My First EC2 Mistake: I Left Port 3000 Open and Almost Got Hacked

Yesterday I made the most beginner mistake in my DevOps journey. I deployed my MERN app to AWS EC2, it was live and I was happy. But I left port 3000 open to the whole internet. Let me explain.

My Node app runs on port 3000. To test quickly, I went to EC2 Security Group and added: Custom TCP, Port 3000, Source 0.0.0.0/0. That means anyone on the internet can access my server on port 3000. I thought "I will close it later." I forgot. Two hours later I ran pm2 logs and saw strange requests from Netherlands, Vietnam and US IPs: /.env, /.aws/credentials, /admin, /wp-login.php. Someone was scanning my open port trying to steal secrets! 

I panicked. I am in Port Harcourt but my server in us-east-1 was being attacked live. 

How I fixed it:

  1. I rushed to AWS Console > EC2 > Security Groups > Inbound Rules and deleted the port 3000 rule.
  2. I configured NGINX as reverse proxy. NGINX now listens on port 80 and 443 and forwards internally to port 3000. My app still runs on 3000 but outsiders cannot see it directly.
  3. I ran:       sudo ufw allow 22,80,443/tcp: 

               sudo ufw deny 3000:
              sudo systemctl restart nginx:
             sudo netstat -tulpn

Now it shows 127.0.0.1:3000 not 0.0.0.0:3000. That means only localhost.

Lesson learned: Never open app ports like 3000, 5000, 8000 to 0.0.0.0/0. Use NGINX reverse proxy. Open only 22 (SSH), 80 (HTTP), 443 (HTTPS). Always check your security group before you sleep.    If you are a beginner, check your security group today. That small mistake could cost you your server.


Read also: Day 3: No Light, But I Finally Understood GitHub & Docker (With Garri & Bus Analogy) 😂



Comments

  1. UPDATE: After publishing, I also added HTTPS (443). Thanks to everyone who pointed it out!

    ReplyDelete

Post a Comment

Popular posts from this blog

How I Fixed GitHub Error: failed to push some refs to github.com in 2026

How I Deployed Netflix Clone (NGold) to AWS EC2 - Live at 32.196.145.76:3000 [Docker + Nginx Guide]

Understanding Linux Environment — The Real Engine Behind My AWS Cloud Deployment