Softaculous BGP hijack - secure risks

Hi, thank you for sharing.

I am curious however how we can control the damage against attacks like these.

In case of a BGP hijack, and to prevent further damage,
we should implement DNSSEC to secure our DNS,
we should configure CAA records and limit accounts that can requests certificates (wildcard and regular).
...
we should implement hsts


What else?

Kr
Dries
 
Back
Top