메뉴 건너뛰기

System Security Research Center

System&Network Security

Hardening Ubuntu. Systemd edition.

SSRC 2022.09.04 21:19 조회 수 : 14

 GitHub 주소: https://github.com/konstruktoid/hardening?fbclid=IwAR3e86xu_XdY7IhTSYWRR61yh7zasTpEgKbjV67m-v2wAd1tzrxgqiq4Dpw

 

Ubuntu Hardening

Hardening Ubuntu. Systemd edition.

A quick way to make a Ubuntu server a bit more secure.

Tested on Ubuntu 20.04 Focal FossaUbuntu 21.04 Hirsute Hippo and Ubuntu 21.10 Impish Indri (development branch).

Systemd required.

If you’re just interested in the security focused systemd configuration, it’s available as a separate document.

If you’re interested in testing your host settings, you’ll find the instructions here.

Note
This is a constant work in progress. Make sure you understand what it does. Read the code and do not run this script without first testing in a non-operational environment.

When possible, use the newly installed and configured system as a reference, or golden, image. Use that image as a baseline installation media and ensure that any future installation comply with benchmarks and policies using a configuration management tool, e.g Ansible or Puppet.

Packer template and Ansible playbook

Packer template is available in the konstruktoid/hardening-geniso repository.

An Ansible playbook is available in the konstruktoid/ansible-role-hardening repository.

번호 제목 글쓴이 날짜
23 Network Infrastructure for Ethernet/IP, Introduction and Considerations file SSRC 2019.05.18
22 Using SNORT for intrusion detection in MODBUS TCP/IP communications file SSRC 2019.07.26
21 위성 통신 취약점과 공격 시나리오 분석 자료파일 file SSRC 2019.10.16
20 ZIgbee 취약점 익스플로잇 툴URL링크 SSRC 2019.10.24
19 PowerShell을 이용한 Windows 운영체제 무결성 점검방법 SSRC 2020.08.21
18 윈도우 방화벽 관련 PowerShell목록 SSRC 2020.08.21
17 Windows 방화벽 사용 Best Practices SSRC 2020.08.21
16 IPtable 사용 튜토리얼 SSRC 2020.08.21
15 윈도우즈 로그 분석 관련 자료 및 세미나 SSRC 2020.08.21
14 Active Directory 정보 추출 스크립트들 SSRC 2020.08.21
13 임메디드 시스템 취약점 점검 방법 구분 SSRC 2021.10.06
12 현대 소프트웨어를 가장 많이 위협하는 건 ‘메모리 변형’ 취약점 SSRC 2022.09.04
11 한국 소프트웨어는 취약점이 없나요? KOREA CVE 논의 시급하다 SSRC 2022.09.04
10 Smart City Cybersecurity Whys and Hows SSRC 2022.09.04
» Hardening Ubuntu. Systemd edition. SSRC 2022.09.04
8 Night PI - Based on a Raspberry Pi 3B+ with Kali Linux SSRC 2023.01.24
7 Network Monitoring and Incident response SSRC 2023.01.24
6 Mapping MITRE ATT&CK with Window Event Log IDs SSRC 2023.01.24
5 Vx Underground SSRC 2023.01.24
4 GitHub - Diverto/nse-log4shell: Nmap NSE scripts to check against log4shell or LogJam vulnerabilities (CVE-2021-44228) SSRC 2023.01.24
위로