Reversible Linux hardening
Out of the box, a fresh Debian or Ubuntu server is wide open — password login on, no brute-force protection, nothing locked down. That's why bots find it and start breaking in within minutes. HardVps closes every door — SSH, passwords, kernel, network — one reviewable fix at a time, and every one of them undoes with a single command.
Ubuntu 24.04 tested · Debian & Ubuntu · x86_64 + ARM64 · no agent, no telemetry
Why not a script?
Free hardening scripts are everywhere. They don't carry the same risk. A script applies everything at once and leaves you to find out what broke — on a machine you may only reach through SSH. HardVps shows you each change before it runs, applies only what you approved, and sets the original aside so you can put it back byte for byte.
The threat
Automated scanners sweep the entire internet, around the clock. A newly exposed service gets its first probes within minutes. Attackers even start scanning for a new vulnerability a median of 15 minutes after it's published. Nobody chose you. They're testing every door on the street, and default configs are the ones that open.
Your CPU starts mining for someone else
The dominant payloads dropped on cracked SSH servers: crypto-miners and self-spreading botnet worms. Your bill, their coins.
Your secrets walk out the door
SSH keys, .env files, database dumps — then every machine and account that server could reach. One weak box compromises the rest.
Your provider pulls the plug
Abuse reports land, the account gets suspended, the IP blacklisted. The cleanup and migration? That's your weekend.
sources: Palo Alto Networks Unit 42 (attack-surface scan study) · AhnLab ASEC honeypot reports, 2025
How it works
Before anything touches your server, HardVps shows you what will change — in plain words, with the exact command it will run. Nothing happens without your OK.
Check the boxes you want — HardVps does the rest. Before each change, the original is set aside in a safe place. Automatically, every single time.
Undo one change — or all of them. Your server comes back exactly as it was, proof included. No snapshot, no reinstall, no sweat.
Proof
Fresh Ubuntu 24.04 cloud instance, Lynis pinned at 3.1.7. Full cycle, measured:
What's this score?
Lynis is a widely used open-source security auditor. It inspects a Linux box and rates its hardening from 0 to 100 — the same yardstick sysadmins use. In our tests, an unhardened Debian/Ubuntu server measured 57. The point isn't the number itself: it's that it's measured on your machine, before and after — by a tool we don't control.
measured 2026-07 · Ubuntu 24.04 LTS x86_64 · Lynis 3.1.7 · same box, same day
The honest part
A deeper tier barely moves the score — and we say so. Tiers buy you deeper hardening (key-only SSH, stricter auth), not vanity points. Every fix shows you the exact command before it runs, so you can judge for yourself whether your box needs it.
What's inside
Thirty-two curated fixes — each one opt-in, each one undoable, each one tied to a real attack, not an abstract checkbox. A sample:
Stops: the password-guessing bots from your auth.log — all of them. No password to guess.
Stops: brute-force floods — repeat offenders get banned at the firewall, automatically.
Stops: spoofing and redirect tricks at the network layer — the plumbing bots poke first.
Stops: “admin123” from ever existing on this box. Weak passwords are how dictionaries win.
Stops: an intruder who lands in one account from reading every other user's files.
Closes: network protocols you've never used — but exploit kits have. If you don't need the door, brick it.
Required by most compliance checklists.
For: the morning after. Who ran what, when — an audit trail that survives an incident.
+ 24 more — sysctl sets, login.defs, core dumps, compiler perms, firewall, auditd…
Pricing
HardVps · medium
◆ Special price
USD/CAD/EUR handled at checkout · VAT/GST included where it appliesRead the license and refund policy before buying
custom hardened image
HardPinext up
audit-pi free · open source
Our security audit for Raspberry Pi. One scan, one readable report — see where yours stands before spending a dollar.
Rather have an expert do it, or rescue a server that's already in trouble?
Hands-on hardening, debloat and rescue on your live server, under the HardStacked name. Guided or supervised access, time-boxed and logged.
Our free Raspberry Pi security audit. See where your Pi stands before spending a dollar.
FAQ
Talk to us
Tell us what you need. We reply from hardstacked@proton.me.
No account, no tracker · bot-filtered
✓ Sent. We'll get back to you.