Skip to contentExploitQuest

Lesson 1 of 1 in Locked Out

Harden The Box

A fresh box, fully open, with the auth log already filling. Do the three things this course has taught — passwords off, firewall default-deny, fail2ban live — and watch the attempts turn from a threat into background noise. You are graded on the box's state, not on a quiz about it.

2 min read

Not yet reviewed

Rookmentor

Here is a box that went online an hour ago. Nothing is hardened. The log is already full. You have learned every move you need — now do them, in order, on a live box, while the knocking continues.

Magpieadversary

I am already here. Passwords are on, the firewall is open, and nothing bans me when I fail. Close those and I have to find an easier box — which is the whole point, and I hate it.

See what you are up against

First, read the room. Here is the auth log — the same relentless brute force from every chapter. Count the attempts if you like, or find the one login that is not a failure. Then, in the challenges that follow, shut each door the attempts are testing. Nothing you do stops the knocking; everything you do makes it futile.

Your turn

The auth log is filling with attempts. Before you harden, prove you can read it: among three hundred failures, print the single line where a login actually succeeded.

you@practice
Practice shell — nothing here is real. Type 'help' to begin.

Close the door — passwords off

Every one of those failures is a password guess. Take the password away. Harden the SSH config so it ends with password authentication off — the guessing then has nothing to guess against.

Your turn

Harden the SSH daemon: append to the config so it contains PasswordAuthentication no.

you@practice
Practice shell — nothing here is real. Type 'help' to begin.

Close the door — default-deny

Now the firewall. Flip the default so nothing gets in unless you named it — and discover, in the flipping, anything you left listening that you should not have.

Your turn

Set the firewall to default-deny incoming: append to the plan so it contains default deny (incoming).

you@practice
Practice shell — nothing here is real. Type 'help' to begin.

Close the door — ban the persistent

Last, make the attempts expensive. Enable the fail2ban jail so an address that keeps failing is dropped at the firewall, and the persistent are removed rather than merely slowed.

Your turn

Turn on the sshd jail: append to the fail2ban config so it contains enabled = true.

you@practice
Practice shell — nothing here is real. Type 'help' to begin.

Lesson 1 of 1

Sign in to track your progress and earn XP as you learn.