Linux Security Tips
Before we deep dive into all the great security measures you can take, here are some tips regarding security.
Security implementation on multiple levels is, in general, a good idea. This way, a hacker requires different approaches to gain access, and this costs them time. Because of this time, and hopefully also because of logging and monitoring, you have a greater chance of detecting unauthorized access.
For files and directories, DAC is still a very good foundation. Make the permissions on files and directories as strict as possible. Check the owner and group ownership and use access control lists (ACLs) instead of permissions for unauthorized users. Try to avoid using the suid/sgid
bit as much as possible. Are there users who need to change their own password? No? Then remove that bit from the passwd
command.
Use partitioning, especially for directories such as /tmp
, /var
, /var/tmp
, and /home
, and mount them with the noexec
, nodev
, and nosuid
flags: