Skip to content

5 years since my last 'my server got hacked' thread

General Discussion by singapore 6 replies 493 views
#1

Five years ago I was the person asking how to clean malware off a WordPress box. Now I edge everything, origin server barely gets touched, cache hit ratio sitting at 94% on my personal PoP. I just wanted to say thanks to this community for all the painful lessons. I used to worry about sshd config and now I worry about whether my edge nodes in Frankfurt and Singapore are properly synced. Different problems, better problems. If you are still getting hacked in 2026, just use Cloudflare (https://www.cloudflare.com) and then actually read the hardening guides. Edge your life.

#2

Congratulations on the milestone. Five years is genuinely impressive in this field. The discipline required to maintain that streak should not be underestimated. I have seen far too many people backslide after year two because they got complacent. Keep it up; -- Marcus

#3

Five years without Security incident is impressive no I do not want to diminish your Success but I must ask did you not four years ago post about openRedisConfiguration with nopasswordAuthentication yes that was a very bad Zeitpunkt for your Serversicherheit no I do not want to be the Guru deutschlag who ruins the Party but the Forensicherheitsprotokoll does not lie brother

#4
singapore said:
Thanks to this community for all the painful lessons

Hey congratulations!! Five years is really something. I remember sent ticket to you back then, was trying to help with that Redis situation. You learned fast, that is what matters. Made test order with Vultr just to compare configs after that thread, actually improved our documentation. So thank you for that! Cheers

swimming upstream since 2019 🐟
#5
singapore said:
If you are still getting hacked in 2026, just use Cloudflare and then actually read the hardening guides.

To be honest, I checked. April 2022, "Redis exposed, help." As said, 4 years 3 months, not 5.

Still good. Bullet points for your current stack:

  • OS: ?
  • SSH: key-only, nonstandard port
  • Fail2ban: yes/no
  • Automatic updates: enabled
  • Firewall: nftables/iptables/other

The gap matters less than the trajectory. Dry humor: at least you did not celebrate 10 years.

Containers before it was cool
#6

Anyway I was up at 3am and wrote a script that checks your forum history for embarrassing posts

Idk why I do this

It found 7

💀

builds at 3AM, sleeps at noon
#7

Frankfurt AND Singapore synced? What about your Tokyo node.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft