Skip Navigation

Posts
4
Comments
104
Joined
2 yr. ago

We must think. Think we must.

  • This whole thread (that I shamelessly hijacked) is very informative and allowed me to understand that cybersecurity is in practice a mixture of concrete nerdy log books and vague feeling of being under a threshold of worthiness.

    I woke up this morning and there was a faint noise coming from the server: immediately thought "ok that's it, it's pawned and become a node in a vast grid of malicious bots"....it was a cron verification of drives

  • Low hanging fruits are, in my personal case, pictures of my cats and public domain cultural artefacts.

    Industrializing hacking of random servers sounds like a shitty idea at the end of the day...

  • Ignoring ? Nah someone mentionned my ISP might be protecting me uphill.

  • Non standard port. But aren't secret chinese hack farm scanning wider than just 22 ? I don't know and deep down believe that it's pawned and scrubbing logs.

  • React2Shell is exactly the shitshow situation yes. Suddenly we are all at risk. But in this case, I'm sorry to say that my cats' pictures are worthless.

    Your point on nginx/wireguard makes me think that it might be better to htaccess through a reverse proxy than relying on a built in login system. For exemple, I should deactivate jellyfin's login and put it behind an htaccess at the proxy's level. Is that completely dumb?

    Anyway, I clearly need to research "threat models" and cyber/infosec more. Thank you very much!

  • This is great thanks for this video

  • Aren't zero day very specific? Or maybe it's become a very generic term.

    Anyway, I am under the impression that either it's suddenly very simple to hack into EVERYONE because someone zero dayed the wireguard protocol and there a major flow in it, it's a shitshow, for all, for some, just me or nobody, whatever. Or it's a very targeted attack on me personaly, and that's a whole other story and the means to protect my pictures of my cats and my cool public domain movies collection are different (think social engineering). Also port 22 being bombarded by brute force attempts so don't choose a password that's 6 letters thanks.

    I KNOW I am missing many things, but still, I don't get it.

  • Quick question: If I look through the ssh log and I don't see the hundred of attempts, what could be going on?..

  • Yeah sorry I missed the part where it has no authentification whatsoever, that's just open bar.

    Authentification + monitoring + fail2ban + ip blacklist

  • Okay thanks for mentionning overblown paranoia, that's what I have.

    What kind of exploitable server misconfigurations are we talking about here?? Brute forcing won't work because fail2ban, right? I'm a noob and deep down I'm convinced that my homeserver is compromised and has beenpart of a bitcoin mining farm for years... Yet, not a single proof...

  • Dumb question: why does everyone is so terribly afraid of opening stuff to the internet ? What's the scenario?

  • Lemmy has cured content, smoked content, also simmered and brothed content, all types of flavory nutritious content

  • "The sweetspot is using both at the moment" - the sweetspot is siphoning knowledge from shitty platform into the fediverse

  • Absolutely! We also need to share existing clubs we are part of, where, why, etc.

  • You can haz cheezburger!

  • No no no no. We are legion. You are not alone. Let them have it. Here, have some popcorn while we watch our ship of Theseus go down in flames. Beautiful isn't it. Now, what would you like to build next? Imagine the possibilities!

    Same age, same story, same feeling. But somehow, I think we should cheer each others up.

  • FOR GREAT JUSTICE

  • Someone somewhere has it tatooed on the forehead

  • No Stupid Questions @lemmy.world

    How could AI be better than an encyclopedia?

  • Selfhosted @lemmy.world

    The hidden cost of self-hosting

  • science @lemmy.world

    Fosdem 2025 Conference in Brussels

    research-fosdem.github.io
  • Science Memes @mander.xyz

    FOSDEM 2025 Open Research devroom