The third edition of Mastering Linux Security and Hardening is an updated, comprehensive introduction to implementing the latest Linux security measures, using the latest versions of Ubuntu and AlmaLinux.
In this new edition, you will learn how to set up a practice lab, create user accounts with appropriate privilege levels, protect sensitive data with permissions settings and encryption, and configure a firewall with the newest firewall technologies.
You’ll also explore how to use sudo to set up administrative accounts with only the privileges required to do a specific job, and you’ll get a peek at the new sudo features that have been added over the past couple of years. You’ll also see updated information on how to set up a local certificate authority for both Ubuntu and AlmaLinux, as well as how to automate system auditing.
Other important skills that you’ll learn include how to automatically harden systems with OpenSCAP, audit systems with auditd, harden the Linux kernel configuration, protect your systems from malware, and perform vulnerability scans of your systems. As a bonus, you’ll see how to use Security Onion to set up an Intrusion Detection System.
By the end of this new edition, you will confidently be able to set up a Linux server that will be secure and harder for malicious actors to compromise.
AI Reading Assistant
Whole-book reading guide from stratified index samples; jump to passages in the text
Tip the Site
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat Pay
Alipay
Open WeChat or Alipay and scan. No login required.
AI guide
【One-Line Pitch】
A hands-on, lab-driven guide that teaches working Linux admins how to lock down Ubuntu and AlmaLinux servers against real-world attacks. Best for sysadmins and security practitioners who already know the command line and want practical hardening skills rather than theory.
【Book Arc】
- **Opening (~0%–10%)**: Sets the scene — why Linux security matters for your career, how to build a safe virtual practice lab (VirtualBox/Cygwin), and the special risks of virtualized and cloud-hosted servers.
- **Early (~10%–35%)**: Account security fundamentals — replacing root with sudo, writing fine-grained sudo policies, locking down normal users, enforcing strong password and expiry policies, and managing updates in enterprise settings.
- **Middle (~35%–55%)**: Network defense — working through firewall utilities (iptables, nftables, firewalld), building default-deny rulesets, handling ICMP safely, and testing your rules with scanning tools.
- **Late (~55%–80%)**: Data protection and access control — encryption at rest and in transit, SSH hardening, file ownership and permissions, SUID/SGID implications, and extended file attributes.
- **Ending (~80%–100%)**: Advanced hardening and monitoring — local certificate authorities, automated auditing with auditd, OpenSCAP-based hardening, kernel configuration, malware protection, vulnerability scanning, and IDS setup with Security Onion.
【Key Takeaways】
- **Build a lab before you touch production** (Opening): The book insists on a virtual environment so you can safely break and rebuild systems while learning — a practical prerequisite most guides skip.
- **sudo beats root for daily administration** (Early): Detailed coverage of sudoers syntax, command aliases, and the subtle trap that listing a command with a subcommand restricts users to only that subcommand.
- **User account hygiene is a layered discipline** (Early): Home directory permissions, UMASK settings, password quality policies, account locking via `usermod -L`, and expiration defaults all combine to shrink the attack surface.
- **Enterprise update management differs from home use** (Early): Restricting installable packages and testing updates on a separate network before production are framed as essential enterprise practices.
- **Firewalls demand a default-deny mindset** (Middle): The book walks through iptables, nftables, and firewalld, emphasizing rule ordering, ICMP selectivity (blocking all ICMP breaks networking), and verifying rules with scans.
- **Encryption and SSH hardening protect data in transit** (Late): Default SSH configuration is called out as insecure, and the book covers both at-rest and in-transit encryption technologies.
- **Permissions are more than chmod** (Late): SUID, SGID, and extended file attributes carry security implications that admins must understand to avoid privilege escalation paths.
- **Automation closes the gap between policy and practice** (Ending): OpenSCAP for automated hardening, auditd for system auditing, and Security Onion for intrusion detection shift security from manual checks to repeatable processes.
【Reading Tips】
- **Deep-read the sudo and permissions chapters** (Early–Late): These contain the most nuanced, easily-misconfigured details — the subcommand restriction trap alone justifies careful reading.
- **Skim the virtualization setup if you already have a lab**: The VirtualBox/Cygwin walkthrough is useful for beginners but skippable for experienced admins.
- **Do the hands-on labs**: The book is structured around practical exercises; reading without executing the firewall and sudo commands loses most of the value.
- **Treat firewall chapters as a reference**: iptables, nftables, and firewalld syntax differ enough that you will return to these sections when configuring real systems.
- **Note the distro differences**: Ubuntu and AlmaLinux diverge on defaults (e.g., UMASK, HOME_MODE), so pay attention to which platform each example targets.
【Coverage Limits】
The excerpts cover the book's structure, account security, firewall fundamentals, and chapter summaries, but do not include detailed content from the encryption, SSH hardening, OpenSCAP, auditd, or Security Onion chapters. Specific commands and configurations from those later chapters are not represented here.
Page 12
..................................................................................................... 167 Further reading ......................................
o Linux security and hardening. In this chapter, we looked at why it’s just as important to know about securing and hardening Linux systems as it is to know...
will have the Zsh shell set as the default shell and will have to have expired passwords changed within five days to prevent the account from being automat-...
the rules that I deleted, I can either reboot the machine or restart the netfilter-persistent service. The latter choice is quicker, so I’ll activate it like...
sudo firewall-cmd --list-ports sudo firewall-cmd --reload sudo firewall-cmd --list-ports sudo firewall-cmd --info-zone=dmz 8. Remove the port that you just a...
y has an option for setting FIPS mode, you’ll never use it. To set FIPS mode on a machine on which the operating system has already been installed, you’d ins...
forwarding, let’s dig some tunnels. Disabling SSH tunneling SSH tunneling, or as it’s sometimes called, SSH port forwarding, is a handy way to protect non-se...
gement It looks good, right? Ah, but looks can be deceiving. Watch what happens when I delete the directory, and then restore it from the backup: [donnie@loc...
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.
Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat PayAlipay
Open WeChat or Alipay and scan. No login required.
Add Tag
Enter tag name (max 50 characters)
Share E-Book
Mastering Linux Security and Hardening A Practical Guide to Protecting Your Linux System from Cyber Attacks (Donald A. Tevault)(Z-Library)
Scan QR code with your phone to access
Copy the link or scan the QR code to access this e-book on your phone
Share E-Book via Email
Please enter email address
Donation Statistics
¥.00
Total Donations
0
Donation Count
Mastering Linux Security and Hardening A Practical Guide to Protecting Your Linux System from Cyber Attacks (Donald A. Tevault)(Z-Library)
Find Your Favorite Books
Only registered users can comment after logging in. Comments need to be reviewed by administrators before being displayed
Loading comments...
Reply to Comment
Edit Comment