this post was submitted on 23 Aug 2023
14 points (100.0% liked)

Selfhosted

61168 readers
260 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

Hi, I'm setting up a public wiki using mediawiki and I'd like some help ensuring the server and mediawiki is safely setup before I start sharing it publicly. I installed it on Vultr using the mediawiki app from the Vultr Marketplace. Are there any things I should ensure before publicly sharing the link?

Some things I've done so far:

  • I disabled password login to the server so its only possible to login via ssh

  • I made it so I have to approve of any edits to the wiki

  • I still haven't enabled uploads of files because I want to ensure I only allow jpeg\png uploads.

I'm relatively new to running servers so any tips are highly appreciated.

you are viewing a single comment's thread
view the rest of the comments
[–] xnx@lemm.ee 1 points 2 years ago (1 children)

Ah ok thanks for the info! Do you know if vultrs firewall would make installing fail2ban redundant?

[–] saint@group.lt 1 points 2 years ago (2 children)

if you configure ssh access only from your home ip - then fail2ban is not needed.

[–] Haui@discuss.tchncs.de 2 points 2 years ago (2 children)

But if your home ip ever changes, you‘re fucked. I would never do that. Pubkey is the way.

[–] saint@group.lt 2 points 2 years ago (1 children)

usually i add more than 1 ip and also vultr firewall can be managed to change ip. tailscale can be used as well. there are options!

[–] Haui@discuss.tchncs.de 2 points 2 years ago

That’s good! Had me worried there.

[–] SheeEttin@lemmy.world 1 points 2 years ago (1 children)

Method of authentication doesn't matter if there's a pre-authentication vulnerability: https://thehackernews.com/2023/02/openssh-releases-patch-for-new-pre-auth.html

Instead of exposing multiple services, I would recommend just one VPN for remote access. Less attack surface.

[–] Haui@discuss.tchncs.de 1 points 2 years ago

Thats how I do it. But I also have physical access so if the vpn fails I don’t get locked out.

[–] xnx@lemm.ee 1 points 2 years ago

Oh perfect thanks