Learning path · 3 lessons + 5 coming · about 1½ h

Security basics: defend your own server

Every server that's on the internet gets poked at, all day, by automated bots. This path teaches you to be the one who's ready for it: to close the doors that shouldn't be open, notice when something is wrong, and check your own machines the way an attacker would, so you find the problems first.

Is this path for you?

You should be comfortable with these (each links to the lesson that teaches it):

Finished Linux Sysadmin? Then you're ready.

What's ahead

LessonYou'll learn to…
lesson 1: think like an attackerknow the rules, build a threat model, and map (then shrink) your server's attack surface
lesson 2: lock down SSHlog in with keys only, turn off root logins, and beat the drop-in files that quietly override your settings
lesson 3: firewalls in depthdefault deny, SSH only from your own network, zones vs rule order, and logging what gets blocked
Coming nextscanning your own lab, spotting trouble in the logs, finding weak permissions, checking nothing was changed, and HTTPS for your website

How this path works

The rule for this whole path

Only test machines you own or have written permission to test. Scanning or trying to log in to someone else's computer is against the law in most countries, even "just to look". Everything in these lessons happens on your own server or the practice lab, and that's where it stays.