Share E-Book

Mastering Linux Security and Hardening A Practical Guide to Protecting Your Linux System from Cyber Attacks (Donald A. Tevault)(Z-Library)

Author

Rating No ratings yet

Log in to rate

Linux
Language English

The third edition of Mastering Linux Security and Hardening is an updated, comprehensive introduction to implementing the latest Linux security measures, using the latest versions of Ubuntu and AlmaLinux. In this new edition, you will learn how to set up a practice lab, create user accounts with appropriate privilege levels, protect sensitive data with permissions settings and encryption, and configure a firewall with the newest firewall technologies. You’ll also explore how to use sudo to set up administrative accounts with only the privileges required to do a specific job, and you’ll get a peek at the new sudo features that have been added over the past couple of years. You’ll also see updated information on how to set up a local certificate authority for both Ubuntu and AlmaLinux, as well as how to automate system auditing. Other important skills that you’ll learn include how to automatically harden systems with OpenSCAP, audit systems with auditd, harden the Linux kernel configuration, protect your systems from malware, and perform vulnerability scans of your systems. As a bonus, you’ll see how to use Security Onion to set up an Intrusion Detection System. By the end of this new edition, you will confidently be able to set up a Linux server that will be secure and harder for malicious actors to compromise.

Format PDF
Size 15.9 MB
6
Views
(First 20 pages)

Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Page 1
(This page has no text content)
Page 2
Mastering Linux Security and Hardening Third Edition A practical guide to protecting your Linux system from cyber attacks Donald A. Tevault BIRMINGHAM—MUMBAI
Page 3
Mastering Linux Security and Hardening Third Edition Copyright © 2023 Packt Publishing All rights reserved. No part of this book may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written permission of the publisher, except in the case of brief quotations embedded in critical articles or reviews. Every effort has been made in the preparation of this book to ensure the accuracy of the information presented. However, the information contained in this book is sold without warranty, either express or implied. Neither the author, nor Packt Publishing or its dealers and distributors, will be held liable for any damages caused or alleged to have been caused directly or indirectly by this book. Packt Publishing has endeavored to provide trademark information about all of the companies and products mentioned in this book by the appropriate use of capitals. However, Packt Publishing cannot guarantee the accuracy of this information. Senior Publishing Product Manager: Aaron Tanna Acquisition Editor – Peer Reviews: Gaurav Gavas Project Editor: Rianna Rodrigues Content Development Editor: Liam Draper Copy Editor: Safis Editing Technical Editor: Karan Sonawane Proofreader: Safis Editing Indexer: Manju Arasan Presentation Designer: Ganesh Bhadwalkar Developer Relations Marketing Executive: Meghal Patel First published: January 2018 Second edition: February 2020 Third edition: February 2023 Production reference: 2170625 Published by Packt Publishing Ltd. Livery Place 35 Livery Street Birmingham B3 2PB, UK. ISBN 978-1-83763-051-6 www.packt.com
Page 4
Contributors About the author Donald A. Tevault – you can call him Donnie – got involved with Linux way back in 2006 and has been working with it ever since. He holds the Linux Professional Institute Level 3 Security certification and the GIAC Incident Handler certification. Donnie is a professional Linux trainer, and thanks to the magic of the Internet, has taught Linux classes all over the world from the comfort of his living room. He has also been a Linux security researcher for an IoT security company. I’d like to thank the good folk at Packt Publishing for making the publishing of this book such a smooth process. I’d also like to thank my cats for graciously allowing me to use their names in the demos, and Mike, my intrepid technical reviewer, for his suggestions that made the book better than it would have been.
Page 5
About the reviewer Michael Ernstoff is a Unix and Linux infrastructure and security specialist with over 25 years of experience. An independent consultant for over 20 years, Michael has worked for many well-known blue-chip companies, mainly in the banking and finance industries. With extensive knowledge of host-based security, security hardening, and identity and access man- agement. Michael has developed and implemented solutions for Security and Regulatory Compliance. He is a keen amateur musician and has four children.
Page 6
Join our book community Join our community’s Discord space for discussions with the author and other readers: https://packt.link/CyberSec
Page 7
(This page has no text content)
Page 8
Table of Contents Preface xxi Part I: Setting up a Secure Linux System 1 Chapter 1: Running Linux in a Virtual Environment 3 Getting the most out of this book – get to know your free benefits .............................................. 4 Looking at the threat landscape ................................................................................................ 6 Why do security breaches happen? ........................................................................................... 6 Keeping up with security news .................................................................................................. 7 Differences between physical, virtual, and cloud setups ............................................................. 7 Introducing VirtualBox and Cygwin .......................................................................................... 8 Installing a virtual machine in VirtualBox • 9 Installing the EPEL repository on the CentOS 7 virtual machine • 13 Installing the EPEL repository on the AlmaLinux 8/9 virtual machines • 14 Configuring a network for VirtualBox virtual machines • 14 Creating a virtual machine snapshot with VirtualBox • 15 Using Cygwin to connect to your virtual machines • 16 Installing Cygwin on your Windows host • 16 Using the Windows 10 SSH client to interface with Linux virtual machines • 17 Using the Windows 11 SSH client to interface with Linux virtual machines • 20 Cygwin versus the Windows shell • 20 Keeping the Linux systems updated ........................................................................................ 21 Updating Debian-based systems • 21 Configuring auto updates for Ubuntu • 22 Updating Red Hat 7-based systems • 24 Updating Red Hat 8/9-based systems • 28 Managing updates in an enterprise • 29
Page 9
Table of Contentsviii Summary ............................................................................................................................... 29 Questions ............................................................................................................................... 30 Further reading ...................................................................................................................... 30 Answers ................................................................................................................................. 31 Chapter 2: Securing Administrative User Accounts 33 The dangers of logging in as the root user ................................................................................ 33 The advantages of using sudo .................................................................................................. 34 Setting up sudo privileges for full administrative users ............................................................ 35 Adding users to a predefined admin group • 35 Creating an entry in the sudo policy file • 37 Setting up sudo for users with only certain delegated privileges ............................................... 38 Hands-on lab for assigning limited sudo privileges • 41 Advanced tips and tricks for using sudo ................................................................................... 43 The sudo timer • 43 View your sudo privileges • 43 Hands-on lab for disabling the sudo timer • 44 Preventing users from having root shell access • 45 Preventing users from using shell escapes • 45 Preventing users from using other dangerous programs • 48 Limiting the user’s actions with commands • 49 Letting users run as other users • 49 Preventing abuse via a user’s shell scripts • 50 Detecting and deleting default user accounts • 52 New sudo features .................................................................................................................. 53 Special sudo considerations for SUSE and OpenSUSE ............................................................... 53 Summary ............................................................................................................................... 55 Questions ............................................................................................................................... 56 Further reading ...................................................................................................................... 57 Answers ................................................................................................................................. 57 Chapter 3: Securing Normal User Accounts 59 Locking down users’ home directories the Red Hat way ........................................................... 59 Locking down users’ home directories the Debian/Ubuntu way ................................................ 61 useradd on Debian/Ubuntu • 61 adduser on Debian/Ubuntu • 62 Hands-on lab for creating an encrypted home directory with adduser • 64
Page 10
Table of Contents ix Enforcing strong password criteria ......................................................................................... 64 Installing and configuring pwquality • 66 Hands-on lab for setting password complexity criteria • 68 Setting and enforcing password and account expiration .......................................................... 69 Configuring default expiry data for useradd for Red Hat-type systems only ............................... 70 Setting expiry data on a per-account basis with useradd and usermod ...................................... 72 Setting expiry data on a per-account basis with chage .............................................................. 73 Hands-on lab for setting account and password expiry data • 75 Preventing brute-force password attacks ................................................................................. 75 Configuring the pam_tally2 PAM module on CentOS 7 • 76 Hands-on lab for configuring pam_tally2 on CentOS 7 • 77 Configuring pam_faillock on AlmaLinux 8/9 • 78 Hands-on lab for configuring pam_faillock on AlmaLinux 8 or AlmaLinux 9 • 78 Configuring pam_faillock on Ubuntu 20.04 and Ubuntu 22.04 • 80 Hands-on lab for configuring pam_faillock on Ubuntu 20.04 and Ubuntu 22.04 • 80 Locking user accounts ............................................................................................................ 80 Using usermod to lock a user account • 81 Using passwd to lock user accounts • 82 Locking the root user account ................................................................................................. 82 Setting up security banners .................................................................................................... 83 Using the motd file • 83 Using the issue file • 84 Using the issue.net file • 85 Detecting compromised passwords ......................................................................................... 86 Hands-on lab for detecting compromised passwords • 89 Understanding centralized user management .......................................................................... 90 Microsoft Active Directory • 90 Samba on Linux ..................................................................................................................... 90 FreeIPA/Identity Management on RHEL-type distros • 91 Summary ............................................................................................................................... 92 Questions ............................................................................................................................... 92 Further reading ...................................................................................................................... 93 Answers ................................................................................................................................. 94 Chapter 4: Securing Your Server with a Firewall – Part 1 95 Technical requirements .......................................................................................................... 95 An overview of the Linux firewall ............................................................................................ 96
Page 11
Table of Contentsx An overview of iptables ........................................................................................................... 97 Mastering the basics of iptables • 97 Blocking ICMP with iptables • 101 Blocking everything that isn’t allowed with iptables • 103 Hands-on lab for basic iptables usage • 106 Blocking invalid packets with iptables • 107 Restoring the deleted rules • 113 Hands-on lab for blocking invalid IPv4 packets • 114 Protecting IPv6 • 115 Hands-on lab for ip6tables • 118 nftables – a more universal type of firewall system ................................................................ 119 Learning about nftables tables and chains • 120 Getting started with nftables • 120 Configuring nftables on Ubuntu • 120 Using nft commands • 124 Hands-on lab for nftables on Ubuntu • 129 Summary ............................................................................................................................. 131 Questions ............................................................................................................................. 131 Further reading .................................................................................................................... 132 Answers ............................................................................................................................... 132 Chapter 5: Securing Your Server with a Firewall — Part 2 133 Technical requirements ........................................................................................................ 134 The Uncomplicated Firewall for Ubuntu systems ................................................................... 134 Configuring ufw • 134 Working with the ufw configuration files • 136 Hands-on lab for basic ufw usage • 139 firewalld for Red Hat systems ................................................................................................ 141 Verifying the status of firewalld • 142 Working with firewalld zones • 142 Adding services to a firewalld zone • 146 Adding ports to a firewalld zone • 151 Blocking ICMP • 152 Using panic mode • 154 Logging dropped packets • 155 Using firewalld rich language rules • 156 Looking at iptables rules in RHEL/CentOS 7 firewalld • 158
Page 12
Table of Contents xi Creating direct rules in RHEL/CentOS 7 firewalld • 160 Looking at nftables rules in RHEL/AlmaLinux 8 and 9 firewalld • 163 Creating direct rules in RHEL/AlmaLinux firewalld • 163 Hands-on lab for firewalld commands • 164 Summary ............................................................................................................................. 167 Questions ............................................................................................................................. 167 Further reading .................................................................................................................... 168 Answers ............................................................................................................................... 168 Chapter 6: Encryption Technologies 169 GNU Privacy Guard (GPG) ..................................................................................................... 170 Hands-on lab – creating your GPG keys • 171 Hands-on lab – symmetrically encrypting your own files • 173 Hands-on lab – encrypting files with public keys • 176 Hands-on lab – signing a file without encryption • 180 Encrypting partitions with Linux Unified Key Setup (LUKS) ................................................... 181 Disk encryption during operating system installation • 181 Hands-on lab – adding an encrypted partition with LUKS • 184 Configuring the LUKS partition to mount automatically • 188 Hands-on lab – configuring the LUKS partition to mount automatically • 188 Encrypting directories with eCryptfs .................................................................................... 190 Hands-on lab – encrypting a home directory for a new user account • 190 Creating a private directory within an existing home directory • 191 Hands-on lab – encrypting other directories with eCryptfs • 192 Encrypting the swap partition with eCryptfs .......................................................................... 194 Using VeraCrypt for cross-platform sharing of encrypted containers ...................................... 195 Hands-on lab – getting and installing VeraCrypt • 195 Hands-on lab – creating and mounting a VeraCrypt volume in console mode • 196 Using VeraCrypt in GUI mode • 198 OpenSSL and the Public Key Infrastructure ........................................................................... 199 Commercial certificate authorities • 200 Creating keys, certificate signing requests, and certificates • 204 Creating a self-signed certificate with an RSA key • 204 Creating a self-signed certificate with an Elliptic Curve key • 205 Creating an RSA key and a Certificate Signing Request • 206 Creating an EC key and a CSR • 207 Creating an on-premises CA • 208
Page 13
Table of Contentsxii Hands-on lab – setting up a Dogtag CA • 209 Adding a CA to an operating system • 213 Hands-on lab – exporting and importing the Dogtag CA certificate • 213 Importing the CA into Windows • 214 OpenSSL and the Apache webserver • 215 Hardening Apache SSL/TLS on Ubuntu • 215 Hardening Apache SSL/TLS on RHEL 9/AlmaLinux 9 • 216 Setting FIPS mode on RHEL 9/AlmaLinux 9 • 218 Hardening Apache SSL/TLS on RHEL 7/CentOS 7 • 220 Setting up mutual authentication • 221 Introducing quantum-resistant encryption algorithms .......................................................... 221 Summary ............................................................................................................................. 222 Questions ............................................................................................................................. 222 Further reading .................................................................................................................... 223 Answers ............................................................................................................................... 224 Chapter 7: SSH Hardening 227 Ensuring that SSH protocol 1 is disabled ................................................................................ 228 Creating and managing keys for passwordless logins ............................................................. 228 Creating a user’s SSH key set • 229 Transferring the public key to the remote server • 232 Hands-on lab – creating and transferring SSH keys • 234 Disabling root user login • 235 Disabling username/password logins • 236 Hands-on lab – Disabling root login and password authentication • 236 Enabling two-factor authentication • 237 Hands-on lab — Setting up two-factor authentication on Ubuntu 22.04 • 238 Hands-on lab – Using Google Authenticator with key exchange on Ubuntu • 240 Hands-on lab — Setting up two-factor authentication on AlmaLinux 8 • 241 Hand-on lab — Using Google Authenticator with key exchange on AlmaLinux 8 • 242 Configuring Secure Shell with strong encryption algorithms • 242 Understanding SSH encryption algorithms • 243 Scanning for enabled SSH algorithms • 246 Hands-on lab – Scanning with Nmap • 246 Disabling weak SSH encryption algorithms • 247 Hands-on lab – disabling weak SSH encryption algorithms – Ubuntu 22.04 • 247 Hands-on lab – disabling weak SSH encryption algorithms – CentOS 7 • 248
Page 14
Table of Contents xiii Setting system-wide encryption policies on RHEL 8/9 and AlmaLinux 8/9 • 250 Hands-on lab – setting encryption policies on AlmaLinux 9 • 251 Configuring more detailed logging • 252 Hands-on lab – configuring more verbose SSH logging • 253 Configuring access control with whitelists and TCP Wrappers ................................................ 254 Configuring whitelists within sshd_config • 255 Hands-on lab – configuring whitelists within sshd_config • 255 Configuring whitelists with TCP Wrappers • 256 Configuring automatic logouts and security banners ............................................................. 258 Configuring automatic logout for both local and remote users • 258 Configuring automatic logout in sshd_config • 258 Creating a pre-login security banner • 259 Configuring other miscellaneous security settings ................................................................. 259 Disabling X11 forwarding • 259 Disabling SSH tunneling • 260 Changing the default SSH port • 261 Managing SSH keys • 262 Setting different configurations for different users and groups ............................................... 265 Creating different configurations for different hosts .............................................................. 265 Setting up a chroot environment for SFTP users .................................................................... 266 Creating a group and configuring the sshd_config file • 267 Hands-on lab – Setting up a chroot directory for the sftpusers group • 268 Sharing a directory with SSHFS ............................................................................................. 269 Hands-on lab – Sharing a directory with SSHFS • 269 Remotely connecting from Windows desktops ....................................................................... 271 Summary ............................................................................................................................. 276 Questions ............................................................................................................................. 277 Further reading .................................................................................................................... 279 Answers ............................................................................................................................... 279 Part II: Mastering File and Directory Access Control (DAC) 281 Chapter 8: Mastering Discretionary Access Control 283 Using chown to change ownership of files and directories • 283 Using chmod to set permissions on files and directories • 286 Setting permissions with the symbolic method • 286
Page 15
Table of Contentsxiv Setting permissions with the numerical method • 287 Using SUID and SGID on regular files • 289 The security implications of the SUID and SGID permissions • 290 Finding spurious SUID or SGID files • 290 Preventing SUID and SGID usage on a partition • 293 Using extended file attributes to protect sensitive files • 293 Setting the a attribute • 294 Setting the i attribute • 295 Securing system configuration files • 297 Summary ............................................................................................................................. 300 Questions ............................................................................................................................. 300 Further reading .................................................................................................................... 302 Answers ............................................................................................................................... 302 Chapter 9: Access Control Lists and Shared Directory Management 305 Creating an ACL for either a user or a group .......................................................................... 305 Creating an inherited ACL for a directory .............................................................................. 308 Removing a specific permission by using an ACL mask .......................................................... 310 Using the tar --acls option to prevent the loss of ACLs during a backup ................................... 311 Creating a user group and adding members to it .................................................................... 313 Adding members as we create their user accounts • 314 Using usermod to add an existing user to a group • 314 Adding users to a group by editing the /etc/group file • 314 Creating a shared directory ................................................................................................... 315 Setting the SGID bit and the sticky bit on the shared directory ................................................ 316 Using ACLs to access files in the shared directory .................................................................. 319 Setting the permissions and creating the ACL • 319 Hands-on lab – creating a shared group directory • 321 Summary ............................................................................................................................. 322 Questions ............................................................................................................................. 322 Further reading .................................................................................................................... 324 Answers ............................................................................................................................... 325
Page 16
Table of Contents xv Part III: Advanced System Hardening Techniques 327 Chapter 10: Implementing Mandatory Access Control with SELinux and AppArmor 329 How SELinux can benefit a systems administrator ................................................................. 330 Setting security contexts for files and directories ................................................................... 331 Installing the SELinux tools • 332 Creating web content files with SELinux enabled • 333 Fixing an incorrect SELinux context • 336 Using chcon • 336 Using restorecon • 337 Using semanage • 338 Hands-on lab – SELinux type enforcement • 340 Troubleshooting with setroubleshoot .................................................................................... 341 Viewing setroubleshoot messages • 341 Using the graphical setroubleshoot utility • 342 Troubleshooting in permissive mode • 344 Working with SELinux policies .............................................................................................. 347 Viewing Booleans • 347 Configuring the Booleans • 348 Protecting your web server • 349 Protecting network ports • 350 Creating custom policy modules • 353 Hands-on lab – SELinux Booleans and ports • 355 How AppArmor can benefit a systems administrator .............................................................. 356 Looking at AppArmor profiles • 356 Working with AppArmor command-line utilities • 359 Troubleshooting AppArmor problems • 362 Troubleshooting an AppArmor profile – Ubuntu 16.04 • 362 Troubleshooting an AppArmor profile – Ubuntu 18.04 • 365 Hands-on lab – Troubleshooting an AppArmor profile • 366 Troubleshooting Samba problems in Ubuntu 22.04 • 367 Exploiting a system with an evil Docker container ................................................................. 368 Hands-on lab – Creating an evil Docker container • 369 Summary ............................................................................................................................. 371 Questions ............................................................................................................................. 371
Page 17
Table of Contentsxvi Further reading .................................................................................................................... 373 Answers ............................................................................................................................... 374 Chapter 11: Kernel Hardening and Process Isolation 375 Understanding the /proc filesystem ....................................................................................... 376 Looking at user-mode processes • 376 Looking at kernel information • 378 Setting kernel parameters with sysctl .................................................................................... 380 Configuring the sysctl.conf file .............................................................................................. 382 Configuring sysctl.conf – Ubuntu • 382 Configuring sysctl.conf – CentOS and AlmaLinux • 386 Setting additional kernel-hardening parameters • 386 Hands-on lab – scanning kernel parameters with Lynis • 387 Preventing users from seeing each others’ processes • 389 Understanding process isolation ........................................................................................... 391 Understanding Control Groups (cgroups) • 391 Understanding namespace isolation • 394 Understanding kernel capabilities • 396 Hands-on lab – setting a kernel capability • 399 Understanding SECCOMP and system calls • 400 Using process isolation with Docker containers • 401 Sandboxing with Firejail • 402 Hands-on lab – using Firejail • 404 Sandboxing with Snappy • 405 Sandboxing with Flatpak • 409 Summary ............................................................................................................................. 412 Questions ............................................................................................................................. 412 Further reading .................................................................................................................... 414 Answers ............................................................................................................................... 415 Chapter 12: Scanning, Auditing, and Hardening 417 Installing and updating ClamAV and maldet .......................................................................... 418 Hands-on lab – installing ClamAV and maldet • 419 Hands-on lab – configuring maldet • 420 Updating ClamAV and maldet • 422 Scanning with ClamAV and maldet ........................................................................................ 424 SELinux considerations • 425
Page 18
Table of Contents xvii Scanning for rootkits with Rootkit Hunter ............................................................................. 426 Hands-on lab – installing and updating Rootkit Hunter • 427 Scanning for rootkits • 428 Performing a quick malware analysis with strings and VirusTotal ........................................... 428 Analyze a file with strings • 429 Scanning the malware with VirusTotal • 430 Understanding the auditd daemon ........................................................................................ 431 Creating audit rules • 432 Auditing a file for changes • 432 Auditing a directory • 434 Auditing system calls • 435 Using ausearch and aureport ................................................................................................ 436 Searching for file change alerts • 436 Searching for directory access rule violations • 438 Searching for system call rule violations • 443 Generating authentication reports • 445 Using pre-defined rulesets • 446 Hands-on lab – using auditd • 448 Hands-on lab –Using pre-configured rules with auditd • 449 Auditing files and directories with inotifywait ........................................................................ 450 Applying OpenSCAP policies with oscap ................................................................................ 451 Installing OpenSCAP • 451 Viewing the profile files • 452 Getting the missing profiles for Ubuntu • 453 Scanning the system • 453 Remediating the system • 455 Using SCAP Workbench • 457 Choosing an OpenSCAP profile • 459 Applying an OpenSCAP profile during system installation • 460 Summary ............................................................................................................................. 462 Questions ............................................................................................................................. 462 Further reading .................................................................................................................... 464 Answers ............................................................................................................................... 464 Chapter 13: Logging and Log Security 465 Understanding the Linux system log files .............................................................................. 465 The system log and the authentication log • 466
Page 19
Table of Contentsxviii The utmp, wtmp, btmp, and lastlog files • 469 Understanding rsyslog .......................................................................................................... 472 Understanding rsyslog logging rules • 472 Understanding journald ....................................................................................................... 474 Making things easier with Logwatch ..................................................................................... 476 Hands-on lab – installing Logwatch • 477 Setting up a remote log server ............................................................................................... 478 Hands-on lab – setting up a basic log server • 478 Creating an encrypted connection to the log server • 480 Creating a stunnel connection on AlmaLinux 9 – server side • 480 Creating a stunnel connection on AlmaLinux – client side • 481 Creating a stunnel connection on Ubuntu – server side • 482 Creating a stunnel connection on Ubuntu – client side • 483 Separating client messages into their own files • 484 Maintaining Logs in Large Enterprises .................................................................................. 485 Summary ............................................................................................................................. 486 Questions ............................................................................................................................. 486 Further reading .................................................................................................................... 487 Answers ............................................................................................................................... 488 Chapter 14: Vulnerability Scanning and Intrusion Detection 489 Introduction to Snort and Security Onion .............................................................................. 489 Obtaining and installing Snort • 490 Hands-on lab – installing Snort via a Docker container • 490 Using Security Onion ............................................................................................................ 492 IPFire and its built-in Intrusion Prevention System (IPS) ........................................................ 494 Hands-on lab – Creating an IPFire virtual machine • 495 Scanning and hardening with Lynis ...................................................................................... 499 Installing Lynis on Red Hat/CentOS • 499 Installing Lynis on Ubuntu • 499 Scanning with Lynis • 500 Finding vulnerabilities with the Greenbone Security Assistant ............................................... 503 Web server scanning with Nikto ............................................................................................ 511 Nikto in Kali Linux • 511 Hands-on lab–Installing Nikto from Github • 512 Scanning a web server with Nikto • 513 Summary ............................................................................................................................. 515
Page 20
Table of Contents xix Questions ............................................................................................................................. 515 Further reading .................................................................................................................... 516 Answers ............................................................................................................................... 516 Chapter 15: Prevent Unwanted Programs from Running 519 Mount Partitions with the no options .................................................................................... 519 Understanding fapolicyd ...................................................................................................... 528 Understanding the fapolicyd rules • 530 Installing fapolicyd • 532 Summary ............................................................................................................................. 533 Further reading .................................................................................................................... 533 Questions ............................................................................................................................. 534 Answers ............................................................................................................................... 535 Chapter 16: Security Tips and Tricks for the Busy Bee 537 Technical requirements ........................................................................................................ 537 Auditing system services ....................................................................................................... 537 Auditing system services with systemctl • 538 Auditing network services with netstat • 538 Hands-on lab – viewing network services with netstat • 544 Auditing network services with Nmap • 544 Port states • 545 Scan types • 546 Hands-on lab – scanning with Nmap • 550 Password-protecting the GRUB2 bootloader .......................................................................... 551 Hands-on lab – resetting the password for Red Hat/CentOS/AlmaLinux • 552 Hands-on lab – resetting the password for Ubuntu • 555 Preventing kernel parameter edits on Red Hat/CentOS/AlmaLinux • 557 Preventing kernel parameter edits or recovery mode access on Ubuntu • 558 Disabling the submenu for Ubuntu • 562 Securely configuring BIOS/UEFI ........................................................................................... 563 Using a security checklist for system setup ............................................................................ 566 Summary ............................................................................................................................. 569 Questions ............................................................................................................................. 569 Further reading .................................................................................................................... 571 Answers ............................................................................................................................... 571
The above is a preview of the first 20 pages. Register to read the complete e-book.

Recommended for You

Loading recommended books...
Failed to load, please try again later

Tip the Site

Scan the WeChat Pay or Alipay code to tip. No login required.

WeChat Pay
Alipay
← Back to List