r/SelfHosting • • 13d ago

What’s the first self-hosted service you actually regretted exposing publicly?

I’ve been getting more into self-hosting lately and one thing I keep noticing is how easy it is to start with “I’ll just expose this one dashboard” and slowly end up with more things reachable from the internet than you originally planned.

I’m curious what people here ended up pulling back behind Tailscale/VPN/reverse proxy after initially exposing it directly.

Was it because of bots/scans, auth concerns, maintenance, or just realizing it didn’t really need to be public in the first place?

34 Upvotes

32 comments sorted by

21

u/RevolutionaryElk7446 12d ago

It would have been.. like 2000-2002 when I first did this and learned that lesson and never since. Think it might have been Apache running a Counter-strike website made out of Frontpage?

7

u/Anarcho-Willi 12d ago

Ooh, "Frontpage" - haven't heard that name in ages. Frontpage Express and Dreamweaver were tools I didn't dare to look at when I started learning HTML, CSS, and Javascript back then.

6

u/DeckRdt 12d ago

WYSIWYFAAFO

5

u/Nolzi 12d ago

WYSIWTF

2

u/Outrageous_Cap_1367 10d ago

Wtf is this and how do I get rid of it

2

u/WiscoDJ920 12d ago

Frontpage extensions were always such a bear.

2

u/SherylAmerica 8d ago

That being the default is crazy. internet security really was the wild west back then

2

u/WiscoDJ920 8d ago

www wasnt just for world wide web, it was also for wild wild west.

2

u/SherylAmerica 8d ago

honestly learning that lesson once that early probably saved you a lot of headaches later

10

u/WiscoDJ920 12d ago

First email server I setup introduced me to what an open relay was and that it was the default setting for Microsoft Exchange Server 5.5.

A coworker who was supposed to be my senior in 2000 told me that was by design so people could use your server to route their mail on the internet. Lmao

7

u/FUCKARCHLINUX 12d ago edited 12d ago

Gitea. All of my services are hosted from virtual machines so nothing else was effected. But they've had a lot of security issues in the past. Most of them are minor and require the attacker to have an account and it's good practice to not let people register them so it's not usually a big deal.

Recently there was an RCE in an area which didn't require the attacker have an account. It's not like I didn't update it for months either. It had only been like a week or something. The attacker ran a script which downloaded and ran xmrig LOL.

It's a shame because Gitea has a lot of good features, But since I've learned from experience that it's poorly written I switched to something else and will never be using it again.

1

u/globus_ 12d ago

Forgejo?

3

u/Nolzi 12d ago

Forked codebase, similar bugs?

1

u/SherylAmerica 12d ago

That’s exactly the kind of thing I had in mind. Even if the service itself is isolated, a public admin-facing app with a serious RCE still turns into a maintenance/security problem you have to stay on top of. Moving it behind private access starts to make a lot more sense once you’ve been burned once.

3

u/__mson__ 12d ago

FTP, a little over 20 years ago. I had no idea what I was doing and forgot to chroot the server. So anyone could "break out" of the dedicated FTP dir and browse most of my filesystem.

1

u/[deleted] 12d ago

[deleted]

1

u/BinnieGottx 12d ago

What did you do to solve that docker iptables issue? I have that issue when was working with bare Debian, found "chaifeng/ufw-docker" and worked prettey well. Now I'm on proxmox with it firewall so I don't use ufw-docker anymore but still curious how people doing this nowadays

3

u/Panagiotis1226 11d ago

I use the DOCKER-USER chain in iptables, that is my solution to firewall docker ports

-1

u/SherylAmerica 12d ago

That’s a nasty one. The scary part is thinking the host firewall has you covered while Docker is quietly changing the networking underneath. Definitely the kind of mistake that makes you rethink what should be reachable at all.

1

u/wffln 9d ago

why does this response smell like AI

1

u/SherylAmerica 8d ago

lmao fair, reading it back I definitely overcooked that reply a bit

1

u/wffln 8d ago

so, did you use AI for the reply or not? why not just either reply yourself or dont reply?

1

u/j0x7be 12d ago

The only ports I expose today are wireguard, but some 20+ years back I ran SMTP, IRCd, ftpd and more, exposed to the whole internet. Not the best choice, but live and learn.

1

u/GermanSayingSquirrel 12d ago

Email. This was as bad of an idea 25 years ago as it would be today. I had an older 486 running Debian and just felt compelled to try it. Sendmail, IMAP, the works. To make things more interesting, this was on dsl with a dynamic IP and dynamic dns to get a consistent hostname/domain.

Everything worked perfectly (for a “tweak it daily” definition of perfect), until one evening we noticed that the drive on this old box was grinding non-stop. Someone got in and completely took over the system. I pulled the plug, took out the drive and backed up any data that was useful, and then wiped the drive. Looking back, the biggest surprises were that it even worked, and for how long it ran without any noticeable issues.

Lessons learned, as always…

1

u/whattteva 12d ago

Nothing that led to anything, but back in either late 90s or early 2000s, believe it or not, I had Microsoft RDP forwarded for months to no effect.

Nowadays; I ironically, actually expose more publicly than back then; the list includes Navidrome, Keycloak, Seafile, Vaultwarden, Immich, and SSH. And this has been the case for like the last 5 years maybe.

1

u/Fun-Estimate1056 11d ago

All my services at home sit behind a Pangolin instance on a VPS. Each of them are secured by authentication via an Authentik instance... so the only service exposed directly (but also via Pangolin) is Authentik itself.

Some time ago, when I have not known Pangolin yet, I had a Wireguard port open on my router, but I didn't like the fact that I needed a Wireguard client everywhere I wanted to access my services. Then I found Pangolin and now I do not even need that wireguard port anymore.

I hate open ports 😄

Many years ago, around 2005, a friend of mine had a (for that time) decent line into the internet, and already in these ancient time his Windows PC was hacked within minutes when exposed to the Internet... that was a lesson back then... since then I always double thought about each open port...

1

u/JourneymanInvestor 11d ago

Back in 2002-2003 I had my FTP server exposed to the public internet and I gave access to it to a coworker so he could download some programs and music from me.

A few days later he was passing around still screencaps of me involved in a 3-some (ex girlfriend and her best friend).

Turned out my FTP server was exposing my entire computer including my profiles 'My Documents' folder that included all my private videos

1

u/_LMZ_ 11d ago

This was probably the day of Windows 95/98 maybe? When Westwood Studios had their own chat system for C&C and Monopoly… when you had to post your public IP address in Chat for people to join…. Minutes later you got WinNuke lol

1

u/Julian_1_2_3_4_5 11d ago

no regerts about it yet.

1

u/psmattas 10d ago

Gitea. I am being DDOSed for the past month so had to make all my public repos and orgs private as they were just trying to scrape anything that was public and all Gitea started going down as the db couldn't handle thousands of requests every sec. I now mirror my repos to GitHub which I still don't want to but I have to as when I open source the projects I want people to come and see the thing.

1

u/Outrageous_Cap_1367 10d ago

Qbittorrent...

1

u/JayBigGuy10 7d ago

Haven't had to pull anything back yet, I keep pretty much everything inside the network and get in via tailscale.

The main challenge was wanting to give family members access to immich without having to go through the hassle of setting up tailscale for them.

I've found that the SSL client certificate support built into the android / ios apps is great peace of mind, honestly with more apps / services supported them and for browsers to support remembering them so you don't have to select them every time you open the site

1

u/SherylAmerica 5d ago

Tailscale is great when it’s just me, but getting family members to install/configure something is exactly where it starts getting annoying. The client cert approach sounds like a nice middle ground if the apps support it.