Final challenge: harden the club server
The club has a new server and it's yours now. Three different people "set it up" over the summer, each in a hurry. Before it goes live, the club wants your sign-off that it's safe. Everything in this path is somewhere on this machine.
No step-by-step instructions. The objectives say what must be true when you're done, and they're checked live as you work. Start like a defender: look before you touch (sudo ss -tlnp, systemctl list-units, sudo sshd -T, sudo find / -perm -4000, curl -I). Make every fix stick after a reboot. The hints below are there if you get stuck.
The brief
- Only the website and SSH are listening to the network. Anything else is switched off for good, or only listens on
127.0.0.1. - The firewall lets in SSH, HTTP and HTTPS, and nothing for the database or old test servers. On Rocky, the permanent rules match.
- SSH takes keys only: no password logins and no root logins.
- Accounts follow least privilege: the old developer account can't log in and isn't an admin, and the deploy account may only restart the web server with sudo.
- No weak permissions: no stray SUID program in
/usr/local, no root-run script anyone can change, and/etc/shadowisn't readable by everyone. - The website is tight-lipped and encrypted: no version in the
Serverheader, no folder listings, HTTPS on, and plain HTTP redirects to HTTPS. - Fingerprint it: once it's all done, an AIDE database of the hardened server exists, ready for next week's check.
Stuck? Hints
Open only as many as you need.
1. What's listening
sudo ss -tlnp shows every listener and its program. A test web server started by systemd needs disable --now. A database should only listen on 127.0.0.1: a bind-address line in a 99-…cnf file, then a restart. Lessons: lesson 1, lesson 4.
2. The firewall
Look at the rules first (sudo firewall-cmd --list-all or sudo ufw status numbered). Remove what shouldn't be there and add HTTPS. On Rocky, change the permanent rules and reload. Lesson: lesson 3.
3. SSH
Check what sshd really uses: sudo sshd -T | grep -iE 'passwordauth|permitroot'. Drop-in files win over the main file. A 00-…conf drop-in, sudo sshd -t, then reload. Lesson: lesson 2.
4. Accounts
getent group wheel / getent group sudo shows the admins. Lock the old account (usermod -L, a nologin shell) and take away admin rights (gpasswd -d). For deploy, read /etc/sudoers.d/, rewrite its rule to one command, and run sudo visudo -c. Lessons: lesson 1, lesson 6.
5. Permissions
sudo find / -perm -4000 -type f 2>/dev/null, sudo find / -xdev -type f -perm -0002 2>/dev/null and ls -l /etc/shadow. Lesson: lesson 6.
6. The website
ServerTokens Prod, take Indexes out of the Options line, turn on HTTPS (mod_ssl on Rocky; a2enmod ssl and a2ensite default-ssl on Ubuntu) and add a Redirect permanent / https://192.168.1.50/ in the port-80 site. Test with configtest, then reload. Lesson: lesson 8.
7. The fingerprint
Install aide. On Rocky: sudo aide --init, then move aide.db.new.gz to aide.db.gz. On Ubuntu: sudo aideinit. Do this last, after everything else. Lesson: lesson 7.