Security
fail2ban status
fail2ban-client status
fail2ban-client status sshd
Scan open ports with nmap
sudo nmap -p- IP # all ports
sudo nmap -A -T4 IP # OS and service detection, faster timing
Check whether a server has been compromised
who
iftop
last
chkrootkit
More: How to Detect if Your Linux System has been Hacked, How To Tell If Your Linux Server Has Been Compromised.
Change a configuration file from a script
For example, change the SSH port:
sed -i 's/#Port 22/Port 123/' /etc/ssh/sshd_config
Convert an SSH2 public key to OpenSSH format
If the public key starts with:
---- BEGIN SSH2 PUBLIC KEY ----
convert it and add it to authorized keys:
ssh-keygen -i -f klucz.pub >> ~/.ssh/authorized_keys
SELinux
- Show the reasons for denials:
audit2allow -w -a - Change the configuration with
setsebool; generating a policy module withaudit2allow -a -M nameis not recommended.
Reference: audit2allow
Let’s Encrypt certificates (certbot)
Install a certificate for nginx (Fedora):
sudo dnf install certbot-nginx
sudo certbot --nginx
Manage certificates:
certbot renew # renew
certbot certificates # list
certbot delete --cert-name domain-name # remove
Scheduled jobs
systemd timers
systemctl list-timers
systemctl enable --now ibm_backend.timer
For user-level timers add --user and put the units into ~/.config/systemd/user/.
E-mail from cron
MAILTO sends any output of the job to the given address:
MAILTO=email@example.com
0 */2 * * * /bin/backup.sh
To get e-mails only when something is written to stderr, discard standard output:
MAILTO=email@example.com
0 */2 * * * /bin/backup.sh > /dev/null
Source: serverfault.com
To check how e-mails sent by your application score in spam filters, use mail-tester.com.
Disks and backups
Force a verbose disk check
sudo fsck.ext4 -fv /dev/sda1
Re-mount a USB drive that failed to mount after reboot
sudo apt-get install udisks2
blkid /dev/sdb1
Script:
#!/bin/bash
MOUNT_POINT="/mnt/usb/adata-backup"
if ! mountpoint -q "$MOUNT_POINT"; then
echo "Mounting drive"
mount /dev/sdb1 "$MOUNT_POINT"
fi
Add it to crontab to run every hour.
Download backups from a remote host
rsync -a --progress --delete -e 'ssh -p 223' user@host:/dir1 local_dir
Add -v for verbose output.
Show progress of a long operation with pv
pv monitors data flowing through a pipe:
-pprogress bar-telapsed time-rtransfer rate-eestimated time to completion
Example — decompress a backup and watch the progress:
pv -ptre /home/backup/backup.dump.gz | gunzip > /tmp/backup_dump
Share USB drives from a Raspberry Pi over NFS
# edit /etc/exports on the Raspberry Pi
systemctl restart nfs-server.service
# on the client
sudo mount -t nfs <rpi-ip>:/mnt/usb1 rpi_usb1
More: Host your own cloud with Raspberry Pi NAS
Network
Monitor network traffic
netstat -tp
iftop
tcptrack -i eth0
ss -tn -o
watch -n 1 "ss -tn -o"
More: Commands to monitor network bandwidth on Linux
Check internet speed from the command line
curl -s https://raw.githubusercontent.com/sivel/speedtest-cli/master/speedtest.py | python -
Project: speedtest-cli
Run a WireGuard client
cp wg0.conf /etc/wireguard
wg-quick up wg0
System configuration
Time zone
timedatectl list-timezones | grep Wars
sudo timedatectl set-timezone Europe/Warsaw
timedatectl status
Locale (Debian, e.g. NextCloudPi)
vim /etc/locale.gen
locale-gen
Reference: Debian Wiki: Locale
