Quick reference for Linux security — permission bits, hardening commands, SSH config, and audit log locations.
PermissionsHardeningSELinuxAuditing
Permission Bits / Octal
| Octal |
Symbolic |
Use |
| 400 | r-------- | Read-only key |
| 600 | rw------- | Private file |
| 644 | rw-r--r-- | Config/doc |
| 700 | rwx------ | Private dir |
| 755 | rwxr-xr-x | Executable/dir |
| 4755 | rwsr-xr-x | SUID (audit!) |
| 1777 | rwxrwxrwt | Sticky (/tmp) |
Essential Commands
| Command |
Purpose |
| chmod 600 f | Set octal permissions |
| chown u:g f | Set owner and group |
| chattr +i f | Make immutable |
| lsattr f | Show ext attributes |
| getcap -r / | List file capabilities |
| setcap cap_net_bind_service=+ep f | Grant a capability |
| umask 027 | Default-deny group/other |
SSH Hardening (sshd_config)
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes
KbdInteractiveAuthentication no
AllowUsers alice bob
MaxAuthTries 3
LoginGraceTime 20
X11Forwarding no
ClientAliveInterval 300
# apply: sudo systemctl reload ssh
ufw Commands
| Command |
Effect |
| ufw default deny incoming | Deny inbound baseline |
| ufw allow 443/tcp | Open a port |
| ufw limit 22/tcp | Rate-limit SSH |
| ufw allow from 10.0.0.0/24 | Allow a subnet |
| ufw enable | Activate firewall |
| ufw status verbose | Show rules |
SUID / Privesc Audit
# SUID binaries
find / -perm -4000 -type f 2>/dev/null
# SGID binaries
find / -perm -2000 -type f 2>/dev/null
# World-writable files
find / -xdev -type f -perm -0002 2>/dev/null
# Files with capabilities
getcap -r / 2>/dev/null
# Sudo rights for current user
sudo -l
Log File Locations
| Path |
Contents |
| /var/log/auth.log | Auth/SSH (Debian) |
| /var/log/secure | Auth (RHEL) |
| /var/log/syslog | General messages |
| /var/log/audit/audit.log | auditd events |
| /var/log/faillog | Failed logins |
| journalctl | systemd unified log |
SELinux / AppArmor
| SELinux |
AppArmor |
| getenforce | aa-status |
| setenforce 1 | aa-enforce <profile> |
| setenforce 0 | aa-complain <profile> |
| sestatus | aa-disable <profile> |
| ausearch -m avc | journalctl audit denials |
File Integrity (AIDE)
sudo aideinit # build baseline DB
sudo cp /var/lib/aide/aide.db.new /var/lib/aide/aide.db
sudo aide --check # detect changes vs baseline