search
  • Sign In
  • Sign Up
Password reset successful

Follow the proiects vou are interested in andi aet the latestnews about them taster

Home Operation and Maintenance Linux Operation and Maintenance Improve Linux server security using command line tools

Improve Linux server security using command line tools

Sep 09, 2023 pm 06:27 PM
linux Safety Command Line

Improve Linux server security using command line tools

Use command line tools to improve Linux server security

In the current Internet era, server security is very important for any enterprise or individual user. As a common server operating system, Linux can improve its security by using command line tools. This article will introduce some common command line tools and give corresponding code examples to help you better protect your Linux server.

  1. SSH (Secure Shell)

SSH is a protocol for encrypted communication over the network. It can provide secure remote login and execution in unsecured networks. The function of the command. With SSH, we avoid transmitting passwords in clear text while also using public key encryption for authentication.

First, we need to ensure that the SSH service is installed and turned on. Execute the following command in the terminal:

sudo apt-get install openssh-server

Next, we need to edit the SSH configuration file /etc/ssh/sshd_config, modify the default port number, prohibit remote login for the root user, etc. You can use the following command:

sudo nano /etc/ssh/sshd_config

You can find configuration items similar to the following in the file:

#Port 22
#PermitRootLogin prohibit-password

Remove the comment symbols and modify the required settings. After modifications are completed, save and exit.

Finally, restart the SSH service to make the configuration take effect:

sudo service ssh restart
  1. Fail2Ban

Fail2Ban is an open source software used to prevent brute force attacks. It can detect multiple failed login attempts and automatically ban the attacker's IP address. Here we give an example for monitoring SSH login failures.

First, we need to install Fail2Ban. Execute the following command in the terminal:

sudo apt-get install fail2ban

Then, we need to create a custom configuration file /etc/fail2ban/jail.local to monitor SSH login failures. You can execute the following command:

sudo nano /etc/fail2ban/jail.local

Add the following content to the file:

[sshd]
enabled = true
port = ssh
logpath = %(sshd_log)s
findtime = 600
bantime = 3600
maxretry = 3

Save and exit the configuration file.

Finally, restart the Fail2Ban service to make the configuration take effect:

sudo service fail2ban restart
  1. iptables

iptables is a firewall tool in the Linux kernel that can filter and forwarding network packets to control network access rules. Below are some common iptables command examples.

Close all inbound connections:

sudo iptables -P INPUT DROP

Allow inbound connections to a specific IP address:

sudo iptables -A INPUT -s <IP地址> -j ACCEPT

Allow inbound connections to a certain port:

sudo iptables -A INPUT -p tcp --dport <端口号> -j ACCEPT

Block inbound connections from specific IP addresses:

sudo iptables -A INPUT -s <IP地址> -j DROP

Save iptables configuration:

sudo service iptables save

The above are several common command line tools through which we can effectively improve the security of Linux servers. . However, please note that before using these tools, you must understand the relevant commands and their usage to avoid misoperations that may cause the server to become unavailable. More importantly, keep the system and software updated at all times, patch vulnerabilities in a timely manner, and strengthen the server's defense capabilities.

I hope this article will be helpful to you, and I wish your Linux server is safe and worry-free!

The above is the detailed content of Improve Linux server security using command line tools. For more information, please follow other related articles on the PHP Chinese website!

Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undress AI Tool

Undress AI Tool

Undress images for free

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

ArtGPT

ArtGPT

AI image generator for creative art from text prompts.

Stock Market GPT

Stock Market GPT

AI powered investment research for smarter decisions

Popular tool

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)

How to install Redis cluster on Linux_Linux distributed cache deployment solution [Advanced] How to install Redis cluster on Linux_Linux distributed cache deployment solution [Advanced] Feb 08, 2026 pm 07:39 PM

The Redis6 cluster must be created with redis-cli--cluster. It requires a minimum of 3 masters and 3 slaves, a total of 6 nodes. The client port and the corresponding cluster bus port (10000) must be opened. Correct configuration but blocked ports is a common cause of failure.

How to import SQL files in mysql_mysql SQL file import method How to import SQL files in mysql_mysql SQL file import method Feb 09, 2026 pm 05:24 PM

The most common and reliable way to import SQL files into MySQL is the command line tool mysql, which supports cross-platform, high efficiency and stability, and is suitable for files of all sizes. It can also be executed in the client through the source command, or using graphical tools such as phpMyAdmin and MySQL Workbench.

How to diagnose mysql query performance bottleneck_mysql performance analysis method How to diagnose mysql query performance bottleneck_mysql performance analysis method Feb 08, 2026 am 09:45 AM

Slow query optimization requires four layers of troubleshooting: "Log → Execution Plan → System Indicators → Configure Hardware": first open slow_query_log to capture queries that exceed 1 second; then use EXPLAIN to analyze type, key, rows and Extra; then check sar, buffer pool hit rate, lock wait and number of connections; finally examine innodb_flush_method, redolog size, large field storage and network architecture.

How to check system vulnerabilities in Linux_Linux installation and use of security scanning tools [Plan] How to check system vulnerabilities in Linux_Linux installation and use of security scanning tools [Plan] Feb 08, 2026 pm 08:22 PM

Linux systems need to use third-party tools for security scanning; lynis is suitable for lightweight local auditing, openvas must be deployed with Docker, nmap and nessus cannot be automatically connected, and the effectiveness of scanning depends on credentials, settings and feed updates.

How to check the MAC address of the network card in Linux_Linux obtains the physical network card information [Notes] How to check the MAC address of the network card in Linux_Linux obtains the physical network card information [Notes] Feb 08, 2026 pm 08:25 PM

The most reliable way is to use the iplinkshow command, because it is compatible with old and new kernels, has clear output, and does not confuse virtual interfaces; the MAC address is located after the link/ether line and can be accurately extracted with grep.

How to install the GCC compiler on Linux_Essential environment for Linux source code compilation [Tutorial] How to install the GCC compiler on Linux_Essential environment for Linux source code compilation [Tutorial] Feb 08, 2026 pm 08:28 PM

Using sudoaptinstallbuild-essential is the fastest under Ubuntu/Debian. It automatically installs gcc, g, make, libc6-dev, etc.; only installing gcc will report an error that stdio.h does not exist due to a missing header file.

How to check the kernel version in Linux_Linux query system kernel uname command [Basic] How to check the kernel version in Linux_Linux query system kernel uname command [Basic] Feb 08, 2026 pm 07:48 PM

uname-r is the most accurate and quick way to obtain the current kernel version number. It only outputs the release field such as 6.1.0-22-amd64, without redundant information, which is convenient for script parsing; other commands such as uname-v, uname-a or /proc/version have their own uses but are not specifically used for version extraction.

Ultimate solution to ZAP installation failure: Why you must install JDK and not just JRE Ultimate solution to ZAP installation failure: Why you must install JDK and not just JRE Feb 08, 2026 am 11:15 AM

When ZAP (ZedAttackProxy) is installed, it prompts "Java 64-bit file not found." The root cause is not that Java is not installed, but that the JRE that only contains the running environment is mistakenly installed; ZAP actually relies on JDK11 (such as JDK21) because it requires the use of development components such as compilers and debugging tools.

Related articles