SSH Fundamentals

SSH Fundamentals

Prerequisite — Asymmetric Cryptography: SSH uses a key pair — a public key (shareable, like a padlock) and a private key (secret, like the key to that padlock). Anyone can encrypt data with your public key, but only your private key can decrypt it. SSH uses this to verify identity: the server challenges the client with the public key, and only the holder of the matching private key can respond correctly.

[Read more]

SSH Hardening and fail2ban

SSH Hardening and fail2ban

Concepts

Why Harden SSH?

SSH is the front door to your server. A default SSH installation accepts password logins from any IP on port 22 — attackers constantly scan for this. Hardening SSH reduces the attack surface.

SSH Server Configuration

The SSH server is configured in /etc/ssh/sshd_config:

sudo nano /etc/ssh/sshd_config

After any change, restart the SSH service:

sudo systemctl restart ssh        # Ubuntu
sudo systemctl restart sshd       # Debian (some installs)

Important: Before making changes, ensure you have an alternative way to access the machine (console, physical access, second SSH session) in case you lock yourself out.

[Read more]

Streams, Redirection, and Pipes

Streams, Redirection, and Pipes

Concepts

The Three Standard Streams

Every program in Linux has three data channels connected by default:

Stream Name File Descriptor Default Destination Purpose
stdin Standard Input 0 Keyboard Where a program reads its input
stdout Standard Output 1 Terminal screen Where a program writes its normal output
stderr Standard Error 2 Terminal screen Where a program writes error messages

A file descriptor is a number the kernel uses to track open streams. You will use these numbers (0, 1, 2) in redirection.

[Read more]

systemd and Services

systemd and Services

Concepts

What Is an Init System?

When Linux boots, the kernel starts a single process: PID 1, the init system. This process is responsible for starting everything else: services, login screens, network interfaces, and more.

On both Ubuntu 24.04 and Debian 12, the init system is systemd. It replaced older init systems (SysVinit, Upstart) and is now the standard on most Linux distributions.

systemd does more than just start services. It manages:

[Read more]

The Boot Process

The Boot Process

Prerequisite — Firmware: Every computer has firmware, low-level software stored on a chip on the motherboard. It initializes hardware and hands control to the operating system. There are two types: BIOS (legacy, from the 1980s) and UEFI (modern replacement, supports larger disks, secure boot, faster startup). Most systems sold after 2012 use UEFI.

Concepts

Boot Sequence Overview

Power on
  │
  ▼
Firmware (BIOS/UEFI)       ← initializes hardware, finds bootloader
  │
  ▼
Bootloader (GRUB)           ← loads the kernel
  │
  ▼
Linux Kernel                ← takes control, detects hardware
  │
  ▼
initramfs                   ← temporary root filesystem (loads drivers)
  │
  ▼
systemd (PID 1)             ← init system, starts services
  │
  ▼
Login prompt / Desktop      ← system ready

Stage 1: Firmware (BIOS/UEFI)

The firmware runs a POST (Power-On Self-Test), initializes hardware (CPU, RAM, display), and looks for a bootable device.

[Read more]