↑ ↓ select, Enter open, Esc close

Security

Harden servers and detect attacks: Fail2ban, firewall rules, suspicious files, login attempts and quick checks after an incident.

18 one-liners: 16 harmless, 2 caution, 0 destructive

All Security one-liners

Block a single IP address immediately with iptables

#iptables -I INPUT -s 203.0.113.25 -j DROP
caution

Detect modified files of installed packages

#dpkg --verify
harmless

Find accounts with UID 0 and root privileges

$awk -F: '$3 == 0 {print $1}' /etc/passwd
harmless

Find hidden PHP files in the web directory

$find /var/www/vhosts/example.com/httpdocs -type f -name '.*.php' -ls
harmless

Find PHP files in the WordPress uploads folder

$find /var/www/vhosts/example.com/httpdocs/wp-content/uploads -type f \( -iname '*.php' -o -iname '*.phtml' -o -iname '*.php[0-9]' \) -ls
harmless

Find processes whose executable was deleted

#ls -l /proc/*/exe 2>/dev/null | grep '(deleted)'
harmless

For the websites on your server

Free SEO and PageSpeed check

GENLOC.SEO analyzes any domain for load time, Core Web Vitals and on-page issues and tells you in plain words what is going on. Available in 11 languages.

by GENLOC.NETWORK, the team behind myline.de

Find recently modified PHP files

$find /var/www/vhosts/example.com/httpdocs -type f -name '*.php' -mtime -7 -printf '%TY-%Tm-%Td %TH:%TM %p\n' | sort -r
harmless

Find world-writable files and directories

$find /var/www/vhosts -xdev -perm -0002 ! -type l -ls 2>/dev/null
harmless

IP addresses with the most failed SSH logins

#journalctl -u ssh --since "24 hours ago" --no-pager | grep -oE 'Failed password for .* from [0-9a-f.:]+' | awk '{print $NF}' | sort | uniq -c | sort -rn | head -20
harmless

List all SSH keys authorized on the server

#find / -xdev -path '*/.ssh/authorized_keys' -type f -exec awk 'NF && !/^#/ {print FILENAME ": " $NF}' {} + 2>/dev/null
harmless

List the members of the sudo group

$getent group sudo
harmless

List user accounts with a login shell

$awk -F: '$7 !~ /(nologin|false)$/ {print $1, $3, $6, $7}' /etc/passwd
harmless

Search PHP files for typical malware patterns

$grep -rlE --include='*.php' 'eval\((base64_decode|gzinflate|gzuncompress|str_rot13)\(' /var/www/vhosts/example.com/httpdocs
harmless

Show commands run with sudo from the journal

#journalctl _COMM=sudo --since "7 days ago" --no-pager | grep 'COMMAND='
harmless

Show recent server logins with IP address

$last -i | head -30
harmless

Show the password status of all user accounts

#passwd -S -a
harmless

Show the status of a Fail2Ban jail and banned IPs

#fail2ban-client status sshd
harmless

Unban an IP address in Fail2Ban

#fail2ban-client set sshd unbanip 203.0.113.25
caution

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.