pajus @published 2026-09-25 · 10 min read restic Backups on Debian 13: Hardened Setup Set up restic backups on Debian 13: SFTP or S3 repos, a sandboxed systemd timer, forget --prune retention, append-only rest-server and restore tests. Tags Debian Linux Security systemd Server Administration Backups
pajus @published 2026-09-24 · 10 min read How Container Escapes Work: runc and Defenses How container escapes work via the 2025 runc procfs bugs, and how to audit and harden a Debian 13 Docker or Podman host with checks you can verify. Tags Docker Privilege Escalation Debian Linux Security Server Hardening
pajus @published 2026-09-24 · 10 min read BIND9 and Unbound Security Updates on Debian 13 Debian 13 fixes BIND9 and Unbound flaws (DSA-6505-1, DSA-6507-1): how to check versions, patch, restart and verify your recursive DNS resolver. Tags DNS Security Updates Debian Linux Security Server Administration
pajus @published 2026-09-24 · 10 min read Sandboxing systemd Services on Debian 13 Sandbox systemd services on Debian 13: score units with systemd-analyze security, harden nginx via a systemd drop-in, then debug whatever breaks. Tags Linux Security Server Hardening Debian systemd Nginx
pajus @published 2026-09-23 · 8 min read Fail2ban on Debian 13 with nftables Set up fail2ban on Debian 13 with nftables: the Debian defaults, systemd journal backend, sshd and recidive jails, incremental bans and how to verify bans. Tags Debian Linux Security Server Hardening SSH Firewall
pajus @published 2026-09-23 · 9 min read Hardening SSH on Debian 13 with OpenSSH 10 Hardening SSH on Debian 13 (trixie): a practical sshd_config drop-in for OpenSSH 10.0, key-only logins, post-quantum KEX, rate limits and open CVEs. Tags SSH Debian Linux Security Server Hardening