Cyber Security · मराठी आवृत्ती
Basic shell scripting
या page मध्ये
आपल्याला येणाऱ्या commands एका file मध्ये योग्य क्रमाने ठेवणं म्हणजे script. Variables, conditions, loops आणि functions जोडले की छोटी automation तयार होते.
#!/bin/bash
# file: sysinfo.sh - print a quick health report
set -uo pipefail # stop on undefined variables and pipe failures
NAME=$(hostname)
echo "Health report for $NAME at $(date)"
echo "---------------------------------"
echo "Uptime : $(uptime -p)"
echo "Disk / : $(df -h / | awk 'NR==2 {print $5 " used"}')"
echo "Memory : $(free -m | awk '/Mem/ {printf "%d/%d MB used", $3, $2}')"
# if-else
if systemctl is-active --quiet nginx; then
echo "Nginx : running"
else
echo "Nginx : NOT running"
fi
# loop
for svc in sshd crond; do
echo "$svc -> $(systemctl is-active $svc 2>/dev/null)"
done
# function with argument
check_port() {
if ss -tln | grep -q ":$1 "; then echo "Port $1 open"; else echo "Port $1 closed"; fi
}
check_port 22
check_port 80
ही script hostname/date, uptime, disk आणि memory usage दाखवते. if Nginx status तपासतो; for sshd/crond services वर loop करतो; check_port argument घेऊन listening port शोधतो. Service names distribution नुसार बदलतात. Port listening आहे म्हणजे internet मधून reachable आहे असं नाही.
Source comment मधली दुरुस्ती: set -uo pipefail मध्ये -u unset variables वापरण्यावर error आणतो; pipefail pipeline चा status ठरवतो. या line मध्ये -e नाही, त्यामुळे प्रत्येक failed command/pipeline वर script आपोआप exit होईल अशी हमी नाही. ही beginner health-report script आहे, production monitoring चा पूर्ण पर्याय नाही.
nano sysinfo.sh # paste the script, save with Ctrl+O, exit with Ctrl+X
chmod +x sysinfo.sh
./sysinfo.sh
| Concept | Syntax |
|---|---|
| Variable | NAME="Ruhi", use $NAME or ${NAME} (no spaces around =) |
| Command चा output | TODAY=$(date +%F) |
| Arguments | $1, $2, all: $@, count: $# |
| मागच्या command चा exit status | $? (0 = success) |
| Regular file आहे का? | if [ -f /etc/nginx/nginx.conf ]; then ... fi |
| Directory आहे का? | [ -d /var/www ] |
| Numbers compare | [ "$a" -gt 10 ] (-eq -ne -lt -le -ge) |
| Strings compare | [ "$a" = "yes" ] |
| Input वाचणे | read -p "Enter name: " NAME |
Variable assignment मध्ये NAME="Ruhi" असे spaces नसतात. Command output साठी $(...). Arguments $1, $2; सर्व arguments $@, count $#; मागच्या command चा exit status $?. Zero म्हणजे साधारण success. File test -f, directory -d, numbers साठी -eq/-ne/-lt/-le/-gt/-ge आणि string compare साठी =. Variables expand करताना साधारण double quotes वापरा.
Lab
sshwatch.sh तयार करा. तुमच्या server च्या आजच्या failed SSH logins चा count आणि top तीन source IPs दाखवा. Log format पाहून journalctl किंवा auth.log, grep, awk, sort आणि uniq -c वापरा. Script executable करून output मूळ logs शी तपासा. Date filter आणि field positions तुमच्या actual log format ला जुळवा.
Part 2 recap
- Search: grep आणि find; text processing: awk आणि sed.
- Pipe commands जोडतो. > overwrite, >> append; root-owned file साठी योग्य sudo tee.
- Tar/gzip/zip archives; backups web root च्या बाहेर.
- Service start/reload आणि boot enable वेगळे. Journalctl logs साठी.
- Network: ip, ss, curl, dig, nc. Storage: df, du, lsblk.
- Cron scheduled jobs; SSH/SCP/rsync remote work; scripts छोटी automation.
पुढे web servers शिकताना हे Linux skills प्रत्यक्ष वापरू.