How unit 5 is examined
This unit covers file and login security with ACLs, root and FTP restriction with TCP wrappers, the DHCP server, and a case study of installing common Linux services; no topic was asked in recent papers, so each is kept short.
Physical Security, Controlling System Access, Restricted Shells Controlling File Access, File Access Commands, Access Control List(ACLs)
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. System security means protecting the machine from physical tampering, unauthorised logins and unauthorised file access; an ACL (Access Control List) gives file permissions to specific users or groups beyond owner, group and other.
Key points.
- Physical security keeps servers in locked rooms, protects the boot loader and BIOS with passwords, and prevents theft or console access.
- System access is controlled with passwords, password ageing, locked accounts and login restrictions in
/etc/passwd,/etc/shadowand/etc/default/login. - A restricted shell (
rshorbash -r) blockscd, changingPATHand running commands with/, so a user stays confined. - File access is controlled with
chmod,chownandchgrp; <mark>an ACL adds per-user and per-group permissions to a file.</mark> setfacl -m u:ravi:rw filesets or modifies an entry,getfacl fileshows it,setfacl -x u:ravi filedeletes one entry andsetfacl -b fileremoves all entries.
Restricting FTP, Root Access and TCP Wrappers
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. These are controls that limit who may use FTP or become root, and TCP Wrappers filter incoming network services by client address using /etc/hosts.allow and /etc/hosts.deny.
Key points.
- FTP is restricted by listing banned users in
/etc/ftpusersand by placing users in a chroot jail so they see only their own directory. - Root access is restricted by allowing root login only on the console (
/etc/default/login,CONSOLE=/dev/console) or withPermitRootLogin noin SSH. - Superuser use is monitored through
suandsudologs (/var/log/secure,/var/adm/sulog), which record who became root and when. - <mark>TCP Wrappers check
hosts.allowfirst, thenhosts.deny; the first match wins, and no match means access is allowed.</mark>
Dynamic Host Configuration Protocol: Introduction, DHCP Leased Time, DHCP Scopes, DHCP IP Address, Allocation Types, DHCP Configuration files, Configuration of DHCP Clients
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. DHCP automatically gives a client an IP address, netmask, gateway and DNS server from a central server.
Key points.
- A lease time is how long a client may keep its address before renewing; it is set with
default-lease-timeandmax-lease-timein seconds. - A scope is the range of addresses the server can hand out, declared as a
subnetblock withrange. - Allocation types are automatic (permanent), dynamic (leased and reusable) and manual (fixed address bound to a MAC address).
- The main configuration file is
/etc/dhcpd.conf, and leases are recorded indhcpd.leases; start the server withsystemctl enable --now dhcpd. - A client is set to DHCP with
BOOTPROTO=dhcpin its interface file; <mark>manual configuration instead uses ahostblock withhardware ethernetandfixed-address.</mark>
Case Study: Installation of Linux, Customization of Linux, Installation of SAMBA, APACHE, TOMCAT, Send MAIL, Postfix, Implementation of DNS, LDAP services, Firewall, Proxy server
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. The case study is installing Linux, customising it, and configuring services such as Samba, Apache, Tomcat, Postfix, DNS, LDAP, firewall and proxy.
Key points.
- Installation uses boot media, disk partitioning, package selection, root password and network setup; customisation adjusts packages, users, services and kernel settings afterwards.
- Samba shares files with Windows through
smb.conf, Apache serves web pages throughhttpd.conf, and Tomcat runs Java servlets and JSP. - Postfix sends mail as an SMTP server through
main.cf; DNS (BIND,named.conf) resolves names, and LDAP serves directory data. - <mark>A firewall filters packets by rule (
iptables), and a proxy server such as Squid caches and controls web requests for clients.</mark>
Last-minute revision
- ACL:
setfacl -mmodifies,getfaclviews,setfacl -xdeletes one entry,setfacl -bdeletes all. - Restricted shell:
rshorbash -r; blockscdandPATHchanges. - FTP ban list is
/etc/ftpusers. - Root login limited to console; watch
sulogs. - TCP Wrappers:
hosts.allowfirst, thenhosts.deny. - DHCP config is
dhcpd.conf; leases indhcpd.leases. - Lease time:
default-lease-timeandmax-lease-time. - Scope is the
rangeof addresses in asubnetblock. - DHCP allocation: automatic, dynamic, manual.
- Client uses
BOOTPROTO=dhcp. - Samba
smb.conf, Apachehttpd.conf, Postfixmain.cf, BINDnamed.conf.
Memory hooks
- ACL commands: Set, Get, X-out, Blank (
-m,getfacl,-x,-b). - TCP Wrappers: Allow before Deny.
- DHCP allocation: Auto, Dynamic, Manual (ADM).
- DHCP client gets IP, Mask, Gateway, DNS (IMGD).
Coverage checklist
- Physical Security, Controlling System Access, Restricted Shells Controlling File Access, File Access Commands, Access Control List(ACLs), Setting ACL Entries, Modifying ACL entries on a file, Deleting ACL entries on a file: no past questions.
- Restricting FTP, Securing Super User Access, Restricting Root Access, Monitoring super user Access, TCP Wrappers: no past questions.
- Dynamic Host Configuration Protocol: Introduction, DHCP Leased Time, DHCP Scopes, DHCP IP Address, Allocation Types, Planning DHCP Deployment, DHCP Configuration files, Automatic Startup of DHCP Server, Configuration of DHCP Clients, Manually Configuring the DHCP: no past questions.
- Case Study: Installation of Linux, Customization of Linux, Installation of SAMBA, APACHE, TOMCAT, Send MAIL, Postfix, Implementation of DNS, LDAP services, Firewall, Proxy server: no past questions.