Welp. My Forgejo instance got popped with an RCE two days ago by CVE-2026-60004. Luckily, I noticed the following morning and had the day free to figure out what happened. Let’s dive in!

As a homelab enthusiast, I found this a very interesting post. Here are my take aways from the post that I’m implementing myself:

  • Miner detection. I’ve updated monitoring rules to now watch the CPU on my hosts. If the same thing happened to me I would not have been alerted at all as I’m doing simple up / down monitoring. Fixed.
  • Access logging. I turned on access logging for my homelab Caddy instances.
  • Log retention. I have increased the amount and retention of my logging. The hope is this will help me reconstruct what happened after a breach.
  • Logs offsite. The VPS access logs now ride along with the normal backup process, which runs hourly. The homelab side still only gets caught by the weekly VM backup, so that’s next.
  • Closed an open signup. My webtrees instance (genealogy) had self registration enabled, which is the same door this guy got hit through. Oops. Fixed.
  • Built a tool. log-inventory.sh, so “could I actually reconstruct what happened” is a command I run instead of a thing I assume.
  • gaylord_fartmaster@lemmy.world
    link
    fedilink
    English
    arrow-up
    58
    arrow-down
    3
    ·
    6 days ago

    I don’t think I will ever be convinced to leave anything on my home network open to the internet no matter how convenient it is.

  • carrylex@lemmy.world
    link
    fedilink
    English
    arrow-up
    35
    arrow-down
    2
    ·
    edit-2
    6 days ago

    Not updating stuff + Public sign ups enabled (did you even read the setup guide?) + Unrestricted internet access

    Yeah I wonder what could possibly go wrong…

    But great writeup

  • epyon22@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    14
    ·
    6 days ago

    Have you thought about log aggregation with something like Prometheus/graphana or ELK?

    Lol thinking about cpu notifications for myself. I get notified when the fans ramp up on my server.

  • PieMePlenty@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    ·
    5 days ago

    My server got hacked once and was mining crypto! I noticed it when I heard the fans were at 100% when walking passed the room lol. Turns out, qbittorrent-nox used UPNP for its web admin endpoint enabled by default and qbittorrent can do many things like run custom scripts. My mistake was not changing its login credentials. Exposed my full system. Live and learn.

  • irmadlad@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    5 days ago

    About the only recent even I’ve had was when I was sitting at my desk reading an article. I noticed the mouse slightly move, but I hand no hand on the mouse. I sit there watching it, not manually moving the mouse or typing on the keyboard. It really freaked me out. Turns out, my old desk pad had a slight curl towards the edge the mouse was at, and the curl would make the mouse sense movement ever so slightly. I deployed a new desk pad, and things are back to normal. Whew!

  • Wispy2891@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    ·
    6 days ago

    And detected mostly because the automated script kiddie set up a cryptominer to generate $0.0001

    There are way more valuable and destructive ways once you have RCE like:

    • Searching for committed API keys “anyway my repo is private”
    • Ransomware in case there were no backups
  • Coolcoder360@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    ·
    6 days ago

    Nice write up, also glad to see someone using bear blog in the field! Adding your blog to my RSS reader!

    • notfromhere@lemmy.ml
      link
      fedilink
      English
      arrow-up
      3
      ·
      6 days ago

      Thanks for posting that. I hadn’t heard of falco before. Cncf graduated, open source, cloud native. I’m going to give this a shot.

    • doeknius_gloek@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      7
      ·
      6 days ago

      Unfortunately, Forgejo only offers versioned image tags, meaning no latest tag. I still had mine pinned to v13 which reached EOL 6 months ago in January, 2026.

  • Klox@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    6 days ago

    OIDC and zero signups for everything. I’ve been very happy with Pomerium (ZTNA) + Keycloak for all my public facing apps, although the free version doesn’t have any client signals which I was hoping for when I starteed.

    My project this week is integrating the app logging I have into Crowdsec and start having Crowdsec do more analysis.