About that, I had the absolutely issue, but I was hosting WordPress.
The first thing I was doing after setting a droplet was changing the password to something that was easier for me to remember, something along the line of 'qweasdzxc' but a bit harder combination. This was huge mistake on my part.
Apparantly my password was being bruteforced and once they get root access the DDOS attacks were being performed. What I did was delete the first droplet, starting a new one and just adding a few numbers after the randomly generated password that is sent to you by email. Then I went ahead and installed fail2ban(https://www.digitalocean.com/community/tutorials/how-to-prot...) + some iptables configurations thats are shown in that link. It practicly makes bruteforcing your droplet close to impossible(at least I think so).
If you need any assistence you can contact me through my profile e-mail and I would gladly help you. Remember though you will need a clean droplet, because your system was already compromised and there are holes in it, that simply installing fail2ban will not be enough.
P.S I have no idea why this post is 'dead' and I can't see your e-mail in your profile to shoot you an email with this information.
If you think you need more lightweight PHP blogging solution, I am a happy user of Anchor CMS[1]. There are some nice free themes for it too at Anchor Themes[2].
They had a Show HN a few months ago
The first thing I was doing after setting a droplet was changing the password to something that was easier for me to remember, something along the line of 'qweasdzxc' but a bit harder combination. This was huge mistake on my part.
Apparantly my password was being bruteforced and once they get root access the DDOS attacks were being performed. What I did was delete the first droplet, starting a new one and just adding a few numbers after the randomly generated password that is sent to you by email. Then I went ahead and installed fail2ban(https://www.digitalocean.com/community/tutorials/how-to-prot...) + some iptables configurations thats are shown in that link. It practicly makes bruteforcing your droplet close to impossible(at least I think so).
If you need any assistence you can contact me through my profile e-mail and I would gladly help you. Remember though you will need a clean droplet, because your system was already compromised and there are holes in it, that simply installing fail2ban will not be enough.
P.S I have no idea why this post is 'dead' and I can't see your e-mail in your profile to shoot you an email with this information.