{"repo":"rockballslab/vps-secure","free":true,"listed":false,"github":"https://github.com/rockballslab/vps-secure","clone":"git clone https://github.com/rockballslab/vps-secure.git","description":"🛡️ VPS-SECURE is the only script that turns a bare VPS into an operational fortress — honeypot, collaborative IPS, real-time dashboard, Telegram alerts — in 15 minutes and 1 command, with zero Linux expertise required. 🚀⚡","language":"HTML","stars":24,"topics":["bash","crowdsec","devops","docker","hardening","homelab","linux","security","selfhosted","server-security"],"license":null,"category":"self-hosted-apps","readme_excerpt":":fr: Version française :zap: +1597 bots blocked in 24h on a standard VPS — is yours really protected? --- VPS-SECURE From naked to bulletproof. One command. :closed lock with key: Your VPS hardens itself while you sleep with a single command. No Linux expertise required. One script. 15 minutes. Never think about it again. --- :shield: What makes this script different? A bare or default-configured server is an easy target — visible and attackable within minutes. VPS-Secure is not just an install script: it's a complete security stack that turns a naked VPS into a hardened, production-ready server — with SSH lockdown, crowdsourced intrusion detection, a honeypot, and real-time alerts. All automated. All in one command. --- Bare VPS vs. VPS-SECURE — The real difference Bare VPS VPS-SECURE --- :---: :---: Default exposed ports ❌ All ✅ 3 only (2222 / 80 / 443) Brute force protection ❌ None ✅ CrowdSec collaborative IPS Port 22 bots ❌ Active attack vector ✅ Trapped for hours by Endlessh SSH root login ❌ Allowed ✅ Permanently disabled SSH authentication ❌ Password (bruteforceable) ✅ Key-only (ed25519) Kernel hardening ❌ 0 parameters ✅ 35 sysctl parameters Rootkit scanning ❌ None ✅ rkhunter — daily at 00:00 UTC File integrity monitoring ❌ None ✅ AIDE — SHA512 baseline daily 03:00 Docker firewall bypass ❌ Exposed by default ✅ Fixed — UFW has full control Security alerts ❌ None ✅ Telegram — instant SSH + daily report Automatic security patches ❌ No ✅ Yes — incl. Docker CE Lynis hardenin","default_branch":null,"files":null,"tree":[],"storefront":"/r/rockballslab","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/rockballslab/vps-secure/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}