Skip to content
AD-506 · Linux Lab/Quick Revision Short Notes

Linux Lab (AD-506) - Unit 5 Short Notes

How unit 5 is examined

This unit covers file and login security with ACLs, root and FTP restriction with TCP wrappers, the DHCP server, and a case study of installing common Linux services; no topic was asked in recent papers, so each is kept short.

Physical Security, Controlling System Access, Restricted Shells Controlling File Access, File Access Commands, Access Control List(ACLs)

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. System security means protecting the machine from physical tampering, unauthorised logins and unauthorised file access; an ACL (Access Control List) gives file permissions to specific users or groups beyond owner, group and other.

Key points.

  1. Physical security keeps servers in locked rooms, protects the boot loader and BIOS with passwords, and prevents theft or console access.
  2. System access is controlled with passwords, password ageing, locked accounts and login restrictions in /etc/passwd, /etc/shadow and /etc/default/login.
  3. A restricted shell (rsh or bash -r) blocks cd, changing PATH and running commands with /, so a user stays confined.
  4. File access is controlled with chmod, chown and chgrp; <mark>an ACL adds per-user and per-group permissions to a file.</mark>
  5. setfacl -m u:ravi:rw file sets or modifies an entry, getfacl file shows it, setfacl -x u:ravi file deletes one entry and setfacl -b file removes all entries.

Restricting FTP, Root Access and TCP Wrappers

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. These are controls that limit who may use FTP or become root, and TCP Wrappers filter incoming network services by client address using /etc/hosts.allow and /etc/hosts.deny.

Key points.

  1. FTP is restricted by listing banned users in /etc/ftpusers and by placing users in a chroot jail so they see only their own directory.
  2. Root access is restricted by allowing root login only on the console (/etc/default/login, CONSOLE=/dev/console) or with PermitRootLogin no in SSH.
  3. Superuser use is monitored through su and sudo logs (/var/log/secure, /var/adm/sulog), which record who became root and when.
  4. <mark>TCP Wrappers check hosts.allow first, then hosts.deny; the first match wins, and no match means access is allowed.</mark>

Dynamic Host Configuration Protocol: Introduction, DHCP Leased Time, DHCP Scopes, DHCP IP Address, Allocation Types, DHCP Configuration files, Configuration of DHCP Clients

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. DHCP automatically gives a client an IP address, netmask, gateway and DNS server from a central server.

Key points.

  1. A lease time is how long a client may keep its address before renewing; it is set with default-lease-time and max-lease-time in seconds.
  2. A scope is the range of addresses the server can hand out, declared as a subnet block with range.
  3. Allocation types are automatic (permanent), dynamic (leased and reusable) and manual (fixed address bound to a MAC address).
  4. The main configuration file is /etc/dhcpd.conf, and leases are recorded in dhcpd.leases; start the server with systemctl enable --now dhcpd.
  5. A client is set to DHCP with BOOTPROTO=dhcp in its interface file; <mark>manual configuration instead uses a host block with hardware ethernet and fixed-address.</mark>

Case Study: Installation of Linux, Customization of Linux, Installation of SAMBA, APACHE, TOMCAT, Send MAIL, Postfix, Implementation of DNS, LDAP services, Firewall, Proxy server

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. The case study is installing Linux, customising it, and configuring services such as Samba, Apache, Tomcat, Postfix, DNS, LDAP, firewall and proxy.

Key points.

  1. Installation uses boot media, disk partitioning, package selection, root password and network setup; customisation adjusts packages, users, services and kernel settings afterwards.
  2. Samba shares files with Windows through smb.conf, Apache serves web pages through httpd.conf, and Tomcat runs Java servlets and JSP.
  3. Postfix sends mail as an SMTP server through main.cf; DNS (BIND, named.conf) resolves names, and LDAP serves directory data.
  4. <mark>A firewall filters packets by rule (iptables), and a proxy server such as Squid caches and controls web requests for clients.</mark>

Last-minute revision

  • ACL: setfacl -m modifies, getfacl views, setfacl -x deletes one entry, setfacl -b deletes all.
  • Restricted shell: rsh or bash -r; blocks cd and PATH changes.
  • FTP ban list is /etc/ftpusers.
  • Root login limited to console; watch su logs.
  • TCP Wrappers: hosts.allow first, then hosts.deny.
  • DHCP config is dhcpd.conf; leases in dhcpd.leases.
  • Lease time: default-lease-time and max-lease-time.
  • Scope is the range of addresses in a subnet block.
  • DHCP allocation: automatic, dynamic, manual.
  • Client uses BOOTPROTO=dhcp.
  • Samba smb.conf, Apache httpd.conf, Postfix main.cf, BIND named.conf.

Memory hooks

  • ACL commands: Set, Get, X-out, Blank (-m, getfacl, -x, -b).
  • TCP Wrappers: Allow before Deny.
  • DHCP allocation: Auto, Dynamic, Manual (ADM).
  • DHCP client gets IP, Mask, Gateway, DNS (IMGD).

Coverage checklist

  • Physical Security, Controlling System Access, Restricted Shells Controlling File Access, File Access Commands, Access Control List(ACLs), Setting ACL Entries, Modifying ACL entries on a file, Deleting ACL entries on a file: no past questions.
  • Restricting FTP, Securing Super User Access, Restricting Root Access, Monitoring super user Access, TCP Wrappers: no past questions.
  • Dynamic Host Configuration Protocol: Introduction, DHCP Leased Time, DHCP Scopes, DHCP IP Address, Allocation Types, Planning DHCP Deployment, DHCP Configuration files, Automatic Startup of DHCP Server, Configuration of DHCP Clients, Manually Configuring the DHCP: no past questions.
  • Case Study: Installation of Linux, Customization of Linux, Installation of SAMBA, APACHE, TOMCAT, Send MAIL, Postfix, Implementation of DNS, LDAP services, Firewall, Proxy server: no past questions.
Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in