Welp. My Forgejo instance got popped with an RCE two days ago by CVE-2026-60004. Luckily, I noticed the following morning and had the day free to figure out what happened. Let’s dive in!

As a homelab enthusiast, I found this a very interesting post. Here are my take aways from the post that I’m implementing myself:

  • Miner detection. I’ve updated monitoring rules to now watch the CPU on my hosts. If the same thing happened to me I would not have been alerted at all as I’m doing simple up / down monitoring. Fixed.
  • Access logging. I turned on access logging for my homelab Caddy instances.
  • Log retention. I have increased the amount and retention of my logging. The hope is this will help me reconstruct what happened after a breach.
  • Logs offsite. The VPS access logs now ride along with the normal backup process, which runs hourly. The homelab side still only gets caught by the weekly VM backup, so that’s next.
  • Closed an open signup. My webtrees instance (genealogy) had self registration enabled, which is the same door this guy got hit through. Oops. Fixed.
  • Built a tool. log-inventory.sh, so “could I actually reconstruct what happened” is a command I run instead of a thing I assume.
  • antianarchist@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    1
    ·
    36 minutes ago

    I hate providers not offering me a latest tag. Is there any valid reason not to do that?

    Even worse, super stupid version tags such as MinIO is using: RELEASE.2025-09-07T16-13-09Z-cpuv1 (I wish I made that up)

  • IanTwenty@piefed.social
    link
    fedilink
    English
    arrow-up
    3
    ·
    2 hours ago

    Firewalling containers’ outbound access seems to be rare but another powerful layer of protection

    • chaospatterns@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      59 minutes ago

      Yeah it’s useful and I’ve been using it for my home lab, but too many of my containers want outbound connections to the Internet. Like Forgejo needs :443 to be able to mirror or remote push repositories, so either I have to identify and allow list github.com, gitlab.com, etc. or end up allowing 0.0.0.0/0:443 which is not very strong protection.

      I’d love for some kind of CNI or network plugin that filtered based on domain name.

  • glizzyguzzler@piefed.blahaj.zone
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 hours ago

    The real takeaway is to run your containers ALL as read-only. There’s no way to run executables like this as read-only. They’d download to /tmp but not have executable access and womp womp.

    Many things aren’t read-only friendly, but so far I’ve found all containers can be beat into read-only mode! (Heimdall is one of the worst, shout out to it)

  • tofu
    link
    fedilink
    English
    arrow-up
    4
    ·
    4 hours ago

    Good write up! Since you’re using Komodo already, are your compose stacks in git? Because if they are, check the renovate bot. It will read your files with their pinned image tags, check upstream for newer tags, and creates MRs (can also be set to auto merge) to update. Can be configured per stack.

    • ExperimentalGuy@programming.dev
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 hours ago

      What’s komodo? I’m thinking of starting a home server so learning how to harden/automate updates (which is what it sounds like you’re saying) is what I want to learn.

  • carrylex@lemmy.world
    link
    fedilink
    English
    arrow-up
    24
    arrow-down
    2
    ·
    edit-2
    6 hours ago

    Not updating stuff + Public sign ups enabled (did you even read the setup guide?) + Unrestricted internet access

    Yeah I wonder what could possibly go wrong…

    But great writeup

  • Decronym@lemmy.decronym.xyzB
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    edit-2
    2 minutes ago

    Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:

    Fewer Letters More Letters
    DNS Domain Name Service/System
    Git Popular version control system, primarily for code
    SSH Secure Shell for remote terminal access
    TLS Transport Layer Security, supersedes SSL
    VPN Virtual Private Network
    VPS Virtual Private Server (opposed to shared hosting)

    6 acronyms in this thread; the most compressed thread commented on today has 7 acronyms.

    [Thread #97 for this comm, first seen 7th Sep 2026, 20:40] [FAQ] [Full list] [Contact] [Source code]

  • gaylord_fartmaster@lemmy.world
    link
    fedilink
    English
    arrow-up
    64
    ·
    9 hours ago

    I don’t think I will ever be convinced to leave anything on my home network open to the internet no matter how convenient it is.

    • leds@feddit.dk
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 hour ago

      I gave up , don’t have the time to maintain it anymore. Changed DNS to make my domain point to local lan IP so everything still works but only at home.

    • lemmyvore@feddit.nl
      link
      fedilink
      English
      arrow-up
      13
      arrow-down
      1
      ·
      6 hours ago

      It’s fairly safe as long as you add a strong enough form of access control. For example if you put it behind a VPN, or a SSH tunnel, or require mTLS. Even a key in a custom HTTP header or Basic HTTP auth can be good enough if the key is strong enough.

      You can further decrease the probability of drive-by bots reaching a publicly exposed service by merely scanning IPs and ports if you use a reverse proxy and hide your service FQDNs and IP.

      You can do this by using TLS certs on wildcard domains rather than explicit domains, using explicit CNAMEs for the service subdomains rather than a wildcard domain, and keeping the A/AAAA records on an obfuscated subdomain rather than the base domain. If the bots can’t figure out a FQDN they’re not getting past the reverse proxy even if they find the IP and port.

      This is obfuscation not real security but it cuts down tremendously on bot hits.

        • frongt@lemmy.zip
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 hour ago

          The VPN service is open to the Internet. But it’s only one service, versus however many things you are running behind it.

      • hietsu@sopuli.xyz
        link
        fedilink
        English
        arrow-up
        4
        ·
        6 hours ago

        I have knockd listening on one very high port number, and only after accessing that reverse proxy whitelists the source ip. Sure some scanners might do a full port scan and try http only after that, but FQDN is required too. Plus I have geo ip list blocking all but my country. Oh and Crowdsec. So far so good…

  • epyon22@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    16
    ·
    9 hours ago

    Have you thought about log aggregation with something like Prometheus/graphana or ELK?

    Lol thinking about cpu notifications for myself. I get notified when the fans ramp up on my server.

  • Coolcoder360@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    ·
    8 hours ago

    Nice write up, also glad to see someone using bear blog in the field! Adding your blog to my RSS reader!

    • notfromhere@lemmy.ml
      link
      fedilink
      English
      arrow-up
      2
      ·
      6 hours ago

      Thanks for posting that. I hadn’t heard of falco before. Cncf graduated, open source, cloud native. I’m going to give this a shot.

  • Klox@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    7 hours ago

    OIDC and zero signups for everything. I’ve been very happy with Pomerium (ZTNA) + Keycloak for all my public facing apps, although the free version doesn’t have any client signals which I was hoping for when I starteed.

    My project this week is integrating the app logging I have into Crowdsec and start having Crowdsec do more analysis.

  • mystik@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    9 hours ago

    What version of forgejo were you using? CVE-2026-60004 references gitea 1.27.1

    • doeknius_gloek@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      6
      ·
      7 hours ago

      Unfortunately, Forgejo only offers versioned image tags, meaning no latest tag. I still had mine pinned to v13 which reached EOL 6 months ago in January, 2026.

    • webghost0101@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      33
      ·
      8 hours ago

      Don’t let this discourage you.

      You can self host on your local network just fine and never portforward which is what exposes it to the outside.

      I don’t need to watch tv or upload pictures to my server outside of my home. Its perfectly useable.

      When you are ready and feel more confident you can setup your own wireguard vpn and only expose that.

      Then Your device can connected to that vpn tunnels inside and can acces everything like home.

      Currently without vpn your device is at risk every time it connects to a network you don’t own. A third party vpn is not a guarantee your data is safe either. Your home vpn though means all your outside the home networking is fully encrypted and outsiders cant even detect your home adresses is running a vpn to hack. (No ping unless you have the key)

      • SusanoStyle@lemmy.ml
        link
        fedilink
        English
        arrow-up
        8
        ·
        7 hours ago

        This! Good advice! I went this path last year so i can give some extra advice for everyone who wants to start:

        Before doing anything, buy a new router and put your iot devices and phones in a isolated guest network. Maintain the router updated. After that, you can work, learn and test without fear. Everything stays in your home.

        Then like @webghost0101@sopuli.xyz already said, once you get confident, you can run a vpn tunnel to access your lan. This setup is pretty robust, hard to fuck up, and doable even for newbies. (If i can do it, everyone can, i assure you). Lots of guides out there.

        Last advice, which you should already be doing, but setup a backup.

    • Onomatopoeia@lemmy.cafe
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      1
      ·
      6 hours ago

      I have a lot of stuff self-hosted.

      Just no outside access. Well, that’s not quite true, I do have a Tailscale VPN for remote management, but only certain machines are allowed to join, joins require my authorization, and access to the account is via two-factor.

      The big thing with external access is to never permit it directly through your local connection. Do it though a Virtual Private Server (VPS) - let it get hit with access attempts. And then only allow specific traffic from the VPS to a specific service in your network using a VPN of some sort.