Security basics · Final challenge

Final challenge: harden the club server

The club has a new server and it's yours now. Three different people "set it up" over the summer, each in a hurry. Before it goes live, the club wants your sign-off that it's safe. Everything in this path is somewhere on this machine.

How this works

No step-by-step instructions. The objectives say what must be true when you're done, and they're checked live as you work. Start like a defender: look before you touch (sudo ss -tlnp, systemctl list-units, sudo sshd -T, sudo find / -perm -4000, curl -I). Make every fix stick after a reboot. The hints below are there if you get stuck.

The brief

  1. Only the website and SSH are listening to the network. Anything else is switched off for good, or only listens on 127.0.0.1.
  2. The firewall lets in SSH, HTTP and HTTPS, and nothing for the database or old test servers. On Rocky, the permanent rules match.
  3. SSH takes keys only: no password logins and no root logins.
  4. Accounts follow least privilege: the old developer account can't log in and isn't an admin, and the deploy account may only restart the web server with sudo.
  5. No weak permissions: no stray SUID program in /usr/local, no root-run script anyone can change, and /etc/shadow isn't readable by everyone.
  6. The website is tight-lipped and encrypted: no version in the Server header, no folder listings, HTTPS on, and plain HTTP redirects to HTTPS.
  7. Fingerprint it: once it's all done, an AIDE database of the hardened server exists, ready for next week's check.

Stuck? Hints

Open only as many as you need.

1. What's listening

sudo ss -tlnp shows every listener and its program. A test web server started by systemd needs disable --now. A database should only listen on 127.0.0.1: a bind-address line in a 99-…cnf file, then a restart. Lessons: lesson 1, lesson 4.

2. The firewall

Look at the rules first (sudo firewall-cmd --list-all or sudo ufw status numbered). Remove what shouldn't be there and add HTTPS. On Rocky, change the permanent rules and reload. Lesson: lesson 3.

3. SSH

Check what sshd really uses: sudo sshd -T | grep -iE 'passwordauth|permitroot'. Drop-in files win over the main file. A 00-…conf drop-in, sudo sshd -t, then reload. Lesson: lesson 2.

4. Accounts

getent group wheel / getent group sudo shows the admins. Lock the old account (usermod -L, a nologin shell) and take away admin rights (gpasswd -d). For deploy, read /etc/sudoers.d/, rewrite its rule to one command, and run sudo visudo -c. Lessons: lesson 1, lesson 6.

5. Permissions

sudo find / -perm -4000 -type f 2>/dev/null, sudo find / -xdev -type f -perm -0002 2>/dev/null and ls -l /etc/shadow. Lesson: lesson 6.

6. The website

ServerTokens Prod, take Indexes out of the Options line, turn on HTTPS (mod_ssl on Rocky; a2enmod ssl and a2ensite default-ssl on Ubuntu) and add a Redirect permanent / https://192.168.1.50/ in the port-80 site. Test with configtest, then reload. Lesson: lesson 8.

7. The fingerprint

Install aide. On Rocky: sudo aide --init, then move aide.db.new.gz to aide.db.gz. On Ubuntu: sudo aideinit. Do this last, after everything else. Lesson: lesson 7.

Complete every objective in the terminal and the challenge is marked done automatically. It's optional, but it goes on your certificate.