All systems operational 21 locations · null network Pay with crypto · ∅ KYC
Start / Guides / VPS Security Hardening Checklist — 12 Steps After the First Login
How-to

VPS Security Hardening Checklist — 12 Steps After the First Login

Padlocks and chain on a dark background

Twelve steps in order: keys before anything else, a default-deny firewall, unattended patches, fail2ban, and a restore you have actually run.

Der Artikeltext ist auf Englisch. Header, Katalog und Kasse sind übersetzt.

Identity and access

  1. Add your SSH public key, then disable password authentication for root — do this before anything else touches the network.
  2. Create a named sudo user for daily work; reserve root for console and rescue contexts only.
  3. Enable 2FA on the hosting panel. The panel resets boxes and edits DNS, which makes it attack surface no matter how clean the VM is.

VPS from $3* (fund $50+), storage 1–5 TB NVMe from $24/mo annual-eff, dedicated with IPMI from $30.80/mo. Crypto invoice, no KYC.

Launch now

Network surface

  1. Set the firewall to default-deny: allow 22 or your moved port, 80/443, and each port a running service actually needs — nothing else.
  2. Bind admin interfaces to localhost or reach them through a tunnel; anything that answers publicly is being scanned right now.
  3. Install fail2ban or sshguard. Brute-force noise against a public IPv4 starts within minutes of first boot, and this is what makes the logs readable again.

System and data

  1. Enable unattended security upgrades so CVE patches land without depending on your memory or your calendar.
  2. Schedule snapshots as the pre-change rollback, plus an off-box copy on different storage — then run a restore into a scratch directory to prove the chain works.
  3. Put sensitive data at rest into a LUKS container opened after boot; the encrypted VPS walkthrough covers the pattern step by step.
Does NulNet harden the server for me?

No. Root is the product, which puts the hardening decisions and their benefits in your hands. This checklist is the baseline a sysadmin would apply on any box; nothing in the catalog pre-applies it for you.

Is a VPS with password login unsafe by default?

It is the weak default on every public IP: brute-force attempts begin within minutes of first boot. Key-only authentication is the highest-value single step on this page — do it first, before the firewall, before updates.

Do I need antivirus on a Linux VPS?

Rarely for the base OS; the server distribution is not the usual infection path. What does need scanning is content you accept from others — uploads, mail spools, user-generated files — where ClamAV-class scanners earn their keep.

How often should the checklist be re-run?

Steps 1–9 are set-and-forget until the architecture changes. Re-verify the backup restore quarterly, re-read the firewall after every new service, and re-check panel access whenever your own team roster changes. The <a href="../dedicated/">dedicated tiers</a> add IPMI, which deserves the same 2FA discipline.

Ready to launch?

Build the box — VPS, storage or bare metal — create the password, pay the invoice that follows.