Author: emmanuelygr
The Linux Security Hardening Toolkit is an open-source, beginner-friendly bash script designed to audit the security posture of a Linux system. Rather than automatically changing system configurations—which can inadvertently break applications or lock users out—this script safely analyzes the system and provides clear, actionable recommendations.
As I delved into Linux administration and cybersecurity, I realized that many hardening scripts available online are overly aggressive. They apply blanket changes without explaining the "why," often leading to broken systems for beginners. I built this toolkit as an educational resource: it teaches fundamental security concepts by safely auditing your system and explaining how to fix misconfigurations manually.
Through building and using this project, the core objectives are to understand:
- How to automate system administration tasks using Bash.
- The principle of least privilege in a practical environment.
- How to interpret and modify Linux file permissions.
- The role of firewalls (like UFW) in defending a network boundary.
- Secure shell (SSH) configuration best practices to prevent unauthorized access.
- Non-Destructive Auditing: Safely checks system settings without modifying any files.
- Privilege Assessment: Detects if operations are dangerously running as root.
- Permission Validation: Inspects sensitive files (like
/etc/shadow) for overly permissive access rights. - SSH Configuration Check: Verifies if password authentication is disabled in favor of safer key-based auth.
- Firewall Status Check: Ensures the UFW firewall is active and protecting network interfaces.
- Update Reminders: Checks for package managers and reminds administrators to patch vulnerabilities.
- Bash Scripting: Core logic and system command execution.
- Linux Core Utilities:
grep,stat,chmod,command. - System Administration Tools:
ufw,sshd, package managers (apt,dnf,pacman).
Linux systems isolate access based on users and groups. Running standard tasks as root is dangerous. Using a standard user with sudo privileges ensures actions are intentional and logged.
Users and programs should only have the bare minimum permissions necessary to function. The toolkit audits this by checking if sensitive files are accessible to unauthorized users.
Linux permissions dictate who can read, write, or execute a file. A file like /etc/shadow (containing password hashes) should ideally be set to 640 or 000 to prevent privilege escalation or password cracking.
SSH is the standard protocol for managing Linux servers remotely. Disabling password authentication and requiring cryptographic keys prevents brute-force credential stuffing attacks.
A firewall acts as a digital bouncer. By checking ufw status, the toolkit emphasizes the importance of dropping unrequested incoming network traffic to minimize attack surfaces.
- The script initializes and runs sequential bash functions.
- It interacts with the local file system (using
stat,grep) to read configurations. - It conditionally evaluates the output against known secure baselines.
- It echoes colored/formatted output to the terminal, detailing a "Pass"
[+], a "Warning"[!], or an "Error"[-].
linux-security-hardening/
├── hardening_check.sh # The main auditing bash script
├── .gitignore # Git ignore file
├── LICENSE # MIT License
└── README.md # Project documentation
- Clone the repository:
git clone https://github.com/emmanuelygr/linux-security-hardening.git
- Navigate to the project directory:
cd linux-security-hardening - Make the script executable:
chmod +x hardening_check.sh
Run the script from your terminal:
./hardening_check.shNote: The script does not require sudo to run, but some checks (like verifying UFW status) might require sudo to provide accurate results.
Example Output:
========================================
Linux Security Hardening Audit
========================================
[*] 1. Checking current user...
[+] You are running as a standard user. (Good practice)
[*] 2. Checking sensitive file permissions...
[!] WARNING: /etc/shadow permissions might be too open (644).
Recommendation: Change permissions to 640 or 000 using 'sudo chmod 640 /etc/shadow'.
To safely experiment with system hardening, it is highly recommended to use a Virtual Machine (VM):
- Hypervisors: VirtualBox, VMware Workstation Player, or QEMU.
- Operating System: Ubuntu Server or Debian (for maximum compatibility with UFW checks).
- Snapshot: Take a snapshot of your VM before making any configuration changes recommended by the script.
- DO NOT run hardening scripts blindly on production servers.
- Changing SSH configurations can lock you out of a remote server. Always keep an active SSH session open while modifying
sshd_config. - Be cautious when enabling firewalls over remote connections; ensure your SSH port (usually 22) is explicitly allowed before enabling UFW.
This toolkit is designed for educational purposes and authorized auditing only.
- Only run this script on systems you own or have explicit permission to audit.
- Unauhorized auditing of corporate or public infrastructure may violate computer fraud laws.
- The script currently focuses on Debian/Ubuntu-based environments (especially regarding UFW).
- It performs a surface-level audit and does not replace professional vulnerability scanning tools (like OpenSCAP or Nessus).
- It does not automatically remediate the found issues.
Q: Why does the firewall check say UFW is not installed?
A: If you are on RHEL/CentOS/Fedora, you likely use firewalld. This script currently looks specifically for ufw.
Q: The script says I shouldn't run as root, but I need root to check UFW?
A: Run the script as a standard user. When the script executes the sudo ufw status command internally, it will prompt you for your user password.
Throughout this project, I improved my bash scripting skills—specifically handling exit codes, parsing file configurations with grep, and checking octal permissions using stat. I also deepened my understanding of how Linux distributes privileges and why a "defense in depth" strategy (passwords, firewalls, permissions) is crucial.
- Multi-OS Support: Add checks for
firewalld(RedHat/CentOS) andiptables. - Automated Remediation (Opt-In): Add a flag (e.g.,
./hardening_check.sh --fix) that asks for user confirmation before automatically applying the recommended fixes. - Log Exporting: Add a feature to output the audit results into a timestamped
.txtor.csvfile. - Additional Checks: Implement checks for disabled root login in SSH (
PermitRootLogin no) and empty passwords. - Fail2Ban Integration: Check if intrusion prevention software like
fail2banis installed and running. - Cron Job Integration: Allow the script to run weekly via cron and email the administrator the audit report.