Security & DDoS20 articles

DDoS handling, account safety and the rules that keep the node clean.

DDoS Mitigation & Null-Route ProtocolHow L4/L7 DDoS mitigation filters traffic, and the safety null-routing trigger.1 min readAcceptable Use Policy (AUP) RestrictionsStrictly prohibited server activities that result in immediate suspension.1 min readOffline Mode (Cracked Server) Security RisksCritical precautions when disabling Mojang authentication (online-mode=false).1 min readMalicious Code & Pirated (Nulled) PluginsRisks of installing non-official plugins and our suspension policy.1 min readBypassing Security on Proxy NetworksPreventing players from connecting directly to backend servers and bypassing auth.1 min readSecuring RCON Access & CredentialsSafety rules to prevent automated bots from hijacking server console controls.1 min readSecuring the account everything else hangs offYour panel account can delete every world you have. Treat it like it can.2 min readDeciding who gets power, and taking it back safelyMost server disasters are not attacks. They are somebody who was given more than they needed.2 min readThe first hour after a griefWhat to do in what order, when the temptation is to start rebuilding immediately.2 min readChecking a plugin before you install itA plugin runs with your server's full authority. Five minutes of checking is proportionate.2 min readAddress privacy and «I'll DDoS you» threatsWhat is actually exposed, what those threats are worth, and the two habits that matter.2 min readThe server.properties settings that are security settingsSix lines that decide whether your server is a server or an open door.2 min readThe permission nodes that quietly hand over your serverSeven grants that look ordinary and are equivalent to operator.2 min readThe backup rule that actually survives thingsThree copies, two places, one of them somewhere you cannot reach by accident.2 min readScams aimed at server owners and staffThe four that actually work, and the one habit that stops all of them.2 min readX-ray: how to tell, and what to do about itThe evidence that actually holds up, and the fix that works without accusing anyone.2 min readBan evasion and alt accountsWhat you can actually do about someone who comes back, and what is not worth trying.2 min readWhich logs to keep, and for how longThe four records that answer questions later, and the one that grows until it fills your disk.2 min readSomething is wrong: a compromise checklistThe order to work in when you think someone else has access.2 min readLinks, downloads and the files people send youRunning a server makes you a target for a specific set of files.2 min read