this post was submitted on 07 Sep 2026
298 points (98.1% liked)

Selfhosted

62026 readers
923 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

Welp. My Forgejo instance got popped with an RCE two days ago by CVE-2026-60004. Luckily, I noticed the following morning and had the day free to figure out what happened. Let's dive in!

As a homelab enthusiast, I found this a very interesting post. Here are my take aways from the post that I'm implementing myself:

  • Miner detection. I've updated monitoring rules to now watch the CPU on my hosts. If the same thing happened to me I would not have been alerted at all as I'm doing simple up / down monitoring. Fixed.
  • Access logging. I turned on access logging for my homelab Caddy instances.
  • Log retention. I have increased the amount and retention of my logging. The hope is this will help me reconstruct what happened after a breach.
  • Logs offsite. The VPS access logs now ride along with the normal backup process, which runs hourly. The homelab side still only gets caught by the weekly VM backup, so that's next.
  • Closed an open signup. My webtrees instance (genealogy) had self registration enabled, which is the same door this guy got hit through. Oops. Fixed.
  • Built a tool. log-inventory.sh, so "could I actually reconstruct what happened" is a command I run instead of a thing I assume.
you are viewing a single comment's thread
view the rest of the comments
[–] chunkystyles@sopuli.xyz 9 points 2 days ago (1 children)

I just recently went through a much more benign, but scary nonetheless version of this.

I realized that my Ansible directory, that I had made public on GitHub to share as an example to some folks, had secrets committed and pushed.

It was the direct URL and credentials of an app I developed to store non-PII customer data. Now, it wouldn't be the end of the world if someone noticed this and scraped the data, but it wouldn't be good, either.

Luckily, I have Caddy access logs, and it appears no one ever accessed it.

So I pulled the secrets out of the Ansible directory and made the repo private, I rotated the credentials, and installed Crowdsec to monitor Caddy access logs and ban bad actors.

I only noticed the secrets because I had just setup Authelia as an OAuth2 provider for my homelab, and I was adding it to my backup scripts.

[–] Appoxo@lemmy.dbzer0.com 3 points 2 days ago

Ayy, just went through the same troubles with Authelia earlier this week.
Only 4 services I could conmect ao far but still neat to have :)