On a Linux VM that you control (never on systems you do not own), apply and document basic hardening. Record commands, outputs and your reasoning.
- Accounts: create a user
svcwithout a login shell for a service; check/etc/passwdand/etc/shadow(which hash algorithm is used? what is the$…$prefix?). Configuresudoso that your admin user needs a password; explain why direct root SSH login should be disabled. - Permissions: create
/srv/appowned bysvcwith mode 750 and a config file with mode 640; set a restrictive umask forsvc. Find setuid files withfind / -perm -4000 -type f 2>/dev/null— why does each need setuid? - Capabilities instead of root: run a small web server on port 80 as
svcusingsetcap cap_net_bind_service=+epon its binary (or a systemd unit withAmbientCapabilities). Verify withgetcapandps. - Sandboxing: run the same server in Docker as a non-root user with
--read-only,--cap-drop ALL,--security-opt no-new-privileges. Which of these would stop what kind of attack? - Network and updates: list listening ports (
ss -tlnp), enable a firewall allowing only SSH and HTTP(S), and enable automatic security updates. Write 5 lines on why patching matters more than any single setting.