadline for patching because this LiteSpeed User End cPanel Plugin vulnerability is a serious risk for anyone on shared hosting. You can find more details and a fix guide at https://gwizit.com/go/YjiP5Pe to help secure your site.
-
🛡️ Oh look, another thrilling #update on how your beloved #Nginx can turn into a #cybersecurity disaster waiting to happen! 🎉 Kudos to the internet heroes who found these digital booby traps—just don’t forget to #patch them up before your server becomes a hacker’s playground! 🙄🔧
https://nginx.org/en/CHANGES #Vulnerability #InternetHeroes #ServerSecurity #HackerNews #ngated -
🛡️ Oh look, another thrilling #update on how your beloved #Nginx can turn into a #cybersecurity disaster waiting to happen! 🎉 Kudos to the internet heroes who found these digital booby traps—just don’t forget to #patch them up before your server becomes a hacker’s playground! 🙄🔧
https://nginx.org/en/CHANGES #Vulnerability #InternetHeroes #ServerSecurity #HackerNews #ngated -
CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers
#HackerNews #CPanel #Vulnerabilities #BlackWeek #Cybersecurity #Ransomware #ServerSecurity
-
CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers
#HackerNews #CPanel #Vulnerabilities #BlackWeek #Cybersecurity #Ransomware #ServerSecurity
-
Sicherheitslücke in cPanel: So schützt du deinen Webserver vor CVE-2026-41940
#technews #cybersecurity #sysadmin #cpanel #serversecurity #webhosting
-
cPanel Discloses Authentication Flaw, Urges Immediate Server Updates
cPanel has uncovered a critical authentication flaw that could let hackers gain unauthorized access to your control panel, and is urging immediate server updates to protect against this threat. Check if your version is vulnerable and update to a patched build right away.
#Cpanel #AuthenticationFlaw #ServerSecurity #ControlPanelExploit #EmergingThreats
-
Ah, the thrilling saga of cosmic whispers! 🚀 Too bad it's more like a muted scream from Antarctica's ice, blocked by a 400 Bad Request. 🔒 Even the universe can't penetrate the impenetrable fortress of server security — cosmic irony at its finest. 🙄
https://phys.org/news/2026-04-deep-antarctic-ice-cosmic-strange.html #cosmicwhispers #Antarctica400BadRequest #serversecurity #cosmicirony #mutedscream #HackerNews #ngated -
Ah, the thrilling saga of cosmic whispers! 🚀 Too bad it's more like a muted scream from Antarctica's ice, blocked by a 400 Bad Request. 🔒 Even the universe can't penetrate the impenetrable fortress of server security — cosmic irony at its finest. 🙄
https://phys.org/news/2026-04-deep-antarctic-ice-cosmic-strange.html #cosmicwhispers #Antarctica400BadRequest #serversecurity #cosmicirony #mutedscream #HackerNews #ngated -
Apache ActiveMQ Vulnerability Exploited, Hits 6,400 Servers
More than 6,400 publicly accessible Apache ActiveMQ servers are under attack, thanks to a high-severity code injection vulnerability that's being actively exploited. Is your server among them?
#ApacheActivemq #CodeInjection #VulnerabilityExploitation #EmergingThreats #ServerSecurity
-
Physical Security Lapses Expose Sensitive Servers
Your cybersecurity is only as strong as the physical locks on your servers - and a recent case where a server-room lock proved laughably easy to bypass is a stark reminder of this often-overlooked vulnerability. Leaving sensitive servers exposed is like leaving a car with cash in the console unlocked - it's an open invitation…
#PhysicalSecurity #ServerSecurity #Cybersecurity #EmergingThreats #VulnerabilityManagement
-
What is Port Knocking Implementation and Security: A Comprehensive Guide
https://denizhalil.com/2026/04/06/port-knocking-implementation-security-guide
#CyberSecurity #PortKnocking #NetworkSecurity #DefenseInDepth #LinuxSecurity #ServerSecurity
-
What is Port Knocking Implementation and Security: A Comprehensive Guide
https://denizhalil.com/2026/04/06/port-knocking-implementation-security-guide
#CyberSecurity #PortKnocking #NetworkSecurity #DefenseInDepth #LinuxSecurity #ServerSecurity
-
Oh joy, another groundbreaking revelation: #SSH #certificates are like the ultimate VIP pass for servers, sparing us the nail-biting suspense of wondering if we're chatting with the right machine 🤯. Because surely, the average user isn't just mindlessly hitting 'yes' and hoping for the best 🤦♂️. Who knew server security could be this exhilarating? 🎉
https://jpmens.net/2026/04/03/ssh-certificates-the-better-ssh-experience/ #ServerSecurity #VIPPass #Cybersecurity #TechHumor #HackerNews #ngated -
Oh joy, another groundbreaking revelation: #SSH #certificates are like the ultimate VIP pass for servers, sparing us the nail-biting suspense of wondering if we're chatting with the right machine 🤯. Because surely, the average user isn't just mindlessly hitting 'yes' and hoping for the best 🤦♂️. Who knew server security could be this exhilarating? 🎉
https://jpmens.net/2026/04/03/ssh-certificates-the-better-ssh-experience/ #ServerSecurity #VIPPass #Cybersecurity #TechHumor #HackerNews #ngated -
Two weeks ago we published our analysis of TURN security threats. Today: how to fix them.
New guides covering implementation-agnostic best practices (IP range blocking, protocol hardening, rate limiting, deployment patterns) and coturn-specific configuration with copy-paste templates at three security levels.
Best practices: https://www.enablesecurity.com/blog/turn-security-best-practices/
coturn guide: https://www.enablesecurity.com/blog/coturn-security-configuration-guide/
Config templates on GitHub: https://github.com/EnableSecurity/coturn-secure-configcoturn 4.9.0 dropped yesterday with fixes for CVE-2026-27624 (IPv4-mapped IPv6 bypass of deny rules) and an inverted web admin password check that had been broken since ~2019. The guides cover workarounds for older versions.
#infosec #webrtc #security #TURN #coturn #penetrationtesting #voip #serversecurity
-
Two weeks ago we published our analysis of TURN security threats. Today: how to fix them.
New guides covering implementation-agnostic best practices (IP range blocking, protocol hardening, rate limiting, deployment patterns) and coturn-specific configuration with copy-paste templates at three security levels.
Best practices: https://www.enablesecurity.com/blog/turn-security-best-practices/
coturn guide: https://www.enablesecurity.com/blog/coturn-security-configuration-guide/
Config templates on GitHub: https://github.com/EnableSecurity/coturn-secure-configcoturn 4.9.0 dropped yesterday with fixes for CVE-2026-27624 (IPv4-mapped IPv6 bypass of deny rules) and an inverted web admin password check that had been broken since ~2019. The guides cover workarounds for older versions.
#infosec #webrtc #security #TURN #coturn #penetrationtesting #voip #serversecurity
-
🛡️ ESET schützt nicht nur PCs – sondern auch eure Server.
Ransomware greift immer die wichtigsten Systeme zuerst an.ESET bietet:
• Schutz für Clients
• Schutz für Windows- & Linux-Server
• geringe Systemlast
• europäische Lösung👉 Mehr Infos: smey-it.de/managed-antivirus
#ESET #ServerSecurity #EndpointSecurity #CyberSecurity #KMU #smeyIT
#ManagedServices #RansomwareProtection #ZeroDay -
Securing servers/services without VPN cần giải pháp nào? Dùng Cloudflare Tunnels + Traefik nhưng mTLS gặp vấn đề với app di động, đặc biệt là iOS. Cloudflare Zero Trust & NordVPN cũng bị xung đột. Tìm cách truy cập an toàn, dễ dùng cho client không dùng web browser. #securingServers #mTLS #Cloudflare #ServerSecurity #Android #iOS #Tailscale #NetworkSecurity
https://www.reddit.com/r/selfhosted/comments/1pof1x9/how_should_i_be_securing_my_serverservices_and/
-
Server Security Checklist — Essential Hardening Guide
Securing your servers isn’t optional — it’s your first line of defense against data breaches, ransomware, insider threats, and lateral movement. Use this checklist as a baseline for Linux, Windows, cloud, hybrid, or on-prem servers.
⸻
🔧 1. System & OS Hardening
• Keep OS & packages updated (apply security patches frequently).
• Remove / disable unused services & software.
• Enforce secure boot + BIOS/UEFI passwords.
• Disable auto-login and guest accounts.
• Use minimal OS images only (reduce attack surface).⸻
🔐 2. Access Control
• Enforce strong passwords & MFA everywhere.
• Use RBAC & least privilege access.
• Disable root/Administrator login over SSH/RDP.
• Rotate credentials & keys regularly.
• Implement just-in-time access for privileged users.⸻
🌐 3. Network Security
• Restrict inbound/outbound traffic via firewalls.
• Segment critical servers from general LANs/VLANs.
• Disable unused ports & protocols.
• Enable DoS/DDoS protection.
• Apply zero-trust network principles.⸻
🔑 4. Secure Remote Access
• Use SSH key-based authentication (disable password login).
• Enforce VPN for admin access.
• Log & monitor all remote access sessions.
• Disable legacy protocols (Telnet, FTP, SMBv1).
• Require bastion/jump host for critical access.⸻
📊 5. Logging & Monitoring
• Enable centralized logging (syslog / SIEM).
• Track failed login attempts & anomalies.
• Configure alerts for privilege escalation or config changes.
• Monitor log tampering.
• Retain logs securely for audits & forensics.⸻
🔒 6. Data Protection
• Encrypt data at rest (LUKS, BitLocker, etc.).
• Encrypt data in transit (TLS 1.2+).
• Strict database access policies.
• Regular, offline, immutable backups.
• Test restore procedures (don’t assume backups work).⸻
🔁 7. Application & Patch Management
• Keep middleware, frameworks, and apps patched.
• Delete default credentials & sample files.
• Enable code signing for software packages.
• Use secure coding practices (OWASP Top 10).
• Implement dependency scanning (Snyk, Trivy, etc.).⸻
🛡️ 8. Malware & Intrusion Defense
• Deploy EDR/AV on endpoints.
• Enable IDS/IPS at network edge.
• Automatic vulnerability scans (schedule weekly/monthly).
• Monitor persistence techniques (cron, startup scripts).
• Block known malicious IP ranges & TLDs.⸻
🏢 9. Physical & Cloud Security
• Restrict physical access to server racks/rooms.
• Enable provider security tools (AWS Security Groups, Azure NSG, IAM).
• Harden cloud images (CIS benchmarks).
• Review cloud logging & audit trails regularly.
• Disable unused cloud API keys / roles.⸻
📜 10. Policy & Compliance
• Use CIS / NIST / ISO-27001 benchmarks.
• Track & document every access change.
• Force annual access reviews & key rotation.
• Perform regular security training for admins.
• Maintain disaster recovery & incident plans.⸻
➕ Additional 5 Critical Controls (Advanced Hardening)
🧠 11. Privileged Access Management (PAM)
• Use jump hosts & session recording.
• Just-In-Time access for admins.
• Store keys in secure vaults (HashiCorp Vault, CyberArk).🚨 12. Real-Time Threat Detection
• Use behavioral analytics → UEBA/XDR.
• AI-based anomaly detection recommended.
• Block suspicious IPs automatically.🧪 13. Red Team & Pentesting
• Run regular internal pentests.
• Validate configuration weaknesses.
• Simulate phishing + lateral movement scenarios.🧱 14. Container / VM Isolation
• Use AppArmor, SELinux, Seccomp profiles.
• Limit Docker socket access & root containers.
• Scan images before deployment.📦 15. Automated Configuration Management
• Use IaC (Terraform, Ansible, Puppet) for repeatable and secure builds.
• Detect drift using compliance scanning.
• Version control all infrastructure.⸻
🧠 Core Reminder
A server is only as secure as the team who maintains it.
Hardening isn’t one task — it’s an ongoing#ServerSecurity #SystemHardening #InfoSec #CyberSecurity #BlueTeam
#DevSecOps #SysAdmin #ThreatDetection #AccessControl #NetworkSecurity
#LinuxSecurity #SecureArchitecture #RiskMitigation #SecurityChecklist
#CloudSecurity #InfrastructureSecurity #ZeroTrust #SecurityMonitoring -
20,000 failed SSH logins in 2 days.
On a server hosting only a static webpage.Recently, I was checking logs on a VM that I own. It has no backend, no database.
Just a static webpage served by NGINX.Yet, I found 20k failed SSH login attempts.
A VM becomes a target the moment it’s online.
Fortunately, password logins were disabled. Here is my new server security routine (non-root user, SSH auth, fail2ban etc.):
https://nerdsid.com/posts/cyber-security/10-steps-to-make-a-new-linux-vm-safe/
-
The Sony PlayStation hack of 2011 is considered the worst breach in gaming history. With 77 million users affected, this episode is often used as an example of the importance of timely patching of servers and firewall security.
Here's what happened and the lessons learnt.#serverSecurity #patchDay #firewallSecurity #PSNhack #PlayStation #gaming
https://negativepid.blog/the-sony-playstation-network-hack/
https://negativepid.blog/the-sony-playstation-network-hack/ -
🐦🥱 Ah yes, because nothing says cutting-edge anthropology like a 400 Bad Request error. Clearly, ancient Patagonian server security was way ahead of its time, blocking all access to any meaningful information. If only their hunter-gatherers had a helpline for their own glitches. 🙄
https://phys.org/news/2025-10-ancient-patagonian-hunter-disabled.html #cuttingedgeanthropology #ancientPatagonia #serversecurity #techhumor #huntergatherers #HackerNews #ngated -
🐦🥱 Ah yes, because nothing says cutting-edge anthropology like a 400 Bad Request error. Clearly, ancient Patagonian server security was way ahead of its time, blocking all access to any meaningful information. If only their hunter-gatherers had a helpline for their own glitches. 🙄
https://phys.org/news/2025-10-ancient-patagonian-hunter-disabled.html #cuttingedgeanthropology #ancientPatagonia #serversecurity #techhumor #huntergatherers #HackerNews #ngated -
🚨 Threat Alert: WireTap Attack on Intel SGX Servers
Physical attacks can now compromise SGX enclaves using a low-cost DIY setup (<$1,000). Attackers can extract cryptographic keys, forge enclaves, and threaten blockchain/Web3 networks and confidential computation.
Mitigation considerations:
🛡 Restrict physical server access
🔑 Review SGX-dependent systems in blockchain & Web3
💡 Monitor for suspicious DRAM bus activity#WireTap #IntelSGX #HardwareSecurity #CyberSecurity #SideChannelAttack #BlockchainSecurity #Web3 #ServerSecurity #Infosec
-
🚨 Threat Alert: WireTap Attack on Intel SGX Servers
Physical attacks can now compromise SGX enclaves using a low-cost DIY setup (<$1,000). Attackers can extract cryptographic keys, forge enclaves, and threaten blockchain/Web3 networks and confidential computation.
Mitigation considerations:
🛡 Restrict physical server access
🔑 Review SGX-dependent systems in blockchain & Web3
💡 Monitor for suspicious DRAM bus activity#WireTap #IntelSGX #HardwareSecurity #CyberSecurity #SideChannelAttack #BlockchainSecurity #Web3 #ServerSecurity
-
📋 Server Security Checklist — Essential Hardening Guide 🛡️
Securing servers is critical to protect sensitive data, applications, and networks. Here’s a quick checklist every sysadmin and security engineer should follow to reduce risk and strengthen resilience. ⚡🔐
1️⃣ System & OS Hardening
🔹 Keep OS and packages updated (apply patches regularly).
🔹 Remove or disable unused services & software.
🔹 Configure secure boot and BIOS/UEFI passwords.2️⃣ Access Control
🔹 Enforce strong passwords + MFA for all accounts.
🔹 Use role-based access (least privilege).
🔹 Disable root/administrator login over SSH/RDP.3️⃣ Network Security
🔹 Restrict inbound/outbound traffic with firewalls.
🔹 Segment critical servers from general networks.
🔹 Disable unused ports & protocols.4️⃣ Secure Remote Access
🔹 Use SSH with key-based auth (disable password logins).
🔹 Enforce VPNs for admin access.
🔹 Monitor and log remote sessions.5️⃣ Logging & Monitoring
🔹 Enable centralized logging (syslog/SIEM).
🔹 Monitor failed login attempts & unusual activity.
🔹 Configure alerts for critical events.6️⃣ Data Protection
🔹 Encrypt sensitive data at rest & in transit (TLS, disk encryption).
🔹 Regularly back up data to secure, offline storage.
🔹 Apply strict database access policies.7️⃣ Application & Patch Management
🔹 Keep middleware, frameworks, and apps patched.
🔹 Remove default credentials and sample configs.
🔹 Use secure coding practices.8️⃣ Malware & Intrusion Defense
🔹 Deploy antivirus/EDR for endpoints.
🔹 Enable IDS/IPS at the network edge.
🔹 Scan regularly for vulnerabilities.9️⃣ Physical & Cloud Security
🔹 Restrict physical access to server rooms.
🔹 Harden cloud instances with provider tools (security groups, IAM).
🔹 Regularly review cloud audit logs.🔟 Policy & Compliance
🔹 Apply CIS/NIST benchmarks.
🔹 Document access, configs, and changes.
🔹 Train admins in security best practices.#ServerSecurity #CyberSecurity #InfoSec #BlueTeam #SysAdmin #ITSecurity #SecurityChecklist #DefensiveSecurity
-
📋 Server Security Checklist — Essential Hardening Guide 🛡️
Securing servers is critical to protect sensitive data, applications, and networks. Here’s a quick checklist every sysadmin and security engineer should follow to reduce risk and strengthen resilience. ⚡🔐
1️⃣ System & OS Hardening
🔹 Keep OS and packages updated (apply patches regularly).
🔹 Remove or disable unused services & software.
🔹 Configure secure boot and BIOS/UEFI passwords.2️⃣ Access Control
🔹 Enforce strong passwords + MFA for all accounts.
🔹 Use role-based access (least privilege).
🔹 Disable root/administrator login over SSH/RDP.3️⃣ Network Security
🔹 Restrict inbound/outbound traffic with firewalls.
🔹 Segment critical servers from general networks.
🔹 Disable unused ports & protocols.4️⃣ Secure Remote Access
🔹 Use SSH with key-based auth (disable password logins).
🔹 Enforce VPNs for admin access.
🔹 Monitor and log remote sessions.5️⃣ Logging & Monitoring
🔹 Enable centralized logging (syslog/SIEM).
🔹 Monitor failed login attempts & unusual activity.
🔹 Configure alerts for critical events.6️⃣ Data Protection
🔹 Encrypt sensitive data at rest & in transit (TLS, disk encryption).
🔹 Regularly back up data to secure, offline storage.
🔹 Apply strict database access policies.7️⃣ Application & Patch Management
🔹 Keep middleware, frameworks, and apps patched.
🔹 Remove default credentials and sample configs.
🔹 Use secure coding practices.8️⃣ Malware & Intrusion Defense
🔹 Deploy antivirus/EDR for endpoints.
🔹 Enable IDS/IPS at the network edge.
🔹 Scan regularly for vulnerabilities.9️⃣ Physical & Cloud Security
🔹 Restrict physical access to server rooms.
🔹 Harden cloud instances with provider tools (security groups, IAM).
🔹 Regularly review cloud audit logs.🔟 Policy & Compliance
🔹 Apply CIS/NIST benchmarks.
🔹 Document access, configs, and changes.
🔹 Train admins in security best practices.#ServerSecurity #CyberSecurity #InfoSec #BlueTeam #SysAdmin #ITSecurity #SecurityChecklist #DefensiveSecurity
-
🔧 You may not notice, but to improve server security, we’ve decided to disable IPv6. Since our provider, OVHCloud, doesn’t offer DDoS protection or edge firewall for IPv6, we made this decision to ensure a better and more stable service.
#ServerSecurity #IPv6 #OVHCloud #NetworkSafety #CyberSecurity
-
🔧 You may not notice, but to improve server security, we’ve decided to disable IPv6. Since our provider, OVHCloud, doesn’t offer DDoS protection or edge firewall for IPv6, we made this decision to ensure a better and more stable service.
#ServerSecurity #IPv6 #OVHCloud #NetworkSafety #CyberSecurity
-
Heads up for any server admins (especially cPanel ones):
Way To The Web Ltd (aka ConfigServer) who provide the very useful and handy ConfigServer Firewall (csf) and many other products are closing down at the end of August - no updates/downloads will be available from that date.
-
Heads up for any server admins (especially cPanel ones):
Way To The Web Ltd (aka ConfigServer) who provide the very useful and handy ConfigServer Firewall (csf) and many other products are closing down at the end of August - no updates/downloads will be available from that date.
-
🌴🔍 "Groundbreaking" findings about #Rapa Nui's "isolation" were so earth-shattering that even the internet refused to serve them. 🤦♂️ Who knew radiocarbon dating had such hard limits... like server security policies? 🚫💻
https://phys.org/news/2025-06-radiocarbon-dating-reveals-rapa-nui.html #Groundbreaking #Nui #RadiocarbonDating #ServerSecurity #InternetIsolation #HackerNews #ngated -
🌴🔍 "Groundbreaking" findings about #Rapa Nui's "isolation" were so earth-shattering that even the internet refused to serve them. 🤦♂️ Who knew radiocarbon dating had such hard limits... like server security policies? 🚫💻
https://phys.org/news/2025-06-radiocarbon-dating-reveals-rapa-nui.html #Groundbreaking #Nui #RadiocarbonDating #ServerSecurity #InternetIsolation #HackerNews #ngated -
Automating UFW Configuration with Ansible: Locking Down the Digital Fortress #Ansible #UFW #Firewall #Automation #Cybersecurity #ServerSecurity #DeadSwitch #OperationalSecurity #AnsiblePlaybook #NetworkSecurity #AutomationTools #AnsibleRoles #SystemAdministration #SecureServer #Encryption #AnsibleVault #PrivacyTools #SecurityAutomation
-
Automating UFW Configuration with Ansible: Locking Down the Digital Fortress #Ansible #UFW #Firewall #Automation #Cybersecurity #ServerSecurity #DeadSwitch #OperationalSecurity #AnsiblePlaybook #NetworkSecurity #AutomationTools #AnsibleRoles #SystemAdministration #SecureServer #Encryption #AnsibleVault #PrivacyTools #SecurityAutomation
-
👨🔬🔍 Apparently, the secret to protein folding was hiding in the 400 Bad Request error all along! Who knew server security policies were the key to solving scientific mysteries? 🧪🔒
https://phys.org/news/2025-03-protein-mystery-core-fractions.html #proteinfolding #serversecurity #scientificbreakthrough #400BadRequest #technologynews #HackerNews #ngated -
👨🔬🔍 Apparently, the secret to protein folding was hiding in the 400 Bad Request error all along! Who knew server security policies were the key to solving scientific mysteries? 🧪🔒
https://phys.org/news/2025-03-protein-mystery-core-fractions.html #proteinfolding #serversecurity #scientificbreakthrough #400BadRequest #technologynews #HackerNews #ngated -
Does anyone have any handy guides for properly locking down a linux server used for hosting? I've been doing an okay job with mine but I think if anyone has a good guide about how to make sure I didn't miss anything, that would be nice!
It's primarily for web hosting, including fedi, and sometimes as a fallback matrix/chat thing. Boosts appreciated!
#linuxSecurity #linuxHelp #serverHosting #serverSecurity -
Does anyone have any handy guides for properly locking down a linux server used for hosting? I've been doing an okay job with mine but I think if anyone has a good guide about how to make sure I didn't miss anything, that would be nice!
It's primarily for web hosting, including fedi, and sometimes as a fallback matrix/chat thing. Boosts appreciated!
#linuxSecurity #linuxHelp #serverHosting #serverSecurity -
LoginSecurity: labākais spraudnis jūsu Minecraft servera aizsardzībai
Ja izmantojat Minecraft serveri un vēlaties to aizsargāt pret nevēlamu pieteikšanos un ielaušanos, LoginSecurity ir lieliska iespēja. LoginSecurity, kas izstrādāts 2012. gadā, ir vienkāršs, viegls un ātrs spraudnis, kas atvieglo lietotāja autentifikāciju, vienlaikus nodrošinot augstākās klases drošības līdzekļus. Pateicoties vienkāršai iestatīšanai un efektīvai veiktspējai, tā ir populāra izvēle starp serveru īpašniekiem, kuri vēlas nodrošināt lietotājiem drošu un vienmērīgu spēli.
Ar ko LoginSecurity izceļas?
LoginSecurity piedāvā plašu funkciju klāstu, kas padara to par jaudīgu rīku servera administratoriem. Lūk, kas to padara īpašu:
- Vienkārši lietojams: spraudnis ir izveidots tā, lai tas būtu vienkāršs. Izmantojot tikai sešas komandas, lai pārvaldītu paroles, tas ir ātri apgūstams un viegli lietojams.
- Ātrs un viegls: LoginSecurity ir izveidots tā, lai tas veiktu darbību, nepalēninot jūsu servera darbību, un tas ir lēts un ātrs un uzticams.
- Spēcīga drošība: izmanto nozares standarta kriptogrāfiju, lai droši glabātu paroles, nodrošinot lietotāju datu aizsardzību.
- Spēlētāju aizsardzība: aizsargā un slēpj spēlētāju atrašanās vietas un krājumus, īpaši noderīgi, lai aizsargātu spēlētāju bāzes no iebrucējiem.
- Sesijas turpinājums: IP un uz laiku balstīta sesijas turpināšana ļauj lietotājiem pēc neilga laika atkal pieteikties, atkārtoti neievadot paroli, padarot to ērti, nezaudējot drošību.
- Atbalsta vairākas valodas: pieejams vairāk nekā 20 valodās, padarot to pieejamu globālai auditorijai.
Galvenās LoginSecurity funkcijas
Sīkāk aplūkosim dažas galvenās funkcijas, kas padara LoginSecurity par lielisku izvēli Minecraft serveru īpašniekiem:
- Droša paroļu glabāšana: paroles tiek glabātas, izmantojot augsta līmeņa kriptogrāfiju, kas nozīmē, ka pat tad, ja kāds mēģina uzlauzt, jūsu spēlētāju dati ir drošībā.
- Captcha sistēma: jauniem spēlētājiem lietotājam draudzīgā captcha sistēma palīdz pārbaudīt cilvēkus, pievienojot papildu drošības līmeni.
- Automātiski atjauninājumi: saglabājiet aizsardzību, saņemot paziņojumus par jauniem atjauninājumiem, nodrošinot, ka jūsu serverim vienmēr ir jaunākie drošības ielāpi.
- Vienkārša konfigurēšana: spraudnis piedāvā vienkāršas administratīvās vadīklas, lai efektīvi pārvaldītu servera drošību.
- Novērš dublētu pieteikšanos: neļauj spēlētājiem tikt izmestiem, ja viņi piesakās no citas vietas, tādējādi nodrošinot vienmērīgu spēles pieredzi.
Kā sākt darbu ar LoginSecurity
Darba sākšana ar LoginSecurity ir vienkārša. Vienkārši lejupielādējiet spraudni no tā oficiālās lapas un izpildiet iestatīšanas norādījumus. Tālāk ir norādītas dažas darbības, lai sāktu darbu:
- Lejupielādēt un instalēt: iegūstiet jaunāko versiju no oficiālās SpigotMC lapas vai GitHub un nometiet to sava servera spraudņu mapē.
- Konfigurēt: rediģējiet konfigurācijas failu, lai iestatītu vēlamos iestatījumus atskaņotāja autentifikācijai, captcha opcijām un citiem.
- Palaidiet serveri: restartējiet serveri, un LoginSecurity būs gatavs aizsargāt jūsu Minecraft pasauli!
- Pārvaldīt komandas: izmantojiet vienkāršas komandas, piemēram,
/registerun/loginspēlētāja autentifikācijai un/lsadmin. administratora iestatījumiem.
The Review
Loginsecurity
5 ScoreViegls un efektīvs spraudnis Minecraft serveru nodrošināšanai ar lietotājam draudzīgām funkcijām un spēcīgu paroles aizsardzību.
PROS
- Vienkāršs un viegli uzstādāms
- Atbalsta vairākas valodas
- Ātri un viegli
- Spēcīga paroles šifrēšana
- Bezmaksas lietošanai
CONS
- Captcha sistēma ne vienmēr var darboties, kā paredzēts
- Iespējamas problēmas ar noteiktām servera konfigurācijām
Review Breakdown
- Kopējais vērtējums
#Captcha #gaming #LoginSecurity #Minecraft #MinecraftMods #MultilingualPlugin #PasswordProtection #plugin #SecureLogin #ServerSecurity #SpigotMC
-
Securing SSH access is critical for protecting your server from unauthorized access. By combining Two-Factor Authentication (2FA) with IPv6-only connections, you add multiple layers of security.
https://linuxexpert.org/enhancing-server-security-with-2fa-and-ipv6-only-ssh-access/
#2FA #TwoFactorAuthentication #SSH #IPv6 #ServerSecurity #SSHKeyAuthentication #OTP #GoogleAuthenticator #PAM #Firewall #Iptables #UFW #Linux #ServerAdministration #Cybersecurity #NetworkSecurity #IPv6Only #SSHConfiguration #EnhancedSecurity #ServerProtection #linux
-
Securing SSH access is critical for protecting your server from unauthorized access. By combining Two-Factor Authentication (2FA) with IPv6-only connections, you add multiple layers of security.
https://linuxexpert.org/enhancing-server-security-with-2fa-and-ipv6-only-ssh-access/
#2FA #TwoFactorAuthentication #SSH #IPv6 #ServerSecurity #SSHKeyAuthentication #OTP #GoogleAuthenticator #PAM #Firewall #Iptables #UFW #Linux #ServerAdministration #Cybersecurity #NetworkSecurity #IPv6Only #SSHConfiguration #EnhancedSecurity #ServerProtection #linux
-
RHEL 9 OpenSSH packages affected by remote code execution flaw
https://stackdiary.com/rhel-9-openssh-packages-affected-by-remote-code-execution-flaw/
#OpenSSH #Vulnerability #RHEL9 #Security #CyberSecurity #CVE20246409 #RemoteCodeExecution #Linux #Fedora #RaceCondition #SIGALRM #Exploit #PatchManagement #Mitigation #Infosec #Threat #Hackers #Bug #Malware #Glitch #Audit #Syslog #Update #Enterprise #LinuxSecurity #NetworkSecurity #ServerSecurity #CyberThreat #SystemAdmin #TechNews #CVE #Mitre #NIST #OpenSource #DevOps #regreSSHion
-
RHEL 9 OpenSSH packages affected by remote code execution flaw
https://stackdiary.com/rhel-9-openssh-packages-affected-by-remote-code-execution-flaw/
#OpenSSH #Vulnerability #RHEL9 #Security #CyberSecurity #CVE20246409 #RemoteCodeExecution #Linux #Fedora #RaceCondition #SIGALRM #Exploit #PatchManagement #Mitigation #Infosec #Threat #Hackers #Bug #Malware #Glitch #Audit #Syslog #Update #Enterprise #LinuxSecurity #NetworkSecurity #ServerSecurity #CyberThreat #SystemAdmin #TechNews #CVE #Mitre #NIST #OpenSource #DevOps #regreSSHion
-
🏆Protect your Linux system with the top 7 firewalls of 2024! Dive into our detailed guide and, for all your server needs, choose xTom’s top-tier colocation, dedicated servers, and NVMe KVM VPS hosting! #TechTips #CloudHosting #ServerSecurity https://xt.om/DAsd
-
"🚨 Critical Security Alert: HikCentral Professional Vulnerabilities Exposed 🚨"
Hikvision's latest advisory reveals severe vulnerabilities in HikCentral Professional, identified by Michael Dubell and Abdulazeez Omar. CVE-2024-25063 and CVE-2024-25064, with CVSS scores of 7.5 and 4.3 respectively, highlight risks of unauthorized access due to insufficient server-side validation. Users are urged to upgrade to versions above V2.5.1 for enhanced security. Stay vigilant and prioritize updating to safeguard your systems! 🛡️💻🔐
CVE Summaries:
- CVE-2024-25063: Attackers could exploit server validation flaws to access restricted URLs, compromising confidentiality.
- CVE-2024-25064: Authenticated users could manipulate parameters to access unauthorized resources, posing a lower risk.
Source: Hikvision Security Advisory
Tags: #CyberSecurity #Hikvision #Vulnerability #CVE2024-25063 #CVE2024-25064 #ServerSecurity #InfoSec #PatchManagement 🌍🔒💡
-
Stretchoid.com is a plague for all server operators. Especially for mail server operators. Recently I have entries like this in my web server logs:
"MGLNDD_[IP-Adress_of_your_server] "-" "-"Do yourself a favor and block stretchoid in your firewalls. A relatively current list that I use on my servers.
45.55.0.0/24 104.131.128.0/24 104.131.144.0/24 104.236.128.0/24 107.170.192.0/24 107.170.208.0/24 107.170.224.0/24 107.170.225.0/24 107.170.226.0/24 107.170.227.0/24 107.170.228.0/24 107.170.229.0/24 107.170.230.0/24 107.170.231.0/24 107.170.232.0/24 107.170.233.0/24 107.170.234.0/24 107.170.235.0/24 107.170.236.0/24 107.170.237.0/24 107.170.238.0/24 107.170.239.0/24 107.170.240.0/24 107.170.241.0/24 107.170.242.0/24 107.170.243.0/24 107.170.244.0/24 107.170.245.0/24 107.170.246.0/24 107.170.247.0/24 107.170.248.0/24 107.170.249.0/24 107.170.250.0/24 107.170.251.0/24 107.170.252.0/24 107.170.253.0/24 107.170.254.0/24 107.170.255.0/24 137.184.255.0/24 138.68.208.0/24 159.203.192.0/24 159.203.208.0/24 159.203.224.0/24 159.203.240.0/24 162.243.128.0/24 162.243.129.0/24 162.243.130.0/24 162.243.131.0/24 162.243.132.0/24 162.243.133.0/24 162.243.134.0/24 162.243.135.0/24 162.243.136.0/24 162.243.137.0/24 162.243.138.0/24 162.243.139.0/24 162.243.140.0/24 162.243.141.0/24 162.243.142.0/24 162.243.143.0/24 162.243.144.0/24 162.243.145.0/24 162.243.146.0/24 162.243.147.0/24 162.243.148.0/24 162.243.149.0/24 162.243.150.0/24 162.243.151.0/24 162.243.152.0/24 192.241.192.0/24 192.241.193.0/24 192.241.194.0/24 192.241.195.0/24 192.241.196.0/24 192.241.197.0/24 192.241.198.0/24 192.241.199.0/24 192.241.200.0/24 192.241.201.0/24 192.241.202.0/24 192.241.203.0/24 192.241.204.0/24 192.241.205.0/24 192.241.206.0/24 192.241.207.0/24 192.241.208.0/24 192.241.209.0/24 192.241.210.0/24 192.241.211.0/24 192.241.212.0/24 192.241.213.0/24 192.241.214.0/24 192.241.215.0/24 192.241.216.0/24 192.241.217.0/24 192.241.218.0/24 192.241.219.0/24 192.241.220.0/24 192.241.221.0/24 192.241.222.0/24 192.241.223.0/24 192.241.224.0/24 192.241.225.0/24 192.241.226.0/24 192.241.227.0/24 192.241.228.0/24 192.241.229.0/24 192.241.230.0/24 192.241.231.0/24 192.241.232.0/24 192.241.233.0/24 192.241.234.0/24 192.241.235.0/24 192.241.236.0/24 192.241.237.0/24 192.241.238.0/24 192.241.239.0/24 198.199.92.0/24 198.199.93.0/24 198.199.94.0/24 198.199.95.0/24 198.199.96.0/24 198.199.97.0/24 198.199.98.0/24 198.199.100.0/24 198.199.101.0/24 198.199.102.0/24 198.199.103.0/24 198.199.104.0/24 198.199.105.0/24 198.199.106.0/24 198.199.107.0/24 198.199.108.0/24 198.199.109.0/24 198.199.110.0/24 198.199.111.0/24 198.199.112.0/24 198.199.113.0/24 198.199.114.0/24 198.199.115.0/24 198.199.116.0/24 198.199.117.0/24 198.199.118.0/24 198.199.119.0/24#server #stretchoid #admin #linux #windows #unix #sysadmin #firewall #webserver #mailserver #postfix #apache #nginx #it #blocklist #administrator #web #serversecurity
-
🚨✨ Critical Alert: SSH ProxyCommand Vulnerability! Dive into the details of CVE-2023-51385, a severe code execution flaw, exposing servers to shell injection. Discover insights, mitigation strategies, and stay ahead of potential threats. 🔐💻
https://www.relianoid.com/blog/ssh-proxycommand-unexpected-code-execution-cve-2023-51385/
#SSHSecurity #CyberRisk #CodeExecutionFlaw #InfoSec #VulnerabilityAlert #SSHProxyCommand #CyberThreats #MitigationStrategies #TechSecurity #CVE2023_51385 #CyberDefense #SSHVulnerability #InfoSecInsights #ServerSecurity #PatchNow
-
🔐Secure #Communication! 🔐
Dive into our article to discover the #evolution of TLS protocols, why checking your server's TLS versions is crucial for data security, and how to perform tests using Nmap's powerful "ssl-enum-ciphers" script.
https://www.relianoid.com/resources/knowledge-base/troubleshooting/testing-ssl-tls-protocols-and-ciphers-for-secured-services/#TLSProtocols #DataSecurity #NetworkSecurity #Nmap #SSLTesting #InfoSec #ServerSecurity #TechSecurity #Encryption #OnlinePrivacy #CyberAwareness #SecurityAudit #TechCompliance #SecureServices #OnlineSafety #DigitalSecurity
-
We always try to make your work #lighter and #help you with your issues and doubts. Do you want to know what is HTTP/2 Reset Attack and how to mitigate it?
https://www.relianoid.com/resources/knowledge-base/howtos/what-is-and-how-to-mitigate-http-2-reset-attack-using-relianoid-load-balancer/
#HTTP2ResetAttack #RST_STREAMAttack #CyberSecurity #WebSecurity #HTTP2Protocol #CyberThreats #DoSAttack #HTTP2Vulnerabilities #ServerSecurity #MitigationStrategies #HTTP2Implementation #LoadBalancerSecurity #RELIANOIDLoadBalancer #SecurityMeasures #RateLimiting #WebCommunication #HTTP2Streams #ServerProtection -
"⚠️ Critical RCE Alert: 3,000 Apache ActiveMQ Servers at Risk! ⚠️"
Over 3,000 Apache ActiveMQ servers are exposed online, vulnerable to a critical RCE flaw (CVE-2023-46604, CVSS v3: 10.0). Immediate patching is urged to prevent potential data theft and network compromise. Stay vigilant! 🛡️💻
Apache ActiveMQ is an open-source message broker for secure communication between clients and servers, supporting Java and various cross-language clients and protocols like AMQP, MQTT, OpenWire, and STOMP.
The flaw in question is CVE-2023-46604, a critical severity (CVSS v3 score: 10.0) RCE that allows attackers to execute arbitrary shell commands by exploiting class types in the OpenWire protocol.
According to Apache's disclosure on October 27, 2023, this vulnerability affects the following Apache ActiveMQ and Legacy OpenWire Module versions:
- Versions before 5.18.3 in the 5.18.x series
- Versions before 5.17.6 in the 5.17.x series
- Versions before 5.16.7 in the 5.16.x series
- All versions before 5.15.16
To address this issue, fixes have been released in versions 5.15.16, 5.16.7, 5.17.6, and 5.18.3. It's recommended to upgrade to one of these versions to enhance your IT security.
Tags: #CyberSecurity #RCE #ApacheActiveMQ #Vulnerability #PatchNow #InfoSec #ServerSecurity #CVE202346604 🚨🔐
Source: BleepingComputer
Author: Bill Toulas