CRITICAL INFRA
Loading critical CVEs…
ALL EXPLOITED
Loading…

Linux-Server-Hardening 2026: kompletter Leitfaden

1. SSH-Lockdown

2. iptables / nftables Firewall

DROP-Default auf INPUT, GeoIP-Filterung, Rate-Limiting pro IP.

3. CrowdSec

Verteilte Threat-Intelligence-Community.

4. Automatische Sicherheitsupdates

unattended-upgrades konfiguriert nur für Sicherheit.

5. CIS Benchmark + Lynis Audit

Lynis monatlich ausführen. Hardening-Score > 80 anstreben.

Basis-Befehle

Einige konkrete Befehle, um sofort mit dem Hardening zu beginnen:

# SSH lockdown + fail2ban (comenzi reale)
sudo sed -i 's/^#\?PermitRootLogin.*/PermitRootLogin no/' /etc/ssh/sshd_config
sudo sed -i 's/^#\?PasswordAuthentication.*/PasswordAuthentication no/' /etc/ssh/sshd_config
sudo systemctl reload ssh
sudo apt -y install fail2ban unattended-upgrades
sudo systemctl enable --now fail2ban
sudo lynis audit system      # scor de hardening

Kernel-Hardening (sysctl)

Einige sysctl-Einstellungen, die die Angriffsflaeche auf Netz- und Kernel-Ebene reduzieren:

cat >/etc/sysctl.d/99-hardening.conf <<'EOF'
net.ipv4.conf.all.rp_filter=1
net.ipv4.tcp_syncookies=1
net.ipv4.conf.all.accept_redirects=0
net.ipv4.conf.all.accept_source_route=0
kernel.randomize_va_space=2
kernel.kptr_restrict=2
fs.protected_hardlinks=1
fs.protected_symlinks=1
EOF
sysctl --system

Dateiintegritaet (AIDE) + Auditing (auditd)

Sie initialisieren die AIDE-Datenbank und setzen auditd-Regeln fuer kritische Dateien:

apt -y install aide auditd
aideinit && mv /var/lib/aide/aide.db.new /var/lib/aide/aide.db
aide --check          # ruleaza zilnic din cron

# audit pe fisiere sensibile
auditctl -w /etc/passwd -p wa -k identity
auditctl -w /etc/ssh/sshd_config -p wa -k sshd
ausearch -k identity | tail

AppArmor: Profil erzwingen

Sie isolieren einen Dienst mit AppArmor im Enforce-Modus:

apt -y install apparmor-utils
aa-status                       # ce profile sunt incarcate
aa-enforce /etc/apparmor.d/usr.sbin.nginx
aa-logprof                      # ajustezi din denials reale
journalctl -k | grep apparmor='DENIED'

SSH-2FA + automatische Updates

Sie fuegen SSH einen TOTP-Code hinzu und aktivieren automatische Sicherheitsupdates:

apt -y install libpam-google-authenticator unattended-upgrades
google-authenticator            # ca user: scanezi QR in app
# /etc/pam.d/sshd:  auth required pam_google_authenticator.so
# /etc/ssh/sshd_config:  AuthenticationMethods publickey,keyboard-interactive
dpkg-reconfigure -plow unattended-upgrades
systemctl reload ssh