Labs · Cyber Security
Lab: Audit Your Own Linux VM with Lynis, Rank the Findings by Risk and Plan the Fixes
Course: Cyber Security · Chapter 20: Vulnerability Scanning and Assessment
Chapter 20 explains vulnerability scanning and assessment; this lab assesses your own machine from the inside and turns findings into a patch plan.
Chala mitrano! A vulnerability assessment is not about finding a hundred problems. It is about deciding which ten to fix first. Today Lynis checks our own Linux VM from the inside, gives a score, and we turn the list into a short plan, fix two things and watch the score go up. Mast vatel!
चला मित्रांनो! Vulnerability assessment म्हणजे शंभर problems शोधणं नाही. आधी कोणते दहा fix करायचे ते ठरवणं. आज Lynis आपला स्वतःचा Linux VM आतून check करणार, score देणार, आणि आपण ती list छोट्या plan मध्ये बदलणार, दोन गोष्टी fix करणार आणि score वाढताना बघणार. मस्त वाटेल!
चलो दोस्तों! Vulnerability assessment सौ problems ढूँढने के बारे में नहीं है। ये तय करने के बारे में है कि पहले कौन से दस fix करें। आज Lynis हमारे अपने Linux VM को अंदर से check करेगा, score देगा, और हम उस list को छोटे plan में बदलेंगे, दो चीज़ें fix करेंगे और score बढ़ते देखेंगे। मज़ा आएगा!
Suppose we are…
Suppose we are a junior in the vulnerability management team at Infosys. A client asks: "Our Linux servers passed the network scan, but are they configured safely inside?" We run Lynis (a free, open-source tool that audits a Linux system's own settings) on a test server, rank the results, and give the client a fix plan, starting with the highest risk.
Goal of this lab
By the end you will have:
- A Lynis audit of your own VM with its hardening index (a score out of 100).
- Warnings and suggestions sorted into Fix now / Fix this month / Accept with a reason.
- Two fixes applied and a second audit showing a higher score.
What you need (all free)
- Your own Ubuntu Server VM (Lab 17 plan) or your Kali VM. For installing packages, the VM can be on NAT for a few minutes; do not do this with Metasploitable.
- 40–45 minutes.
Safety and ethics
Lynis audits the machine it runs on, so run it only on systems you own or manage. Do not paste full reports online: they list your system's weak points.
Steps
-
On your Ubuntu VM, update and install Lynis:
sudo apt update sudo apt install -y lynis lynis show version -
Run the audit (
--quickmeans do not pause between sections):sudo lynis audit system --quickWhat you should see: many coloured
[ OK ],[ WARNING ]and[ SUGGESTION ]lines, and at the end a block likeHardening index : 62 [############ ]. -
Write down the hardening index and the numbers of Warnings and Suggestions.
-
Read the findings from the report file, which is easier than scrolling:
sudo grep -E "^warning\[\]|^suggestion\[\]" /var/log/lynis-report.dat | head -n 40What you should see: lines such as
suggestion[]=SSH-7408|Consider hardening SSH configuration|MaxAuthTries (6 --> 3)|...andwarning[]=PKGS-7392|Found one or more vulnerable packages.|.... The code before|is the test ID. -
Check how many packages have updates (often the biggest risk):
apt list --upgradable 2>/dev/null | wc -l -
Rank the findings. Make a table with Test ID, Finding, Risk (High/Medium/Low), Plan. Rule of thumb: missing security updates and remote-login weaknesses (SSH) are High; local hardening such as file permissions or banners is Medium/Low.
-
Fix 1, security updates:
sudo apt upgrade -y sudo apt install -y unattended-upgrades -
Fix 2, SSH hardening with a separate drop-in file:
echo -e "MaxAuthTries 3\nPermitRootLogin no\nX11Forwarding no" | sudo tee /etc/ssh/sshd_config.d/99-lab-hardening.conf sudo sshd -t && sudo systemctl reload sshsshd -ttests the config first, just likenginx -t. -
Run the audit again and compare:
sudo lynis audit system --quick | grep -A1 "Hardening index"What you should see: a higher hardening index than in step 3, and SSH-7408 no longer suggesting MaxAuthTries.
-
Finish your plan: for each remaining High and Medium item write who fixes it and by when. Items you decide not to fix go under Accept with a reason (for example, "no USB on a VM").
Ravindra Bagale's Tip
Don't chase 100 points. A score of 75 with all updates installed and SSH locked down is safer than 85 with old packages. Fix risk, not score. Ani pratyek badal nantar service test kara!
Ravindra Bagale's Tip – मराठी
100 points च्या मागे धावू नका. सगळे updates install केलेले आणि SSH lock केलेला 75 score, जुन्या packages असलेल्या 85 पेक्षा जास्त safe आहे. Risk fix करा, score नाही. आणि प्रत्येक बदलानंतर service test करा!
Ravindra Bagale's Tip – हिंदी
100 points के पीछे मत भागो। सारे updates install और SSH lock वाला 75 score, पुराने packages वाले 85 से ज़्यादा safe है। Risk fix करो, score नहीं। और हर बदलाव के बाद service test करो!
Common mistakes
| Mistake | What happens | Fix |
|---|---|---|
Running Lynis without sudo |
Many tests are skipped and the score is wrong | sudo lynis audit system |
Changing sshd_config and reloading without sshd -t |
A typo can lock you out of a remote server | Always sudo sshd -t before reload |
| Fixing low-risk items first because they are easy | High risks stay open | Updates and remote access first |
| Treating every suggestion as mandatory | Hours wasted on things that do not apply | Write Accept with a reason |
| Pasting the full report in a public forum | You publish your weak points | Share only the item you need help with |
Self-check checklist
0 of 5 done
Try-at-home challenge
Pick one finding you marked Medium and research its test ID with lynis show details <TEST-ID>. Write the fix, apply it, and confirm the suggestion disappears.
Check your answer
Example: lynis show details AUTH-9230 (password hashing rounds). The details show what Lynis checked and why. After applying the fix (for example editing /etc/login.defs), run sudo lynis audit system --quick --tests AUTH-9230 to re-run just that test and confirm it no longer appears as a suggestion.
Samjla ka? Audit, rank, fix the high risks first, and re-run to prove it. Aata pudhe jaauya: Chapter 21 looks at web application testing tools.