What is SSH?
SSH stands for Secure Shell. It lets you log in to a remote server and type commands, safely and with encryption (scrambling so others cannot read it). It is like a private phone line to your server. Many of these commands need root access, so they fit a VPS or dedicated server.
Connect to your server
ssh username@your-server-ip
This logs you in. Replace the parts with your own details, which are in your welcome email.
Commands to know
See who is logged in
who
Shows users who are connected now. Unknown names are a warning sign.
See recent logins
last
Lists past logins with time and place. Look for addresses you do not know.
See failed logins
lastb
Lists failed login tries. Many tries from one address could be an attack. It needs root.
Check running programs
top
Shows what uses your CPU and memory. Press q to leave.
Check open ports
ss -tuln
Lists the doors (ports) that listen for connections. Close the ones you do not need.
Change your password
passwd
Lets you set a new password for your user.
Find recently changed files
find /var/www -type f -mtime -2
Lists files changed in the last two days. Useful after a hack.
Check the login log
tail -n 50 /var/log/auth.log
Shows the last 50 login events on Ubuntu or Debian. On CentOS or AlmaLinux use /var/log/secure.
Check file permissions
ls -l
Shows who may read, write or run each file.
Safer SSH habits
- Use SSH keys instead of passwords. A key is a long secret file that only you hold.
- Do not log in as root every day. Use a normal user and
sudo. - Turn off root login and password login in
/etc/ssh/sshd_configonly after your key works. Back up the file first. - Keep the server updated.
Quick recap
- SSH is a safe way to control your server.
- Use
who,lastandlastbto watch logins. - Use
ssandtopto check ports and programs. - Prefer SSH keys over passwords.