Skip to Content
Advanced Infrastructure Penetration Testing
book

Advanced Infrastructure Penetration Testing

by Chiheb Chebbi
February 2018
Intermediate to advanced
396 pages
9h 38m
English
Packt Publishing
Content preview from Advanced Infrastructure Penetration Testing

Linux hardening

In the previous sections, we discovered the required methods and tools to attack the Linux infrastructure. Now it is time to deploy safeguards and learn how to defend against these attacks and secure your infrastructure. To harden your Linux systems, you need to do the following:

  • Update Linux kernel and applications
  • Avoid using insecure services such as FTP and telnet and use SFTP and OpenSSH instead
  • Minimize the attack surface by using only the needed applications and services
  • If possible, use SELinux
  • Use a strong password policy
  • Keep an eye on faillog records
  • Harden /etc/sysctl.conf 
  • Use an authentication server

Center of Internet Security (CIS) provides many hardening guides for a various number of operating systems including ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Practical Web Penetration Testing

Practical Web Penetration Testing

Gus Khawaja
Securing Network Infrastructure

Securing Network Infrastructure

Sairam Jetty, Sagar Rahalkar

Publisher Resources

ISBN: 9781788624480Supplemental Content