Guida

Proteggi un nuovo VPS in 10 minuti

PrincipianteLettura di 10 minAggiornato 18 giugno 2026
Risposta breve

Cinque modifiche eliminano essenzialmente ogni attacco automatizzato contro un nuovo server: SSH con chiavi e password disabilitate, nessun login root diretto, firewall predefinito deny che copre sia IPv4 che IPv6, aggiornamenti di sicurezza automatici, e fail2ban. Insieme richiedono circa dieci minuti e contano più di qualsiasi funzionalità del provider.

01 Genera e installa una chiave SSH

Do this from your own machine, not the server. Ed25519 keys are shorter and faster than RSA and are supported everywhere that matters.

ssh-keygen -t ed25519 -C "onionvps-$(date +%Y%m)"
ssh-copy-id -i ~/.ssh/id_ed25519.pub root@YOUR_SERVER_IP

02 Crea un utente non root

Working as root all the time removes a useful safety net and makes every mistake maximally expensive.

adduser --gecos "" ops
usermod -aG sudo ops
rsync --archive --chown=ops:ops ~/.ssh /home/ops

03 Rafforza il demone SSH

Disable password authentication entirely — brute force against key-only SSH is not possible. Keep a second terminal connected while you do this, so a mistake does not lock you out.

cat >/etc/ssh/sshd_config.d/99-hardening.conf <<'EOF'
PasswordAuthentication no
PermitRootLogin no
KbdInteractiveAuthentication no
AllowUsers ops
EOF
sshd -t && systemctl reload ssh

04 Imposta un firewall predefinito deny

Cover IPv6 as well as IPv4. Every OnionVPS instance has a routed /64, so a v4-only ruleset leaves every service publicly reachable over v6.

ufw default deny incoming
ufw default allow outgoing
ufw allow 22/tcp
ufw allow 80,443/tcp
ufw enable
ufw status verbose   # confirm IPv6 shows as enabled

05 Attiva aggiornamenti di sicurezza automatici

Unattended upgrades close the window between a patch being published and you noticing it exists.

apt install -y unattended-upgrades
dpkg-reconfigure -plow unattended-upgrades

06 Installa fail2ban e fai uno snapshot

fail2ban mostly reduces log noise once passwords are disabled, but it is cheap. Then snapshot the configured state — that becomes your known-good baseline.

apt install -y fail2ban && systemctl enable --now fail2ban

Domande frequenti

Dovrei cambiare la porta SSH?

È una riduzione del rumore più che sicurezza, ma è una riduzione del rumore efficace: la stragrande maggioranza degli scanner prova solo la porta 22. Combinata con l'autenticazione solo chiave, il rischio residuo è trascurabile in entrambi i casi.

E se resto chiuso fuori?

Usa la console VNC fuori banda nel pannello di controllo. Si collega alla console seriale virtuale e funziona senza alcuna rete.