Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


What are the most comon security mistakes that newbie VPS users make?
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

What are the most comon security mistakes that newbie VPS users make?

Hi,

Just curious, what do you think are some of the common security mistakes that newbie VPS users (not providers) make when they are getting into hosting services on a vps.

«13

Comments

  • I think insecure passwords is probably the highest one... The amount of people we have had to explain to that a simple password will simply not cut it is scary...

  • NeoonNeoon Community Contributor, Veteran

    Not installing security updates, weak passwords, insecure configuration of services.

  • Choose wrong providers.

  • wychwych Member
    edited March 2015

    password="password"

  • 4n0nx4n0nx Member

    not installing updates, misconfigured programs

  • uses passwords as "incorrect"
    i asked them why ?
    they replied to me that if they forget the password then the system will tell them, "Your password is incorrect" >.>

  • Gives SolusVM a secure password

  • not disabling root login
    not disabling password logins
    not following step by step guides that tell you how to do above
    following above step by step guides, then claiming they are server admins
    more to come.

    Thanked by 1mehargags
  • @Jonchun said:
    not disabling root login
    not disabling password logins
    not following step by step guides that tell you how to do above
    following above step by step guides, then claiming they are server admins
    more to come.

    I do neither of the top two /yet/

    On my to-do list haha.

  • ehabehab Member
    edited March 2015

    how can i install windows?

  • port 22 :D

    Thanked by 1mehargags
  • MunMun Member

    They dont run apt-get install fail2ban

  • @Mun said:
    They dont run apt-get install fail2ban

    apt-get update && apt-get upgrade -y && apt-get install denyhosts unattended-upgrades -y
  • MadMad Member

    Insecure passwords, no firewall, no change SSH port.
    These are some of the most important basic steps needed to secure a VPS :)

  • LAMP stack on some linux, passworded SSH, panels for everything.

  • Knowing nothing a the OS they're using on the server.

  • 4n0nx4n0nx Member

    jaypeesmith said: Knowing nothing a the OS they're using on the server.

    isn't that typical for a newbie? >.>

    bsdguy said: passworded SSH

    I see nothing wrong with non dictionary passwords :0 I want to see the bot that tries p€n!5 ;D

    Thanked by 2mehargags kingpin
  • using the default configuration, like using the default passwords/login etc

  • purchase vps(s) and not logging into his vps(s)

  • ehabehab Member

    i have a real case.... not testing the provider long enough for example 2months while adding too much credit in first 2 weeks ...oh yeah-

    Thanked by 1NodePing
  • stenysteny Member

    They don't read pages like this one.

    Thanked by 1ehab
  • NomadNomad Member

    Getting an OpenVZ :D

  • Not removing user accounts that came pre-installed from the provider's OS template, right @Nick_A?

  • You may take a look at my guide about the first 10 things you should do with a Linux server, including securing it: https://www.bitforce.io/linux-server/die-ersten-10-dinge-die-man-mit-einem-linux-server-tun-sollte/

  • They install stupid software like zPanel/Sentorra, etc.

  • khavkhav Member

    @RockBeltHOST said:
    uses passwords as "incorrect"
    i asked them why ?
    they replied to me that if they forget the password then the system will tell them, "Your password is incorrect" >.>

    I laugh so hard on this one

  • Misconfigurations...

  • TheLonelyTheLonely Member
    edited March 2015

    @Mun said:
    They dont run apt-get install fail2ban

    -bash: apt-get: command not found

    RHEL masterrace!

  • IkoulaIkoula Member, Host Rep
    edited March 2015

    Misunderstanding on files and folder rights, there is so many sites with 777 just to make the CMS working many people dont know how to set permissions.

  • @Ikoula said:
    Misunderstanding on files and folder rights, there is so many sites with 777 just to make the CMS working many people dont know how to set permissions.

    Does it REALLY matter in single tenant VPSs? ;)

Sign In or Register to comment.