THINK FIRST·CODE LATER

← All labs

Linux in practice: harden a small server

Problem

On a Linux VM that you control (never on systems you do not own), apply and document basic hardening. Record commands, outputs and your reasoning.

  1. Accounts: create a user svc without a login shell for a service; check /etc/passwd and /etc/shadow (which hash algorithm is used? what is the $…$ prefix?). Configure sudo so that your admin user needs a password; explain why direct root SSH login should be disabled.
  2. Permissions: create /srv/app owned by svc with mode 750 and a config file with mode 640; set a restrictive umask for svc. Find setuid files with find / -perm -4000 -type f 2>/dev/null — why does each need setuid?
  3. Capabilities instead of root: run a small web server on port 80 as svc using setcap cap_net_bind_service=+ep on its binary (or a systemd unit with AmbientCapabilities). Verify with getcap and ps.
  4. Sandboxing: run the same server in Docker as a non-root user with --read-only, --cap-drop ALL, --security-opt no-new-privileges. Which of these would stop what kind of attack?
  5. Network and updates: list listening ports (ss -tlnp), enable a firewall allowing only SSH and HTTP(S), and enable automatic security updates. Write 5 lines on why patching matters more than any single setting.

Work it out on paper, in a document or here, then compare with the model answer. Your answer stays in your browser — it is never sent to or stored on the server.