Learning path · 3 lessons + 5 coming · about 1½ h
Security basics: defend your own server
Every server that's on the internet gets poked at, all day, by automated bots. This path teaches you to be the one who's ready for it: to close the doors that shouldn't be open, notice when something is wrong, and check your own machines the way an attacker would, so you find the problems first.
Is this path for you?
You should be comfortable with these (each links to the lesson that teaches it):
- SSH, keys and the two families' services (Linux Basics, lesson 3, Linux Basics, lesson 14)
- Permissions, users and sudo (Linux Basics, lesson 10, Linux Basics, lesson 12)
- Reading logs and fixing a broken service (Linux Sysadmin, lesson 4)
- Basic networking: addresses, ports and
ss(Linux Sysadmin, lesson 1, Linux Sysadmin, lesson 2)
Finished Linux Sysadmin? Then you're ready.
What's ahead
| Lesson | You'll learn to… |
|---|---|
| lesson 1: think like an attacker | know the rules, build a threat model, and map (then shrink) your server's attack surface |
| lesson 2: lock down SSH | log in with keys only, turn off root logins, and beat the drop-in files that quietly override your settings |
| lesson 3: firewalls in depth | default deny, SSH only from your own network, zones vs rule order, and logging what gets blocked |
| Coming next | scanning your own lab, spotting trouble in the logs, finding weak permissions, checking nothing was changed, and HTTPS for your website |
How this path works
- Defence first. Every lesson is about protecting machines you're responsible for. When we look at a server "like an attacker", it's always our own server, in our own practice lab.
- Still two families. Rocky and Ubuntu protect themselves differently: different default files, firewalls and security modules. You'll learn both.
- Safe to break. Locking yourself out is part of learning SSH security. In the practice terminal, Reset gives you a fresh server.
The rule for this whole path
Only test machines you own or have written permission to test. Scanning or trying to log in to someone else's computer is against the law in most countries, even "just to look". Everything in these lessons happens on your own server or the practice lab, and that's where it stays.