JA 日本語 Brochures Contact
  1. Home
  2. Works & Tech
  3. Server Recovery and Security Measures for Next Time

Tech ArticlesWeb

Server Recovery and Security Measures for Next Time

1. Recovering the server

We want to recover a server that was taken down by an attack from the internet, using the same domain name.
The VPS we had been using is no longer available because our account was forcibly terminated,
but by moving to another VPS service, we can recover the server under the same domain name.
However, if we continue to use a domain name that has been attacked in the past,
the risk of being attacked again is high, so thorough security measures are essential.
We also consulted ChatGPT about the risks of recovering the server under the same domain name.

ChatGPT's answer

This told us that recovering the server under the same domain name carries more risk than the first time.
We therefore believe we need to strengthen our security measures further next time.

2. Security measures

To strengthen security, we considered the following measures.
• Delete unnecessary accounts
• Disable password login to the SSH server
• Update software regularly
• Introduce a CDN
• Use a reverse proxy
• Since a static IP address cannot be hidden completely, configure settings to hide it as much as possible
• Protect DNS information

Looking back on this incident
The attacked server environment used a CDN, but not a reverse proxy.
We believed we had implemented most of the security measures, with the exception of software updates.
However, even though password login to the SSH server had been disabled, a fault occurred with SSH connections,
and we think using Telnet and FTP as substitutes was one of the causes of the problem.
Going forward, we need to be prepared to respond quickly to SSH server faults if a similar problem occurs.
Next time, we intend to pay close attention to how we operate the SSH server and run it more securely.

3. Consulting the police

We asked ChatGPT whether we should report the damage from this incident to the police.

ChatGPT's answer

Because we do not have time to go to the police right away, we have put this on hold for now.
If the police contact us, the course of events is recorded in our emails,
so we plan to explain based on those.
We have also already emailed the VPS administrator to state that we were not at fault,
and we believe the VPS administrator is investigating on their side as well.

4. Summary

It is possible to sign up for a new VPS under the same domain name and republish the blog.
However, unless sufficient measures are taken against past attacks, the risk of being attacked again increases.
The most important thing is to review security and put strong defenses in place.
With appropriate measures, publishing safely under the same domain name should be entirely achievable.
In addition, backing up the blog content and server environment in advance, in preparation for recovery, makes quick recovery possible.

Share this article Share on X

Shall we create
the next surprise together?

3DCG, XR, simulation, film, web and AI. We welcome ideas that have not taken shape yet.