Десять минут до первой атаки
11 октября запустил этот сайт на чистом сервере. В первые же минуты fail2ban забанил двух ботов, которые подбирали пароль root по SSH, а файрвол за десять минут отбил два десятка попыток достучаться до закрытых портов.
Вывод простой: «настрою потом» в интернете не существует. Сервер должен выходить в сеть уже с закрытым файрволом, входом по ключам и fail2ban. Живая статистика атак на этот сервер — в строке выше.
Ten minutes to the first attack
On October 11 I launched this site on a fresh server. Within the first minutes fail2ban banned two bots brute-forcing the root password over SSH, and the firewall dropped a couple dozen probes against closed ports in ten minutes.
The takeaway is simple: “I will harden it later” does not exist on the internet. A server should go online with a closed firewall, key-only access and fail2ban already in place. Live attack statistics for this server are in the strip above.