HockeyEros’s Birth and its Technical Difficulties

Man wearing a red hockey uniform kneeling on an arena's ice while holding a hockeystick

Hello, HockeyGod here with his technical difficulties…

This is my first time working with WordPress, and I already have complaints.

Why isn’t the editor more intuitive? It seems like options are hidden under other options and I don’t know where to look (said the person who’s used DreamWeaver before).

Anyways, we are looking for someone who is likely more experienced with this technology and our LAMP stack. And, also a security consultant who can tell us where the gaps in our security are!

We are running our stack on an Azure Spot Instance (since it’s cheaper) and using a local script to poll uptime. Technically, we have the resources to migrate off the cloud and onto dedicated home-lab hardware (it’s likely going to live on a VirtualBox VM [I don’t want to learn Docker, but Docker would be the best option for us (probably) (also, I don’t have a Docker box :/ )]), but doing an actual firewall setup on HockeyGod’s LAN sounds like a burden (I don’t want to secure my shit).

We do the standard SSH-key-based authentication (per Azure spec + IP-based firewall port access) and have changed the stock WP hosting credentials, but what else do we do?

Cloudflare’s reverse proxy is protecting us (and they are handling our SSL), which makes it probably unlikely to expose our raw Azure IP. (I’ve definitely seen auto-configs that have exposed our IP.)

Also, we have CrowdSec enabled with their Cloudflare Agent, so hopefully, that’ll solve the bots (part of it).

How do I actually harden my Ubuntu server (yes, I know I’m Linux trash)?

This is me (we love Taylor) asking tech support for my technical difficulties on a blog that probably no one will read…

Anyways, if you do have some tips and tricks, drop us an email @ [email protected]

Thanks, we’ll see you around (hopefully)
🙂 HockeyGod

Update 8/6/2023

One person came around and tried brute-forcing our login page with common WordPress usernames. We saw you 😉 (in our logs :/ ). Pretty please, don’t do that again…

Who are we?

Check us out on…
Insta! https://instagram.com/thehockeyeros
Twitter / X! https://twitter.com/thehockeyeros