How to Harden a Linux Server (Checklist)
Hardening a Linux server means shrinking what attackers can use: update packages, lock down SSH, enable a host firewall after allowing SSH, remove unused services, fix permissions (never world-writable shortcuts like chmod 777), add logging and backups. Work from a checklist so you do not lock yourself out.
Friends, a new EC2 / VPS is often a bit open by default. Hardening means shrinking the attack surface. Today’s checklist is vertical: update → SSH → firewall → services → permissions → logs → backup. Commands for Ubuntu and Amazon Linux — pick your OS.
मित्रांनो, नवीन EC2 / VPS अनेकदा थोडे उघडे असतात. कठीणीकरण म्हणजे हल्ल्याचा attack surface लहान करणे. आजची यादी उभी आहे: update → SSH → फायरवॉल → सेवा → परवानग्या → नोंदी → बॅकअप. Ubuntu आणि Amazon Linux दोन्हीसाठी command; तुमची प्रणाली निवडा.
मित्रों, नया EC2 / VPS अक्सर थोड़ा खुला होता है. मज़बूती यानी हमले की सतह छोटी करना. आज की सूची ऊर्ध्व है: अपडेट → SSH → फ़ायरवॉल → सेवाएँ → अनुमतियाँ → लॉग → बैकअप. Ubuntu और Amazon Linux दोनों की commands; अपनी प्रणाली चुनो.
Quick answer
Baseline order (do not skip ahead of SSH allow rules):
- Apply OS updates and reboot if the kernel requires it.
- Prefer SSH keys; disable password login for SSH when keys work.
- Disable direct root SSH login; use
sudofrom a named user. - Configure the host firewall; allow SSH before enable.
- Remove or stop packages/services you do not need.
- Set sensible ownership and modes on web content (for example directories
755, files644— not777). - Configure time sync, logging, and unattended security updates where appropriate.
- Snapshot / backup before major changes.
Amazon Linux 2023 sketch:
sudo dnf update -y
sudo systemctl enable --now chronyd
# SSH: edit /etc/ssh/sshd_config.d/ then:
sudo systemctl reload sshd
sudo firewall-cmd --permanent --add-service=ssh
sudo firewall-cmd --permanent --add-service=http
sudo firewall-cmd --reload
Ubuntu sketch:
sudo apt update && sudo apt upgrade -y
sudo ufw allow OpenSSH
sudo ufw allow http
sudo ufw enable
sudo ufw status
What do I need before this guide?
- SSH access to a lab or production server you are authorised to change.
- Console / cloud “serial” access in case a firewall mistake happens.
- A second terminal open before you reload SSH or enable a firewall.
What does the hardening flow look like?
Harden in order: update packages, lock SSH, allow SSH in the firewall before enabling it, remove unused services, then permissions, logs and backups.
क्रमाने मजबूत करा: पॅकेज update, SSH कुलूप, फायरवॉल सुरू करण्याआधी SSH परवानगी, नको असलेल्या सेवा काढा, मग परवानग्या, नोंदी आणि बॅकअप.
क्रम से मज़बूत करो: पैकेज अपडेट, SSH ताला, फ़ायरवॉल चालू करने से पहले SSH अनुमति, अनावश्यक सेवाएँ हटाओ, फिर अनुमतियाँ, लॉग और बैकअप.
- Patch known vulnerabilities in packages.
- Make remote login hard to brute-force (keys, no root login).
- Block unexpected inbound ports on the host itself (and keep cloud security groups tight too).
- Turn off software you are not using.
- Keep audit trails and a restore path.
How do I harden the server (checklist steps)?
Step 1 — Update and inventory
- Run the OS update command for your family (
dnf/apt). - Reboot if a new kernel was installed (schedule a window).
- List listening ports:
sudo ss -tlnp
- Write down which ports should remain public.
Step 2 — SSH hardening
- Confirm your key login works in a second session before disabling passwords.
-
Set in
sshdconfig (via a drop-in file when possible):PasswordAuthentication no(after keys work)PermitRootLogin no- Optional: allow only specific users
-
Reload
sshd. - Keep cloud security group SSH limited to your IP / bastion — see related AWS guides.
- Optional: install
fail2banor use cloud WAF / rate controls for exposed services.
Step 3 — Host firewall (order matters)
- Install/enable
firewalld(many RHEL-like) orufw(Ubuntu). - Allow SSH first.
- Allow only the application ports you need (80/443 common for web).
- Enable the firewall.
- Re-test SSH from your laptop before closing the console.
Ravindra Bagale's Tip
💡 On Ubuntu, if you run ufw enable before ufw allow OpenSSH, you can lock yourself out. Many students have done it. Same idea on Amazon Linux / security groups: allow access first, then restrict. Order = safety. Keep a second session and the cloud console ready.
Ravindra Bagale's Tip – मराठी
💡 Ubuntu वर ufw enable आधी ufw allow OpenSSH विसरले की स्वतःला lock-out. खूप students ने केलंय. Amazon Linux / security group पण एकच विचार: आधी access rule, मग restrict. क्रम = safety. घाबरू नका – second session आणि cloud console ready ठेवा.
Ravindra Bagale's Tip – हिंदी
💡 Ubuntu पर ufw enable से पहले ufw allow OpenSSH भूल गए तो खुद को lock-out कर लोगे. बहुत students ये कर चुके हैं. Amazon Linux / security group में भी वही सोच: पहले access rule, फिर restrict. क्रम = safety. घबराओ मत – second session और cloud console ready रखो.
Step 4 — Packages, users and permissions
- Remove unused daemons.
- Create named sudo users; avoid shared root passwords.
- For web roots, use the service user ownership with tight modes — do not use
chmod 777. - Find world-writable surprises carefully in lab:
# Lab only — review carefully before changing production
sudo find /var/www -perm -0002 -type f 2>/dev/null | head
Step 5 — Logging, time and backups
- Ensure chrony/ntp time sync (logs and TLS need correct time).
- Confirm
journalctl/ log files rotate; ship logs if you have a SIEM. - Take an AMI / snapshot or other backup before big upgrades.
- Document open ports and owners in a short notes file.
How do I fix common hardening mistakes?
Ghabru naka 😅 — these are the usual ones:
| Symptom | Likely cause | Fix |
|---|---|---|
SSH times out after ufw enable |
SSH not allowed before enable | Use provider console; ufw allow OpenSSH then reload |
Permission denied (publickey) after reload |
Password auth off but key not installed | Console access; fix ~/.ssh/authorized_keys modes (700 / 600 style — not 777) |
| Website 403 after tightening perms | Web user cannot read files | Fix owner to the web user; dirs 755, files 644 |
| Still scanned on unused ports | Package still listening + SG open | Stop service; remove package; close security group port |
| Time skew / TLS errors | chrony not running | Enable chrony/ntp; check timedatectl |
Try it at home
On a lab VM only, complete and tick:
- Updated today:
- SSH keys only:
- Firewall status pasted:
ss -tlnpreviewed:- Snapshot taken:
Learn it properly
Got it? Update, SSH keys, firewall (allow SSH first), unused services off, tight permissions, logs + backup. No chmod 777. Follow the checklist and the server stays much calmer. Next, see the Nmap lab guide with ethical framing.
समजलं का? update, SSH किल्ल्या, फायरवॉल (आधी SSH परवानगी), नको असलेल्या सेवा बंद, घट्ट परवानग्या, नोंदी व बॅकअप. chmod 777 नको. यादी पाळली की computer खूप शांत वाटतो. आता नैतिक चौकटीसह nmap प्रयोग मार्गदर्शक बघा.
समझ में आया? अपडेट, SSH कुंजियाँ, फ़ायरवॉल (पहले SSH अनुमति), अनावश्यक सेवाएँ बंद, कसी अनुमतियाँ, लॉग व बैकअप. chmod 777 नहीं. सूची मानो तो computer बहुत शांत लगता है. अब नैतिक फ़्रेम के साथ nmap प्रयोग गाइड देखो.
Frequently asked questions
What does hardening mean?
Reducing attack surface: fewer open services, safer remote access, tighter permissions and better visibility.
Why allow SSH before enabling ufw?
Otherwise you can lock yourself out. Allow OpenSSH first, then enable.
Is chmod 777 ever recommended here?
No. It makes files writable by everyone on the system. Use proper ownership with tighter modes.
Do I still need cloud security groups?
Yes. Host firewall and cloud security groups are complementary layers.
Which OS commands does this cover?
Examples for Amazon Linux (dnf, firewalld) and Ubuntu (apt, ufw), plus shared SSH guidance.
Where are the deeper lessons?
Cyber Security Part 11 — Linux and network hardening.