grep -rl "security" ./blog

Linux Security and Hardening

Locking systems down: SSH hardening, firewalls, permissions, encryption, intrusion prevention, and the security models like SELinux and AppArmor that sit underneath it all.

61 articles

CrowdSec vs Fail2ban: Blocking Attackers on Linux Servers Fail2ban bans IPs that fail too often in your logs. CrowdSec does the same and shares signals with every other CrowdSec user. How each works, setup for SSH, the bouncer model, privacy trade-offs, and which to run. Malware Scanning on Linux: ClamAV, rkhunter, and Lynis Compared Three different tools that are often lumped together as Linux antivirus. What ClamAV, rkhunter, chkrootkit, and Lynis each actually detect, how to run them, how to read their false positives, and when scanning is worth it. The nmap Command Explained: Scanning Your Own Network the Right Way How to use nmap to discover devices on your network, find open ports, identify services and versions, and read the results, with the scan types that matter and the legal line you should not cross. Passkeys on Linux: Browsers, Password Managers, and Security Keys Linux has no built-in passkey store like Windows Hello or iCloud Keychain, but passkeys work well through password managers, hardware security keys, and your phone. Where passkeys live on Linux, how to set each option up, and how to avoid lockouts. How to Reset a Forgotten Root or User Password on Linux Locked out of your own Linux machine? How to reset the root or a user password from the GRUB menu with init=/bin/bash or rd.break, from Ubuntu's recovery mode, or from a live USB, including SELinux and encrypted-disk caveats. Securely Wiping Drives on Linux: shred, SSD Secure Erase, and NVMe Sanitize Why shred works on hard drives but not SSDs, how to wipe a whole HDD, how to use ATA secure erase and NVMe format or sanitize to erase SSDs properly, and why encryption plus key destruction is the most reliable approach. Two-Factor Authentication for SSH: TOTP Codes and FIDO2 Security Keys Add a second factor to SSH logins two ways: time-based one-time codes with pam_google_authenticator, or hardware-backed ed25519-sk keys on a YubiKey. Exact sshd configuration, how to avoid locking yourself out, and which to choose. How to Check Whether Your Linux Kernel Is Patched Against a CVE uname -r does not tell you whether a fix is in your kernel, because distributions backport patches without changing the version. How to check a specific CVE on Debian, Ubuntu, Fedora, RHEL, and Arch, and how to confirm you are actually running the fixed kernel. run0 vs sudo-rs vs sudo: The Three Ways to Get Root on Modern Linux sudo is being rewritten in Rust, and systemd now ships run0, which gets root without a setuid binary at all. How each one works, what they do differently, what sudo-rs leaves out, and which to use. Rust Coreutils Explained: What uutils Changes on Ubuntu and What Still Differs From GNU Ubuntu now ships uutils, a Rust rewrite of ls, cp, cat and the rest of coreutils, in place of the GNU versions. What changed, why Canonical did it, where the two still behave differently, and how to switch back. Unlock LUKS With the TPM: systemd-cryptenroll Explained Bind your encrypted disk to the TPM so it unlocks automatically at boot, or with a short PIN, and only on your untouched machine. How TPM sealing and PCRs work, the exact enrollment steps, recovery keys, and the security trade-offs. chattr and Extended Attributes: File Properties Beyond Permissions A file root cannot delete, a directory where files can only be appended to, and where SELinux labels and capabilities actually live. Two different mechanisms people conflate, and what each is genuinely useful for. Firmware Updates on Linux: fwupd, CPU Microcode and Why Order Matters fwupd updates your BIOS, SSD and peripherals from the package manager. CPU microcode is a separate mechanism that loads fresh every boot. One of them can brick hardware, and revisions are not always safe to skip. OpenSSL, CSRs and Self-Signed Certificates: What Each Piece Is For A private key, a CSR and a certificate are three different things and people conflate all three. What actually gets signed, why SANs matter more than Common Name, and when a self-signed certificate is the right answer instead of a mistake. PAM Explained: How Linux Actually Decides Who Gets In Every login, sudo and ssh session runs through a stack of PAM modules before it succeeds. The four module types, what required and sufficient really do, why order changes the outcome, and how to edit it without locking yourself out. Supply Chain Security: Verifying What You Install Your distribution signs packages and your package manager checks them automatically. Everything outside that, curl piped to shell, language registries, container images, has weaker guarantees or none. What each layer actually proves. Valkey and Redis Basics: Caching, Persistence and Not Losing Data An in-memory store used as a cache, a queue and a session store. Why the fork happened, what persistence does and does not guarantee, the eviction policy that decides whether it is a cache or a database, and how it gets left open to the internet. auditd: The Linux Audit Framework Explained How auditd records syscalls at the kernel level, why that makes it tamper-evident in a way application logs are not, and how to write rules without drowning in events. Single Sign-On for Self-Hosted Services with Authelia How forward auth puts a login in front of services that have none, why that is better than exposing a dozen separate login pages, and what it does not protect. Container Security Hardening: What the Defaults Leave Open Why a default docker run is more privileged than you think, what capabilities each container keeps, and the flags that turn a container into an actual boundary. Kernel Live Patching: Fixing the Kernel Without Rebooting How livepatch redirects functions in a running kernel, why it only covers a subset of fixes, and why it delays reboots rather than eliminating them. Secure Boot with Your Own Keys Replacing Microsoft's keys with your own so Secure Boot verifies what you chose rather than what a vendor signed. Including how to avoid bricking the machine. SSH Certificate Authorities: Access Control That Scales How SSH certificates replace authorized_keys sprawl, why they solve revocation and host key verification at once, and how to set up a CA properly. Hardening systemd Services: The Directives That Actually Confine ProtectSystem, PrivateTmp, NoNewPrivileges, and the rest, what each one blocks, and how to use systemd-analyze security to find out how exposed your services are right now. Writing AppArmor Profiles Building a profile from scratch with aa-genprof, what complain mode is for, and why AppArmor confines paths while SELinux labels inodes. Firejail and Bubblewrap: Sandboxing Individual Applications Two ways to confine a single program, why Firejail being setuid root is a real concern, and when bubblewrap is the better foundation. Flatpak Permissions Explained: What the Sandbox Actually Confines How Flatpak sandboxing works, why filesystem=home makes it decorative, how to inspect and tighten what an app can reach, and what portals do. pass: The Unix Password Manager How pass stores each secret as a GPG-encrypted file in a Git repository, why that design is durable, and the honest limitations of using it on a phone. ssh-agent and Agent Forwarding Explained How ssh-agent holds your decrypted keys, why agent forwarding is convenient and risky, and what ProxyJump does instead. IPv6 on Linux: Addresses, Autoconfiguration, and Why Your Firewall Might Be Open IPv6 is on by default and most people never configure it, which is exactly how a machine ends up firewalled on IPv4 and reachable on IPv6. Here is what the address types mean and what to check. LUKS Disk Encryption: Setting Up and Managing Encrypted Volumes Full disk encryption protects data at rest, which means a stolen laptop or a returned disk. Here is how key slots work, how to add and revoke passphrases, and what LUKS does not protect against. Container Networking Explained: Bridges, Ports, and Why Your Containers Cannot Talk Published ports, user-defined networks, DNS between containers, and why binding to 0.0.0.0 exposes a service your firewall thinks is closed. Rootless Containers: Running Podman and Docker Without a Root Daemon Rootless containers run as your ordinary user, so a container escape lands in an unprivileged account rather than as root. Here is how the UID mapping works and which limitations you will actually hit. The First Ten Minutes on a New Linux Server A fresh VPS is reachable from the entire internet within seconds of provisioning. Here is the short, ordered list of things to do before you install anything else. WireGuard vs OpenVPN vs Tailscale: Choosing a VPN for a Homelab Three tools, three different problems. One is a protocol, one is an older protocol with more options, and one is a coordination layer that removes the hard part. Here is which to use when. firewalld Explained: Zones, Services, and Runtime vs Permanent Fedora and RHEL ship firewalld rather than ufw, and its zone model confuses people arriving from other distributions. Here is how zones work and why half your rules disappear on reboot. netcat Explained: Testing Ports, Moving Files, and Debugging Protocols netcat reads and writes arbitrary TCP and UDP connections, which makes it the fastest way to answer is this port actually open and what is that service really saying. TLS Certificates on Linux: Let's Encrypt, certbot, and What Actually Happens Free automated certificates removed the last excuse for running services over plain HTTP. Here is how the ACME challenge works, how to get a certificate with certbot, and how to handle wildcards and renewal properly. SSH Keys Explained: Generating, Using, and Not Losing Them Password authentication over SSH is a liability on any internet-facing server. Key authentication is better in every way and takes two minutes to set up. Here is how keys work, which type to generate, and how to manage them properly. Linux ACLs Explained: getfacl and setfacl Beyond rwx Permissions Standard permissions give you one owner, one group, and everyone else. Access control lists let you grant specific users and groups their own permissions on a file, and getfacl and setfacl are how you manage them. SSH Tunneling Explained: Local, Remote, and Dynamic Port Forwarding SSH can carry more than shells. With -L, -R, and -D it forwards ports through encrypted tunnels, reaching firewalled services, exposing local apps, and acting as a instant SOCKS proxy. WireGuard Explained: The Modern Linux VPN WireGuard is a VPN protocol built into the Linux kernel: a few thousand lines of code, public-key pairs instead of certificate bureaucracy, and configs short enough to read. Here is how it works and a working two-peer setup. GPG Basics on Linux GPG provides encryption and digital signatures using public-key cryptography, and it underlies how Linux package repositories verify software has not been tampered with. This guide covers generating a key pair, encrypting and decrypting files, and signing and verifying. SGID Explained The SGID bit behaves differently on files versus directories, most commonly used to keep every new file in a shared team folder consistently owned by the same group. This guide explains both behaviors clearly. SUID Explained The SUID bit lets a program run with the permissions of its file owner instead of the user who launched it. This guide explains how SUID works, why it exists, and why it is a common security concern. AppArmor Explained AppArmor is a mandatory access control system for Linux that confines programs to a limited set of resources using per-application profiles. This guide covers how AppArmor works, how to read and write profiles, and how to move from complain mode to enforce mode. Checking Open Ports on Linux Knowing which ports are open and which processes are listening on them is essential for security audits, debugging, and firewall configuration. This guide covers ss, lsof, nmap, and related tools. Encrypting Your Linux Installation with LUKS Full disk encryption protects your data if your laptop is lost or stolen. Linux uses LUKS (Linux Unified Key Setup) to encrypt partitions at the block device level. This guide explains how to enable it at install time, how it works, and how to manage it after installation. Fail2Ban Setup Fail2ban monitors log files for repeated authentication failures and automatically bans the offending IP addresses using firewall rules. This guide covers installation, configuration, and managing jails for SSH, nginx, and other services. How Linux Permissions Work Linux permissions control who can read, write, and execute every file and directory on the system. This guide explains the permission model from the basics through to special bits, umask, and ACLs. Keeping Linux Updated Staying current with security patches is the single highest-impact thing you can do to protect a Linux system. This guide covers update commands for every major distro, how to automate security updates, and how to handle kernel updates safely. Linux Firewall Basics Linux firewalls control which network traffic is allowed in and out of your system. This guide covers the concepts, ufw for simple setups, and an introduction to the underlying nftables rules that power them all. Linux Malware Myths The idea that Linux cannot get malware is dangerously wrong. Linux systems -- especially servers -- are actively targeted. This guide covers what real Linux malware looks like, how it gets in, and how to detect and prevent it. Linux Security Best Practices A practical security checklist for Linux systems -- covering user privileges, SSH hardening, firewall setup, automatic updates, file integrity monitoring, and auditing tools like Lynis. Linux Users, Groups, and Ownership Explained Linux is a multi-user operating system built around a clear identity model. Understanding users, groups, UIDs, GIDs, sudo, and the root account is essential for administering any Linux system. Secure Boot Explained: What It Is and How Linux Handles It Secure Boot is a UEFI feature that verifies the digital signature of the bootloader before running it. Most major Linux distributions handle it transparently, but some setups require additional configuration. This guide explains how it works and what to do. SELinux Explained SELinux (Security-Enhanced Linux) is a mandatory access control system built into the Linux kernel. This guide explains how SELinux works, what contexts and policies mean, how to read denials, and how to write rules with audit2allow. SSH Beginner's Guide SSH (Secure Shell) lets you log into remote Linux systems, run commands, and transfer files over an encrypted connection. This guide covers key-based authentication, the SSH config file, port forwarding, and common SSH patterns. SSH Hardening Guide SSH is the most commonly attacked service on internet-facing Linux servers. This guide covers every important sshd_config setting, key management practices, and tools like fail2ban to reduce your exposure. Sudo Explained sudo lets non-root users run commands with elevated privileges in a controlled, auditable way. This guide covers how sudo works, how to configure /etc/sudoers, and common patterns for granting the right level of access. Updating Linux Safely Keeping a Linux system updated is straightforward -- until an update breaks something. This guide covers how to update safely, how to snapshot before major changes, how to hold back problematic packages, and how to recover when something goes wrong.