Lesson 1 of 1 in Locked Out
Harden The Box
A fresh box, fully open, with the auth log already filling. Do the three things this course has taught — passwords off, firewall default-deny, fail2ban live — and watch the attempts turn from a threat into background noise. You are graded on the box's state, not on a quiz about it.
2 min read
Not yet reviewed
Here is a box that went online an hour ago. Nothing is hardened. The log is already full. You have learned every move you need — now do them, in order, on a live box, while the knocking continues.
I am already here. Passwords are on, the firewall is open, and nothing bans me when I fail. Close those and I have to find an easier box — which is the whole point, and I hate it.
See what you are up against
First, read the room. Here is the auth log — the same relentless brute force from every chapter. Count the attempts if you like, or find the one login that is not a failure. Then, in the challenges that follow, shut each door the attempts are testing. Nothing you do stops the knocking; everything you do makes it futile.
The auth log is filling with attempts. Before you harden, prove you can read it: among three hundred failures, print the single line where a login actually succeeded.
Close the door — passwords off
Every one of those failures is a password guess. Take the password away. Harden the SSH config so it ends with password authentication off — the guessing then has nothing to guess against.
Harden the SSH daemon: append to the config so it contains PasswordAuthentication no.
Close the door — default-deny
Now the firewall. Flip the default so nothing gets in unless you named it — and discover, in the flipping, anything you left listening that you should not have.
Set the firewall to default-deny incoming: append to the plan so it contains default deny (incoming).
Close the door — ban the persistent
Last, make the attempts expensive. Enable the fail2ban jail so an address that keeps failing is dropped at the firewall, and the persistent are removed rather than merely slowed.
Turn on the sshd jail: append to the fail2ban config so it contains enabled = true.