Recipes

The lessons, turned into checklists for real servers. Work down a recipe in order and tick each step as you go. Your ticks stay in this browser only. Single commands are on the cheat sheet.

New server: the first hour

Do these in order on any server you're responsible for, before anything goes on it. Keep your first SSH session open the whole time, so one mistake can't lock you out.

StepRocky / RHELUbuntu / Debian
Lesson: Updates done right sudo dnf upgrade -y sudo rebootsudo apt update sudo apt full-upgrade -y sudo reboot
Lesson: Managing users & groups sudo useradd -m -G wheel NAME sudo passwd NAMEsudo adduser NAME sudo usermod -aG sudo NAME
Lesson: Lock down SSH ssh-keygen -t ed25519 ssh-copy-id NAME@SERVER same on both
Lesson: Lock down SSH printf 'PasswordAuthentication no\nPermitRootLogin no\n' | sudo tee /etc/ssh/sshd_config.d/00-hardening.conf sudo sshd -t sudo systemctl reload sshdprintf 'PasswordAuthentication no\nPermitRootLogin no\n' | sudo tee /etc/ssh/sshd_config.d/00-hardening.conf sudo sshd -t sudo systemctl reload ssh
Lesson: Firewalls in depth sudo firewall-cmd --list-all sudo firewall-cmd --permanent --remove-service=cockpit sudo firewall-cmd --reloadsudo ufw allow OpenSSH sudo ufw enable sudo ufw status verbose
Lesson: Updates done right sudo dnf install dnf-automatic sudoedit /etc/dnf/automatic.conf sudo systemctl enable --now dnf-automatic.timer

In the file, set upgrade_type = security and apply_updates = yes.

cat /etc/apt/apt.conf.d/20auto-upgrades systemctl list-timers 'apt-daily*'

unattended-upgrades is installed and on by default; just check it.

Lesson: Think like an attacker sudo ss -tlnp systemctl list-units --type=service --state=running sudo systemctl disable --now NAME same on both
Lesson: Scan your own lab with nmap nmap SERVER nmap -p- SERVER same on both
Lesson: Did anyone change anything? sudo dnf install aide sudo aide --init sudo mv /var/lib/aide/aide.db.new.gz /var/lib/aide/aide.db.gzsudo apt install aide sudo aideinit
Lesson: Backups: tar, rsync & cron sudo tar czf /root/etc-$(date +%F).tar.gz /etc rsync -a /root/*.tar.gz BACKUPHOST:backups/ same on both

Put a website online safely

From an empty server to a site that's tight-lipped, encrypted and checked. Do "New server: the first hour" first.

StepRocky / RHELUbuntu / Debian
Lesson: Services & your first website sudo dnf install httpd sudo systemctl enable --now httpd

Rocky waits for you to start it.

sudo apt install apache2 systemctl status apache2

Ubuntu starts Apache as soon as it's installed.

Lesson: Firewalls in depth sudo firewall-cmd --permanent --add-service=http --add-service=https sudo firewall-cmd --reloadsudo ufw allow 'Apache Full'
Lesson: Web server hardening & HTTPS sudoedit /etc/httpd/conf.d/security.confsudoedit /etc/apache2/conf-available/security.conf
Lesson: Web server hardening & HTTPS sudoedit /etc/httpd/conf/httpd.confsudoedit /etc/apache2/apache2.conf
Lesson: Web server hardening & HTTPS Header always set X-Content-Type-Options "nosniff" Header always set X-Frame-Options "SAMEORIGIN"sudo a2enmod headers Header always set X-Content-Type-Options "nosniff" Header always set X-Frame-Options "SAMEORIGIN"
Lesson: Web server hardening & HTTPS sudo apachectl configtest sudo systemctl reload httpdsudo apache2ctl configtest sudo systemctl reload apache2
Lesson: Web server hardening & HTTPS sudo dnf install epel-release sudo dnf install certbot python3-certbot-apache sudo certbot --apache -d YOUR.DOMAIN

certbot offers to redirect HTTP to HTTPS: say yes.

sudo apt install certbot python3-certbot-apache sudo certbot --apache -d YOUR.DOMAIN

certbot offers to redirect HTTP to HTTPS: say yes.

Lesson: Web server hardening & HTTPS sudo certbot renew --dry-run same on both
Lesson: Scan your own lab with nmap, Web server hardening & HTTPS curl -I https://YOUR.DOMAIN curl -I http://YOUR.DOMAIN nmap -sV -p 80,443 YOUR.DOMAIN same on both

Someone got in: what to do

Stay calm and go in order. Close the door before you chase anyone out, and keep the evidence.

StepRocky / RHELUbuntu / Debian
Lesson: Spot trouble in the logs last | head -20 w sudo ss -tnp ps auxf same on both
Lesson: Spot trouble in the logs mkdir ~/evidence sudo cp -a /var/log/secure* ~/evidence/

Then copy them off the server too (scp or rsync to a machine you trust).

mkdir ~/evidence sudo cp -a /var/log/auth.log* ~/evidence/

Then copy them off the server too (scp or rsync to a machine you trust).

Lesson: Spot trouble in the logs sudo grep Accepted /var/log/secure sudo lastb | headsudo grep Accepted /var/log/auth.log sudo lastb | head
Lesson: Spot trouble in the logs sudo usermod -L NAME sudo usermod -s /sbin/nologin NAME same on both
Lesson: Spot trouble in the logs sudo pkill -KILL -u NAME same on both
Lesson: Spot trouble in the logs sudo cat /home/NAME/.ssh/authorized_keys sudo crontab -l -u NAME same on both
Lesson: Did anyone change anything? sudo grep sudo /var/log/secure awk -F: '$3 == 0' /etc/passwd sudo rpm -Vasudo grep sudo /var/log/auth.log awk -F: '$3 == 0' /etc/passwd sudo dpkg --verify
Lesson: Backups: tar, rsync & cron, Did anyone change anything?

Take the server off the network, install fresh, restore data from a backup made before the break-in, and change every password and key that was on it. You can't trust anything on a server someone controlled.

Lesson: Lock down SSH printf 'PasswordAuthentication no\n' | sudo tee /etc/ssh/sshd_config.d/00-hardening.conf sudo sshd -t sudo systemctl reload sshdprintf 'PasswordAuthentication no\n' | sudo tee /etc/ssh/sshd_config.d/00-hardening.conf sudo sshd -t sudo systemctl reload ssh

Monthly security check-up

Twenty minutes once a month. Put it in your calendar.

StepRocky / RHELUbuntu / Debian
Lesson: Updates done right sudo dnf check-update sudo dnf updateinfo list --securitysudo apt update apt list --upgradable
Lesson: Spot trouble in the logs last | head -20 sudo lastb | head same on both
Lesson: Think like an attacker sudo ss -tlnp same on both
Lesson: Scan your own lab with nmap nmap SERVER same on both
Lesson: Find the weak spots getent group wheel sudo ls /etc/sudoers.d/ sudo -l -U NAMEgetent group sudo sudo ls /etc/sudoers.d/ sudo -l -U NAME
Lesson: Find the weak spots sudo find / -xdev -perm -4000 -type f 2>/dev/null sudo find / -xdev -type f -perm -0002 2>/dev/null same on both
Lesson: Did anyone change anything? sudo aide --check sudo rpm -Vasudo aide --config /etc/aide/aide.conf --check sudo dpkg --verify
Lesson: Web server hardening & HTTPS sudo certbot certificates same on both
Lesson: Backups: tar, rsync & cron tar -tzf BACKUP.tar.gz | head tar -xzf BACKUP.tar.gz -C /tmp/restore-test etc/hostname same on both