Anleitungen

Neuen VPS in 10 Minuten absichern

Anfänger10 Min. LesezeitAktualisiert 18. Juni 2026
Kurze Antwort

Fünf Änderungen eliminieren praktisch jeden automatisierten Angriff gegen einen neuen Server: Schlüsselbasierte SSH mit deaktivierten Passwörtern, kein direkter Root-Login, eine Standard-Deny-Firewall für IPv4 und IPv6, automatische Sicherheitsupdates und fail2ban. Zusammen dauern sie etwa zehn Minuten und sind wichtiger als jede Anbieterfunktion.

01 SSH-Schlüssel generieren und installieren

Do this from your own machine, not the server. Ed25519 keys are shorter and faster than RSA and are supported everywhere that matters.

ssh-keygen -t ed25519 -C "onionvps-$(date +%Y%m)"
ssh-copy-id -i ~/.ssh/id_ed25519.pub root@YOUR_SERVER_IP

02 Nicht-Root-Benutzer erstellen

Working as root all the time removes a useful safety net and makes every mistake maximally expensive.

adduser --gecos "" ops
usermod -aG sudo ops
rsync --archive --chown=ops:ops ~/.ssh /home/ops

03 SSH-Daemon härten

Disable password authentication entirely — brute force against key-only SSH is not possible. Keep a second terminal connected while you do this, so a mistake does not lock you out.

cat >/etc/ssh/sshd_config.d/99-hardening.conf <<'EOF'
PasswordAuthentication no
PermitRootLogin no
KbdInteractiveAuthentication no
AllowUsers ops
EOF
sshd -t && systemctl reload ssh

04 Standard-Deny-Firewall einrichten

Cover IPv6 as well as IPv4. Every OnionVPS instance has a routed /64, so a v4-only ruleset leaves every service publicly reachable over v6.

ufw default deny incoming
ufw default allow outgoing
ufw allow 22/tcp
ufw allow 80,443/tcp
ufw enable
ufw status verbose   # confirm IPv6 shows as enabled

05 Automatische Sicherheitsupdates aktivieren

Unattended upgrades close the window between a patch being published and you noticing it exists.

apt install -y unattended-upgrades
dpkg-reconfigure -plow unattended-upgrades

06 Fail2ban installieren und Snapshot erstellen

fail2ban mostly reduces log noise once passwords are disabled, but it is cheap. Then snapshot the configured state — that becomes your known-good baseline.

apt install -y fail2ban && systemctl enable --now fail2ban

Häufig gestellte Fragen

Sollte ich den SSH-Port ändern?

Es ist eher Rauschunterdrückung als Sicherheit, aber effektive Rauschunterdrückung – die überwiegende Mehrheit der Scanner probiert nur Port 22. In Kombination mit ausschließlich schlüsselbasierter Authentifizierung ist das Restrisiko in beiden Fällen vernachlässigbar.

Was, wenn ich mich aussperre?

Nutzen Sie die Out-of-Band-VNC-Konsole im Kontrollzentrum. Sie verbindet sich mit der virtuellen seriellen Konsole und funktioniert ohne Netzwerk.