Hướng dẫn

Bảo mật VPS mới trong 10 phút

Người mới bắt đầu10 phút đọcCập nhật 18 tháng 6, 2026
Câu trả lời ngắn

Năm thay đổi loại bỏ gần như mọi cuộc tấn công tự động vào máy chủ mới: SSH bằng khóa với mật khẩu bị vô hiệu hóa, không cho đăng nhập root trực tiếp, tường lửa mặc định chặn tất cả cho cả IPv4 và IPv6, cập nhật bảo mật tự động và fail2ban. Tổng cộng mất khoảng mười phút và quan trọng hơn bất kỳ tính năng nào của nhà cung cấp.

01 Tạo và cài đặt khóa SSH

Do this from your own machine, not the server. Ed25519 keys are shorter and faster than RSA and are supported everywhere that matters.

ssh-keygen -t ed25519 -C "onionvps-$(date +%Y%m)"
ssh-copy-id -i ~/.ssh/id_ed25519.pub root@YOUR_SERVER_IP

02 Tạo người dùng không phải root

Working as root all the time removes a useful safety net and makes every mistake maximally expensive.

adduser --gecos "" ops
usermod -aG sudo ops
rsync --archive --chown=ops:ops ~/.ssh /home/ops

03 Tăng cường daemon SSH

Disable password authentication entirely — brute force against key-only SSH is not possible. Keep a second terminal connected while you do this, so a mistake does not lock you out.

cat >/etc/ssh/sshd_config.d/99-hardening.conf <<'EOF'
PasswordAuthentication no
PermitRootLogin no
KbdInteractiveAuthentication no
AllowUsers ops
EOF
sshd -t && systemctl reload ssh

04 Thiết lập tường lửa mặc định chặn tất cả

Cover IPv6 as well as IPv4. Every OnionVPS instance has a routed /64, so a v4-only ruleset leaves every service publicly reachable over v6.

ufw default deny incoming
ufw default allow outgoing
ufw allow 22/tcp
ufw allow 80,443/tcp
ufw enable
ufw status verbose   # confirm IPv6 shows as enabled

05 Bật cập nhật bảo mật tự động

Unattended upgrades close the window between a patch being published and you noticing it exists.

apt install -y unattended-upgrades
dpkg-reconfigure -plow unattended-upgrades

06 Cài fail2ban và chụp ảnh nhanh

fail2ban mostly reduces log noise once passwords are disabled, but it is cheap. Then snapshot the configured state — that becomes your known-good baseline.

apt install -y fail2ban && systemctl enable --now fail2ban

Câu hỏi thường gặp

Tôi có nên thay đổi cổng SSH không?

Đó là giảm tiếng ồn chứ không phải bảo mật, nhưng giảm tiếng ồn hiệu quả — phần lớn máy quét chỉ thử cổng 22. Kết hợp với xác thực chỉ bằng khóa, rủi ro còn lại là không đáng kể trong cả hai trường hợp.

Nếu tôi tự khóa mình thì sao?

Sử dụng bảng điều khiển VNC ngoài dải tần trong bảng điều khiển. Nó kết nối với bảng điều khiển nối tiếp ảo và hoạt động mà không cần mạng gì cả.