Ravindra Bagale · Cyber Securityसर्व coursesया course चे lessonsशोधाEnglish

Cyber Security · मराठी आवृत्ती

Linux मधल्या folders ची रचना

रवींद्र बागले यांच्या course वर आधारित · सहज मराठीत explanation

या page मध्ये

Windows मध्ये C: drive दिसतो. Linux मध्ये सर्व paths / या root directory पासून सुरू होतात. कोणत्या folder मध्ये काय असतं हे समजलं की troubleshooting आणि investigation दोन्ही सोपं होतं.

/                  root of everything
├── bin, sbin      essential commands (now links to /usr/bin, /usr/sbin)
├── boot           kernel and boot loader
├── dev            device files (/dev/nvme0n1, /dev/xvda)
├── etc            configuration files (nginx, ssh, fstab, passwd)
├── home           users' home folders (/home/ec2-user, /home/ubuntu)
├── root           home of the root user
├── opt            optional / third-party software
├── tmp            temporary files (cleared on reboot)
├── usr            programs, libraries, docs (/usr/share/nginx/html)
├── var            variable data: logs (/var/log), web (/var/www), databases (/var/lib/mysql)
├── proc, sys      virtual files with kernel & hardware info
└── mnt, media     mount points for extra disks

Folders समजून घेऊ

“Everything is a file” म्हणजे काय?

Linux अनेक resources file-like interface मधून उपलब्ध करतो: disk /dev/nvme1n1, process /proc/1234, hardware माहिती वगैरे. Paths case-sensitive असतात: Index.html आणि index.html या वेगळ्या files आहेत.

Security मध्ये महत्त्वाचा path काय माहिती असते?
/etc/passwd, /etc/shadow User accounts आणि password hashes
/​etc/​ssh/​sshd_​config SSH settings—root/password login
/var/log/ Evidence: auth, web आणि system logs
/tmp, /dev/shm Shared writable paths; संशयास्पद tools तपासतात
/home/*/.ssh/ Private keys आणि authorized_keys
/var/www/ Web app code/config; secrets च्या permissions तपासा

Security मध्ये हा map कसा उपयोगी?

/etc/passwd मध्ये accounts, /etc/shadow मध्ये password hashes, /etc/ssh/sshd_config मध्ये SSH settings, /var/log मध्ये evidence, /home/*/.ssh मध्ये keys आणि authorized_keys असू शकतात. /tmp व /dev/shm सारख्या shared writable paths मध्ये संशयास्पद files तपासतात. /var/www मध्ये application code/config असू शकतो. Paths ची माहिती असणं म्हणजे secrets share करायचे असा अर्थ नाही; permissions जपा.

Privilege escalation तपासताना चुकीच्या permissions किंवा exposed keys शोधल्या जातात. Incident response मध्ये याच ठिकाणी evidence तपासतात.

Practice

ls /, ls /etc | head, ls -la ~ आणि sudo ls /var/log चालवा. प्रत्येक folder कशासाठी आहे ते एका ओळीत लिहा.