By iconxweb
My droplet has been compromised and i create new droplet with snapshot of old one.
the new droplet has been compromised too.
how can find problem
please help me
This textbox defaults to using Markdown to format your answer.
You can type !ref in this text area to quickly search our full set of tutorials, documentation & marketplace offerings and insert the link!
In cases like you I usually recommend to ‘nuke it from orbit’. In other words, my recommendation would be to create completely new droplet, and configure it on higher security.
PRE-start: Be sure you use new password for everything on server. If you are using SSH keys, generate new pairs, in case it got compromised.
PermitRootLogin directive to no (by default it is yes) e.g.PermitRootLogin no
-Optional- 5. Install fail2ban for enchanted security. Fail2ban is used to ban brute force attacks against your server. Learn more about fail2ban. Beside SSH, it can be used for protecting Apache or Nginx server. 6. Install other packages but don’t use same passwords
If you are using Wordpress, research about your theme and plugins. There could be some security holes. If you are using some other random program, make sure it is secured.
Why I’m for this: You have backup, but once hole is found, there is VERY high probability that security hole existed before, even in backup. This is usually why you should start with new Droplet if possible and make high attention to security settings. If you need more help, we will try to help, but this is my usual procedure for hacked Droplets: never believe in backup, nuke it from orbit :P
Get paid to write technical tutorials and select a tech-focused charity to receive a matching donation.
Full documentation for every DigitalOcean product.
The Wave has everything you need to know about building a business, from raising funding to marketing your product.
Stay up to date by signing up for DigitalOcean’s Infrastructure as a Newsletter.
New accounts only. By submitting your email you agree to our Privacy Policy
Scale up as you grow — whether you're running one virtual machine or ten thousand.
Sign up and get $200 in credit for your first 60 days with DigitalOcean.*
*This promotional offer applies to new accounts only.