Peaked at #8 Off the board
Open-source VPS hardening script
A developer released vps-security-hardening, an MIT-licensed script that hardens a VPS in one command via SSH, fail2ban and UFW.
Original post
VPS 到手,第一件事永远是加固,装东西都往后排。
22 端口全网都在扫,裸奔的机器活不过三天。我以前加固一台 VPS:改 sshd_config、建 sudo 用户、换 SSH 端口、配 UFW、装 fail2ban,半小时起步,还总担心漏了哪项。
现在用 vps-security-hardening,一条命令远程全自动跑完:SSH 连通检测、系统更新、建用户禁 root 密码登录、SSH 改端口+密钥登录、fail2ban 防爆破、UFW 防火墙(22 端口直接删掉)、Docker 配置不绕过防火墙,最后自动验一遍配置。
./scripts/harden-vps.sh --ip <VPS_IP> --root-pass <ROOT_PASSWORD> --user <NEW_USER> --user-pass <NEW_USER_PASSWORD> --port <SSH_PORT>
两个前置:VPS 商后台防火墙先放行新 SSH 端口;本地装个 sshpass。
开源 MIT,7 层防护一次配齐,拿去用。
Top replies on X
Sign in to see 4 top replies from X
From @breezpoet, @dotdevnull, @qashfj and others. Spam removed, with English and Chinese translations.
Discussion 0
Sign up Sign in to join the discussion
No comments yet. Start the conversation.