That’s the difficult thing about high uptime with internet-connected devices. I remember watching uptimes go to astronomical numbers on netcraft, today all I can think about is how unpatched those systems must have been.
- BIND
- an MTA/MSA (probably the riskiest thing)
- MySQL (local only)
- PHP + Apache2
- SSH
So the attack surface was larger than you’d think. I only had hundreds of blog visitors to be honest.
But the world has changed over the years. Even the existence of things like residential proxies makes fail2ban pointless nowadays. You have to be better. I was young and foolish and lucky.