Security hardening
The security checks, what they mean and how to fix them.
How Tickhound checks security
Tickhound only looks at servers you own. The checks read your config files, the facts the plugin reports (operator count, default permissions, suspicious plugin code), and one bounded network test: your address and a few well-known risky ports, one connection each. It never scans ranges, floods, guesses passwords or exploits anything.
For every problem the Server optimizer can apply the fix through Pterodactyl, and the Tools page builds firewall commands and forwarding secrets.
Exposed services
Databases (MySQL, PostgreSQL, Redis, MongoDB, Memcached), the Docker API, Remote Desktop and VNC must never answer from the internet. Close the port in the firewall or bind the service to 127.0.0.1. SSH is fine if it only accepts keys; add fail2ban or limit it to your own address.
JMX
enable-jmx-monitoring=true opens a Java management port. Switch it off.
Query and the plugin list
The query protocol can list your plugins. Attackers use that to pick exploits. Keep enable-query=false and settings.query-plugins: false.
Connection throttle
settings.connection-throttle in bukkit.yml should be 4000. It slows down login floods from one address.
PROXY protocol
PROXY protocol must only be on behind HAProxy or TCPShield. Otherwise clients can fake their address.
Operators
Keep op for two or three trusted admins. Everyone else gets specific permissions from a permissions plugin. The plugin only reports the number of operators, never their names.
Default permissions
Some plugins give powerful permissions to every player. The plugin lists the permission nodes that are on by default and look like admin power (wildcards, op, world editing). Remove them from your default group.
Plugin jars
The plugin scans each jar for code that starts operating-system programs or loads classes from a URL. Updaters and backup tools do this legitimately, so treat the list as a reason to check, not as proof.
Firewall rules
Backends should accept connections only from your proxy. The Tools page generates the commands for ufw, iptables, nftables and the Windows firewall. With Pterodactyl, also bind backend allocations to a private address, because Docker can bypass ufw.
Velocity forwarding secret
Modern forwarding signs player data with a secret shared by the proxy and all backends. The Tools page makes one in your browser. A secret that is empty or short makes the backend trust forged players.
