10 Tips for Hardening your Linux Servers

10 Tips for Hardening your Linux Servers

Learn Linux TV

3 года назад

70,170 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

@BloodAsp
@BloodAsp - 22.04.2021 03:21

I think the wording you were looking for is that you were not looking to incite baseles panic. It is always good to know that you don't know what you don't know, which can be scary when you have a lot hanging on the line.

Ответить
@bulcub
@bulcub - 22.04.2021 04:18

how about some examples?

Ответить
@WeedMIC
@WeedMIC - 23.04.2021 02:03

Pls consider timestamps

Ответить
@kosmonautofficial296
@kosmonautofficial296 - 23.04.2021 17:12

Looking forward to it! Great first video.

Ответить
@LiveWireBT
@LiveWireBT - 23.04.2021 17:44

No chapter marks, no meaningful description about the content. One has to skip through the video to learn what these "great" 10 tips are. I wouldn't call it hardening, but consumer-ish admins who never thought twice about what they install and run have to start somewhere. Very clickbaity. Of course you have to have lighting like a dance club or a brothel. Day in, day out, sustainability doesn't matter.

Ответить
@scorp73
@scorp73 - 25.04.2021 01:12

If it was only (not) patching the servers... I so hate it that at my new workplace their lifecycling policies just plain suck. E.g. distributions such as Ubuntu 14.04 and Debian 7.x have been EOL+EOS for quite some time now.... but there are still tons of those servers around, still allowed to run :( It's a tiring uphill battle I'm fighting here. :´(

Ответить
@fullscale4me
@fullscale4me - 25.04.2021 05:04

Port scanning and what to shut off as determined by the server's role.

Ответить
@fullscale4me
@fullscale4me - 25.04.2021 05:07

Plans vs accessibility: in the DMZ [needs a public IP] vs behind a NAT firewall vs only accessed externally via VPN.

Ответить
@QuarKSonTV
@QuarKSonTV - 25.04.2021 15:21

Keeping server up to date is important, although it's worth noting auto-updates can break your server and your service could be down for some time before fixing it

Ответить
@faizansalam
@faizansalam - 25.04.2021 23:33

quality stuff

Ответить
@peterjansen4826
@peterjansen4826 - 29.04.2021 05:14

Good growth of the channel. Hard work and consistency paying of.

Ответить
@AndersJackson
@AndersJackson - 30.04.2021 01:02

#3 Number 3, best is no passwords at all...

Ответить
@Steamrick
@Steamrick - 21.05.2021 22:38

I've actually experienced failed no-boot backups (not on my own environment and none I was in charge of, luckily). Not fun.

Ответить
@IAmNumber4000
@IAmNumber4000 - 09.07.2021 23:07

Also a nice tip for important admin web interfaces like Portainer, Traefik, etc. is to put it behind Cloudflare Access, which will require a one-time password from your email address before allowing anybody to connect to it and can set all kinds of device-based authentication rules.

Ответить
@wekiwa7055
@wekiwa7055 - 19.07.2021 19:35

Great video Jay. A multi part on Locking down a public facing server to maybe DOD levels would be great. Your common sense approach is refreshing.

Ответить
@kamillewan4636
@kamillewan4636 - 27.07.2021 22:29

1.I have a queston. What about really system critical servers? One thing is hosting website, other medical/milirary/finantial stuff. Example from real life. I'm worling in company related with cryptocurrency, and lets say we need to store hot wallet - real actiall money on servers. We have some lowering risk procedures, like managing balances to only what we need, but I'm wondering what others do. For example if only option to be relative secure (im ignoring inside/phisical attack), is to disconnect from public network?

Ответить
@jschucke
@jschucke - 27.08.2021 20:16

In addition to patching the OS, don't forget about driver & firmware updates.

Ответить
@SupraRyu
@SupraRyu - 26.11.2021 00:11

You really found your speciality.. Excellent videos. Best for your success!

Ответить
@kishistudios
@kishistudios - 17.12.2021 18:02

U r doing a good job with these videos my friend.. keep it up..

Ответить
@majorgear1021
@majorgear1021 - 06.02.2022 19:28

Video chapters would be nice. That way viewers can rewatch topics they need to refresh themselves on.

Ответить
@13thravenpurple94
@13thravenpurple94 - 05.09.2022 18:21

Great work 🥳 Thank you 💜

Ответить
@yeoucheoub3535
@yeoucheoub3535 - 12.10.2022 03:38

Can you make traps too

Ответить
@АнгелИнокентий
@АнгелИнокентий - 27.01.2023 11:24

In windows I have administrative policies, where I change the rules for remote users. My rules is 3 wrong passwords and then block a user account. What the Linux have on his board?

Ответить
@АнгелИнокентий
@АнгелИнокентий - 27.01.2023 11:25

What the program for backups Linux have on his board?

Ответить
@АнгелИнокентий
@АнгелИнокентий - 27.01.2023 11:33

One moment I configured My Linux work machine, after I upgraded my Linux machine and after she had problems with programs that have stopped working. It's ok, or did I something wrong?

Ответить
@АнгелИнокентий
@АнгелИнокентий - 27.01.2023 11:33

Thank you for your lessons.

Ответить
@abytebit
@abytebit - 24.02.2023 15:44

Is there any real content in this video except Ads?

Ответить
@abdalla8114
@abdalla8114 - 08.03.2023 10:56

Going into my second year into System Administration, I'm very much thankful for your information. I will be looking forward to apply them in my company's servers.

Ответить
@BrickTamlandOfficial
@BrickTamlandOfficial - 29.06.2023 08:45

A note about patching. many patches open new security holes. it's really a double edge sword. if a patch breaks business continuity then it could be just as costly as getting hacked, and if the patch opens up another security issue, doing nothing and "taking the gamble" (risk acceptance) is what business owners try to do.

Ответить
@EGGNBEENZ
@EGGNBEENZ - 14.09.2023 23:48

1.5x speed is just right

Ответить
@joelsschwarz
@joelsschwarz - 30.09.2023 05:39

This is gold. Thanks!

Ответить
@billbailey273
@billbailey273 - 04.10.2023 17:55

Have you considered doing a desktop hardening, for those who use Linux as a daily driver?

Ответить
@camaycama7479
@camaycama7479 - 09.11.2023 17:00

for point 10, that's why kubernetes (and harvester) are there as a true solution for HA and self remedy ;)

Ответить
@فیزیکاستراتژیک
@فیزیکاستراتژیک - 16.12.2023 12:41

Do you have any plan to make a video about SELinux?

Ответить
@shadanequbal6756
@shadanequbal6756 - 04.03.2024 10:12

Very helpful video sir. May I have the link of next videos in this series?

Ответить
@aniksen3831
@aniksen3831 - 19.03.2024 23:57

I am using deepin how to secure it ?

Ответить
@damianlopez9493
@damianlopez9493 - 18.04.2024 17:27

Thank you for your invaluable guidance! I’ve recently set up my first home server using Ubuntu, and I’m currently running an open-source application called Immich. This app serves as a great alternative to Google Photos and operates with Docker.

While I didn’t identify any security risks when running it on my local server, I’ve noticed that the application’s capabilities significantly expand when connected to the internet. To expose it, I’ve employed a Cloudflare Tunnel. However, as I’m not an expert in network security, I’m unable to fully assess all potential risks. As you’ve rightly pointed out, any risk is possible.

I would appreciate your insights on tunneling and any advice you might have to enhance the security of this service.

Thanks!

Ответить
@waltsullivan8986
@waltsullivan8986 - 13.07.2024 05:47

Before locking down SSH (or messing with login or sudo) is to have, running in another terminal window, an SSH/root connection active. Then, when you lock EVERYBODY out (oops, did that mean me, too?), you can restore the original configuration (you preserved it?) or fix.

Ответить
@stefandevos1520
@stefandevos1520 - 31.07.2024 14:22

As an aspiring Linux System Administrator, this video is invaluable. Thank you

Ответить
@paulgreene9997
@paulgreene9997 - 09.09.2024 05:17

The DISA STIGS and Center for Internet Security have security checklists that go into enough detail to configure security settings to make a grown man cry.

Ответить
@TheDutchManMain
@TheDutchManMain - 13.09.2024 23:19

Adjust your mindset? Really?
Patch your servers? Obviously!
Strengthen your passwords? No shit!
Don't open services to the public internet (unless...) Sure, fine. Still obvious though.
Lock down SSH. Good, we got a decent tip here.

Now we got a banger tip...
Implement as many as layers of security as possible.
ARE YOU JOKING!?!
Aren't you supposed to tell us these security layers right now!?
That is like saying "How to harden you system: Step one, take as many hardening steps as possible"
That is like saying "How to get stronger: Step one, do as many strength exercises as possible"

After that you either give us more basic tips that has barley anything to do with hardening a system if anything at al, or you give us business tips...
The video is titled "10 Tips for Hardening your Linux Servers" and not "10 Tips for basic security and some business advice for dummy's".
Where are tips for settings to change, software to install, things to disable/enable, deep things to look out for?
This video was 50% life advice and 50% how to basic.
Somehow I got triggered enough by this shit to write my first hate comment ever that I have spend valuable time on because this is way to long.
Have a very nice day

Ответить