🛡️ Security Report

Wednesday, June 17, 2026 — 22:52 ICT

💻 System Health

43G/473G
Disk Used
1.5Gi/30Gi
Memory (5%)
3.58, 4.85, 3.97
Load Average
6 days, 11 hours, 23 minutes
Uptime

Fail2ban: active  ·  UFW Blocks (24h): 17,269

📡 Open Ports

✓ ufw-docker active Docker ports on 0.0.0.0 are blocked from external access

Cross-referenced with Docker port mappings and UFW rules

Local AddressServiceType
100.80.139.9:8000docker-proxy Docker internal
10.0.1.1:22sshd
0.0.0.0:443docker-proxy Docker 0.0.0.0 (ufw-docker blocked)
0.0.0.0:80docker-proxy Docker 0.0.0.0 (ufw-docker blocked)
100.80.139.9:6002docker-proxy Docker internal
100.80.139.9:6001docker-proxy Docker internal
127.0.0.1:22sshd loopback
100.80.139.9:36486tailscaled Tailscale
127.0.0.1:8000docker-proxy loopback
127.0.0.1:24543moshi-hook loopback
127.0.0.1:6012cloudflared loopback
0.0.0.0:8080docker-proxy Docker 0.0.0.0 (ufw-docker blocked)
127.0.0.54:53systemd-resolve
100.80.139.9:22sshd Tailscale
127.0.0.53%lo:53systemd-resolve
10.0.0.1:22sshd
100.80.139.9:8443tailscaled Tailscale
[::]:443docker-proxy Docker internal
[::]:80docker-proxy Docker internal
[fd7a:115c:a1e0::533b:8b09]:22sshd Tailscale
[::]:8080docker-proxy Docker internal
[fd7a:115c:a1e0::533b:8b09]:8443tailscaled Tailscale
[fd7a:115c:a1e0::533b:8b09]:43591tailscaled Tailscale

🔥 Firewall (UFW)

Status: active

To                         Action      From
--                         ------      ----
41641/udp                  ALLOW       Anywhere                  
22/tcp on tailscale0       ALLOW       Anywhere                   # SSH via Tailscale only
Anywhere on tailscale0     ALLOW       Anywhere                  
60000:61000/udp on tailscale0 ALLOW       Anywhere                   # Mosh via Tailscale
22/tcp on docker0          ALLOW       Anywhere                  
41641/udp (v6)             ALLOW       Anywhere (v6)             
22/tcp (v6) on tailscale0  ALLOW       Anywhere (v6)              # SSH via Tailscale only
Anywhere (v6) on tailscale0 ALLOW       Anywhere (v6)             
60000:61000/udp (v6) on tailscale0 ALLOW       Anywhere (v6)              # Mosh via Tailscale
22/tcp (v6) on docker0     ALLOW       Anywhere (v6)

🔐 SSH Activity

0
Failed Attempts (24h)
6198
New Sessions (24h)

🔒 Tailscale SSH Logins (last 10)

TimeIPHostTailscale UserNode
06/17 15:33100.95.106.126iphoneairtagged-devicesiphoneair
06/17 15:35100.95.106.126iphoneairtagged-devicesiphoneair
06/17 15:36100.95.106.126iphoneairtagged-devicesiphoneair
06/17 15:38100.95.106.126iphoneairtagged-devicesiphoneair
06/17 15:39100.95.106.126iphoneairtagged-devicesiphoneair
06/17 15:41100.95.106.126iphoneairtagged-devicesiphoneair
06/17 15:42100.95.106.126iphoneairtagged-devicesiphoneair
06/17 15:43100.95.106.126iphoneairtagged-devicesiphoneair

🔑 Other SSH Logins (last 10)

TimeIPHostPort
06/17 21:5510.0.0.210.0.0.260796
06/17 22:0110.0.0.210.0.0.233906
06/17 22:0710.0.0.210.0.0.238042
06/17 22:1310.0.0.210.0.0.236894
06/17 22:1910.0.0.210.0.0.244394
06/17 22:2510.0.0.210.0.0.250586
06/17 22:3110.0.0.210.0.0.259604
06/17 22:3710.0.0.210.0.0.248996
06/17 22:4310.0.0.210.0.0.241434
06/17 22:4910.0.0.210.0.0.257234

🔍 Processes

✓ No high CPU processes

✓ No high memory processes

🌐 Tailscale

12/15 peers online

NodeOSIPStatus
ssdnode this machinelinux100.80.139.9✓ Online
boxlinux100.86.226.66✓ Online
contabolinux100.111.135.6✓ Online
glkvmlinux100.123.198.85✓ Online
hkrouterlinux100.66.31.7✓ Online
ipad13tviOS100.117.146.121✓ Online
ipadproiOS100.65.224.43✓ Online
iphone-14-pro-maxiOS100.92.136.103✓ Online
iphoneairiOS100.95.106.126✓ Online
kitailinux100.97.4.90✓ Online
kits-macbook-airmacOS100.127.101.27✓ Online
kits-macbook-pro-9h4ymacOS100.123.239.87✓ Online
tencentlinux100.109.227.19✓ Online
appletvtvOS100.108.161.6✗ Offline
kitlegiongowindows100.67.231.89✗ Offline
mobilerouterlinux100.127.101.21✗ Offline

🐣 Docker

✓ No TCP daemon exposure

ContainerStatusPorts
coolify-sentinelUp 3 days (healthy)
so13t9jiakgbyzwp863dmvzu-103035573499Up 6 days3000/tcp
lijg3ncf0yp8on32jagmeg0yUp 6 days (healthy)5432/tcp
lkn2msiqhoymcuyaa64cnazj-065012572847Up 6 days3000/tcp
ithh2dbx1jyjl6dejr3mre1kUp 6 days (healthy)5432/tcp
enthri8p43s4atofatobcunp-232449789422Up 6 days3000/tcp
coolifyUp 6 days (healthy)8000/tcp, 8443/tcp, 9000/tcp, 100.80.139.9:8000->8080/tcp, 127.0.0.1:8000->8080/tcp
coolify-proxyUp 6 days (healthy)0.0.0.0:80->80/tcp, [::]:80->80/tcp, 0.0.0.0:443->443/tcp, [::]:443->443/tcp, 0.0.0.0:8080->8080/tcp, [::]:8080->8080/tcp, 0.0.0.0:443->443/udp, [::]:443->443/udp
coolify-realtimeUp 6 days (healthy)100.80.139.9:6001-6002->6001-6002/tcp
coolify-dbUp 6 days (healthy)5432/tcp
coolify-redisUp 6 days (healthy)6379/tcp

🚫 UFW Block Details (24h)

Top Source IPs

6253 10.0.0.3
   1896 10.0.0.2
    662 2
    527 2001
    231 2607
    141 2604
    119 173.247.226.62
     81 79.124.62.230
     79 79.124.62.134
     69 185.150.191.236

Top Targeted Ports

6273 8000
   1896 23517
    368 23
    169 2221
     94 22
     86 3389
     62 8443
     49 1433
     36 5060
     35 53

☁️ Cloudflare Tunnel

Uptime: Thu 2026-06-11 04:29:24 UTC · 0 domains routed

4
HA Connections
3
Edge Locations
432
Request Errors
0
Active Sessions

Edges: sin11, sin15, sin16

DomainStatus

⚠ Attack Attempts (7d) 432

TypeCount
Other402
AWS credential probe25
App probe5

📋 Report History