Security & DDoS20 articles
DDoS handling, account safety and the rules that keep the node clean.
DDoS Mitigation & Null-Route ProtocolHow L4/L7 DDoS mitigation filters traffic, and the safety null-routing trigger.Acceptable Use Policy (AUP) RestrictionsStrictly prohibited server activities that result in immediate suspension.Offline Mode (Cracked Server) Security RisksCritical precautions when disabling Mojang authentication (online-mode=false).Malicious Code & Pirated (Nulled) PluginsRisks of installing non-official plugins and our suspension policy.Bypassing Security on Proxy NetworksPreventing players from connecting directly to backend servers and bypassing auth.Securing RCON Access & CredentialsSafety rules to prevent automated bots from hijacking server console controls.Securing the account everything else hangs offYour panel account can delete every world you have. Treat it like it can.Deciding who gets power, and taking it back safelyMost server disasters are not attacks. They are somebody who was given more than they needed.The first hour after a griefWhat to do in what order, when the temptation is to start rebuilding immediately.Checking a plugin before you install itA plugin runs with your server's full authority. Five minutes of checking is proportionate.Address privacy and «I'll DDoS you» threatsWhat is actually exposed, what those threats are worth, and the two habits that matter.The server.properties settings that are security settingsSix lines that decide whether your server is a server or an open door.The permission nodes that quietly hand over your serverSeven grants that look ordinary and are equivalent to operator.The backup rule that actually survives thingsThree copies, two places, one of them somewhere you cannot reach by accident.Scams aimed at server owners and staffThe four that actually work, and the one habit that stops all of them.X-ray: how to tell, and what to do about itThe evidence that actually holds up, and the fix that works without accusing anyone.Ban evasion and alt accountsWhat you can actually do about someone who comes back, and what is not worth trying.Which logs to keep, and for how longThe four records that answer questions later, and the one that grows until it fills your disk.Something is wrong: a compromise checklistThe order to work in when you think someone else has access.Links, downloads and the files people send youRunning a server makes you a target for a specific set of files.