Comment on My stupidity saved me from being hacked today!

<- View Parent
haui_lemmy@lemmy.giftedmc.com ⁨10⁩ ⁨months⁩ ago

Imo we are all constantly learning. Otherwise we stagnate. What I say makes perfect sense, you just dont get it. So let me explain it again, in more detail:

I was going through my docker compose files to sanitize them and upload them to my private forgejo instance.

While doing that I found a directory in my filesystem, a remnant of the early days of my server where my knowledge was severely more limited, that was a docker volume mapped to a regular directory, something I wouldnt do today for something like this.

It was owned by root:root and had 777 permissions which is a bad idea imo. So I changed it to 700 since I dont think I had any other users in group root and others, well.

Nothing bad happened, until today when my unattended backups triggered a restart at noon and the tragedy started. I put it back for now to 777 but I‘ll try and integrate it in a real docker volume which resides in the docker folders.

source
Sort:hotnewtop