• railsdev@programming.dev
    cake
    link
    fedilink
    arrow-up
    2
    ·
    2 years ago

    Yeah, that’s a fair point. I’ve been surprised to see a website is Wordpress from time to time.

    As far as /wp-admin goes, I know all about that! Any web server I’ve run is constantly overrun with bots trying to hack it. A lot of times I configure nginx to simply drop connections to any URL ending in .php or GZIP bomb.

    • blkpws@lemmy.ml
      link
      fedilink
      arrow-up
      3
      ·
      2 years ago

      I suppose you also configure some fail2ban rules to ban those bots. Seems to be the easier way.

      • railsdev@programming.dev
        cake
        link
        fedilink
        arrow-up
        1
        ·
        2 years ago

        I’ve looked into it a few times and it just seemed complicated to do within a Docker container but I could be wrong. I might have ChatGPT guide me on that endeavor.

          • railsdev@programming.dev
            cake
            link
            fedilink
            arrow-up
            1
            ·
            edit-2
            2 years ago

            Thanks! Though I’m mainly only wanting to protect ports 80 and 443. Usually when it comes to web apps I Dockerize it and call it a day, so there is no SSH daemon hanging around.

            • blkpws@lemmy.ml
              link
              fedilink
              arrow-up
              2
              ·
              2 years ago

              Oh well, I only run services on my cloud, so I need to get SSH to manage them. hehehe 😄

              • railsdev@programming.dev
                cake
                link
                fedilink
                arrow-up
                1
                ·
                2 years ago

                Yeah for personal stuff I prefer my own stuff, but for business I find Fly to be phenomenal. I can always “SSH” into a container if needed (though it’s definitely not SSH).