Did my home server just get breached??
I had docker containers running only in the internal home network, on Ubuntu server LTS.
I installed Cosmos Server with a strong password and MFA. Enabled LetsEncrypt and DNS Challenge. Set my domain to point to my home IP with a cloudflare DNS A record, without proxied status.
UFW was set to deny all incoming except for ssh, 80 and 443. Set the router to port forward only 80,443 to the ubuntu server. My ssh and sudo passwords are strong and complex.
Being paranoid I was checking settings and in Ubuntu I saw UFW was no longer installed.
I immediately tried 'sudo shutdown now'. Normally the PC responds with 'Broken Pipe, Connection Closed' but this time it just stayed logged in.
It was under 5 mins between enabling port forwarding and me hard shutting of power to the ubuntu PC. Am I fucked do I need to wipe the ubuntu PC?
EDIT: I'm done for the night. Exhausted. Hard lesson learned. Wiped the PC and updated all my passwords/keys. Thanks to those of you that provided useful guidance, I really needed it right now.