Comprehensive security for newly created Linux VPS
Comprehensive Security Handbook for New Linux VPS: Essential Post-Purchase Steps
When you first acquire a VPS (Virtual Private Server) running Linux, your primary task isn't installing applications or web source code—it is tightening security. The digital landscape is teeming with automated bots performing port scanning and Brute-force attacks just minutes after a new IP address is activated. This article will guide you through building a solid "fortress" for your server.
1. System Updates - The Foundation of Safety
Before configuring any security features, ensure your operating system is running the latest software versions to patch known security vulnerabilities. Running outdated packages is an open invitation for exploits.
// Simulating a system update command on a management platform (Node.js/TypeScript)
const updateSystem = async (os: "Ubuntu" | "CentOS"): Promise => {
const command = os === "Ubuntu"
? "sudo apt update && sudo apt upgrade -y"
: "sudo yum update -y";
console.log(`Executing: ${command}`);
return "System update completed successfully!";
};
updateSystem("Ubuntu").then(res => console.log(res));
2. Changing the Default SSH Port (Port 22)
By default, the SSH service runs on port 22. This is the primary target for automated port scanning attacks. Changing the SSH port to a random number (e.g., 2289) can reduce unauthorized login attempts from bots by up to 90%.
Note: Always ensure you have opened this new port on your firewall before restarting the SSH service, otherwise, you will be locked out of your own server.
3. Setting Up SSH Key Authentication (Disabling Passwords)
Password authentication is always susceptible to being cracked through social engineering or brute force. Using SSH Keys is a method based on a pair of public and private keys. This is currently the most robust authentication method available.
- Public Key: Stored on the server.
- Private Key: Stored on your local computer and must never be shared.
// Defining SSH Key configuration in a VPS management application
interface SSHKeyConfig {
label: string;
publicKey: string;
algorithm: "RSA" | "ED25519";
bits: number;
}
const userKey: SSHKeyConfig = {
label: "My-Work-Macbook",
publicKey: "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAI...",
algorithm: "ED25519",
bits: 256
};
function generateSSHConfig(config: SSHKeyConfig): string {
return `Using ${config.algorithm} algorithm for optimal security.`;
}
console.log(generateSSHConfig(userKey));
4. Firewall Configuration with UFW or Firewalld
A firewall acts as a filter, only allowing connections from approved ports to enter the system. On Ubuntu, UFW (Uncomplicated Firewall) is the top choice due to its simplicity and effectiveness.
| Service | Default Port | Recommended Status |
|---|---|---|
| HTTP / HTTPS | 80 / 443 | ALLOW |
| SSH (Custom) | 2289 (Example) | ALLOW |
| MySQL / PostgreSQL | 3306 / 5432 | DENY - Only open for internal IPs |
// Firewall status check logic before deployment
type FirewallStatus = "active" | "inactive";
interface FirewallRule {
port: number;
protocol: "tcp" | "udp";
action: "ALLOW" | "DENY";
}
const rule1: FirewallRule = { port: 443, protocol: "tcp", action: "ALLOW" };
function applyRule(rule: FirewallRule): void {
console.log(`Executing: ufw ${rule.action.toLowerCase()} ${rule.port}/${rule.protocol}`);
}
applyRule(rule1);
5. Installing Fail2ban - The Anti Brute-force Shield
Even if you change the SSH port, hackers can still find the new port and attempt continuous logins. Fail2ban is a tool that monitors log files (such as /var/log/auth.log) and automatically bans the IP addresses of attackers if they exceed a set number of failed login attempts.
Fail2ban's mechanism typically relies on parameters: bantime (duration of the ban), findtime (monitoring window), and maxretry (maximum failed attempts).
// Sample Fail2ban configuration via TypeScript
interface Fail2banJailConfig {
service: string;
maxRetry: number;
banTime: string; // e.g., "1h", "1d"
enable: boolean;
}
const sshJail: Fail2banJailConfig = {
service: "sshd",
maxRetry: 3,
banTime: "24h",
enable: true
};
function getFail2banStatus(config: Fail2banJailConfig): string {
return `Service ${config.service} will ban IP after ${config.maxRetry} failed attempts for ${config.banTime}.`;
}
console.log(getFail2banStatus(sshJail));
6. Disabling Root Login and Using Sudo
The root user is the most powerful account but also the most targeted. You should create a new user with sudo privileges, then disable the ability to log in directly as root via SSH. This forces any attacker to first guess a valid username before they can even attempt a password.
7. Summary: A Secure Workflow
Security is a continuous process, not a "set and forget" task. You should perform periodic checks:
- Regularly check the list of IPs banned by Fail2ban.
- Use security assessment tools like Lynis to evaluate server health.
- Always apply security patches on a weekly basis.
By strictly following these steps, you have built a highly secure Linux VPS foundation, ready for deploying NestJS, ReactJS, or any of your projects without worrying about basic internet-born attacks.
