Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Donald A. Tevault

Rating No ratings yet

The third edition of Mastering Linux Security and Hardening is an updated, comprehensive introduction to implementing the latest Linux security measures, using the latest versions of Ubuntu and AlmaLinux. In this new edition, you will learn how to set up a practice lab, create user accounts with appropriate privilege levels, protect sensitive data with permissions settings and encryption, and configure a firewall with the newest firewall technologies. You’ll also explore how to use sudo to set up administrative accounts with only the privileges required to do a specific job, and you’ll get a peek at the new sudo features that have been added over the past couple of years. You’ll also see updated information on how to set up a local certificate authority for both Ubuntu and AlmaLinux, as well as how to automate system auditing. Other important skills that you’ll learn include how to automatically harden systems with OpenSCAP, audit systems with auditd, harden the Linux kernel configuration, protect your systems from malware, and perform vulnerability scans of your systems. As a bonus, you’ll see how to use Security Onion to set up an Intrusion Detection System. By the end of this new edition, you will confidently be able to set up a Linux server that will be secure and harder for malicious actors to compromise.

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A hands-on, lab-driven guide that teaches working Linux admins how to lock down Ubuntu and AlmaLinux servers against real-world attacks. Best for sysadmins and security practitioners who already know the command line and want practical hardening skills rather than theory. 【Book Arc】 - **Opening (~0%–10%)**: Sets the scene — why Linux security matters for your career, how to build a safe virtual practice lab (VirtualBox/Cygwin), and the special risks of virtualized and cloud-hosted servers. - **Early (~10%–35%)**: Account security fundamentals — replacing root with sudo, writing fine-grained sudo policies, locking down normal users, enforcing strong password and expiry policies, and managing updates in enterprise settings. - **Middle (~35%–55%)**: Network defense — working through firewall utilities (iptables, nftables, firewalld), building default-deny rulesets, handling ICMP safely, and testing your rules with scanning tools. - **Late (~55%–80%)**: Data protection and access control — encryption at rest and in transit, SSH hardening, file ownership and permissions, SUID/SGID implications, and extended file attributes. - **Ending (~80%–100%)**: Advanced hardening and monitoring — local certificate authorities, automated auditing with auditd, OpenSCAP-based hardening, kernel configuration, malware protection, vulnerability scanning, and IDS setup with Security Onion. 【Key Takeaways】 - **Build a lab before you touch production** (Opening): The book insists on a virtual environment so you can safely break and rebuild systems while learning — a practical prerequisite most guides skip. - **sudo beats root for daily administration** (Early): Detailed coverage of sudoers syntax, command aliases, and the subtle trap that listing a command with a subcommand restricts users to only that subcommand. - **User account hygiene is a layered discipline** (Early): Home directory permissions, UMASK settings, password quality policies, account locking via `usermod -L`, and expiration defaults all combine to shrink the attack surface. - **Enterprise update management differs from home use** (Early): Restricting installable packages and testing updates on a separate network before production are framed as essential enterprise practices. - **Firewalls demand a default-deny mindset** (Middle): The book walks through iptables, nftables, and firewalld, emphasizing rule ordering, ICMP selectivity (blocking all ICMP breaks networking), and verifying rules with scans. - **Encryption and SSH hardening protect data in transit** (Late): Default SSH configuration is called out as insecure, and the book covers both at-rest and in-transit encryption technologies. - **Permissions are more than chmod** (Late): SUID, SGID, and extended file attributes carry security implications that admins must understand to avoid privilege escalation paths. - **Automation closes the gap between policy and practice** (Ending): OpenSCAP for automated hardening, auditd for system auditing, and Security Onion for intrusion detection shift security from manual checks to repeatable processes. 【Reading Tips】 - **Deep-read the sudo and permissions chapters** (Early–Late): These contain the most nuanced, easily-misconfigured details — the subcommand restriction trap alone justifies careful reading. - **Skim the virtualization setup if you already have a lab**: The VirtualBox/Cygwin walkthrough is useful for beginners but skippable for experienced admins. - **Do the hands-on labs**: The book is structured around practical exercises; reading without executing the firewall and sudo commands loses most of the value. - **Treat firewall chapters as a reference**: iptables, nftables, and firewalld syntax differ enough that you will return to these sections when configuring real systems. - **Note the distro differences**: Ubuntu and AlmaLinux diverge on defaults (e.g., UMASK, HOME_MODE), so pay attention to which platform each example targets. 【Coverage Limits】 The excerpts cover the book's structure, account security, firewall fundamentals, and chapter summaries, but do not include detailed content from the encryption, SSH hardening, OpenSCAP, auditd, or Security Onion chapters. Specific commands and configurations from those later chapters are not represented here.
Page 12
..................................................................................................... 167 Further reading ......................................
View in text
Excerpt 2
o Linux security and hardening. In this chapter, we looked at why it’s just as important to know about securing and hardening Linux systems as it is to know...
View in text
Excerpt 3
will have the Zsh shell set as the default shell and will have to have expired passwords changed within five days to prevent the account from being automat-...
View in text
Excerpt 4
the rules that I deleted, I can either reboot the machine or restart the netfilter-persistent service. The latter choice is quicker, so I’ll activate it like...
View in text
Excerpt 5
sudo firewall-cmd --list-ports sudo firewall-cmd --reload sudo firewall-cmd --list-ports sudo firewall-cmd --info-zone=dmz 8. Remove the port that you just a...
View in text
Excerpt 6
y has an option for setting FIPS mode, you’ll never use it. To set FIPS mode on a machine on which the operating system has already been installed, you’d ins...
View in text
Excerpt 7
forwarding, let’s dig some tunnels. Disabling SSH tunneling SSH tunneling, or as it’s sometimes called, SSH port forwarding, is a handy way to protect non-se...
View in text
Excerpt 8
gement It looks good, right? Ah, but looks can be deceiving. Watch what happens when I delete the directory, and then restore it from the backup: [donnie@loc...
View in text
Tags
AI categories
LinuxCybersecurityDevOps
ISBN: 1837630518
Publisher: Packt Publishing
Publish Year: 2023
Language: English
Pages: 621
File Format: PDF
File Size: 15.9 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…