Skip to contentExploitQuest

Lesson 1 of 1 in Default Deny

Only What You Can Name

Turn the default from "allow unless blocked" to "block unless allowed", then open ports one at a time, saying why each is open. What you cannot name, you close — and closing it is how you find the things you did not know were exposed.

3 min read

Not yet reviewed

Wrenlearner

SSH is locked down. But the box runs a web app, and I think the database is on there too. Is that a problem?

Magpieadversary

The database is my favourite thing you forgot. You opened 80 and 443 on purpose. You did not mean to leave 5432 open to the whole internet — but you installed Postgres and it listened, and nobody told the door to stay shut.

Rookmentor

So we stop trusting the list of doors we remember and flip the default. Deny everything. Then open exactly what the box is *for*, and be able to say what each open port does.

Block first, then open

A default-allow firewall protects you from the ports you thought to block. A default-deny firewall protects you from the ports you forgot — which are the dangerous ones, because you are not watching them. So the rule is: deny all incoming, allow all outgoing, then add back the incoming ports the server genuinely needs, one at a time.

ufw default deny incoming      # nothing gets in unless a rule says so
ufw default allow outgoing     # the box can still reach out
ufw allow OpenSSH              # so you do not lock yourself out — do this FIRST
ufw allow 80/tcp              # the web app, in the clear
ufw allow 443/tcp             # the web app, over TLS
ufw enable                    # turn it on
  1. Line 3Allow SSH *before* you enable the firewall. Enabling default-deny with no SSH rule from a remote session locks you out of your own box — a rite of passage nobody enjoys.
  2. Line 4Two ports the server is *for*. Everything else — the database, a metrics endpoint, a language's dev server — stays closed to the world, reachable only from the box itself.

Your database only ever talks to the app on the same machine. Someone suggests "just firewall-allow Postgres from your app server's IP." Why is closing the port to the internet entirely the better answer here?

What the deny finds

The best thing about turning on default-deny is what breaks. If flipping it on takes down something you did not expect, you have just discovered a service that was reachable from the internet and should not have been. The firewall is not only a wall; switching it on is an audit of what your box was quietly offering to everyone.

Your turn

This box's firewall plan is a file. Make it default-deny for incoming by appending the line that sets it, so the file contains deny (incoming).

you@practice
Practice shell — nothing here is real. Type 'help' to begin.