A note on securing Webmin
Webmin by default allows root access to a system, and by default allows terminal access to the root user. Care should be taken to properly setup Webmin to disable the root user. Enable Two-Factor Authentication TOTP authentication can be enabled without installing any extra modules. Enable it by allowing TOTP Authentication in the Webmin configuration. Then, for each user enable TOTP authentication separately and save the resulting QR code (authentication key) into a password manager like Bitwarden or Microsoft authenticator. Make sure to test your two factor authentication for each user before you continue. Root should probably have this setup before you disable it. Disable… Read More »A note on securing Webmin