Spamhaus Update: Security Audit Completed

in #blog7 hours ago

Previously that I shared that one of my VPS was listed on spamhaus,

https://steemit.com/blog/@justyy/one-vps-suspended-because-ip-address-is-currently-listed-on-spamhaus

And Racknerd was kind to re-instate my server to let me backup data and perform security audit. I've done that and sent them the email.

Hello,

Thank you for reinstating the server.

I have now performed an initial security review of the VPS environment.

As part of the remediation and hardening work, I have enabled UFW and restricted the firewall rules to only allow the required services, including SSH on the custom port, HTTP, and HTTPS. I have also blocked direct outbound SMTP traffic on port 25, and Postfix/SMTP is no longer exposed publicly on port 25.

I reviewed the currently running processes, listening services, cron jobs, and recent activity, and I did not find anything obviously suspicious at this stage.

For application email sending, I will avoid direct SMTP delivery from the VPS and use authenticated SMTP on ports such as 587 or 465 where required.

If the current IP address remains a concern due to the broader Spamhaus subnet listing, I am also willing to switch the VPS IPv4 address via the Client Portal as advised.

Please let me know if there are any additional logs, timestamps, or indicators you would like me to review.

Best regards,
XXXX

Steem to the Moon🚀!

Support me, thank you!

Why you should vote me? My contributions
Please vote me as a witness or set me as a proxy via https://steemitwallet.com/~witnesses

image.png

Sort:  

Enabling UFW is a great step in securing your VPS environment, did you consider implementing a regular backup and update schedule for Postfix and other exposed services? 🚀💻🔒