Skip to content

Latest commit

 

History

19 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 

Repository files navigation

██████╗  ██████╗ ██████╗ ███╗   ██╗    ██████╗ ██████╗ ███████╗    ██████╗  ██████╗  ██████╗ ████████╗
██╔══██╗██╔═══██╗██╔══██╗████╗  ██║    ╚════██╗██╔══██╗██╔════╝    ██╔══██╗██╔═══██╗██╔═══██╗╚══██╔══╝
██████╔╝██║   ██║██████╔╝██╔██╗ ██║     █████╔╝██████╔╝█████╗      ██████╔╝██║   ██║██║   ██║   ██║   
██╔══██╗██║   ██║██╔══██╗██║╚██╗██║    ██╔═══╝ ██╔══██╗██╔══╝      ██╔══██╗██║   ██║██║   ██║   ██║   
██████╔╝╚██████╔╝██║  ██║██║ ╚████║    ███████╗██████╔╝███████╗    ██║  ██║╚██████╔╝╚██████╔╝   ██║   
╚═════╝  ╚═════╝ ╚═╝  ╚═╝╚═╝  ╚═══╝    ╚══════╝╚═════╝ ╚══════╝    ╚═╝  ╚═╝ ╚═════╝  ╚═════╝    ╚═╝

Born 2 be Root

Born 2be Root? actually am not.

anyway what is that?

so basically its:

a project aims to introduce you to the wonderful world of virtualization. you will create your first machine in virtualbox (or utm if you can’t use virtualbox) using specific instructions. then, at the end of this project, you will be able to set up your own operating system while implementing strict rules.

sound cool, huh?!

Just a quick note, I am not a native English speaker, sooo, you know what's coming.

Anyway, if u doesn't know what’s that mean, am also, doesn't know;

but let me tell you that we'll be apple to configure our machine and do whatever we want with it,

you see? its cool now?

but what is not, is that phrase “implementing strict rules”,

sound like we’ll suffering with that, anyway. so before anything lets understand what the purpose of this project:

we asked to create a machine in virtualbox using specific instructions

so basically as its say, its just an machine, nothing hard, lets go.

for who are new to that like me, the virtualization concept is about to make a new machines inside the same machine, but guess what? each one of those machines think its a real machine,

so even if u hosted them, they believe that they are independent real machines, anyway we will see about that,

now we now what we wanna do so lets jump.

as they say, its our world now lets break some stuff

screenshot

first lets look here:

“this project consists of setting up your first server by following specific rules. since it is a matter of setting up a server, you will install the minimum of services. for this reason, a graphical interface is of no use here. it is therefore forbidden to install x.org or any other equivalent graphics server.”

so first what is a server, u can look here → client-server ←, its basically like a machine configured to do some specific job, or to provide some information so its siting there waiting for a call or request to give it or respond to it with the information that its has, think of it like this:

screenshot

just read about it quick and u good.

yeah and also they say we’ll go with the minimum soo we won’t need the graphical system, of course you have idea what is graphical interface. → gui ← its like this collection of layers and content and buttons those let us interact with the computer without the command line, and you can check that also → x window system ←, something like that.

ok now lets choice the operating system we will work with, and to the one is new to that → operating system
the os is like the middleman or the interface between our programs and the hardware, actually its not a surprise to us, since if we have the direct access to the hardware components, its will not resist even a week, anyway so the os is who manage the hardware that will be used from our programs,

so now we can choose between rocky or Debian, soo of course we’ll go with Debian, and since you must know some information about the os you will use, so lets resume that with a historical story,

hmm, lets say Debian is an operating system (os) that is based on the Linux kernel, along with a collection of software components, tools, and package management systems to create a complete, functional os, such easy as that, and after that some people see that the os is still need some stuff so they take that Debian one and add to it some tools, and wolla they create another os called ubuntu which is based on Debian.

anywayyyyyy, enough theory, lets jump and open our oracle vm virtualbox, just one thing before we start, yeah really this will be last one, we say that the virtualization is creating a machine inside another machine, if you think about that machine we’ll create, where it must get its resource? think about it, and yes its will got them from that machine hosting it, which mean our current machine will share the resource with the new one that we’ll create, ok and we already say that the os is managing the hardware that we interact with, which mean our current os will take the resource from the actual hardware and pass it to that new machine we trying to create it, so our os will play as a middle man between the original machine and the virtual machine(that machine we’ll create), and what’s happen now is called hosted virtualization (hosted hypervisor) , so basically in the virtualization there is two type, the first is that one we just discuss, its simply when we use that hypervisor which is the software will create and run this virtual machine on it, what happen here is that the software run on top of the host machine which mean that its a normal software who got its resource from our original os , so its not interact directly with the actual hardware,

and since we say this last phrase that mean we have another type that actually receive its resource from the hardware component directly, its called bare metal virtualization its basically a hypervisor runs directly on the physical hardware without a host OS, commonly used in enterprise and data center environments, since we won’t use it here so no need to dig in it.

good now we now what we using and that is better,

Process

you can use any hosed software they do the same function, i’ll go with oracle vm virtualbox , open it and we got:

screenshot as simple as that, lets hit this new at the top: screenshot name is for the virtual machine name, you can name it what you want.

the second field is where that virtual machine configuration will live, you can use any place that has some space.

about the iso you put there the iso of your os or just leave it for now will fill it later,

and above just choose Linux with the version of that os you wanna use.

screenshot now as you see we'll choose how much resource to give that server, and since we'll going with a minimal server without any graphical interface then, I'll just give it kinda of 2gb as ram and like 2 cpu cores

screenshot here you select how much space to give to the virtual machine, but be aware from this check box pre-allocated space , at the default behavior your virtual machine won't reserve the actual size you choose until its actually need it. instead if you check that box, the reserved space will immediately be allocated for you virtual machine even if you don't need it yet.

screenshot and as you see now you can just click finish, and you will got this:

screenshot now we need something which is our iso file, its the os that we'll use, since we'll going with Debian, so lets got one:

screenshot so just go to the website of debain and download the iso, its similiar to above ^^ ok then lets go back to our page, screenshot hit this yellow setting at the top, then at that pop up window go storage then click that little disk, then another little disk icon at the right, then just choose your iso from your system files and just hit ok. then you are ready to go, click that start arrow at the top, and here we go you got the installation start. screenshot here hit the second one since we going with minimal simple installation so no need for graphical even in the installer screenshot screenshot screenshot here just some simple things like your language, country, keyboard.

screenshot here we must set a hostname, hostname its just a human-readable name that we assign to our machine so its has an identifier in the network instead of getting called by its ip address, so its just like a nickname or something, you can google it if you interest, about us, the subject specify that we must use our login ending with 42 as a hostname so just use your login42, screenshot a domain name is a unique, easy-to-remember address used to access websites, and just left is empty, no need to do anything here, screenshot screenshot so here is the root user, what is that, its just a user but guess what, its has unrestricted access to all system files, commands, and settings, so its actually can miss with anything, and that is the root password and you know that its a something important so use a password that you can remember. screenshot here is a user full name, just put anything you want. screenshot screenshot screenshot here that is just a normal user, give it your login as the subject request, and password, just do it now, you will play with that later, screenshot here we have some work that how that partitions must be configured, so basically the concept is just we separate the hold disk space to several parts and each part, must handle a specific task, something like that, here you can go with some of those guide and just modify some stuff, but where is the fun here? lets go manual: screenshot that you see its like your harddisk lets choose it since we trying to organize it, screenshot confirm that we'll going to create a table screenshot here is our configuration settings, in the subject if you plan to go with the bonus as we'll do so we must configure the partitions as the bonus require, lets see what the difference: screenshot screenshot As we see here its not that much difference, so lets try to implement that bonus one, screenshot So lets select our disk and select that create a new partition screenshot Here the size of that partition, as its look above the first one was 500MB, so lets just try give it something like that. screenshot Here something important, its the type of that partition, so what's difference between primary and logical, So after google it, i got that, basically all that is coming from that MBR (Master Boot Record) scheme, its an old scheme that has an limitation, what that mean, so in this old disk partitions scheme an primary partition its that normal bootable section that used normal and important files, but guess what, we are limited to have 4 parts, just 4 partitions per disk, so that a problem, and need to be solved, which is some people got the idea of if we want more than 4 parts lets use 3 parts as normal, and the last one lets make it an extended one, which is a type that make the partition is extended to another logical partitions so basically the partition 4 will hold another several parts and those who called logical partitions, about those logical ones, you can have a lot, you can google how much exactly if you want, but its depend on some other stuff, anyway, let continue.

So our partition will be primary screenshot Here lets just make it at the beginning, its just like when that part will be created in the disk.

screenshot Here our configuration for that part. in the first option

screenshot This is how you want the structure of that partition file system to be, there is a lot of type, they basically how that partition in the disk will be structured and its also provide some features and the most important is that journaling, its like you know when you was copying something or moving and an error happen or the operation stop immediately at the middle, here the journaling protect the data corruption so next time its can continue with your data without issues, so basically how its work something like its log or register the operation, kinda like : The file system maintains a special area (journal or log) where it records metadata changes (like directory updates, file creation, deletion) and sometimes actual data. Before making changes to files or directories, the system writes a "log entry" describing the change into the journal. Once the journal entry is safely written, the actual data or metadata update occurs on the disk.

something like that, you can google it of course, if you want, but for that project you not require to dive deep on it,

so lets just use that Ext4 its good for our case, Screenshot Here at the mount point make sure to select is for boot so we use that partition for bootable files, and turn on the bootable flag option, its basically we use that part for bootable files and tag it so the machine now that is the part who has the files, and what that bootable files mean, its basically when our machine turn on, the first thing its run is that bios so what that bios do is looking for a program called GRUD and also the bootloader and kernel files needed to actually run our operation system so the files run the hole system and guess what its look for that partition with bootable files, its find those files, and also find the GRUD program, what its do now its waking up that GRUD and pass those file to it, and say "hey go ahead and continue running the system bro", then he load those files and the kernel and pass the control to it to complete the run, something like that.

Anyway our partition is good now, go ahead an click "done...", if you interest of any other option for those you see, you know what to do, but for our case they not that matter. Screenshot And here is our table now, so lets complete the parts, but as you see in the partitions structure above, you see that the sda2 partition has a 1k, and its mount nothing so i look for it several times, but i got several answers and the most logical one i got is that : "It could be just a placeholder or alignment gap to ensure proper partition alignment for performance reasons" and so for that we wont create it as also we cant create a part with size 1k so lets hope its got automatically created after setup, yeah and its will do... I hope.

Screenshot

So now lets go and create the sda5 partition which will be an encrypted and logical partition, To do that just use the disk with free space

Screenshot;

So for this one lets just give it the max space left with us. Screenshot

and since we'll use this part to hold another logical partitions so select logical Screenshot

and so about the mount point, as you see this partition wont mount point to anything since its just like a container, and about the mount points its like an entry point or something, its like a pointer to another disk partition so we just like linking the hole partitions with each other, anyway for this partition select: Screenshot Screenshot Screenshot

Now here is how our table look like.

Screenshot

And now if you like here again even if you going with the mandatory structure, you see that the sda5 has another container with type crypt Which mean that partition is encrypted, and as simple is that, its just mean that we encrypting it with a password and cannot access it without bypass it,

Screenshot

And to do that here is the option for that,

Screenshot

Here they ask you to write changes hit yes, its just like we save what we already do.

Screenshot

Select first one.

Screenshot

Here select the partition you wanna encrypt, in our case, its the sda5, navigate to it with arrows and select it with space, and hit enter.

Screenshot

Here no need to miss with any of those options, since the default its good for our case now.

Screenshot

So just select "done..."

Screenshot

Hit this "Yes"

Screenshot

we done here so hit finish

Screenshot

Here they say something about erase the data on our partition yeah yeah lets hit yes.

Screenshot

Here its look like they cleaning our partition, but since we doesn't have any data on it, you can hit cancel if you want, or just wait, you can go with both. for me I'll wait, i don't know why, but here we are.

Screenshot

now they ask for the password of that encrypted partition, so enter one and remember,

Screenshot

Confirm your password here.

Screenshot

Here for my case my password was short so its weak that's why its confirm me to use it as it is, anyway lets hit yes.

Screenshot

Here is our beautiful table now. Now we have that encrypted partition and also its a container for our logical volumes, And since we hit that LVM what is that? What i got its a system that called logical volumes management, the idea behind that system is tree steps, first : (PV) which is physical volume, its like the actual partition or device. second : (VG) is Volumes Group, its like a container or as they say a pool of storage, its like combines multiple physical storage devices (Physical Volumes) into a single, large, flexible storage space. third : (LVs), and last thing inside that volumes group, we create those logical volumes who act as flexible normal partitions can be formatted with filesystems and mounted like regular disks.

hmm, as simple as that. lets go back and click that configure the logical volume manager

Screenshot

Screenshot

Write those changes to the disk.

Screenshot

So here is our current lvm table, so lets create a volume group on top of this partition

Screenshot

Here the volume group name, in the mandatory part, i think its named "wil--vg", and for the bonus its "LVMGroup"

Screenshot

Here select the physical volume for that volume group, and of course its our encrypted sda5

Screenshot

Here lets confirm this action.

Screenshot

This how our table look now, now our group is ready, so we can create those logical volume and mount them with the specific point.

Screenshot

Click this create logical volume

Screenshot

Select the volume group we will use.

Screenshot

So the start will be with the root logical volume, so select the name.

Screenshot

Here lets select the size of that logical volume, and as the subject say lets give it 10GB

Screenshot

And here we are, and if you ask about the mounting, we'll do it later so now just create those logical volumes, Go ahead and create the rest with the correct name and size, After that you will got a table look like this:

Screenshot

So now after done your volumes, you can also check them with Display configuration detail otherwise just hit finish

Screenshot

Now this home our hole table look like after creating the logical volumes, so now we need to configure the system file and the mount point for them.

Screenshot

so lets select our first one.

Screenshot

Here lets select Ext4 since its common for Linux, also i think its can't work directly in windows so its fit us very well,

Screenshot

So after selecting Ext4, choose the correct mount point for the partition, in our case, its the /home You can think of a mount point as a link or gateway that connects a directory in your file system to the actual data stored on a device or partition. Its just like linking some folders to the actual data in the physical real device, something like that.

So now just go ahead and continue with the rest, specify the file system with the mount point for each one as the subject, And one note, about the sizes of those volumes, actually the subject just give us an arbitrary sizes, so its up to you to figure out the actual size that its fit your purpose. And you are smart enough to figure out that.

Screenshot

After setting them, you will got something like this one, as you see just the other with Ext4 file system except for the swap you must use the swap area system and about the last one which is var/log you must set the mount point manually. and with that you done just hit finish partitioning and write changes to disk

Screenshot

Confirm the changes...,

Screenshot

Here is the progress

Screenshot

Here select no since we doesn't need any extra packages

Screenshot

Here select your country or anyone near to you, just make sure that the server on this country are working well, otherwise the installation will fail and you must modify mirror later from the setting of apt, Why? Cause Debian has a mirrors in multiple countries, which mean that its repository are available on all those servers, what that mean?, when we want to install some software on Debian we use that APT which is a packages manager that help us to install software's easily and fast, and how that apt work, when we request a package, its hit to those repositories and check if that application is exists then its install it and its dependencies, so at the end we interact with those repositories, so where those repositories live? The are in some servers managed by Debian developers, and where that server? Here is the key, that they are a several servers hold the repositories and that what called mirrors so we choose which server to fetch the data from, when we install some packages. Something like that~ you can google it for more information.

If your server fail, its will look something like this: Screenshot

For my case am going with France mirror.

Screenshot

And here click the first one.

Screenshot

Hit enter again.

Screenshot

Here is our scanning, let it finish.

Screenshot

Here just hit no, its just like report our statistics to the developers.

Screenshot

Here at first you'll find some other packages checked, go ahead and uncheck them since we just wanna that ssh server, you can check/uncheck with space bar, and hit enter.

Screenshot

Here is an important component in a computer called GRUB. It’s like the program that actually loads the kernel into memory when you turn on your computer. Depending on whether your computer uses BIOS or UEFI firmware—these are like instructions or built-in programs that control the initial startup process—GRUB is stored and executed differently. BIOS systems typically install GRUB in the Master Boot Record (MBR) of your primary drive. UEFI systems usually store GRUB in an EFI System Partition, which is a special partition on your drive. In essence, GRUB is installed somewhere on your primary drive, and its job is to load the operating system’s kernel into memory and start it. While UEFI offers some extra features, the core idea remains the same: GRUB lives on your main drive and is responsible for booting your OS.

And that what google say^^ Anyway we got the idea, so lets hit this yes

Screenshot

And here where we will install that GRUB on, so its kinda the things google was saying seem logic, so here basically we gonna use that dev/sda so its got installed in the same device when we already have the bootable files, so its the best approach, But, if you wanna play around you can go with the manual one, and... Maybe break some stuff, its actually up to you, as they say its your world. So lets use that /dev/sda, and after some installations you'll got:

Screenshot

So yeah the installation done, just hit that reboot so the system start.

Screenshot

So after starting, its ask you to bypass your partition, remember you encrypt it at the installation, so open it now.

Screenshot

Here its ask for your user login, if you still remember it, Also your password for the user (i wont tell you that your password will be hidden since you know that the default behavior on linux).

Screenshot

And now here we go, that's you prompt now.

Now we on our server, so we need to configure it, the recommended first thing is to install the sudo program, since we'll need it, A quick note about what is that sudo: basically the root controls everything all paths, directories, mount points, so its has the hole power so why not just stick with that root user since its do everything, but we have also normal users, so multiple people can share a computer, Sometimes we need root power to change something in the system, We could use su to enter root mode entirely, but that's inefficient, We just want that power temporarily for one command, so sudo exists—it gives us root power temporarily for just that specific command, that's more flexible.

Anyway lets just go ahead and install that sudo program.

Screenshot

So we already have the apt, its our package manager, and to install something actually you need the root user power, but we still doesn't have sudo so instead, lets use this program su that's switch user program to enter the root mode, you can use su or su root then go ahead and update the packages, apt update and then apt install sudo, and its will installed. If you got an error with that and its rare if you going with the guide, but if that happen, check the internet ping google.com if its doesn't work then its about how the virtual box program handle your network to the server, anyway. Lets keep our work...

If you wanna check the installation or something, just do which sudo and its will show you the bath when the program installed.

ok about what called groups, so we say that the sudo program give us the power we want, and its actually give that power to a specific group, yeah as its called, think of it like a group, so the sudo give the power to that group and any user belong to that group will inherit that power, so we need to add our user to the group, but before that, lets just do a quick thing, as they also ask for another group must be present lets create it first, with the command, sudo addgroup user42 yeah yeah since we in the root mode, no need for sudo keyword, but just do it what the problem, anyway now have the sudo and user42 groups, and also the system have a much more than those two, so for instance if you wanna check, you can list cat etc/group or if you line the commmands, go with getent group,

Screenshot

And you see here that sudo group doesn't has our user, so lets add it to both the sudo and user42 groups by the command sudo usermod -aG sudo,user42 aarid just list the two groups first by separating them by comma, then your user which is your login probably.

Screenshot

Here our user is now belong to those two groups, And you can check it by groups <username> to see that its also belong a several groups, anyway we are good now. Now you can use sudo with your regular user without entering the root mod, something like that below:

Screenshot

Ok now we are good here.

SSH Service

So lets follow the flow of the subject, they ask for that ssh to be set, and configured and running at the start of the machine. Will cover that, but first lets understand what that ssh, so if you google it you will find : "SSH, or Secure Shell, is a cryptographic network protocol that provides a secure way to access and manage remote computers over an unsecured network like the internet.", Ok and what that mean, so basically its all start with the internet, since the internet its a gateways and roots and a lot of information changes actually its not secure since the hackers may interact those information in the transfer, so the good at the ssh is it guarantee that your information exchange will be secure, how that. so the ssh provide a service, its like let you remotely control another machine, How that? So listen here, its give you to services one is for the server machine, the one you want to ssh into it, and the other one is the client service that the host machine you wanna use to control the server machine, so here each service has a configuration file. Just think of them as a separate services like one is set to wait and listen for a request, and the other one is do the first step and try to connect to the one that waiting.

So since its a service, if you remember we actually already install it in the installer, if you actually not, you can install it and enable it with something like: sudo apt install openssh-server sudo systemctl enable ssh --now

Otherwise you are good. So what we wanna do here is setting that server ssh service to listen to the port 4242 as the subject specify, so navigate to the file cd /etc/ssh/,

Screenshot

As you see here there is two ssh configuration files, here we are going to modify that sshd_config file, that d at the end of name stand from daemon, Which mean its the service who will run at the background without controlling, just google it for more information, anyway lets open it sudo vim sshd_config, here am using vim since am already install it, you can install it also or just use nano.

Screenshot

If we take a look at this line in the subject, its say: "An SSH service will be running on the mandatory port 4242 in your virtual machine. For security reasons, it must not be possible to connect using SSH as root."

Its say to set the port to 4242, first you will see 22, just go and uncomment the line by removing #, and change the number to 4242, also they say "must not be possible to connect using SSH as root.", what that mean is, when later we try to ssh into the server, we need actually to specify which user we'll use, and for that, the hackers often use the root user since they are sure its exists, otherwise they should know which user you have and guess its password and use it to access root power, that's a lot of work, and for that they ask to prevent the root access to all will do is change that line PermitRootLogin to no, as simple as that. Its good now, we will play more with that ssh later, but now we have something to do.

Install UFW

We know that when machines communicate with each other they do that in the network, which is a network traffic, and also to access a specific service or purpose we use those ports, as above we the port 4242 to represent the ssh service, so with that we actually have something to control that network traffic, And its called firwwall, which is actually like a system or mechanism its come built-in into the OS kernel, so here its control those traffics by specifying which ports are allowed and which not, and to do that we need a program that lets use control that firewall system, and that program is called ufw, which we'll install it now, also what i forget to say is that firewall system by default its deny all the ports and we should modify that behavior, <-- that what google say :)

Lets go and install it quick:

Screenshot

Here just go and install it as any other program.

Screenshot

Here first time you'll check it sudo ufw status, its not active, just go and enable it sudo ufw enable, now its enabled and active, lets check it with systemctl status ufw, now lets allow that 4242 port by the command sudo ufw allow 4242 and all good.

Now we still need something, but before that you can take a screenshot of your current process,

Screenshot

Click at that list beside the virtual machine name, then go to Snapshots, then as you see this button top left just click it and choose a name for the snapshot, and you are good, then just go back to your machine and turn if off, there is several ways, but just use sudo shutdown now.

Usage of ssh

So now what if you still follow the flow, you remember that ssh control the machines remotely, so basically how that is by command ssh -p 4242 aarid@localhost, what am trying to do here is using my hosting machine (the original one) to ssh into the virtual machine, at the specific port 4242 and by the localhost which is the local ip address, But if we do that now, we'll got some errors, something like that:

Screenshot

So we got error here, so lets see how we can fix it. We already turn off our machine, so now.

Basically this virtual machine you working on it now its kinda isolated, so since we use the network on it so we need a way to let the connection and the network to reach it, and for that lets modify the network setting of that vm, something like that:

Screenshot Screenshot

So here at the setting of the VM, click Advanced then Port Forwarding its like redirect that connection coming in those settings into the ones in the VM, Yeah something like that but, actually when am trying it its got me some ugly error : kex_exchange_identification: Connection closed by remote host Connection closed by 127.0.0.1 port 4242

And I've already try several solutions but nothing work, so i use another approach which is instead of NAT ill use Bridged Adapter. So what is that is like treating that VM as an actually device and give it an ip address, so now its can accept the connection directly. so now if i check the Ip address of the VM and use it to ssh into it:

Screenshot Screenshot

Now as you see it work and we successfully ssh into the VM machine so we can control it now remotely and our session now its based on the VM machine, so any command you run here its same as you run it in the VM machine, that's the simplify idea. And about the network as we say its your world go ahead and try the first one if its work, perfect, if not you can try the second one.

Now after you successfully access to your machine remotely, you can keep the work from each places, both are do same job.

Password Rules

Okay Now look at this sentence "You have to implement a strong password policy". So you realize that passwords we just go and use them everywhere they are actually has some rules, and the subject ask to adjust some rules time based like password must expired after some time, or like the password should have uppercase characters and those stuff,

Since each rules has their configuration file, lets start with the time based rules.

Time Based Rules

Your password has to expire every 30 days The minimum number of days allowed before the modification of a password will be set to 2 The user has to receive a warning message 7 days before their password expires.

Lets handle those, so open the configuration file: sudo vim /etc/login.defs

Screenshot

After opening the file, look for those tree lines, set them like the above, The first one is the expired days, so we set it to expire the password after 30 days, Second one is how much time you can change your password again after change it, Set to 2 days. Last one is the warning message which will be received 7 days before expiration.

All good as the subject require.

Pattern Based Rules

Now, we should configure the pattern and the characters rules, and those stuff, basically the configuration file live in cat /etc/pam.d/common-password:

Screenshot

So basically, first what is PAM: PAM is a modular system that manages authentication, account, session, and password management by using various interchangeable modules.

As simple as that, Actually i don't really get it, but anyway, as they say its a framework that allow system administrators to configure the authentication and some other stuff, If you look to the screenshot above, at the first active line at the end of line its like use some module, which is a shared library, yeah that we want but actually even with that library its still doesn't have the advanced complexity checking we need, so how its will check the passwords, for that we must install that module called libpam-pwquality, which is simple like this:

Screenshot

sudo apt update | sudo apt install libpam-pwquality

And process "y".

So now we have that PAM Module, which is enforce the quality of the password, so when we try to change the password its gonna check that new password with the configuration its has, if its fail to meet the requirement its reject it.

So if you check the /security folder you should find that new configuration file pwquality.conf which is for applying the rules for system wide, kinda like a global settings. But for us we can just go back to the sudo vim /etc/pam.d/common-password and we'll set them here, its actually like overridden the default settings. So no problem lets just go ahead and set those options, but just before that lets talk about something, so basically after installing the module if go-back to the file etc/pam.d/common-password, you see now the first active line look like this:

"password requisite pam_pwquality.so retry=3"

Set Password Rules options

So here the basic idea what the most do is just go ahead and set the options after the retry=3, something like this: password requisite pam_pwquality.so retry=3 minlen=10 ucredit=-1 lcredit=-1 dcredit=-1 maxrepeat=3 reject_username difok=7 enforce_for_root

And the options is :

minlen=10: Password must be at least 10 characters.

ucredit=-1: Must contain at least 1 Uppercase letter. (Negative number means "mandatory").

lcredit=-1: Must contain at least 1 Lowercase letter.

dcredit=-1: Must contain at least 1 Digit.

maxrepeat=3: Prevents more than 3 consecutive identical characters (e.g., "aaaa" is forbidden).

reject_username: The password cannot contain the user's name.

difok=7: The new password must have 7 characters different from the old one.

enforce_for_root: Enforces the length and complexity rules on the root user.

But actually if you notice that we have issue here. The subject clearly say:

"The following rule does not apply to the root password: The password must have at least 7 characters that are not part of the former password."

And we actually use that enforce_for_root rule which is apply all those rules to the root user including that difok=7, Also there is no direct way in PAM that let us disable that rule for root. Which mean we need a way to apply all the rules except difok=7 for the root.

So basically there is to ways that work for me, first its the easiest one:

First config

Screenshot

What's happen here is that we actually set the options for the normal users and turn off the enforce_for_root=0 flag, and also set the difok=7, so that line we'll apply to the normal users.

And in the second line we declare the same options but we include the enforce_for_root, but we also set the difok=0 which mean that the root user doesn't have the rule of 7 different characters, which is what we want.

And we have this second approach.

Second config

Screenshot

Its actually more complexity, its based on some kind of the conditions, Its check first if the user has the (UID=0) which is for the root user, if so its skip the next line which is for the normal users, so its will got into the fourth line, Otherwise if its a normal use will apply the second line and skip the 4 line.

Its actually kinda complicated, but yeah its work also.

And a quick note when you wanna check, if you trying to change the password of a normal user just use passwd username and its work, actually i was using sudo passwd username , but which that when i use sudo with the command its executed as a superuser which got the (UID=0) and its behave as a root and its break the rules, so be aware of that. :)

So now we are soo good, just go quick and change each account password you have, including the root one. Just use the command passwd user and enter the current one and the new one, and for root go with sudo passwd root, and enter the new one.

Sudo Configuration

Now were going to configure the sudo group, what's happen is that we'll set tome rules for it also, the reason why is something about the security, like... Why authentication limited to 3 attempts: to restrict the password attacks. Why custom message: simply for clarity so we know whats happen. Why save the actions in /var/log: to track what's the sudoers trying to do. Why enabling tty mode: to restrict the usage of sudo from a script. Why restrict the paths: let the sudo access just to the programs that not required for the system to boot.

All that is just my reasoning but its look logically so why not lets configure it. First since will track the actions in /var/log/sudo/ lets create that folder.

sudo mkdir /var/log/sudo Screenshot

Ok now since we wanna configure a file so basically we check /etc since its for the configuration, and yes we find a configuration file called sudoers and its look like this:

Screenshot

Yeah its actually for configuration but guess what we wont touch it, am also asked why? But they say its the main sudo configuration and its very recommended to avoid modifying it since something like if you miss with a typo or syntax that mean your hole sudo system will break and even if we wanna fix it we cant access the sudo needed to fix it, and for that you should just create a new file and set the configuration in it, which mean if a error happen you can just remove that new file and you are good, But actually isn't that the same?? If the sudo system broken how we can actually remove that new file, and maybe you say that we'll switch to root mode but if we can do that we can do it with the original config file so we can fix it from root mode, so we is the actual reason, But anyway since they say that maybe there is another reason so for us lets follow them, and create a new file in the specific folder sudoers.d/

Screenshot

so create a file in /etc/sudoers.d/sudo_config actually you can call that file what you want, the name doesn't matter here since all files in that directory gonna loaded. Just a quick note before we continue, when i was testing i discover the reason why its separate file, since actually i miss with the main config a little like this:

Screenshot

And am trying to fix it and even with switching to root mode, its doesn't help, so that just a clarity for my last opinion, anyway

Now about that file we just created, etc/sudoers.d/sudo_config fill it with something like that:

Screenshot

So as am already comment there, passwd_tries is the attempts for you to try passwords. badpass_message is clearly that its the message its displayed when you hit the attempts limit, (also you can use any badpass message its up to you). log_input, log_output that enable the input output actions to got tracked and logged into the /var/log partition. iolog_dir her you specify where those logs must stored, so we already create a folder called sudo in sudo mkdir /var/log/sudo. requiretty , as its commented, its like strict the sudo command to be executed from the terminal not from a script or something so its require the human interact with the tty which is like the manager of the terminal sessions. secure_path those is the path that sudo able to run programs from.

And now the good news that i think we done with the sudo configuration, The worse is that we should shell script now, but we'll figure it, somehow :)

Shell Script

The shell name is monitoring.sh what that shell do is:

Screenshot

Yeah as you see all that things, and actually am bad at scripting, but lets see what's going here.

Basically script is a way to combine collection of commands to do some specific tasks, cool. And we actually put those commands in a file which is the script, cool. But we need to specify the interpreter for that script, like bash or sh, since the terminal is just a software that provide a way to us for inputing and outputing, but who actually do the work is the shell, The shell is the heart who take our commands and interpret them as a language the kernel can understand, so the terminal is like a container hold the shell, cool. Now we must use a specific shell to interpret that script, in our case we'll use bash its just modern and more features and those stuff, anyway.

To specify the interpreter you gonna use you must tell the OS at the first line, which called shebang its look like this #!/bin/bash the # symbol basically used for comments but when combined with ! its purpose for specifying the program uses for interpretation, so we here put the path for the bash program.

So enough theory, first they ask for the architecture, its actually like the name of the hardware of more precise the name of the instructions set that the cpu use, the cpu is the unit and its also has some instructions so it can know what it should do, and those set of instructions has a name which is something like x86_64 anyway what they ask for is a set of information on our architecture so we'll need the command uname -a, if you interest of anything of what am saying go ahead and google it for more information and that's the heart of learning, anyway also they ask for the physical processour and virtual processour, anyway the first one is the actual peace those plugged into the motherboard, and the second one think of it like the representation of the physical ones, but with some cases, anyway what i understand is that a machine can have multiple CPU's which are the physical processor, and each one of those CPU's can have multi cores, but the problem is that each core can have multiple threads, So the idea is virtual cpu's == cores but that just if the cores has 1 threads, so if its multi threads like 2 so its actually counted by the threads, actually that need more interacting maybe I'll take a look on it later, check this:

Screenshot

So for now we have the commands to check the both on our machine, which is something like that:

Screenshot

So lets start with something like this, the idea is that we just grep those information from proc/cpuinfo file.

Anyway if you like scripting this is a good opportunity to go with it even if the tasks is simple, anyway Here is the final look of the script, even am actually getting some helps from AI and another guide, to got the helpful commands, you can look for another commands if you want.

Lets just take an overview of what there:

RAM | STORAGE | CPU

They ask to print some machine information like the total and usage of RAM, STORAGE, and CPU. You can solve that just by some greps and formulates to get the percentage.

Last Reboot

Here you can use who -b command and process with awk to get specific parts.

LVM

We can use a conditions here to check if lsblk and grep if there is a LVM word which mean we already apply the lvm.

TCP connections

Here we check the tcp connections those are successfully established to our server so first we list all connections then filter them to got only the TCP ones, since no use of udp, anyway then we use the flags -t to got the tcp sockets, and then -a for got all connections so we cal later grep only the established ones.

Count users

This one is to to grep the how much user are connected to your server.

IP Address & MAC

Here your IP Address of that machine, also the MAC which is kinda like the identifier of the physical network card this plugged into you hardware, its kinda like to help the routers later to reach the necessary machine that request some specific data.

SUDO command count

Its like count the number of times you use the sudo command, so its about check the Journaling tracker and try to filter the information of sudo and then grep just those are commands since its may be another usage of sudo.

Wall

This wall is like a small program let you broadcast a message to all users connected to the machine so its not exactly like printing since its will show the message even if you inside a file or you doing some tasks.

So with that the script will look something like this:

Screenshot Screenshot

Now we need to make the script run every 10 minute, so lets use the crontab program. Lets config it, use this command to open the configuration crontab -e.

Screenshot

That just if you have multi editors and no one are specified as the default, so just use anyone.

Screenshot

Now this is cron table which where you list your scheduled tasks, its a personal configuration, and also has a specific syntax for it.

Screenshot

Here is what we should do, its take a pattern of: { minute hours day_on_mounth month day_on_week command }

Which is mark the time that the script or the command will run on it. So '*' this asterisk mean 'every', and when we combine it with /10 its specify the how much exact time, so we say every 10 in the minute field which is what we want. And at the end we specify the exact path to our script, so now its run the script every 10 minute which we want.

Screenshot

After saving you may see that message so you crontab are saved.

Now after its saved its actually will create a configuration file under the path "/var/spool/cron/crontabs/", and if you try to browser it here with the normal user, its will denied you permission, even if you use sudo, That based on the design of the tool crontab so its even if the configuration is yours, you should just configure it with the command crontab -e, but even with that if you su root now you're using the root power so you can check it.

By that the script will run every 10 minute and broadcast to each active user, as the subject require.

So i think we stop here since, at this moment you are successfully set the server as required, alternatively you can go on and try to complete the bonus part but overall you are good now. AND as you see am still learning also i don't expert at that field, so may i be wrong on several things so don't forget to check each information by yourself, this is a part of learning process. So even if you born as a root, you still can be root :) .

About

Implementation of the Born2beRoot project from 42 curriculum

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors