{"repo":"imthenachoman/How-To-Secure-A-Linux-Server","free":true,"listed":false,"github":"https://github.com/imthenachoman/How-To-Secure-A-Linux-Server","clone":"git clone https://github.com/imthenachoman/How-To-Secure-A-Linux-Server.git","description":"An evolving how-to guide for securing a Linux server.","language":null,"stars":30292,"topics":["linux","hardening","hardening-steps","security","security-hardening","server","linux-server","cc-by-sa"],"license":"CC-BY-SA-4.0","category":"security-tools","readme_excerpt":"How To Secure A Linux Server An evolving how-to guide for securing a Linux server that, hopefully, also teaches you a little about security and why it matters. Table of Contents - Introduction - Guide Objective - Why Secure Your Server - Why Yet Another Guide - Other Guides - To Do / To Add - Guide Overview - About This Guide - My Use-Case - Editing Configuration Files - For The Lazy - Contributing - Before You Start - Identify Your Principles - Picking A Linux Distribution - Installing Linux - Pre/Post Installation Requirements - Other Important Notes - Using Ansible Playbooks to secure your Linux Server - The SSH Server - Important Note Before You Make SSH Changes - SSH Public/Private Keys - Create SSH Group For AllowGroups - Secure /etc/ssh/sshd config - Remove Short Diffie-Hellman Keys - 2FA/MFA for SSH - The Basics - Limit Who Can Use sudo - Limit Who Can Use su - Run applications in a sandbox with FireJail - NTP Client - Securing /proc - Force Accounts To Use Secure Passwords - Automatic Security Updates and Alerts - More Secure Random Entropy Pool (WIP) - Add Panic/Secondary/Fake password Login Security System - The Network - Firewall With UFW (Uncomplicated Firewall) - iptables Intrusion Detection And Prevention with PSAD - Application Intrusion Detection And Prevention With Fail2Ban - Application Intrusion Detection And Prevention With CrowdSec - The Auditing - File/Folder Integrity Monitoring With AIDE (WIP) - Anti-Virus Scanning With ClamAV (WIP) - Rootkit Detectio","default_branch":null,"files":null,"tree":[],"storefront":"/r/imthenachoman","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/imthenachoman/How-To-Secure-A-Linux-Server/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}