3 ms·
About that, I had the absolutely same issue, but I was hosting WordPress. The first thing I was doing after setting a droplet was changing the password to some
by nemexy 12y ago
About that, I had the absolutely same issue, but I was hosting WordPress.
The first thing I was doing after setting a droplet was changing the password to something that was easier for me to remember, something along the line of 'qweasdzxc' but a bit harder combination. This was huge mistake on my part.
Apparantly my password was being bruteforced and once they get root access the DDOS attacks were being performed. What I did was delete the first droplet, starting a new one and just changing the default password by adding a few numbers after it. Then I went ahead and installed fail2ban(https://www.digitalocean.com/community/tutorials/how-to-prot... https://www.digitalocean.com/community/tutorials/how-to-prot...) + some iptables configurations thats are shown in that link. It practicly makes bruteforcing your droplet close to impossible(at least I think so).
If you need any assistence you can contact me through my profile e-mail and I would gladly help you. Remember though you will need a clean droplet, because your system was already compromised and there are holes in it, then simply installing fail2ban will not be enough.
P.S I had to make a new account to post that comment, I guess my old account was punished or something.
- general_failure 12y agoThe link is broken
- nemexy 12y agoYes, the right link is here - https://www.digitalocean.com/community/tutorials/how-to-install-and-use-fail2ban-on-ubuntu-14-04 https://www.digitalocean.com/community/tutorials/how-to-inst...