Articles
Even with the OS itself patched, individual application dependencies (libraries, frameworks) can...
How to Audit User Accounts and Remove Unused OnesOver time, servers accumulate user accounts — former team members, test accounts, service...
How to Audit and Fix File and Directory Permissions on a Linux VPSIncorrect file permissions are a common, often invisible security weakness — either too...
How to Configure UFW Firewall on a Linux VPS (Ubuntu & Debian)UFW (Uncomplicated Firewall) is the standard firewall front-end on Ubuntu and Debian. A correctly...
How to Detect Unauthorized File Changes with AIDE Integrity MonitoringAIDE (Advanced Intrusion Detection Environment) creates a baseline snapshot of your file system...
How to Detect and Remove Rootkits on a Linux VPS (rkhunter & chkrootkit)Rootkits are malicious tools designed to hide their presence while giving an attacker persistent...
How to Detect and Respond to a Compromised VPSDiscovering (or suspecting) your VPS has been compromised is stressful — this guide covers...
How to Disable Unnecessary Services to Reduce Attack SurfaceEvery running service is a potential attack vector — disabling anything not genuinely...
How to Enable Automatic Security Updates on Ubuntu & DebianUnpatched software is one of the most common ways servers get compromised. The...
How to Enable Two-Factor Authentication (2FA) for SSH on a Linux VPSTwo-Factor Authentication (2FA) adds a second layer of protection to SSH: even if your password...
How to Enforce Mandatory Access Control with AppArmorAppArmor restricts what individual applications can do — which files they can access, what...
How to Harden Kernel Parameters for SecurityBeyond application and network-layer hardening, several kernel-level parameters directly affect...
How to Harden a Fresh Linux VPS in 15 MinutesThis is a condensed, copy-paste-ready runbook for securing a brand-new Ubuntu or Debian VPS...
How to Install and Configure Fail2Ban on Ubuntu & Debian (Complete Guide)Fail2Ban monitors your server's log files and automatically blocks (bans) IP addresses that show...
How to Monitor Auth Logs and Detect Intrusion Attempts on a Linux VPSYour server's authentication logs record every login attempt, successful or failed. Reviewing...
How to Prevent Privilege Escalation via Cron Jobs and Scheduled TasksCron jobs, especially those running as root, are a commonly overlooked security consideration...
How to Protect Against Brute Force Attacks Beyond Fail2BanFail2Ban is an excellent foundational defense against brute force attacks, but layering...
How to Set Up Automated VPS Backups (rsync, cron & Off-Site Storage)A firewall and hardened SSH configuration protect against intrusion, but nothing protects against...
How to Set Up Security Auditing with LynisLynis is a comprehensive, open-source security auditing tool that scans your system and provides...
How to Set Up Security Banners and Legal Warnings for SSHAn SSH login banner displays a message before or after authentication — commonly used to...
How to Set Up a Bastion/Jump Host for Secure SSH AccessA bastion host (also called a jump host) is a single, hardened server that acts as the only entry...
How to Set Up a Honeypot to Detect AttackersA honeypot is a deliberately exposed, fake service designed to attract and detect attackers...
SSH Hardening: Change the Port, Disable Root Login & Use SSH Keys (Ubuntu & Debian)SSH is the front door to your VPS — and by default it listens on a well-known port, often...
Security Hardening Checklist for a Production VPS (Complete Reference)A consolidated, comprehensive checklist bringing together this entire category's security...
Understanding and Preventing Privilege Escalation AttacksPrivilege escalation is how an attacker with limited initial access (a low-privilege account, a...
VPS Security Checklist for Beginners: 12 Essential StepsEvery new VPS is deployed with default settings that are convenient but not secure. This...