Selfhosted
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.
-
No spam posting.
-
Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.
-
Don't duplicate the full text of your blog or github here. Just post the link for folks to click.
-
Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).
-
No trolling.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
view the rest of the comments
Check the web server access logs. I'm sure you'll see exploit attempts, but for software you're not running. WordPress is what I see most often. Those probably won't generate emails.
Yeah, literally all of mine these days are trying to go to /wp_admin.php and /phpmyadmin.
Side note: this made me think, "I wonder how the phpMyAdmin project is doing these days," and wow, all of their corporate sponsors are online vape shops and places to buy fake social media followers. (https://www.phpmyadmin.net/) What the heck is going on there? I know that funding open source projects is almost impossible, so I understand taking whatever money you can get. But it looks pretty bad when phpMyAdmin is a huge target for bots trying to steal your database, and then the entire project seems to be sponsored by companies that need emails and passwords to create fake social media activity.
What is it about Wordpress? I've never used it, but it seems that every other day there is a new Wordpress exploit, and that's been going on for years.
It's a huuuugely popular CMS used on around 40% of all websites on the internet, and it has around 70,000 plugins available of varying quality. Most exploits are from badly written plugins.
I think of it like Bethesda games.
It's passable for what you want, but the real value is the plugins that can fix what problems you have.
But all those plugins also have security vulnerabilities that need to be managed.
Just don't look behind the curtain to see what the CEO is up to.
Incredible yet accurate analogy
Had to go look it up. What a cluster. Anyways, I don't blog mainly because I don't have anything to say that people would be interested in. Maybe farming. LOL I've just wondered down through the years why someone didn't fix all the attack surfaces Wordpress seems to have. Plus it drives a substantial share of websites, so I guess it's a good target to go after.