English — Linux Basics
Ten lessons for someone who has never opened a terminal.
Lesson 01
The terminal
A place where you type one sentence and get one answer.
Nothing in this lesson can break anything. Every command here only looks.
The terminal waits. You type one instruction, you press Enter, and it answers. Then it waits again. That is the whole idea, and it never becomes more complicated than that — only the instructions get more interesting.
Before you type anything, the terminal already tells you three things. Your name, the name of the machine, and where you are standing inside it. That short line before the cursor is called the prompt, and once you can read it you are never lost.
Opening a terminal
Any system
Hold Ctrl and Alt together, then press T. On most Linux systems a terminal opens immediately.
Linux Mint
Click the menu in the bottom-left corner, type the word terminal, and open the black icon that appears.
Ubuntu
Press the Super key (the one with the Windows logo), type terminal, and press Enter.
Fedora
Press Super, type terminal, press Enter. Or click Activities in the top-left corner first.
On your own machine
pwd — Where am I?
A path — the address of the folder you are standing in. It begins at / , which is the top of everything on this machine, and ends at your own folder. Your own folder is the one place you can change things without asking anyone.
whoami — Who am I?
Your username. The machine keeps one for every person and also for every program that runs quietly in the background. Later, this name is what decides what you are allowed to do.
date — Is it actually working?
The current time, according to the machine. A pointless command with a real purpose: it proves the terminal is listening and answering.
Exercise
Tap the part of this path that means the top of everything.
/home/student
What does this answer mean?
/
Yes. Every path on this machine starts there, and nothing exists above it.
Security note
Why this matters later
A button hides what it does. A command says it out loud. Everyone who works seriously with security — the people defending a system and the people attacking it — ends up here, because the terminal is exact and a window full of icons is not.
Lesson 02
Where you are
Everything on the machine hangs from one point.
You will move around and look, and nothing will change.
There is no C drive and no D drive. Everything on a Linux machine hangs from a single point called / , and every file has exactly one address underneath it. Your own things live in /home and then your name.
Two commands do almost all the walking. ls shows you what is here. cd moves you somewhere else. Two dots mean the folder above you, and a lone ~ always means your own folder, wherever you happen to be.
On your own machine
ls — What is here?
The names of everything in this folder. Names ending in / are folders you can walk into. Nothing here is a surprise — it is your own home folder.
cd Documents — Walk into a folder.
No answer at all. That is not a failure — Linux is quiet when a command works and only speaks up when something goes wrong. Run pwd now and you will see you have moved.
cd .. — Go back up one.
Two dots always mean the folder above this one. Silence again, which again means it worked.
ls -a — What was hidden?
Names that start with a dot are hidden from ordinary listings. They are not secret and not dangerous — mostly they hold settings for programs you use.
Exercise
Which command moves you into a different folder?
lscdpwdcat
What does this answer mean?
cd
Yes. cd is change directory — it is the only one of the four that moves you.
Security note
Why this matters later
Where a file sits and which permissions it has help decide who may read it. A misplaced or overly readable file can expose data without any sophisticated attack.
Lesson 03
Looking inside a file
Reading is not changing.
Every command here opens a file and puts it on screen. None of them can alter a single letter.
There is a hard line in Linux between looking and touching. cat, head and less only read. You can point them at anything you are allowed to open and the file will be exactly as it was afterwards.
That line is worth trusting, because it means you can investigate freely. Almost everything you will ever want to know about a machine can be answered without changing it — and the habit of reading first is what separates someone careful from someone lucky.
On your own machine
cat notes.txt — Show me the whole file.
The entire contents, printed at once. Fine for something short. On a long file it would scroll past faster than you can read, which is what the next two commands are for.
head shopping-list.txt — Just the beginning.
The first ten lines. When you only need to know what kind of file this is, ten lines is usually enough.
wc -l shopping-list.txt — How long is it?
A count of lines. Useful more often than you would expect — it answers how big is this before you decide how to look at it.
cat /etc/os-release — Which Linux is this?
A file the system keeps about itself. Note that you can read something outside your own folder: plenty of the machine is readable by everyone, and only some of it is protected.
Exercise
You run cat notes.txt twice. What happened to the file?
It was emptiedIt is exactly as it wasIt was copiedIt was locked
What does this answer mean?
It is exactly as it was
Exactly. Reading a file leaves it untouched, however many times you do it.
Security note
Why this matters later
A careful security review often begins with observations that do not change the system. You look, record what you found, and decide what—if anything—should change. This preserves evidence and reduces accidental damage.
Lesson 04
What is running
The machine is doing far more than you asked it to.
A list of programs you never started, all running quite normally.
A program sitting on disk is just a file. The moment it starts running it becomes a process, and the machine gives it a number — a PID. That number is how you talk about one particular running thing.
Most of the processes on a Linux machine were never started by you. They came with the system and they keep it working. This is the first lesson where you look at something you cannot see on your screen, and the first list where you will meet names you do not recognise. That is normal, and being able to say so is the point.
On your own machine
ps — What am I running right now?
Almost nothing — just this shell and the command you typed. ps on its own is deliberately narrow: it shows only what belongs to this terminal window.
ps aux — What is the whole machine running?
Everything. The first column is who owns each process, the second is its PID. Notice that many are owned by root and by names like avahi or systemd rather than by you.
top — What is busy right now?
The same idea, sorted by how much work each process is doing and refreshing every few seconds on a real machine. Press q to leave it — that trips up nearly everyone the first time.
Exercise
What is a PID?
The name of a programA number identifying one running processThe user who started itHow much memory it uses
What does this answer mean?
A number identifying one running process
Yes. One number, one running process. Start the same program twice and you get two PIDs.
Security note
Why this matters later
A process nobody can explain is the first thing a defender looks at. Not because unknown means malicious — it usually does not — but because you cannot protect a machine while there are things running on it that no one can account for.
Lesson 05
Who you are
Permission is not a setting. It is who you are.
You will be refused something, on purpose, and it will be the most useful answer of the lesson.
Every file on the machine belongs to a user, and carries a short note about who may read it, change it or run it. Every process belongs to a user too. When you try to do something, Linux does not ask what you intend — it checks who you are.
The root account can bypass many traditional file-permission checks, although capabilities and security policies can still restrict a process. On many systems, sudo can authorize a command with elevated privileges. That boundary deserves care because mistakes can affect the whole machine.
On your own machine
id — Who am I, exactly?
Your user number, your group, and the extra groups you belong to. If sudo is in that list, this account is allowed to borrow root — which is a privilege, not a default.
ls -l — Who owns these files?
The long form. Those letters at the start are the permissions, then the owner, then the size and the date. d at the very beginning means it is a folder.
cd /root — Try to go somewhere you should not.
Permission denied — and that is the system working correctly. /root is the root user’s own folder and you are not root. Being refused is information, not a fault.
sudo ls /root — Now borrow root.
The same request, with sudo in front, and now it is allowed. On a real machine this is the moment you would be asked for your password. Notice how little effort that was — which is exactly why sudo deserves respect.
Exercise
What does sudo do in this lesson?
Makes the command run fasterAuthorizes this command with root privilegesLogs you in as root permanentlySkips all safety checks
What does this answer mean?
Authorizes this command with root privileges
Yes. In this configured example, one command receives root privileges; sudo policy can differ on another system.
Security note
Why this matters later
A careless command with elevated privileges can cause serious damage. Before you press Enter on a sudo command, be able to say in one sentence what it will change.
Lesson 06
Programs that stay
Some things run because someone decided they always should.
Two questions that sound the same and are not: is it running, and will it come back?
In lesson 4 you saw processes. A systemd service describes how a program is managed. Whether systemd restarts it after failure depends on the unit’s restart policy; whether it is started during boot depends on enablement, dependencies and other activation mechanisms.
So there are two separate questions about any service, and mixing them up is one of the most common beginner mistakes. Is it running right now — that is active. Will it start again by itself next time the machine boots — that is enabled. A service can be either without the other.
On your own machine
systemctl status ssh — Tell me about this service.
The unit name and description, whether it is loaded, whether it is active, whether it is enabled, and the PID of the process behind it. This one screen connects a service to the process you already know how to find.
systemctl is-active ssh — Is it running now?
One word. Exactly the sort of answer you want when you are checking twenty things rather than reading about one.
systemctl is-enabled docker — Will it come back after a reboot?
Disabled — so no. Docker is installed on this machine but will not start by itself. Installed, running and enabled are three different states.
systemctl list-units — What services exist here?
The standing instructions on this machine. Most of them came with the system. A short list you can explain is worth far more than a long list you cannot.
Exercise
A service is active but disabled. What happens when you reboot?
It keeps runningIt does not startIt starts and stops againsystemd asks you
What does this answer mean?
It does not start
Correct. Active is only about now. Enabled is about next time — and disabled means it will not return.
Security note
Why this matters later
Enabled usually means a unit is linked into a boot target, but it does not prove that it will run successfully or that a disabled unit can never be activated another way. Check both unit-file state and what is actually running.
Lesson 07
On the network
Your machine has more than one address, and they mean different things.
One machine, three interfaces, and one of them does not go anywhere at all.
A network interface is a door to a network. Wired, wireless, or virtual — the machine treats them all the same way and gives each an address. Your laptop has several, and knowing which is which is most of what network trouble comes down to.
One of them is special. lo is the loopback interface, address 127.0.0.1, and it connects the machine to itself. In a normal host network, a service bound only to loopback is not directly reachable through an external interface. Keep that address in mind — the next lesson turns on it entirely.
On your own machine
ip -brief address — What are my addresses?
Every interface with its state and its address. lo is the machine talking to itself. wlan0 is the wireless card with a real address on a real network. docker0 is virtual, made by software, and currently down.
ip route — Where does traffic leave?
The first line is the important one: default via, followed by the address of your router. Anything not on your own network leaves through there.
hostname — What is this machine called?
The name the machine answers to. On a home network this is often how other devices find it.
Exercise
What can reach 127.0.0.1 on your machine?
Anyone on the internetAnyone on your home networkOnly programs on this machineOnly the router
What does this answer mean?
Only programs on this machine
Yes. 127.0.0.1 never leaves the machine. That single fact carries the whole of the next lesson.
Security note
Why this matters later
127.0.0.1 is the local loopback address. A listener on 0.0.0.0 binds to all local IPv4 interfaces, but actual reachability still depends on routing, firewalls, namespaces and other controls.
Lesson 08
What is listening
Some programs sit waiting for something to knock.
Eight open doors on a machine that looked idle.
A program can ask the system to hold a door open and wait. Somebody arrives, the program answers. That waiting door is a socket, the number on it is a port, and a program in that state is listening.
This is the question that lessons one to seven were built for. Reading the answer needs a process (lesson 4), a service (lesson 6) and an interface (lesson 7) to already mean something to you. Now look at what has been true of your machine the whole time.
On your own machine
ss -tulpn — What is listening?
Every waiting door. But look at the Process column — mostly empty. Without sudo the machine will not tell you who owns a socket that belongs to someone else, which is most of them.
sudo ss -tulpn — Now with the names.
The same doors, now with the program behind each one. This is the single most useful command in these ten lessons. Read it slowly: address, port, and the process that owns it.
cat project/server.py — What is that python3 one?
A note to yourself. Something started for a five-minute job, still listening on every interface. On a real machine this is exactly the kind of line you find and cannot justify.
Exercise
In this line, tap the part that determines the local bind scope.
0.0.0.0:22sshd
What does this answer mean?
0.0.0.0
Yes — the address, not the port. 0.0.0.0 binds on all local IPv4 interfaces; firewalls and routing still determine who can actually connect.
Security note
Why this matters later
Every listening socket is a door that answers when something knocks. You do not need to know how anyone would attack it. You need to know it is there, why it is there, and whether it should be — and you now have the command that tells you.
Lesson 09
Who can reach it
Your first real security judgement.
The same list as last lesson, sorted by a question rather than by port.
Now put two lessons together. From lesson 7 you know what addresses this machine has. From lesson 8 you know what is listening on them. Cross the two and you have the honest answer to who could reach this, which is the only version of the question that matters.
Three kinds of answer. Bound only to 127.0.0.1: normally local to this host. Bound to 0.0.0.0: listening on all local IPv4 interfaces, although routing and firewalls still control reachability. Multicast discovery is a separate case and should be assessed with its protocol and network scope.
On your own machine
sudo ss -tulpn — What is listening?
Sort them by bind address. 127.0.0.1 is loopback-only in the normal host network. 0.0.0.0 listens on every local IPv4 interface; then inspect firewall and routing rules to determine real reachability.
ip -brief address — Which networks does 0.0.0.0 mean?
This is what turns 0.0.0.0 from an abstraction into a fact. Every address here is somewhere those listeners can be reached from — right now, by anyone else on that network.
systemctl is-enabled cups — And will it still be there tomorrow?
Enabled, so yes. A printing service, listening, coming back after every reboot. Fine if you print. Worth a thought if you never do.
Exercise
Which deserves investigation first in this simulator?
127.0.0.1:631 cupsd0.0.0.0:22 sshd0.0.0.0:8000 python3127.0.0.53:53 systemd-resolve
What does this answer mean?
0.0.0.0:8000 python3
Yes. In this scenario, the unexplained python3 listener is bound to all local IPv4 interfaces and has no application authentication shown. SSH authentication can also use keys or policies rather than a password.
Security note
Why this matters later
Keep, restrict, remove, or find out more. Four honest decisions, and you now have enough to make them about your own machine. Notice that the reasoning never needed an attacker — only an accurate description of what is there.
Lesson 10
Write it down
What normal looks like, recorded on a day when nothing is wrong.
The last lesson produces a file instead of an answer.
A baseline is a short written description of what is normal for one machine, and why. Today it is worth almost nothing. In a month, when a line appears that you cannot explain, it is worth everything — because you will be able to tell that it is new.
That is all detection is. Not clever software: a description of normal, and the habit of comparing. Everything sophisticated in security is built on top of this one idea, and nothing works without it.
On your own machine
sudo ss -tulpn — What is listening today?
Copy the whole answer into a plain text file with today’s date on it. Beside each line, write one sentence saying why it is allowed to be there.
ip -brief address — On which networks?
Keep this next to the listener list, otherwise 0.0.0.0 means nothing to you when you read the file back in a month.
systemctl is-enabled ssh — And what comes back after a reboot?
Do this for anything you cared about above. Enabled is the part that persists, so it is the part worth recording.
Exercise
What makes a baseline useful?
It lists every command you knowIt proves the machine is secureIt lets you notice what changedIt replaces a firewall
What does this answer mean?
It lets you notice what changed
Exactly. A baseline does not protect anything. It makes change visible, which is the thing you could not do before.
Security note
Where this goes next
You have done a real piece of security work: an inventory, an exposure assessment and a written baseline, on a machine you understand. Everything after this — firewalls, monitoring, incident response — assumes someone did what you just did. Most of the time, nobody has.
Nederlands — Linux Basis
Tien lessen voor iemand die nog nooit een terminal heeft geopend.
Les 01
De terminal
Een plek waar je één zin typt en één antwoord krijgt.
Niets in deze les kan iets stukmaken. Elk commando hier kijkt alleen.
De terminal wacht. Je typt één instructie, je drukt op Enter, en hij antwoordt. Daarna wacht hij weer. Dat is het hele idee, en het wordt nooit ingewikkelder dan dit — alleen de instructies worden interessanter.
Voordat je iets typt, vertelt de terminal je al drie dingen. Je naam, de naam van de machine, en waar je staat. Dat korte regeltje voor de cursor heet de prompt, en zodra je hem kunt lezen ben je nooit meer verdwaald.
Een terminal openen
Elk systeem
Houd Ctrl en Alt samen ingedrukt en druk op T. Op de meeste Linux-systemen opent er direct een terminal.
Linux Mint
Klik op het menu linksonder, typ het woord terminal en open het zwarte icoon dat verschijnt.
Ubuntu
Druk op de Super-toets (die met het Windows-logo), typ terminal en druk op Enter.
Fedora
Druk op Super, typ terminal, druk op Enter. Of klik eerst linksboven op Activiteiten.
Op je eigen machine
pwd — Waar ben ik?
Een pad — het adres van de map waar je staat. Het begint bij / , de bovenkant van alles op deze machine, en eindigt bij je eigen map. Je eigen map is de enige plek waar je dingen mag veranderen zonder iets te vragen.
whoami — Wie ben ik?
Je gebruikersnaam. De machine houdt er één bij voor elke persoon en ook voor elk programma dat stil op de achtergrond draait. Later bepaalt deze naam wat je mag doen.
date — Werkt het eigenlijk?
De huidige tijd, volgens de machine. Een nutteloos commando met een echt doel: het bewijst dat de terminal luistert en antwoordt.
Oefening
Tik op het deel van dit pad dat de bovenkant van alles betekent.
/home/student
Wat betekent dit antwoord?
/
Ja. Elk pad op deze machine begint daar, en daarboven bestaat niets.
Veiligheidsnotitie
Waarom dit later belangrijk is
Een knop verbergt wat hij doet. Een commando zegt het hardop. Iedereen die serieus met veiligheid werkt — de mensen die een systeem verdedigen en de mensen die het aanvallen — komt hier uit, omdat de terminal precies is en een venster vol iconen dat niet is.
Les 02
Waar je bent
Alles op de machine hangt aan één punt.
Je gaat rondlopen en kijken, en er verandert niets.
Er is geen C-schijf en geen D-schijf. Alles op een Linux-machine hangt aan één punt dat / heet, en elk bestand heeft daaronder precies één adres. Jouw eigen dingen staan in /home en dan je naam.
Twee commando’s doen bijna al het lopen. ls laat zien wat hier staat. cd brengt je ergens anders. Twee puntjes betekenen de map erboven, en een losse ~ betekent altijd je eigen map, waar je ook bent.
Op je eigen machine
ls — Wat staat hier?
De namen van alles in deze map. Namen die eindigen op / zijn mappen waar je in kunt lopen. Niets hier is een verrassing — het is je eigen thuismap.
cd Documents — Loop een map in.
Helemaal geen antwoord. Dat is geen fout — Linux is stil als een commando werkt en zegt alleen iets als er iets misgaat. Voer nu pwd uit en je ziet dat je verplaatst bent.
cd .. — Ga één stap terug.
Twee puntjes betekenen altijd de map hierboven. Weer stilte, wat weer betekent dat het werkte.
ls -a — Wat was verborgen?
Namen die met een punt beginnen worden niet in gewone lijsten getoond. Ze zijn niet geheim en niet gevaarlijk — meestal bevatten ze instellingen voor programma’s die je gebruikt.
Oefening
Welk commando brengt je naar een andere map?
lscdpwdcat
Wat betekent dit antwoord?
cd
Ja. cd is change directory — het enige van de vier dat je verplaatst.
Veiligheidsnotitie
Waarom dit later belangrijk is
Waar een bestand staat en welke rechten het heeft, helpen bepalen wie het mag lezen. Een verkeerd geplaatst of te ruim leesbaar bestand kan gegevens blootstellen zonder ingewikkelde aanval.
Les 03
In een bestand kijken
Lezen is niet veranderen.
Elk commando hier opent een bestand en zet het op je scherm. Geen enkele kan één letter wijzigen.
In Linux ligt er een harde grens tussen kijken en aanraken. cat, head en less lezen alleen. Je kunt ze op alles richten wat je mag openen, en het bestand is daarna precies zoals het was.
Die grens is te vertrouwen, en dat betekent dat je vrij kunt onderzoeken. Bijna alles wat je ooit over een machine wilt weten kun je beantwoorden zonder hem te veranderen — en de gewoonte om eerst te lezen is wat iemand zorgvuldig maakt in plaats van iemand met geluk.
Op je eigen machine
cat notes.txt — Laat het hele bestand zien.
De volledige inhoud, in één keer. Prima voor iets korts. Bij een lang bestand zou het sneller voorbijschieten dan je kunt lezen, en daar zijn de volgende twee commando’s voor.
head shopping-list.txt — Alleen het begin.
De eerste tien regels. Als je alleen wilt weten wat voor bestand dit is, zijn tien regels meestal genoeg.
wc -l shopping-list.txt — Hoe lang is het?
Een aantal regels. Vaker nuttig dan je zou denken — het antwoordt op hoe groot is dit voordat je besluit hoe je ernaar gaat kijken.
cat /etc/os-release — Welke Linux is dit?
Een bestand dat het systeem over zichzelf bijhoudt. Merk op dat je iets buiten je eigen map kunt lezen: veel van de machine is voor iedereen leesbaar, en slechts een deel is beschermd.
Oefening
Je voert cat notes.txt twee keer uit. Wat is er met het bestand gebeurd?
Het is leeggemaaktHet is precies zoals het wasHet is gekopieerdHet is vergrendeld
Wat betekent dit antwoord?
Het is precies zoals het was
Precies. Een bestand lezen laat het onaangeroerd, hoe vaak je het ook doet.
Veiligheidsnotitie
Waarom dit later belangrijk is
Een zorgvuldig veiligheidsonderzoek begint vaak met observaties die het systeem niet veranderen. Je kijkt, legt vast wat je vond en beslist daarna pas wat eventueel moet veranderen. Zo behoud je bewijs en verklein je de kans op onbedoelde schade.
Les 04
Wat er draait
De machine doet veel meer dan jij gevraagd hebt.
Een lijst programma’s die je nooit gestart hebt, en die allemaal heel normaal draaien.
Een programma op de schijf is gewoon een bestand. Zodra het gaat draaien wordt het een proces, en de machine geeft het een nummer — een PID. Met dat nummer praat je over één bepaald draaiend ding.
De meeste processen op een Linux-machine zijn niet door jou gestart. Ze kwamen met het systeem en houden het werkend. Dit is de eerste les waarin je naar iets kijkt dat je niet op je scherm ziet, en de eerste lijst met namen die je niet kent. Dat is normaal, en dat kunnen zeggen is het punt.
Op je eigen machine
ps — Wat draai ik nu?
Bijna niets — alleen deze shell en het commando dat je typte. ps op zichzelf is bewust smal: het toont alleen wat bij dit terminalvenster hoort.
ps aux — Wat draait de hele machine?
Alles. De eerste kolom is wie elk proces bezit, de tweede is de PID. Merk op dat veel processen van root zijn en van namen als avahi of systemd, niet van jou.
top — Wat is nu bezig?
Hetzelfde idee, gesorteerd op hoeveel werk elk proces doet, en op een echte machine elke paar seconden verversend. Druk op q om eruit te gaan — daar loopt bijna iedereen de eerste keer op vast.
Oefening
Wat is een PID?
De naam van een programmaEen nummer dat één draaiend proces aanduidtDe gebruiker die het startteHoeveel geheugen het gebruikt
Wat betekent dit antwoord?
Een nummer dat één draaiend proces aanduidt
Ja. Eén nummer, één draaiend proces. Start hetzelfde programma twee keer en je hebt twee PID’s.
Veiligheidsnotitie
Waarom dit later belangrijk is
Een proces dat niemand kan uitleggen is het eerste waar een verdediger naar kijkt. Niet omdat onbekend kwaadaardig betekent — dat is het meestal niet — maar omdat je een machine niet kunt beschermen zolang er dingen op draaien waar niemand rekenschap van kan geven.
Les 05
Wie je bent
Toestemming is geen instelling. Het is wie je bent.
Je wordt iets geweigerd, met opzet, en dat is het nuttigste antwoord van de les.
Elk bestand op de machine hoort bij een gebruiker en draagt een kort briefje over wie het mag lezen, wijzigen of uitvoeren. Elk proces hoort ook bij een gebruiker. Als je iets probeert te doen, vraagt Linux niet wat je van plan bent — het controleert wie je bent.
Het root-account kan veel traditionele bestandsrechten omzeilen, al kunnen capabilities en beveiligingsbeleid een proces nog beperken. Op veel systemen kan sudo een commando met verhoogde rechten toestaan. Die grens verdient zorg, omdat fouten de hele machine kunnen raken.
Op je eigen machine
id — Wie ben ik precies?
Je gebruikersnummer, je groep, en de extra groepen waar je bij hoort. Staat sudo in die lijst, dan mag dit account root lenen — een voorrecht, geen standaard.
ls -l — Wie bezit deze bestanden?
De lange vorm. Die letters vooraan zijn de rechten, daarna de eigenaar, dan de grootte en de datum. Een d helemaal vooraan betekent dat het een map is.
cd /root — Probeer ergens te komen waar je niet mag.
Permission denied — en dat is het systeem dat correct werkt. /root is de eigen map van de root-gebruiker en jij bent root niet. Geweigerd worden is informatie, geen fout.
sudo ls /root — Leen nu root.
Hetzelfde verzoek, met sudo ervoor, en nu mag het wel. Op een echte machine zou je hier je wachtwoord moeten geven. Merk op hoe weinig moeite dat was — precies daarom verdient sudo respect.
Oefening
Wat doet sudo in deze les?
Het commando sneller laten draaienDit commando met rootrechten toestaanJe permanent inloggen als rootAlle controles overslaan
Wat betekent dit antwoord?
Dit commando met rootrechten toestaan
Ja. In dit ingestelde voorbeeld krijgt één commando rootrechten; sudo-beleid kan op een ander systeem verschillen.
Veiligheidsnotitie
Waarom dit later belangrijk is
Een onzorgvuldig commando met verhoogde rechten kan ernstige schade veroorzaken. Voordat je Enter indrukt bij een sudo-commando, moet je in één zin kunnen zeggen wat het gaat veranderen.
Les 06
Programma’s die blijven
Sommige dingen draaien omdat iemand besloot dat ze altijd moeten draaien.
Twee vragen die hetzelfde klinken en dat niet zijn: draait het, en komt het terug?
In les 4 zag je processen. Een systemd-dienst beschrijft hoe een programma wordt beheerd. Of systemd het na een fout herstart hangt af van het herstartbeleid; starten tijdens het opstarten hangt af van enablement, afhankelijkheden en andere activeringsmechanismen.
Er zijn dus twee losse vragen over elke dienst, en die verwarren is een van de meest gemaakte beginnersfouten. Draait het nu — dat is active. Start het bij de volgende keer opstarten vanzelf weer — dat is enabled. Een dienst kan het ene zijn zonder het andere.
Op je eigen machine
systemctl status ssh — Vertel me over deze dienst.
De naam en beschrijving, of hij geladen is, of hij actief is, of hij enabled is, en de PID van het proces erachter. Dit ene scherm verbindt een dienst met het proces dat je al kunt vinden.
systemctl is-active ssh — Draait het nu?
Eén woord. Precies het soort antwoord dat je wilt als je twintig dingen controleert in plaats van over één te lezen.
systemctl is-enabled docker — Komt het terug na een herstart?
Disabled — dus nee. Docker staat op deze machine maar start niet vanzelf. Geïnstalleerd, draaiend en enabled zijn drie verschillende toestanden.
systemctl list-units — Welke diensten bestaan hier?
De staande instructies op deze machine. De meeste kwamen met het systeem. Een korte lijst die je kunt uitleggen is veel meer waard dan een lange die je niet kunt uitleggen.
Oefening
Een dienst is active maar disabled. Wat gebeurt er bij een herstart?
Hij blijft draaienHij start nietHij start en stopt weersystemd vraagt het je
Wat betekent dit antwoord?
Hij start niet
Klopt. Active gaat alleen over nu. Enabled gaat over de volgende keer — en disabled betekent dat hij niet terugkomt.
Veiligheidsnotitie
Waarom dit later belangrijk is
Enabled betekent meestal dat een unit aan een opstartdoel is gekoppeld, maar bewijst niet dat hij succesvol draait of dat een disabled unit nooit anders geactiveerd wordt. Controleer zowel de unit-file-status als wat werkelijk draait.
Les 07
Op het netwerk
Je machine heeft meer dan één adres, en ze betekenen niet hetzelfde.
Eén machine, drie interfaces, en één ervan gaat helemaal nergens naartoe.
Een netwerkinterface is een deur naar een netwerk. Bedraad, draadloos of virtueel — de machine behandelt ze allemaal hetzelfde en geeft elk een adres. Je laptop heeft er meerdere, en weten welke welke is, is het grootste deel van netwerkproblemen.
Eén is bijzonder. lo is de loopback-interface, adres 127.0.0.1, en die verbindt de machine met zichzelf. In een normale hostnetwerkconfiguratie is een dienst die alleen aan loopback bindt niet rechtstreeks via een externe interface bereikbaar.
Op je eigen machine
ip -brief address — Wat zijn mijn adressen?
Elke interface met zijn toestand en adres. lo is de machine die tegen zichzelf praat. wlan0 is de wifikaart met een echt adres op een echt netwerk. docker0 is virtueel, door software gemaakt, en nu uit.
ip route — Waar gaat verkeer naar buiten?
De eerste regel is de belangrijke: default via, gevolgd door het adres van je router. Alles wat niet op je eigen netwerk staat gaat daar naar buiten.
hostname — Hoe heet deze machine?
De naam waarop de machine reageert. Op een thuisnetwerk vinden andere apparaten hem hier vaak mee.
Oefening
Wie kan 127.0.0.1 op jouw machine bereiken?
Iedereen op internetIedereen op je thuisnetwerkAlleen programma’s op deze machineAlleen de router
Wat betekent dit antwoord?
Alleen programma’s op deze machine
Ja. 127.0.0.1 verlaat de machine nooit. Dat ene feit draagt de hele volgende les.
Veiligheidsnotitie
Waarom dit later belangrijk is
127.0.0.1 is het lokale loopbackadres. Een listener op 0.0.0.0 bindt aan alle lokale IPv4-interfaces, maar werkelijke bereikbaarheid hangt ook af van routing, firewalls, namespaces en andere controles.
Les 08
Wat er luistert
Sommige programma’s zitten te wachten tot er geklopt wordt.
Acht open deuren op een machine die stil leek te staan.
Een programma kan het systeem vragen een deur open te houden en te wachten. Er komt iemand, het programma antwoordt. Die wachtende deur is een socket, het nummer erop is een poort, en een programma in die toestand luistert.
Dit is de vraag waarvoor de lessen één tot zeven gebouwd zijn. Om het antwoord te lezen moeten een proces (les 4), een dienst (les 6) en een interface (les 7) al iets voor je betekenen. Kijk nu naar wat de hele tijd waar was van je machine.
Op je eigen machine
ss -tulpn — Wat luistert er?
Elke wachtende deur. Maar kijk naar de kolom Process — vooral leeg. Zonder sudo vertelt de machine niet wie een socket bezit die van iemand anders is, en dat zijn de meeste.
sudo ss -tulpn — Nu met de namen.
Dezelfde deuren, nu met het programma erachter. Dit is het nuttigste commando van deze tien lessen. Lees het langzaam: adres, poort, en het proces dat het bezit.
cat project/server.py — Wat is die python3 dan?
Een briefje aan jezelf. Iets dat voor een klusje van vijf minuten gestart is en nog steeds op elke interface luistert. Op een echte machine is dit precies het soort regel dat je vindt en niet kunt verantwoorden.
Oefening
Tik in deze regel op het deel dat het lokale bindbereik bepaalt.
0.0.0.0:22sshd
Wat betekent dit antwoord?
0.0.0.0
Ja — het adres, niet de poort. 0.0.0.0 bindt aan alle lokale IPv4-interfaces; routing en firewalls bepalen nog wie werkelijk kan verbinden.
Veiligheidsnotitie
Waarom dit later belangrijk is
Elke luisterende socket is een deur die antwoordt als er geklopt wordt. Je hoeft niet te weten hoe iemand hem zou aanvallen. Je moet weten dat hij er is, waarom hij er is, en of dat zo moet blijven — en je hebt nu het commando dat je dat vertelt.
Les 09
Wie erbij kan
Je eerste echte veiligheidsafweging.
Dezelfde lijst als vorige les, gesorteerd op een vraag in plaats van op poort.
Leg nu twee lessen bij elkaar. Uit les 7 weet je welke adressen deze machine heeft. Uit les 8 weet je wat daarop luistert. Kruis die twee en je hebt het eerlijke antwoord op wie hier bij zou kunnen, wat de enige versie van de vraag is die telt.
Drie soorten antwoord. Alleen gebonden aan 127.0.0.1: normaal lokaal voor deze host. Gebonden aan 0.0.0.0: luisterend op alle lokale IPv4-interfaces, terwijl routing en firewalls de bereikbaarheid blijven bepalen. Multicast discovery is een afzonderlijk geval dat je per protocol en netwerkbereik beoordeelt.
Op je eigen machine
sudo ss -tulpn — Wat luistert er?
Sorteer ze op bindadres. 127.0.0.1 blijft in het normale hostnetwerk op loopback. 0.0.0.0 luistert op alle lokale IPv4-interfaces; controleer daarna firewall en routing voor de werkelijke bereikbaarheid.
ip -brief address — Welke netwerken bedoelt 0.0.0.0?
Dit maakt van 0.0.0.0 een feit in plaats van een abstractie. Elk adres hier is een plek waar die luisteraars vandaan te bereiken zijn — nu, door iedereen anders op dat netwerk.
systemctl is-enabled cups — En staat het er morgen nog?
Enabled, dus ja. Een printdienst, luisterend, terugkomend na elke herstart. Prima als je print. Even nadenken waard als je dat nooit doet.
Oefening
Welke verdient in deze simulator als eerste onderzoek?
127.0.0.1:631 cupsd0.0.0.0:22 sshd0.0.0.0:8000 python3127.0.0.53:53 systemd-resolve
Wat betekent dit antwoord?
0.0.0.0:8000 python3
Ja. In dit scenario bindt de onverklaarde python3-listener aan alle lokale IPv4-interfaces en is geen applicatie-authenticatie zichtbaar. SSH kan ook sleutels of ander beleid gebruiken in plaats van een wachtwoord.
Veiligheidsnotitie
Waarom dit later belangrijk is
Houden, beperken, weghalen, of meer uitzoeken. Vier eerlijke beslissingen, en je hebt nu genoeg om ze over je eigen machine te nemen. Merk op dat het denkwerk nooit een aanvaller nodig had — alleen een nauwkeurige beschrijving van wat er is.
Les 10
Schrijf het op
Hoe normaal eruitziet, vastgelegd op een dag dat er niets aan de hand is.
De laatste les levert een bestand op in plaats van een antwoord.
Een baseline is een korte geschreven beschrijving van wat normaal is voor één machine, en waarom. Vandaag is die bijna niets waard. Over een maand, als er een regel opduikt die je niet kunt uitleggen, is hij alles waard — omdat je dan kunt zien dat hij nieuw is.
Dat is alles wat detectie is. Geen slimme software: een beschrijving van normaal, en de gewoonte om te vergelijken. Alles wat geavanceerd is in veiligheid staat op dit ene idee, en zonder dit werkt niets.
Op je eigen machine
sudo ss -tulpn — Wat luistert er vandaag?
Kopieer het hele antwoord naar een tekstbestand met de datum van vandaag erop. Schrijf naast elke regel één zin waarom hij daar mag zijn.
ip -brief address — Op welke netwerken?
Zet dit naast de lijst met luisteraars, anders betekent 0.0.0.0 niets voor je als je het bestand over een maand teruglees.
systemctl is-enabled ssh — En wat komt terug na een herstart?
Doe dit voor alles waar je hierboven om gaf. Enabled is het deel dat blijft, dus dat is het deel dat het opschrijven waard is.
Oefening
Wat maakt een baseline nuttig?
Hij bevat elk commando dat je kentHij bewijst dat de machine veilig isJe merkt eraan wat er veranderd isHij vervangt een firewall
Wat betekent dit antwoord?
Je merkt eraan wat er veranderd is
Precies. Een baseline beschermt niets. Hij maakt verandering zichtbaar, en dat kon je daarvoor niet.
Veiligheidsnotitie
Waar dit verder gaat
Je hebt echt veiligheidswerk gedaan: een inventarisatie, een beoordeling van blootstelling en een geschreven baseline, op een machine die je begrijpt. Alles hierna — firewalls, monitoring, incidentrespons — gaat ervan uit dat iemand deed wat jij net deed. Meestal heeft niemand dat gedaan.
Français — Linux Débutant
Dix leçons pour quelqu’un qui n’a jamais ouvert un terminal.
Leçon 01
Le terminal
Un endroit où vous tapez une phrase et obtenez une réponse.
Rien dans cette leçon ne peut rien casser. Chaque commande ici ne fait que regarder.
Le terminal attend. Vous tapez une instruction, vous appuyez sur Entrée, et il répond. Puis il attend à nouveau. C’est toute l’idée, et cela ne devient jamais plus compliqué — seules les instructions deviennent plus intéressantes.
Avant même que vous tapiez, le terminal vous dit déjà trois choses. Votre nom, le nom de la machine, et où vous vous trouvez à l’intérieur. Cette courte ligne devant le curseur s’appelle l’invite, et dès que vous savez la lire vous n’êtes plus jamais perdu.
Ouvrir un terminal
Tout système
Maintenez Ctrl et Alt ensemble, puis appuyez sur T. Sur la plupart des systèmes Linux un terminal s’ouvre aussitôt.
Linux Mint
Cliquez sur le menu en bas à gauche, tapez le mot terminal, et ouvrez l’icône noire qui apparaît.
Ubuntu
Appuyez sur la touche Super (celle avec le logo Windows), tapez terminal, puis Entrée.
Fedora
Appuyez sur Super, tapez terminal, puis Entrée. Ou cliquez d’abord sur Activités en haut à gauche.
Sur votre propre machine
pwd — Où suis-je ?
Un chemin — l’adresse du dossier où vous vous trouvez. Il commence par / , le sommet de tout sur cette machine, et se termine à votre propre dossier. Votre dossier est le seul endroit où vous pouvez changer des choses sans rien demander.
whoami — Qui suis-je ?
Votre nom d’utilisateur. La machine en garde un pour chaque personne et aussi pour chaque programme qui tourne discrètement en arrière-plan. Plus tard, ce nom décide de ce que vous avez le droit de faire.
date — Est-ce que ça marche vraiment ?
L’heure actuelle, selon la machine. Une commande inutile avec un vrai but : elle prouve que le terminal écoute et répond.
Exercice
Touchez la partie de ce chemin qui signifie le sommet de tout.
/home/student
Que signifie cette réponse ?
/
Oui. Tous les chemins de cette machine commencent là, et rien n’existe au-dessus.
Note de sécurité
Pourquoi cela comptera plus tard
Un bouton cache ce qu’il fait. Une commande le dit à voix haute. Tous ceux qui travaillent sérieusement en sécurité — ceux qui défendent un système comme ceux qui l’attaquent — finissent ici, parce que le terminal est exact et qu’une fenêtre pleine d’icônes ne l’est pas.
Leçon 02
Où vous êtes
Tout sur la machine part d’un seul point.
Vous allez vous déplacer et regarder, et rien ne changera.
Il n’y a pas de disque C ni de disque D. Tout sur une machine Linux part d’un point unique appelé / , et chaque fichier a exactement une adresse en dessous. Vos affaires sont dans /home puis votre nom.
Deux commandes font presque toute la marche. ls montre ce qui est ici. cd vous emmène ailleurs. Deux points signifient le dossier au-dessus, et un ~ seul signifie toujours votre propre dossier, où que vous soyez.
Sur votre propre machine
ls — Qu’y a-t-il ici ?
Les noms de tout ce qui se trouve dans ce dossier. Les noms finissant par / sont des dossiers dans lesquels vous pouvez entrer. Rien ici n’est une surprise — c’est votre propre dossier personnel.
cd Documents — Entrez dans un dossier.
Aucune réponse du tout. Ce n’est pas un échec — Linux se tait quand une commande fonctionne et ne parle que si quelque chose va mal. Lancez pwd maintenant et vous verrez que vous avez bougé.
cd .. — Remontez d’un cran.
Deux points signifient toujours le dossier au-dessus. Silence à nouveau, ce qui veut dire à nouveau que ça a marché.
ls -a — Qu’est-ce qui était caché ?
Les noms qui commencent par un point ne s’affichent pas dans les listes ordinaires. Ils ne sont ni secrets ni dangereux — le plus souvent ils contiennent des réglages de programmes que vous utilisez.
Exercice
Quelle commande vous déplace dans un autre dossier ?
lscdpwdcat
Que signifie cette réponse ?
cd
Oui. cd veut dire change directory — la seule des quatre qui vous déplace.
Note de sécurité
Pourquoi cela comptera plus tard
L’emplacement et les permissions d’un fichier contribuent à déterminer qui peut le lire. Un fichier mal placé ou trop lisible peut exposer des données sans attaque sophistiquée.
Leçon 03
Regarder dans un fichier
Lire n’est pas modifier.
Chaque commande ici ouvre un fichier et l’affiche. Aucune ne peut changer une seule lettre.
Il y a une frontière nette sous Linux entre regarder et toucher. cat, head et less ne font que lire. Vous pouvez les pointer sur tout ce que vous avez le droit d’ouvrir, et le fichier sera après exactement tel qu’il était.
Cette frontière mérite votre confiance, car elle vous permet d’enquêter librement. Presque tout ce que vous voudrez savoir sur une machine peut être répondu sans la modifier — et l’habitude de lire d’abord est ce qui sépare quelqu’un de soigneux de quelqu’un de chanceux.
Sur votre propre machine
cat notes.txt — Montre-moi tout le fichier.
Le contenu entier, d’un coup. Très bien pour quelque chose de court. Sur un long fichier cela défilerait plus vite que vous ne pouvez lire, et c’est à cela que servent les deux commandes suivantes.
head shopping-list.txt — Juste le début.
Les dix premières lignes. Quand vous voulez seulement savoir de quel genre de fichier il s’agit, dix lignes suffisent presque toujours.
wc -l shopping-list.txt — Quelle longueur ?
Un décompte de lignes. Utile plus souvent qu’on ne le croit — cela répond à quelle taille avant de décider comment le regarder.
cat /etc/os-release — Quel Linux est-ce ?
Un fichier que le système garde sur lui-même. Notez que vous pouvez lire quelque chose en dehors de votre dossier : une bonne partie de la machine est lisible par tous, et seule une partie est protégée.
Exercice
Vous lancez cat notes.txt deux fois. Qu’est-il arrivé au fichier ?
Il a été vidéIl est exactement comme avantIl a été copiéIl a été verrouillé
Que signifie cette réponse ?
Il est exactement comme avant
Exactement. Lire un fichier le laisse intact, quel que soit le nombre de fois.
Note de sécurité
Pourquoi cela comptera plus tard
Un examen de sécurité prudent commence souvent par des observations qui ne modifient pas le système. On regarde, on consigne les faits, puis on décide de ce qui doit éventuellement changer. Cela préserve les preuves et réduit les dégâts accidentels.
Leçon 04
Ce qui tourne
La machine fait bien plus que ce que vous lui avez demandé.
Une liste de programmes que vous n’avez jamais lancés, et qui tournent tout à fait normalement.
Un programme posé sur le disque n’est qu’un fichier. Dès qu’il se met à tourner il devient un processus, et la machine lui donne un numéro — un PID. Ce numéro est ce qui permet de parler d’une chose en cours précise.
La plupart des processus d’une machine Linux n’ont pas été lancés par vous. Ils sont venus avec le système et le font fonctionner. C’est la première leçon où vous regardez quelque chose d’invisible à l’écran, et la première liste avec des noms que vous ne connaissez pas. C’est normal, et savoir le dire est justement le but.
Sur votre propre machine
ps — Qu’est-ce que je fais tourner maintenant ?
Presque rien — juste ce shell et la commande que vous avez tapée. ps seul est volontairement étroit : il ne montre que ce qui appartient à cette fenêtre de terminal.
ps aux — Que fait tourner la machine entière ?
Tout. La première colonne dit à qui appartient chaque processus, la deuxième est son PID. Notez que beaucoup appartiennent à root et à des noms comme avahi ou systemd, pas à vous.
top — Qu’est-ce qui travaille en ce moment ?
La même idée, triée selon la charge de chaque processus et rafraîchie toutes les quelques secondes sur une vraie machine. Appuyez sur q pour sortir — presque tout le monde s’y fait piéger la première fois.
Exercice
Qu’est-ce qu’un PID ?
Le nom d’un programmeUn numéro identifiant un processus en coursL’utilisateur qui l’a lancéLa mémoire qu’il utilise
Que signifie cette réponse ?
Un numéro identifiant un processus en cours
Oui. Un numéro, un processus en cours. Lancez deux fois le même programme et vous obtenez deux PID.
Note de sécurité
Pourquoi cela comptera plus tard
Un processus que personne ne peut expliquer est la première chose qu’un défenseur regarde. Non parce qu’inconnu veut dire malveillant — ce n’est généralement pas le cas — mais parce qu’on ne peut pas protéger une machine tant qu’il y tourne des choses dont personne ne peut rendre compte.
Leçon 05
Qui vous êtes
La permission n’est pas un réglage. C’est qui vous êtes.
On va vous refuser quelque chose, exprès, et ce sera la réponse la plus utile de la leçon.
Chaque fichier de la machine appartient à un utilisateur et porte une courte note sur qui peut le lire, le modifier ou l’exécuter. Chaque processus appartient aussi à un utilisateur. Quand vous tentez quelque chose, Linux ne demande pas vos intentions — il vérifie qui vous êtes.
Le compte root peut contourner de nombreux contrôles de permissions traditionnels, même si les capabilities et les politiques de sécurité peuvent encore limiter un processus. Sur beaucoup de systèmes, sudo peut autoriser une commande avec des privilèges élevés.
Sur votre propre machine
id — Qui suis-je, exactement ?
Votre numéro d’utilisateur, votre groupe, et les groupes supplémentaires auxquels vous appartenez. Si sudo est dans cette liste, ce compte peut emprunter root — un privilège, pas un réglage par défaut.
ls -l — À qui appartiennent ces fichiers ?
La forme longue. Ces lettres au début sont les permissions, puis le propriétaire, puis la taille et la date. Un d tout au début signifie que c’est un dossier.
cd /root — Essayez d’aller où vous ne devez pas.
Permission denied — et c’est le système qui fonctionne correctement. /root est le dossier de l’utilisateur root et vous n’êtes pas root. Être refusé est une information, pas une faute.
sudo ls /root — Empruntez root maintenant.
La même demande, avec sudo devant, et cette fois c’est permis. Sur une vraie machine c’est le moment où l’on vous demanderait votre mot de passe. Remarquez le peu d’effort — et c’est exactement pourquoi sudo mérite du respect.
Exercice
Que fait sudo dans cette leçon ?
Il accélère la commandeIl autorise cette commande avec les privilèges rootIl vous connecte en root définitivementIl désactive toutes les vérifications
Que signifie cette réponse ?
Il autorise cette commande avec les privilèges root
Oui. Dans cet exemple configuré, une commande reçoit les privilèges root ; la politique sudo peut différer ailleurs.
Note de sécurité
Pourquoi cela comptera plus tard
Une commande négligente exécutée avec des privilèges élevés peut causer de graves dégâts. Avant d’appuyer sur Entrée pour une commande sudo, soyez capable de dire en une phrase ce qu’elle va changer.
Leçon 06
Les programmes qui restent
Certaines choses tournent parce que quelqu’un a décidé qu’elles devaient toujours tourner.
Deux questions qui se ressemblent et qui ne sont pas les mêmes : est-ce que ça tourne, et est-ce que ça reviendra ?
À la leçon 4 vous avez vu des processus. Un service systemd décrit comment un programme est géré. Son redémarrage après un échec dépend de la politique de redémarrage ; son lancement au démarrage dépend de l’activation, des dépendances et d’autres mécanismes.
Il y a donc deux questions distinctes sur tout service, et les confondre est l’une des erreurs de débutant les plus fréquentes. Est-ce que ça tourne maintenant — c’est active. Est-ce que ça redémarrera tout seul au prochain démarrage — c’est enabled. Un service peut être l’un sans l’autre.
Sur votre propre machine
systemctl status ssh — Parle-moi de ce service.
Le nom de l’unité et sa description, s’il est chargé, s’il est actif, s’il est activé, et le PID du processus derrière. Cet écran relie un service au processus que vous savez déjà trouver.
systemctl is-active ssh — Est-ce que ça tourne maintenant ?
Un mot. Exactement le genre de réponse qu’on veut quand on vérifie vingt choses plutôt que d’en lire une.
systemctl is-enabled docker — Est-ce que ça revient après un redémarrage ?
Disabled — donc non. Docker est installé sur cette machine mais ne démarrera pas seul. Installé, en cours et activé sont trois états différents.
systemctl list-units — Quels services existent ici ?
Les instructions permanentes de cette machine. La plupart sont venues avec le système. Une courte liste que vous pouvez expliquer vaut bien plus qu’une longue que vous ne pouvez pas.
Exercice
Un service est active mais disabled. Que se passe-t-il au redémarrage ?
Il continue de tournerIl ne démarre pasIl démarre puis s’arrêtesystemd vous demande
Que signifie cette réponse ?
Il ne démarre pas
Correct. Active ne parle que du présent. Enabled parle de la prochaine fois — et disabled veut dire qu’il ne reviendra pas.
Note de sécurité
Pourquoi cela comptera plus tard
Enabled signifie généralement qu’une unité est liée à une cible de démarrage, mais ne prouve pas qu’elle fonctionnera ni qu’une unité disabled ne peut jamais être activée autrement. Vérifiez l’état du fichier d’unité et ce qui tourne réellement.
Leçon 07
Sur le réseau
Votre machine a plus d’une adresse, et elles ne veulent pas dire la même chose.
Une machine, trois interfaces, et l’une d’elles ne va nulle part du tout.
Une interface réseau est une porte vers un réseau. Filaire, sans fil ou virtuelle — la machine les traite toutes pareil et donne à chacune une adresse. Votre portable en a plusieurs, et savoir laquelle est laquelle représente l’essentiel des problèmes de réseau.
L’une est particulière. lo est l’interface de bouclage, adresse 127.0.0.1, et elle relie la machine à elle-même. Dans une configuration réseau hôte normale, un service lié uniquement au bouclage n’est pas directement joignable par une interface externe.
Sur votre propre machine
ip -brief address — Quelles sont mes adresses ?
Chaque interface avec son état et son adresse. lo est la machine qui se parle à elle-même. wlan0 est la carte sans fil avec une vraie adresse sur un vrai réseau. docker0 est virtuelle, créée par un logiciel, et actuellement éteinte.
ip route — Par où sort le trafic ?
La première ligne est l’importante : default via, suivi de l’adresse de votre routeur. Tout ce qui n’est pas sur votre réseau sort par là.
hostname — Comment s’appelle cette machine ?
Le nom auquel la machine répond. Sur un réseau domestique, c’est souvent ainsi que les autres appareils la trouvent.
Exercice
Qui peut atteindre 127.0.0.1 sur votre machine ?
N’importe qui sur internetN’importe qui sur votre réseauSeuls les programmes de cette machineSeul le routeur
Que signifie cette réponse ?
Seuls les programmes de cette machine
Oui. 127.0.0.1 ne quitte jamais la machine. Ce seul fait porte toute la leçon suivante.
Note de sécurité
Pourquoi cela comptera plus tard
127.0.0.1 est l’adresse de bouclage locale. Un service sur 0.0.0.0 se lie à toutes les interfaces IPv4 locales, mais sa joignabilité dépend aussi du routage, des pare-feux, des namespaces et d’autres contrôles.
Leçon 08
Ce qui écoute
Certains programmes attendent qu’on frappe à la porte.
Huit portes ouvertes sur une machine qui semblait au repos.
Un programme peut demander au système de tenir une porte ouverte et d’attendre. Quelqu’un arrive, le programme répond. Cette porte qui attend est un socket, le numéro dessus est un port, et un programme dans cet état écoute.
C’est la question pour laquelle les leçons un à sept ont été construites. Lire la réponse demande qu’un processus (leçon 4), un service (leçon 6) et une interface (leçon 7) veuillent déjà dire quelque chose pour vous. Regardez maintenant ce qui était vrai de votre machine depuis le début.
Sur votre propre machine
ss -tulpn — Qu’est-ce qui écoute ?
Chaque porte qui attend. Mais regardez la colonne Process — presque vide. Sans sudo la machine ne dit pas qui possède un socket appartenant à quelqu’un d’autre, et c’est le cas de la plupart.
sudo ss -tulpn — Maintenant avec les noms.
Les mêmes portes, avec le programme derrière chacune. C’est la commande la plus utile de ces dix leçons. Lisez-la lentement : adresse, port, et le processus qui la possède.
cat project/server.py — C’est quoi ce python3 ?
Une note à vous-même. Quelque chose lancé pour cinq minutes de travail, toujours à l’écoute sur toutes les interfaces. Sur une vraie machine, c’est exactement le genre de ligne qu’on trouve et qu’on ne peut pas justifier.
Exercice
Dans cette ligne, touchez la partie qui détermine la portée de liaison locale.
0.0.0.0:22sshd
Que signifie cette réponse ?
0.0.0.0
Oui — l’adresse, pas le port. 0.0.0.0 lie le service à toutes les interfaces IPv4 locales ; le routage et les pare-feux déterminent encore qui peut se connecter.
Note de sécurité
Pourquoi cela comptera plus tard
Chaque socket à l’écoute est une porte qui répond quand on frappe. Vous n’avez pas besoin de savoir comment quelqu’un l’attaquerait. Vous avez besoin de savoir qu’elle est là, pourquoi elle est là, et si elle devrait l’être — et vous avez maintenant la commande qui vous le dit.
Leçon 09
Qui peut l’atteindre
Votre premier vrai jugement de sécurité.
La même liste que la leçon précédente, triée par une question plutôt que par port.
Assemblez maintenant deux leçons. De la leçon 7 vous savez quelles adresses a cette machine. De la leçon 8 vous savez ce qui écoute dessus. Croisez les deux et vous avez la réponse honnête à qui pourrait atteindre ceci, la seule version de la question qui compte.
Trois types de réponse. Lié uniquement à 127.0.0.1 : normalement local à cet hôte. Lié à 0.0.0.0 : à l’écoute sur toutes les interfaces IPv4 locales, tandis que le routage et les pare-feux contrôlent encore la joignabilité. La découverte multicast est un cas distinct à évaluer selon son protocole et sa portée.
Sur votre propre machine
sudo ss -tulpn — Qu’est-ce qui écoute ?
Triez-les par adresse de liaison. 127.0.0.1 reste sur le bouclage dans le réseau hôte normal. 0.0.0.0 écoute sur toutes les interfaces IPv4 locales ; examinez ensuite pare-feu et routage pour connaître la joignabilité réelle.
ip -brief address — Quels réseaux veut dire 0.0.0.0 ?
C’est ce qui transforme 0.0.0.0 d’une abstraction en un fait. Chaque adresse ici est un endroit d’où ces programmes peuvent être atteints — maintenant, par n’importe qui d’autre sur ce réseau.
systemctl is-enabled cups — Et sera-ce encore là demain ?
Enabled, donc oui. Un service d’impression, à l’écoute, qui revient après chaque redémarrage. Très bien si vous imprimez. Digne d’une pensée si vous ne le faites jamais.
Exercice
Lequel mérite d’être examiné en premier dans ce simulateur ?
127.0.0.1:631 cupsd0.0.0.0:22 sshd0.0.0.0:8000 python3127.0.0.53:53 systemd-resolve
Que signifie cette réponse ?
0.0.0.0:8000 python3
Oui. Dans ce scénario, le service python3 inexpliqué écoute sur toutes les interfaces IPv4 locales et aucune authentification applicative n’est montrée. SSH peut aussi utiliser des clés ou d’autres politiques.
Note de sécurité
Pourquoi cela comptera plus tard
Garder, restreindre, retirer, ou en savoir plus. Quatre décisions honnêtes, et vous avez maintenant de quoi les prendre sur votre propre machine. Remarquez que le raisonnement n’a jamais eu besoin d’un attaquant — seulement d’une description exacte de ce qui est là.
Leçon 10
Écrivez-le
À quoi ressemble la normale, notée un jour où rien ne va mal.
La dernière leçon produit un fichier au lieu d’une réponse.
Une référence est une courte description écrite de ce qui est normal pour une machine, et pourquoi. Aujourd’hui elle ne vaut presque rien. Dans un mois, quand une ligne apparaîtra que vous ne pouvez pas expliquer, elle vaudra tout — parce que vous pourrez voir qu’elle est nouvelle.
C’est tout ce qu’est la détection. Pas un logiciel astucieux : une description du normal, et l’habitude de comparer. Tout ce qui est sophistiqué en sécurité est bâti sur cette seule idée, et rien ne marche sans elle.
Sur votre propre machine
sudo ss -tulpn — Qu’est-ce qui écoute aujourd’hui ?
Copiez toute la réponse dans un fichier texte portant la date du jour. À côté de chaque ligne, écrivez une phrase disant pourquoi elle a le droit d’être là.
ip -brief address — Sur quels réseaux ?
Gardez ceci à côté de la liste, sinon 0.0.0.0 ne voudra rien dire pour vous quand vous relirez le fichier dans un mois.
systemctl is-enabled ssh — Et qu’est-ce qui revient après un redémarrage ?
Faites-le pour tout ce qui vous a intéressé plus haut. Enabled est la partie qui persiste, donc c’est la partie qui vaut d’être notée.
Exercice
Qu’est-ce qui rend une référence utile ?
Elle liste toutes les commandes connuesElle prouve que la machine est sûreElle permet de remarquer ce qui a changéElle remplace un pare-feu
Que signifie cette réponse ?
Elle permet de remarquer ce qui a changé
Exactement. Une référence ne protège rien. Elle rend le changement visible, ce que vous ne pouviez pas faire avant.
Note de sécurité
La suite
Vous avez fait un vrai travail de sécurité : un inventaire, une évaluation de l’exposition et une référence écrite, sur une machine que vous comprenez. Tout ce qui vient après — pare-feux, surveillance, réponse aux incidents — suppose que quelqu’un a fait ce que vous venez de faire. La plupart du temps, personne ne l’a fait.