↑ ↓ select, Enter open, Esc close

#security

18 one-liners with this tag.

All one-liners tagged security

Securely overwrite and delete a file

$shred -u -z -n 3 -- /root/old-dump.sql
destructiveFilesystem

Check Composer packages for known vulnerabilities

$composer audit --working-dir=/var/www/vhosts/example.com/httpdocs
harmlessPHP

Check whether a server supports TLS 1.3

$openssl s_client -connect example.com:443 -servername example.com -tls1_3 </dev/null 2>/dev/null | grep -E "^New,|Protocol *:"
harmlessSSL and certificates

Check WordPress core files for tampering

$wp core verify-checksums --path=/var/www/vhosts/example.com/httpdocs
harmlessWP-CLI

Compare plugin files with the originals from wordpress.org

$wp plugin verify-checksums --all --path=/var/www/vhosts/example.com/httpdocs
harmlessWP-CLI

Find a hacked mail account by its SMTP logins

#grep -o "sasl_username=[^ ,]*" /var/log/maillog | sort | uniq -c | sort -rn | head -20
harmlessMail

Find files with the SUID or SGID bit

#find / -xdev \( -perm -4000 -o -perm -2000 \) -type f -exec ls -l {} + 2>/dev/null
harmlessPermissions and ownership

Find world-writable files and directories

$find /var/www/vhosts -xdev -perm -0002 ! -type l -ls 2>/dev/null
harmlessPermissions and ownership

List all MySQL users with their host

#mysql -e 'SELECT user, host FROM mysql.user ORDER BY user;'
harmlessMySQL and MariaDB

List all WordPress administrators

$wp user list --role=administrator --fields=ID,user_login,user_email,user_registered --path=/var/www/vhosts/example.com/httpdocs
harmlessWP-CLI

Regenerate WordPress security keys (salts)

$wp config shuffle-salts --path=/var/www/vhosts/example.com/httpdocs
cautionWP-CLI

Remove write permission for others recursively

$chmod -R o-w /var/www/vhosts/example.com/httpdocs
cautionPermissions and ownership

Secure the permissions of wp-config.php

$chmod 600 /var/www/vhosts/example.com/httpdocs/wp-config.php
cautionPermissions and ownership

Show all requests from one IP address in the access log

#awk -v ip="203.0.113.10" '$1 == ip' /var/www/vhosts/system/example.com/logs/access_ssl_log | tail -50
harmlessLogs

Show only pending security updates

$apt list --upgradable 2>/dev/null | grep -- -security
harmlessDebian and APT

Show recently registered WordPress users

$wp user list --orderby=registered --order=DESC --fields=ID,user_login,user_email,user_registered,roles --path=/var/www/vhosts/example.com/httpdocs | head -n 15
harmlessWP-CLI

Show the Web Application Firewall (ModSecurity) status in Plesk

#plesk bin server_pref --show-web-app-firewall
harmlessPlesk

Test automatic updates (unattended-upgrades) with a dry run

#unattended-upgrade --dry-run -d
harmlessDebian and APT

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.