Basic Tutorial to Secure an Ubuntu VPS

Secure Ubuntu VPS
Secure Ubuntu VPS

Securing your Ubuntu VPS is essential for protecting data, ensuring stability, and preventing unauthorized access. Here’s a straightforward guide on some basic yet effective steps to secure an Ubuntu VPS.


1. Update Your System

Start by updating your system to ensure all software is up-to-date with the latest security patches.

sudo apt update && sudo apt upgrade -y

2. Create a New User and Disable Root Login

For security, avoid using the root account directly and create a new user with sudo privileges.

  1. Create a new user: sudo adduser yourusername
  2. Add the user to the sudo group: sudo usermod -aG sudo yourusername
  3. Switch to the new user: su - yourusername
  4. Disable root login by editing the SSH configuration file: sudo nano /etc/ssh/sshd_config Find the line:
   PermitRootLogin yes

Change it to:

   PermitRootLogin no
  1. Restart SSH to apply changes:
    sudo systemctl restart ssh

3. Enable Firewall (UFW)

Ubuntu’s Uncomplicated Firewall (UFW) provides a straightforward way to manage firewall settings.

  1. Allow SSH access: sudo ufw allow OpenSSH
  2. Enable the firewall: sudo ufw enable
  3. Check the status:
    sudo ufw status

Optionally, if you’re hosting a web server, allow HTTP and HTTPS traffic:

sudo ufw allow http
sudo ufw allow https

4. Change the Default SSH Port

Changing the SSH port can add an additional layer of security against automated attacks.

  1. Open the SSH configuration file: sudo nano /etc/ssh/sshd_config
  2. Find the line: #Port 22 Uncomment and change 22 to your desired port, e.g., 2222: Port 2222
  3. Restart SSH to apply changes: sudo systemctl restart ssh
  4. Don’t forget to allow the new SSH port through the firewall:
    bash sudo ufw allow 2222/tcp

5. Disable Password Authentication and Enable SSH Key Authentication

Using SSH keys instead of passwords enhances security.

  1. Generate an SSH key pair on your local machine: ssh-keygen -t rsa -b 4096
  2. Copy your public key to your VPS: ssh-copy-id -p 2222 yourusername@your_server_ip
  3. Disable password authentication for SSH: sudo nano /etc/ssh/sshd_config Find the line: PasswordAuthentication yes Change it to: PasswordAuthentication no
  4. Restart SSH:
    sudo systemctl restart ssh

6. Install Fail2ban

Fail2ban monitors login attempts and blocks IPs with repeated failures, protecting against brute-force attacks.

  1. Install Fail2ban: sudo apt install fail2ban -y
  2. Start and enable Fail2ban: sudo systemctl start fail2ban sudo systemctl enable fail2ban
  3. Configure Fail2ban by creating a local jail file: sudo cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local
  4. Modify settings as needed: sudo nano /etc/fail2ban/jail.local You can adjust the ban time, retry limits, and monitored services.
  5. Restart Fail2ban:
    sudo systemctl restart fail2ban

7. Install and Configure Automatic Updates

Automatic updates reduce the risk of security vulnerabilities by ensuring software remains current.

  1. Install the unattended-upgrades package: sudo apt install unattended-upgrades -y
  2. Enable automatic updates:
    sudo dpkg-reconfigure --priority=low unattended-upgrades

8. Regular Backups

Always keep regular backups to quickly recover in case of an attack or data loss. Many hosting providers, like Hosteons, offer backup solutions, making it easy to automate and restore from snapshots or backups.


Summary

By following these steps, you enhance the security of your Ubuntu VPS against common threats. Regular updates, secure login configurations, a robust firewall, and monitoring tools like Fail2ban all contribute to a safer and more reliable server environment. With these basics covered, your VPS will be better protected against potential attacks.

Ransomware: A Real Threat to Your VPS and Servers – How to Protect Your Infrastructure

Ransomware Threat
Ransomware A Real Threat

Ransomware is one of the most pressing cybersecurity threats today. For businesses and individuals relying on VPS and servers, a ransomware attack could mean lost data, compromised security, and significant downtime. While ransomware can be devastating, implementing proactive security measures can significantly reduce the risk. Here’s a guide on understanding ransomware, recognizing the risks it poses, and taking effective steps to protect your VPS and servers.

What is Ransomware?

Ransomware is a type of malware that encrypts data on a server, system, or device, rendering it inaccessible. Attackers demand a ransom (often in cryptocurrency) to unlock or decrypt the files. Ransomware attacks are highly targeted, and the costs of an attack can be tremendous—both financially and operationally.

Why is Ransomware a Serious Threat to VPS and Servers?

VPS and servers host valuable data, databases, applications, and other assets crucial for businesses. An attack on these systems can lead to:

  • Data Loss and Corruption: Encrypted files can become irretrievable without paying a ransom, and even paying doesn’t guarantee data recovery.
  • Downtime and Operational Disruption: A compromised server could mean hours or days of downtime, impacting user experience and operations.
  • Financial Losses: Besides ransom payments, recovering from a ransomware attack involves costs for restoration, data retrieval, and enhanced security measures.
  • Reputational Damage: Customers and users may lose trust in a company that has suffered a data breach, leading to longer-term business challenges.

How to Protect Your VPS and Servers from Ransomware

1. Implement Regular Backups

Regular backups are essential for mitigating the impact of a ransomware attack. With recent and secure backups, you can restore your system to a pre-attack state without needing to pay a ransom. At Hosteons, for example, we offer free backup and snapshot options with our VPS and Hybrid Dedicated Server hosting, ensuring you can quickly revert to a secure point if an attack occurs.

2. Use Robust Security Software and Firewalls

Install strong anti-malware and antivirus software on your VPS to detect and block malicious software. Configuring firewalls to restrict access to essential services only, and regularly updating your firewall rules, will provide an additional layer of protection.

3. Regularly Update and Patch Your Server Software

Ransomware often exploits known vulnerabilities in outdated software. Ensure all server software, operating systems, and applications are kept up-to-date with the latest security patches.

4. Implement Access Controls and Authentication

Restrict access to your VPS to only those who need it. Enforce strong, unique passwords, and use two-factor authentication (2FA) wherever possible. Limiting the number of people who can access sensitive systems will reduce the risk of unauthorized access.

5. Disable Remote Desktop Protocol (RDP) or Secure It

RDP is a common entry point for ransomware attacks. If you don’t need it, disable it. If you do need it, restrict access through a VPN, or limit it to specific IP addresses and ensure it is only available over encrypted connections.

6. Monitor Network Traffic

Implement network monitoring to detect any suspicious activity, like unauthorized access attempts or unusual data flows. Monitoring helps in early detection, allowing you to intervene before ransomware spreads.

7. Educate Your Team

Human error is a common cause of security breaches. Train your team to recognize phishing emails, suspicious attachments, and best practices for secure server access. This awareness reduces the risk of accidentally downloading ransomware.

Responding to a Ransomware Attack

Even with the best protection, incidents can happen. If ransomware is detected:

  • Disconnect the Infected Server: Immediately isolate the compromised server from the network to prevent the spread of ransomware.
  • Restore from Backups: If possible, restore the affected system from a clean, recent backup.
  • Report the Attack: Notify relevant authorities to assist in tracking the source of the attack and possibly retrieve your data.
  • Analyze and Improve Security: Conduct a post-attack review to understand how the ransomware infiltrated your system and strengthen your defenses.

Conclusion

Ransomware is a serious threat, but with the right security practices, you can protect your VPS and servers from devastating attacks. Regular backups, strong security measures, and constant monitoring are key to keeping your data secure. At Hosteons, we prioritize your security by offering free backup and snapshot features with our VPS and Hybrid Dedicated Server hosting, helping you stay prepared and resilient against ransomware threats. Protect your digital assets today, and ensure your online presence remains safe from this growing menace.

Why Hybrid Servers (VDS) are the Best Alternative to Dedicated Servers: Hosteon’s Ryzen 7950x VDS with NVMe Performance Advantage

Hybrid 7950x vs Dedicated Servers

Choosing the right server type is crucial for any business or personal project requiring high-performance hosting. While dedicated servers have traditionally been the go-to for maximum power and control, Virtual Dedicated Servers (VDS) or Hybrid Servers offer an incredible alternative—delivering dedicated-like performance without the hefty price tag. At Hosteons, our Ryzen 7950x-based Hybrid Servers come equipped with NVMe disks, providing a superior balance of performance and cost-effectiveness that often outshines traditional Intel Xeon dedicated servers.

VDS vs. Dedicated Servers: Understanding the Difference

A VDS/Hybrid Server is essentially a high-performance VPS, offering isolated resources similar to a dedicated server. However, unlike dedicated servers, where a single user occupies the entire hardware, VDS uses powerful virtualization technology to create dedicated environments within the server. This setup allows VDS users to benefit from dedicated server-level resources at a fraction of the cost.

Advantages of Using a Ryzen 7950x-Based Hybrid Server with NVMe Disks

Hosteons has carefully designed our Ryzen 7950x Hybrid Servers to deliver high performance and flexibility, perfect for applications with demanding resource requirements. Here’s how our Ryzen 7950x Hybrid Servers outperform typical Intel Xeon-based dedicated servers:

  • Superior Processing Power: Ryzen 7950x processors offer higher single-threaded and multi-threaded performance compared to many Intel Xeon CPUs, making them ideal for both web hosting and resource-intensive applications.
  • Enhanced Disk Performance: NVMe disks are several times faster than traditional SSDs, allowing for quicker data read/write speeds, which improves application response times and overall performance.
  • Cost Efficiency: With our VDS offerings, you gain similar performance to a dedicated server at a much lower price, ensuring that you get excellent value for your investment.

Key Benefits of Hosteons’ VDS/Hybrid Servers

  1. One-Click OS Reinstallation
    Managing and experimenting with different OS configurations has never been easier. With a single click, you can reinstall your OS, saving time and effort typically needed for reinstallation on dedicated servers.
  2. One-Click Backups/Snapshots
    Data protection is vital, and with Hosteons’ VDS, you can create backups and snapshots instantly, allowing you to revert to previous states easily if needed.
  3. Instant Activation
    Our Hybrid Servers are activated instantly, so you don’t have to wait to get started. Immediate access to server resources helps you quickly set up and launch your applications.
  4. Cost-Effective Solution
    With Hosteons’ VDS, you get dedicated-like performance at a fraction of the cost. This is ideal for users seeking power-packed hosting without a heavy financial commitment.
  5. Performance on Par with Dedicated Servers
    Equipped with Ryzen 7950x processors and NVMe disks, Hosteons’ Hybrid Servers are optimized to offer equal or even better performance than many dedicated servers, especially those using older Intel Xeon architectures.
  6. Custom OS Installation
    Need a specific OS? Our VPS control panel allows you to upload and install your own ISO, giving you complete control over your server environment.
  7. RDNS Control
    Hosteons provides you with RDNS control, empowering you to manage reverse DNS records for better email deliverability and SEO benefits.

Is a Hybrid Server Right for You?

Whether you’re running a high-traffic website, handling large databases, or developing custom applications, Hosteons’ Ryzen 7950x-based VDS is a powerful, flexible, and budget-friendly choice. Hybrid Servers deliver similar control and power to dedicated servers but with added convenience and features suited for modern needs.

Conclusion

Hosteons’ Ryzen 7950x-based Hybrid Servers with NVMe disks deliver an unbeatable combination of performance, flexibility, and cost savings, making them an exceptional alternative to traditional dedicated servers. With one-click features, instant activation, and the ability to handle high workloads, our VDS offering is ideal for users who want dedicated-like performance without the associated costs. Explore the power and value of our Hybrid Servers today and experience hosting without limits.

The Importance of Backups for VPS Hosting: Keep Your Data Safe with Hosteons Free Backup Service

Free VPS Backups or snapshot
Free VPS Backups or snapshot

In today’s digital landscape, data is the backbone of any online presence, whether you’re managing a personal blog, an eCommerce website, or a mission-critical application. For VPS (Virtual Private Server) users, ensuring that data is safe, secure, and recoverable is more than just a precaution—it’s essential for maintaining uptime, protecting business continuity, and safeguarding user trust. At Hosteons, we understand this need, which is why we offer free backups and snapshots with our VPS and Hybrid Dedicated Server hosting. Here’s why having regular backups is vital and how Hosteons is here to support you.

Why Are Backups Essential for VPS Hosting?

  1. Data Protection Against Cyber Threats Cyberattacks and ransomware threats are on the rise, and VPS servers are a prime target for malicious actors. Regular backups can safeguard your data, allowing you to recover quickly in case of an attack. With Hosteons’ free backup services, your data remains protected without additional cost, ensuring your digital assets are always safe.
  2. Minimizing Downtime and Recovery Time For websites or applications, downtime is detrimental—not only for revenue but also for user trust. Backups allow for quick recovery in the event of server failures, data corruption, or accidental deletions, reducing downtime significantly. Hosteons’ backup solutions are designed to minimize the time needed to restore operations, keeping your business running smoothly.
  3. Testing and Development Many developers and IT teams use VPS environments for testing and development. Regular backups allow you to restore your server to a previous state, making it easy to troubleshoot, test configurations, or revert changes without risk.
  4. Compliance and Data Integrity Depending on your industry, you may need to retain certain data for legal or compliance reasons. Backups offer a simple way to ensure data is maintained securely, helping your business meet regulatory requirements.

Hosteons.com Backup and Snapshot Solutions

At Hosteons, we pride ourselves on providing high-quality hosting solutions that prioritize user needs. Our budget US KVM VPS and EU KVM VPS hosting (powered by Intel Xeon servers) and premium Ryzen KVM VPS servers are designed with performance and reliability in mind. For those needing a more robust solution, we offer Hybrid Servers (VDS) on Ryzen 7950x servers. With data center locations in Los Angeles, New York, Portland, Dallas, Miami, Salt Lake City, Frankfurt, and Paris, you can select a location that suits your audience best, all while enjoying 24×7 support.

With our free backup and snapshot service, you can rest easy knowing that you can roll back your VPS to a previous state whenever you need it. Whether you’re a small business or a large enterprise, this feature adds an invaluable layer of security and flexibility to your hosting experience.

Hosteons: Reliable Hosting with Free Backups

When you choose Hosteons, you’re choosing more than just a VPS provider—you’re partnering with a company dedicated to your digital success. From shared and reseller web hosting to hybrid dedicated servers, Hosteons ensures that your data is protected with regular, accessible backups. Let us handle the technical challenges, so you can focus on what you do best.

Start your journey with Hosteons today, and experience the peace of mind that comes with knowing your data is always secure and recoverable.

🎆 Celebrate Diwali with Hosteons: Empower Your Online Presence with Robust Hosting Solutions! 🎇

Happy Diwali

Diwali, the festival of lights, symbolizes new beginnings, growth, and prosperity. At Hosteons.com, we’re delighted to celebrate this special occasion with our valued customers and partners. As we light up our homes and hearts, we wish you a Diwali filled with joy, success, and new opportunities, both online and offline.

Diwali: The Perfect Time for New Beginnings

Diwali isn’t just about illuminating our surroundings but also about brightening our paths forward. In the digital age, establishing a strong online presence is crucial for entrepreneurs, developers, and creators. This Diwali, let Hosteons be the foundation for your online success, with hosting solutions designed to support every step of your digital journey.

Hosteons.com Hosting Solutions for Every Need

Whether you’re launching a new blog, setting up an eCommerce platform, or expanding your digital reach, Hosteons offers reliable, secure, and high-performance hosting solutions tailored to your needs:

  1. Web Hosting – For bloggers, small business owners, and creatives, our web hosting plans provide the perfect blend of affordability and performance to support your growing projects.
  2. VPS Hosting – Gain complete control over your online environment with our VPS hosting options, ideal for applications that require greater flexibility and power.
  3. Reseller Hosting – Looking to start your own hosting business? Our reseller hosting options allow you to seamlessly manage and grow your own customer base with Hosteons as your support partner.

Why Hosteons Stands Out

At Hosteons, we prioritize quality, reliability, and customer satisfaction above all. Here’s what makes us a trusted hosting provider:

  • 99.9% Uptime Guarantee – Your website stays online, keeping your users connected.
  • 24/7 Customer Support – Our dedicated team is available day and night to assist you with any queries or technical needs.
  • Transparent Pricing – No hidden fees or surprises, only straightforward solutions you can trust.
  • High-Performance Infrastructure – We use top-tier technology to deliver speed and security, enhancing your website’s performance.

Wishing You a Bright and Successful Diwali!

As we celebrate the triumph of light over darkness, Hosteons stands by you to illuminate your path in the online world. Let’s create a brighter future together—one that’s secure, prosperous, and filled with success.

Happy Diwali from the Hosteons Team! May your journey be lit with growth and positivity this festive season and beyond.

So what’s new with hostEONS after the Dedipath Drama ?

So after all the DRAMA of Dedipath closing down without notice and how we survived without downtime, we have expanded a lot. Until now we were just offering Regular KVM VPS (Ryzen and Intel) and OpenVZ VPS from 5 Datacenters, but now after we survived the DP Drama, we have expanded not only our Line of Product but we have also expanded to 7 Datacenter Across US and 2 Locations Coming Soon (Within a week) even Europe, guess which locations ?

Paris (France) and Frankfurt (Germany) are our new upcoming locations in Europe

So right we are offering our VPS Service from these 7 US locations + 2 in EU

US Locations:

  1. Los Angeles
  2. New York
  3. Salt Lake City DC 1
  4. Salt Lake City DC 2
  5. Dallas
  6. Miami
  7. Portland

Upcoming EU Locations:

  1. Paris (France)
  2. Frankfurt (Germany)

Until July 2023 we had just close to 100 VPS Nodes, but now have 170+ VPS Nodes and lot more are on the way.

Until July 2023 we were just offering Ryzen KVM VPS, Intel KVM VPS and OpenVZ VPS, but now we are offering:

  1. Ryzen KVM VPS
  2. Intel KVM VPS
  3. OpenVZ VPS
  4. 3950x Based VDS
  5. 7950x Based VDS

VDS = Virtual Dedicated Server or some even call it Hybrid Dedicated Server

With VDS you can basically use 100% CPU 24×7 without restriction as CPU Cores are assigned dedicatedly to your VPS/Server

Our Ryzen 7950x based VDS Starts at just $7 per month and available across 3 locations:

  1. Salt Lake City
  2. Los Angeles
  3. Dallas

These 7950x Based VDS can be ordered from https://my.hosteons.com/store/ryzen-7950x-based-hybrid-dedicated-server

Our Ryzen 3950x Based VDS starts at just $4.99 per month and currently available in Salt Lake City and can be ordered from https://my.hosteons.com/store/hybrid-dedicated-server-special

Our upcoming EU Locations are using Equinix in France as well as Germany and we are starting over there with VPS Nodes with following specs:

Dual Xeon Gold 6410

256 GB RAM

2 x 6 TB NVME

10G Network

These are going to some premium VPS but at same price as our Budget Gigabit KVM VPS

So stay tuned for more our new EU Launch and grab our VDS to get performance of a Dedicated Server at the price of a VPS

One more Datacentre Location Being Added in Salt Lake City

As posted in our previous POST, that how and we had to do emergency migration of all our VPS Nodes and Shared Web Hosting, but now once all the data has been migrated, we even need to utilise our Colocated Servers that were there with Dedipath, today we were provided access and were able to pickup our Servers from their Los Angeles, location, though other location is still pending, but to utilise these servers, we have taken a full 42U RACK in Salt Lake City, this is different from our current Salt Lake City Datacentre, this location also has very good network, along with DDOS Protection provided by PATH. This new location has very good network globally including China and Asia.

These servers just landed at the new facility in Salt Lake City, we plan to use these servers for our regular Ryzen VPS nodes as well to offer Virtual Dedicated Server, i.e. with Dedicated CPU Cores and all resource, with these package you will be able to max out your CPU without any restricitons

We will post an update about once its ready for production, hopefully in next 3-4 days

9288 VPS Safely Migrated, how did we dodge the DEATH BALL ? How a Hunch Saved the Business and Data of Thousands of Clients

Below is a snippet of our sudden announcement of migrating all our servers to a different datacentre:

We made this announcement on 6th of August, though we started planning for it in July itself, but it was just a hunch hence we could not make it public as we have yet to find a reliable provider, arrange for 11000+ IP, arrange for close 100 Servers, find locations that are suitable for our clients etc…

But what made us take this decision as we have been using DEDIPATH services for over 5 years without any trouble ?

There were few warning signs:

  1. Their CTO Left the company
  2. Support tickets were delayed a lot
  3. Nobody from management was approachable
  4. Then I think in July end two of their facilities went offline for over 3 hours – NJ and LA, this was the biggest warning sign, but then after asking repeatedly they finally sent RFO
  5. This RFO was the final NAIL in the COFFIN and forced us to take this decision of migrating out of Dedipath. This RFO said the reason behind the outage was routing issue, but how can two different locations have routing issue at the same time ? I tried to inquire a lot about it to know the actual reason, but everybody at DP was behind NDA hence could not utter a word, but this made us decide to finally migrate out.

This sudden Emergency Migration was not appreciated by all clients, but we even could not tell the clients that we are doing it on the basis of a hunch that things are not alright at DP hence we had to migrate out, but most of the clients did not complained but still I know it’s a lot of trouble for clients to change their IP in the web server, mail server, DNS Servers, proxy, vpn or for whatever services they were using their VPS.

We appreciate patience shown by all clients during this migration, but whatever we did was in the best interest of our clients, their data and also for survival of Hosteons.

Usually providers physically move servers to another Datacentre as it saves a lot of costs, though it causes downtime but still it’s the most economical way to do migration especially if you own the servers/hardware, but in our case even this was not possible and also we did not wanted to cause hours of downtime and sometimes servers do break during transport that could again cause more problems and data loss.

If we move the servers physically it has many risks:

  1. Server Damage During Transportation
  2. Hours of Downtime as it’s takes lots of time if you have to UNRACK 100 servers, then transport them, then again bring them online in the new datacentre with new IP, new network configuration
  3. Not only this how do we change IP of 9000 VPS all at once ? It could take days before we do this, so this just means downtime of days or even weeks
  4. Moreover there were rumours in Forums that Remote Hands is at HOLD in DP, as the Datacentre “EVOCATIVE” is not doing it, I won’t get in details what exactly is the problem, so we could not expect that we will be actually provided access to our servers

So this option was OFF the TABLE

So how exactly did we migrate 9288 VPS Safely ?

We decided that we will first get the following:

  1. Our own ASN – If we use ASN of our Datacentre it causes lots of problems like if the Datacentre has abusive users it even affects our IP Reputation. So we got our own ASN before migration – AS142036
  2. Our own IP – We have some of our own IP Blocks from APNIC, we used them along with, we directly did contract with IP Vendors and got IP on long term contract, so that we don’t need to change IP every now and then as we had to do when IP are provided by Datacentre, because if Datacentre wants they change or pull back their IP blocks anytime they want, so this time we got IP Directly from IP Vendors and used our own IP
  3. We got new servers, but new server hardware delivery takes time it is not instant, so this took almost 10 days and even in these 10 days we did not got all the servers, even some servers failed hardware diagnostics, we had to get them replaced, rack etc… it was a period of sleepless nights that just finished today earlier with our FINAL Server migration without any DATA LOSS to any client.
  4. It was not easy to apply and get ASN, get new IP, arrange for new servers that too in locations that are similar to what we currently have and above all, all these things require a lot of CASH.
  5. But we have a solid business plan and we keep our business profitable unlike many low end providers who just keep discounting their prices to get sales and ultimately end up shutting down, but due to our SOLID BUSINESS PLAN and over 2 decades of experience in HOSTING INDUSTRY, we were able to pull through this tough phase.

But AGAIN YOU MUST BE THINKING WAS THIS EVEN WORTH IT ?

YES ABSOLUTELY, JUST READ THIS ANNOUNCEMENT BY DEDIPATH:

This is just a partial announcement but they did shutdown with less then 24 hours notice, and if we had not migrated out in time, then we would have lost data of almost all clients by now as it was not possible to arrange for 100 Servers in such a short period and also migrate data of 9000+ VPS within 24 hours, as I know it take us over 20 days to migrate out data of 9000 VPS

The best part is our clients had close to ZERO DOWNTIME, the reason being we did a live migration of VPS, just the IP was changed, so it all depends how quickly they start using the new IP

So this is how we DODGED the DEATH BALL just on the basis of a hunch and over 2 decades of experience in HOSTING INDUSTRY