create account

Note to BPs - How not to get hacked! by eluzgin

View this thread on: hive.blogpeakd.comecency.com
· @eluzgin ·
$4.46
Note to BPs - How not to get hacked!
Many BP candidates have went through a lot  of public campaigns, talks, events and community work to make it to this point and stand a chance to get elected.

However getting elected will be a small comfort if BP fails to keep his Block Producing node up and running. Besides connecting it to the Mainnet there are other security concerns that needs to be addressed if BP node wants to run BP operations longer then one day.

There are basic rules to follow when setting up security:
1. Shutdown any and all services you don't use on your machine.
2. Move ssh port from 22 to a higher number port (ex. 6007).
3. Setup ssh key login and disable password login.
4. Enable ufw firewall on your ubuntu machine, only allow access to ports you need, disable default ports like 22, etc.
5. Do no use default ports for anything including EOS ports.
6. Do not run any plugins except producer plugin on BP node.
7. Ideally run BP nodes behind full node and not exposed publicly. 

Install nmap unix utility on another machine and scan your IP address for open ports:
nmap -sT <IP>
If you do everything right - you should get nothing back.

Additional reference material:
- [UFW Essentials](https://www.digitalocean.com/community/tutorials/ufw-essentials-common-firewall-rules-and-commands )

- [Changing SSH port](https://www.godaddy.com/help/changing-the-ssh-port-for-your-linux-server-7306) 

- [Understanding-the-eos-ghostbusters-security-approach](https://steemit.com/eos/@eosrio/understanding-the-eos-ghostbusters-security-approach) 

👍  , , , , , , , , , , , , , ,
properties (23)
authoreluzgin
permlinknote-to-bps-how-not-to-get-hacked
categoryeos
json_metadata{"community":"busy","app":"busy/2.4.0","format":"markdown","tags":["eos","bp","launch","security"],"users":["eosrio"],"links":["https://www.digitalocean.com/community/tutorials/ufw-essentials-common-firewall-rules-and-commands","https://www.godaddy.com/help/changing-the-ssh-port-for-your-linux-server-7306","https://steemit.com/eos/@eosrio/understanding-the-eos-ghostbusters-security-approach"]}
created2018-06-03 11:19:36
last_update2018-06-03 11:19:36
depth0
children5
last_payout2018-06-10 11:19:36
cashout_time1969-12-31 23:59:59
total_payout_value3.464 HBD
curator_payout_value0.993 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length1,530
author_reputation48,344,025,750
root_title"Note to BPs - How not to get hacked!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id59,031,676
net_rshares1,204,347,438,333
author_curate_reward""
vote details (15)
@barrydutton ·
This was just shared on the eosgo livestream, so figured you would like to know.
properties (22)
authorbarrydutton
permlinkre-eluzgin-note-to-bps-how-not-to-get-hacked-20180603t225900978z
categoryeos
json_metadata{"tags":["eos"],"app":"steemit/0.1"}
created2018-06-03 22:59:00
last_update2018-06-03 22:59:00
depth1
children0
last_payout2018-06-10 22:59:00
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length80
author_reputation333,942,309,404,197
root_title"Note to BPs - How not to get hacked!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id59,114,545
net_rshares0
@eluzgin ·
Additional tips on two factor authentication :
https://www.linuxbabe.com/ubuntu/ssh-two-factor-authentication-ubuntu-16-04-google-authenticator
👍  
properties (23)
authoreluzgin
permlinkre-eluzgin-note-to-bps-how-not-to-get-hacked-20180604t032619426z
categoryeos
json_metadata{"tags":["eos"],"community":"busy","app":"busy/2.4.0"}
created2018-06-04 03:26:15
last_update2018-06-04 03:26:15
depth1
children1
last_payout2018-06-11 03:26:15
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length143
author_reputation48,344,025,750
root_title"Note to BPs - How not to get hacked!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id59,139,592
net_rshares417,198,995
author_curate_reward""
vote details (1)
@kabrony ·
Can not wait to get x64 ubuntu OS on laptop, windows really sucks

Posted using [Partiko Android](https://play.google.com/store/apps/details?id=io.partiko.android)
properties (22)
authorkabrony
permlinkkabrony-re-eluzgin-re-eluzgin-note-to-bps-how-not-to-get-hacked-20180604t045159698z
categoryeos
json_metadata{"app":"partiko"}
created2018-06-04 04:52:00
last_update2018-06-04 04:52:00
depth2
children0
last_payout2018-06-11 04:52:00
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length163
author_reputation17,972,959,886
root_title"Note to BPs - How not to get hacked!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id59,148,052
net_rshares0
@eluzgin ·
Two factor authentication:
https://www.linuxbabe.com/ubuntu/ssh-two-factor-authentication-ubuntu-16-04-google-authenticator
properties (22)
authoreluzgin
permlinkre-eluzgin-note-to-bps-how-not-to-get-hacked-20180604t032711577z
categoryeos
json_metadata{"tags":["eos"],"community":"busy","app":"busy/2.4.0"}
created2018-06-04 03:27:09
last_update2018-06-04 03:27:09
depth1
children0
last_payout2018-06-11 03:27:09
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length123
author_reputation48,344,025,750
root_title"Note to BPs - How not to get hacked!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id59,139,700
net_rshares0
@eluzgin ·
Two factor authentication:
https://www.linuxbabe.com/ubuntu/ssh-two-factor-authentication-ubuntu-16-04-google-authenticator
properties (22)
authoreluzgin
permlinkre-eluzgin-note-to-bps-how-not-to-get-hacked-20180604t054115565z
categoryeos
json_metadata{"tags":["eos"],"community":"busy","app":"busy/2.4.0"}
created2018-06-04 05:41:15
last_update2018-06-04 05:41:15
depth1
children0
last_payout2018-06-11 05:41:15
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length123
author_reputation48,344,025,750
root_title"Note to BPs - How not to get hacked!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id59,152,778
net_rshares0