MDKadiwal
    HomeProductsWorkNewsletterAbout
    MDKadiwal

    Software Engineer & AI Entrepreneur building products that solve real problems.6 products launched, 0+ users served.

    Resources

    • Newsletter
    • Case Studies

    Quick Links

    • Products
    • Client Work
    • About

    Products

    • ScanZen AI
    • PhotoFy AI
    • Fillora AI
    • TryFitNow AI
    • Cardlyx
    • QC HRMS

    Tools

    • PDF to Word Converter
    • Word to PDF Converter
    • PDF to Excel Converter
    • Image to PDF Converter
    • PDF Merger & Splitter
    • PPT to PDF Converter
    • PDF to JPG Converter
    • All tools

    Legal

    • Privacy Policy
    • Terms of Service

    © 2026 MdKadiwala. All rights reserved.

    Built by MD Kadiwal

    Back to Newsletter
    Security

    From VPS Compromise to Fort Knox: Hardening Your Server Security

    MD Kadiwala
    MD KadiwalaSoftware Engineer & AI Entrepreneur
    Follow on
    Dec 5, 2024
    10 min read
    0 views
    SecurityDevOpsVPSLinux
    After experiencing a security breach, I implemented comprehensive security measures. Here's everything I learned about securing production servers...

    ## The Wake-Up Call

    Three months into running my SaaS, I noticed unusual CPU spikes. A crypto miner had made my server its home. Here's how I locked things down.

    ## Immediate Steps

    1. **Change all passwords and keys**
    2. **Audit all SSH access**
    3. **Check for backdoors**

    ## Security Hardening Checklist

    ### SSH Configuration
    ```bash
    # /etc/ssh/sshd_config
    PermitRootLogin no
    PasswordAuthentication no
    Port 2222 # Non-standard port
    AllowUsers yourusername
    ```

    ### Firewall Setup with UFW
    ```bash
    ufw default deny incoming
    ufw default allow outgoing
    ufw allow 2222/tcp # SSH
    ufw allow 80/tcp # HTTP
    ufw allow 443/tcp # HTTPS
    ufw enable
    ```

    ### Fail2Ban Configuration
    Automatically bans IPs after failed login attempts.

    ### Automatic Security Updates
    ```bash
    apt install unattended-upgrades
    dpkg-reconfigure -plow unattended-upgrades
    ```

    ## Monitoring

    - Set up alerting for unusual activity
    - Monitor authentication logs
    - Regular security audits

    ## The Result

    Zero security incidents in 12 months since implementing these measures.