Private message me for the list
если не очень интересная - то зашифруй диск, НЕ ХРАНИ ПАРОЛЬ В TPM, а вводи его вручную через IPMI, и обязательно залей на IPMI собственный SSL сертификат. это уже достаточно усложнит работу товарищу майору.
The connection between the VM and VPS. How to hide yourself?
Hello guys. How is possible to hide the connection between the Virtual Machine (Linux/Windows) and VPS (Windows) from where you work? Usually people are using VPN or Tor or TOR +VPN but there are a lot of additional problems in this topic. How you can hide the hardware of the machine from which u make the VM and etc. Can someone explain possible options. I heard a lot of people are using their private physical server using Proxmos virtual machines and etc?
The connection between the VM and VPS. How to hide yourself?
Hello guys. How is possible to hide the connection between the Virtual Machine (Linux/Windows) and VPS (Windows) from where you work? Usually people are using VPN or Tor or TOR +VPN but there are a lot of additional problems in this topic. How you can hide the hardware of the machine from which u make the VM and etc. Can someone explain possible options. I heard a lot of people are using their private physical server using Proxmos virtual machines and etc?
If you are worried about hiding your machine you can just connect to the VM using other machine or RDP as well. In the end you need a machine you have to trust so don't do anything stupid
sudo apt update
sudo apt upgrade
sudo apt install unattended-upgrades
sudo dpkg-reconfigure unattended-upgrade
/var/run/reboot-required
sudo apt install rkhunter
sudo rkhunter --check
lwp-request is a script that allows making http requests to web servers. To suppress the error you need to allow the /usr/bin/lwp-request command to be used as a script. This can be done by adding the line:/usr/bin/lwp-request [Warning]
nano /etc/rkhunter.conf
sudo apt install chkrootkit
chkrootkit
sudo apt install ntp
sudo nano /etc/ntp.conf
sudo service ntp restart
It will shows all the time service pool use by your system.sudo service ntp status
sudo -ntpq -p
ssh-keygen -t ed25519
ssh-copy-id username@xxx.xxx.xxx.xxx
ssh username@server-ip
sudo nano /etc/ssh/sshd_config
sudo service ssh restart.
ssh username@server-ip-address
sudo nano /etc/ssh/sshd_config
sudo apt install libpam-google-authenticator
google-authenticator
nano /etc/pam.d/sshd
Standard Un*x Authentication
include common-auth
auth required pam_google_authenticator.so nullok
nano /etc/ssh/sshd_config
(1) After install the linux distribution first thing to do is update the system:
$ sudo apt update
[sudo] password for root:
bash: apt: command not found
I would also regenerate moduli (deleting all smaller than 3k bits https://infosec.mozilla.org/guidelines/openssh#modern-openssh-67 ) and change the default ciphers and MACs.(5) Secure of your VPS (by edit sshd_config)
I appreciate your suggestion.first of all,
(0) install a minimal distribution from a trusted .iso (downloaded from an official website)
Код:$ sudo apt update [sudo] password for root: bash: apt: command not found
you should mention the exact distribution name you talk about
I would also regenerate moduli (deleting all smaller than 3k bits https://infosec.mozilla.org/guidelines/openssh#modern-openssh-67 ) and change the default ciphers and MACs.
also one important step left:
(7) Firewall setup
а опенвпн сервер настроил, к чему твою маршрутизатор с опенвпн клиентом должен подключаться?поставил на openwrt openvpn
если тебе нужно напрямую подключаться к впс(без использоваания каких-либо промежуточных серверов), то никак. Читай основы сети и зачем нужен ipкак скрыть реальный ip от vps сервера ?
поищи IP своего сервера в паблик логах стилеров)зашли
Кроме паролей там могут быть еще ключи SSH.пароли поменены