Welp. My Forgejo instance got popped with an RCE two days ago by CVE-2026-60004. Luckily, I noticed the following morning and had the day free to figure out what happened. Let’s dive in!
As a homelab enthusiast, I found this a very interesting post. Here are my take aways from the post that I’m implementing myself:
- Miner detection. I’ve updated monitoring rules to now watch the CPU on my hosts. If the same thing happened to me I would not have been alerted at all as I’m doing simple up / down monitoring. Fixed.
- Access logging. I turned on access logging for my homelab Caddy instances.
- Log retention. I have increased the amount and retention of my logging. The hope is this will help me reconstruct what happened after a breach.
- Logs offsite. The VPS access logs now ride along with the normal backup process, which runs hourly. The homelab side still only gets caught by the weekly VM backup, so that’s next.
- Closed an open signup. My webtrees instance (genealogy) had self registration enabled, which is the same door this guy got hit through. Oops. Fixed.
- Built a tool.
log-inventory.sh, so “could I actually reconstruct what happened” is a command I run instead of a thing I assume.



I gave up , don’t have the time to maintain it anymore. Changed DNS to make my domain point to local lan IP so everything still works but only at home.
I wonder if the person who downvoted you thought you pointed your public DNS record to a 192.168 network, instead of making a change to your local DNS server like I’m assuming you did.
If you want https it’s gotta be a external DNS record anyway, might as well point to internal ips
Depending on how paranoid your setup is not everything will use the DHCP provided DNS servers
Not sure what you mean by that, but off the top of my head, you can get certificates via challenges that prove DNS control (rather than checking if the DNS points to your server), and you can get wildcard certificates so you don’t even have to expose the existence of subdomains.
And that’s ignoring the option of using your own CA, which only really works with your own devices, but for local access might be viable.
No it doesn’t. I run https with my own CA server.