{"id":1193,"date":"2026-07-18T11:42:39","date_gmt":"2026-07-18T08:42:39","guid":{"rendered":"https:\/\/itgen.itbumper.com\/?page_id=1193"},"modified":"2026-07-18T11:42:40","modified_gmt":"2026-07-18T08:42:40","slug":"0049_mobaxterm-macros-07-debian-security_assessment","status":"publish","type":"page","link":"https:\/\/itgen.itbumper.com\/?page_id=1193","title":{"rendered":"0049_MobaXterm macros: 07.Debian-Security_Assessment"},"content":{"rendered":"\n<p>7.1 Current User Context (+ Remote Session Variables)<br \/>7.2 Sudo Configuration (+ Visudo Check &amp; Files Listing)<br \/>7.3 Logged-in Users &amp; systemd-logind Sessions<br \/>7.4 Privileged Accounts (UID 0 &amp; Administrative Groups)<br \/>7.5 Account Status (Shells, Empty Passwords &amp; Locked Summary)<br \/>7.6 SSH Effective Configuration (sshd -T Engine Evaluation)<br \/>7.7 SSH Listening State7.8 Open Ports (Global Socket Mapping)<br \/>7.9 Firewall Status (+ IPv4\/IPv6 Kernel Forwarding States)<br \/>7.10 nftables Active Ruleset (Top 120 lines)<br \/>7.11 iptables Ruleset (IPv4 &amp; IPv6 Legacy Rule Matrices)<br \/>7.12 Fail2ban (Dynamic Active Jails Evaluation Loop)<br \/>7.13 AppArmor \/ SELinux Active Enforcement Profiles<br \/>7.14 Failed Login Attempts (Log Grep &amp; lastb DB Hunt)<br \/>7.15 Recent Successful Logins (last History Profile)<br \/>7.16 Password Policy (login.defs Aging &amp; PAM Complexity Vectors)<br \/>7.17 SSH Authorized Keys (Permissions &amp; Paths Hunt)<br \/>7.18 Pending Security Updates (APT \/ DNF Metadata Mapping)<\/p>\n<p>\u00a0<\/p>\n<p><strong>Copy&#8211;&gt;Past<\/strong><\/p>\n\n\n<div class=\"wp-block-syntaxhighlighter-code \"><pre class=\"brush: bash; title: ; notranslate\" title=\"\">\necho &quot;==================== 07. SECURITY ASSESSMENT ====================&quot;; printf &quot;\\n&quot;; echo &quot;7.1 CURRENT USER&quot;; echo &quot;--- Account Identity ---&quot;; id 2&gt;\/dev\/null || echo &quot;Unable to determine current identity&quot;; printf &quot;\\n&quot;; echo &quot;--- Environment Context ---&quot;; env | grep -E '^(USER|LOGNAME|HOME|SHELL|SUDO_USER|SUDO_COMMAND|SSH_CONNECTION|SSH_CLIENT|SSH_TTY)=' || echo &quot;No relevant session variables found&quot;; printf &quot;\\n%.0s&quot; {1..3}; echo &quot;7.2 SUDO CONFIGURATION&quot;; echo &quot;--- Non-Interactive Sudo Check ---&quot;; if command -v sudo &gt;\/dev\/null 2&gt;&amp;1; then timeout 3 sudo -n -l 2&gt;\/dev\/null || echo &quot;Passwordless sudo unavailable, credentials required, or sudo access denied&quot;; else echo &quot;sudo not installed&quot;; fi; printf &quot;\\n&quot;; echo &quot;--- Sudoers Files ---&quot;; ls -la \/etc\/sudoers \/etc\/sudoers.d\/ 2&gt;\/dev\/null || echo &quot;Sudoers configuration unavailable or access restricted&quot;; printf &quot;\\n&quot;; echo &quot;--- Sudoers Syntax Check ---&quot;; if command -v visudo &gt;\/dev\/null 2&gt;&amp;1; then timeout 5 sudo -n visudo -c 2&gt;\/dev\/null || echo &quot;Unable to validate sudoers without elevated privileges&quot;; else echo &quot;visudo not installed&quot;; fi; printf &quot;\\n%.0s&quot; {1..3}; echo &quot;7.3 LOGGED-IN USERS&quot;; echo &quot;--- Active Sessions ---&quot;; who -a 2&gt;\/dev\/null || w 2&gt;\/dev\/null || echo &quot;Unable to inspect active sessions&quot;; printf &quot;\\n&quot;; echo &quot;--- systemd-logind Sessions ---&quot;; loginctl list-sessions --no-pager 2&gt;\/dev\/null || echo &quot;systemd-logind session data unavailable&quot;; printf &quot;\\n%.0s&quot; {1..3}; echo &quot;7.4 PRIVILEGED ACCOUNTS&quot;; echo &quot;--- Accounts with UID 0 ---&quot;; awk -F: '$3 == 0 {printf &quot;%-20s UID=%s SHELL=%s\\n&quot;, $1, $3, $7}' \/etc\/passwd 2&gt;\/dev\/null || echo &quot;Unable to inspect \/etc\/passwd&quot;; printf &quot;\\n&quot;; echo &quot;--- Administrative Groups ---&quot;; getent group sudo 2&gt;\/dev\/null || echo &quot;sudo group not found&quot;; getent group admin 2&gt;\/dev\/null || true; getent group wheel 2&gt;\/dev\/null || true; printf &quot;\\n%.0s&quot; {1..3}; echo &quot;7.5 ACCOUNT STATUS&quot;; echo &quot;--- Accounts with Interactive Shells ---&quot;; awk -F: '$7 !~ \/(nologin|false|sync)$\/ { printf &quot;%-20s UID=%-6s HOME=%-30s SHELL=%s\\n&quot;, $1, $3, $6, $7 }' \/etc\/passwd 2&gt;\/dev\/null || echo &quot;Unable to inspect account shells&quot;; printf &quot;\\n&quot;; echo &quot;--- Empty Password Fields ---&quot;; if &#x5B; -r \/etc\/shadow ]; then awk -F: '$2 == &quot;&quot; {print $1}' \/etc\/shadow; EMPTY_PASSWORD_COUNT=$(awk -F: '$2 == &quot;&quot; {count++} END {print count+0}' \/etc\/shadow); &#x5B; &quot;${EMPTY_PASSWORD_COUNT:-0}&quot; -eq 0 ] &amp;&amp; echo &quot;No accounts with empty password fields&quot;; else echo &quot;\/etc\/shadow requires elevated privileges&quot;; fi; printf &quot;\\n&quot;; echo &quot;--- Locked Account Summary ---&quot;; if &#x5B; -r \/etc\/shadow ]; then awk -F: '$2 ~ \/^(!|\\*)\/ { printf &quot;%-20s LOCKED\\n&quot;, $1 }' \/etc\/shadow | head -40; else echo &quot;\/etc\/shadow requires elevated privileges&quot;; fi; printf &quot;\\n%.0s&quot; {1..3}; echo &quot;7.6 SSH EFFECTIVE CONFIGURATION&quot;; if command -v sshd &gt;\/dev\/null 2&gt;&amp;1; then sshd -T 2&gt;\/dev\/null | grep -E '^(port|listenaddress|addressfamily|permitrootlogin|passwordauthentication|kbdinteractiveauthentication|pubkeyauthentication|authenticationmethods|maxauthtries|maxsessions|allowusers|allowgroups|denyusers|denygroups|x11forwarding|allowtcpforwarding|permitopen|clientaliveinterval|clientalivecountmax|loglevel|usepam) ' || echo &quot;Unable to read effective sshd configuration&quot;; else echo &quot;sshd not installed&quot;; fi; printf &quot;\\n&quot;; echo &quot;--- SSH Configuration Files ---&quot;; ls -la \/etc\/ssh\/sshd_config \/etc\/ssh\/sshd_config.d\/ 2&gt;\/dev\/null || echo &quot;SSH server configuration files unavailable&quot;; printf &quot;\\n%.0s&quot; {1..3}; echo &quot;7.7 SSH LISTENING STATE&quot;; ss -ltnp 2&gt;\/dev\/null | grep -Ei 'sshd|ssh' || echo &quot;No active SSH listener associated with sshd&quot;; printf &quot;\\n%.0s&quot; {1..3}; echo &quot;7.8 OPEN PORTS&quot;; ss -tulpn 2&gt;\/dev\/null || echo &quot;Socket information unavailable&quot;; printf &quot;\\n%.0s&quot; {1..3}; echo &quot;7.9 FIREWALL STATUS&quot;; echo &quot;nftables : $(systemctl is-active nftables 2&gt;\/dev\/null || echo inactive\/not-installed)&quot;; echo &quot;ufw      : $(systemctl is-active ufw 2&gt;\/dev\/null || echo inactive\/not-installed)&quot;; echo &quot;firewalld: $(systemctl is-active firewalld 2&gt;\/dev\/null || echo inactive\/not-installed)&quot;; printf &quot;\\n&quot;; echo &quot;--- IPv4 Forwarding ---&quot;; sysctl net.ipv4.ip_forward 2&gt;\/dev\/null || echo &quot;IPv4 forwarding status unavailable&quot;; printf &quot;\\n&quot;; echo &quot;--- IPv6 Forwarding ---&quot;; sysctl net.ipv6.conf.all.forwarding 2&gt;\/dev\/null || echo &quot;IPv6 forwarding status unavailable&quot;; printf &quot;\\n%.0s&quot; {1..3}; echo &quot;7.10 NFTABLES RULES&quot;; if command -v nft &gt;\/dev\/null 2&gt;&amp;1; then nft list ruleset 2&gt;\/dev\/null | head -120 || echo &quot;nftables rules unavailable or insufficient privileges&quot;; else echo &quot;nft command not installed&quot;; fi; printf &quot;\\n%.0s&quot; {1..3}; echo &quot;7.11 IPTABLES RULES&quot;; if command -v iptables &gt;\/dev\/null 2&gt;&amp;1; then echo &quot;--- IPv4 Filter Rules ---&quot;; iptables -L -n -v --line-numbers 2&gt;\/dev\/null | head -120 || echo &quot;IPv4 iptables rules unavailable&quot;; printf &quot;\\n&quot;; echo &quot;--- IPv4 Default Policies ---&quot; ; iptables -S 2&gt;\/dev\/null | grep '^-P ' || echo &quot;IPv4 default policies unavailable&quot;; else echo &quot;iptables not installed&quot;; fi; printf &quot;\\n&quot;; if command -v ip6tables &gt;\/dev\/null 2&gt;&amp;1; then echo &quot;--- IPv6 Filter Rules ---&quot;; ip6tables -L -n -v --line-numbers 2&gt;\/dev\/null | head -80 || echo &quot;IPv6 iptables rules unavailable&quot;; fi; printf &quot;\\n%.0s&quot; {1..3}; echo &quot;7.12 FAIL2BAN&quot;; echo &quot;fail2ban: $(systemctl is-active fail2ban 2&gt;\/dev\/null || echo inactive\/not-installed)&quot;; printf &quot;\\n&quot;; if command -v fail2ban-client &gt;\/dev\/null 2&gt;&amp;1; then fail2ban-client status 2&gt;\/dev\/null || echo &quot;Unable to query fail2ban status&quot;; printf &quot;\\n&quot;; JAILS=$(fail2ban-client status 2&gt;\/dev\/null | awk -F: '\/Jail list\/ { gsub(\/&#x5B; \\t]\/, &quot;&quot;, $2); print $2 }'); if &#x5B; -n &quot;$JAILS&quot; ]; then OLD_IFS=$IFS; IFS=','; for JAIL in $JAILS; do echo &quot;--- Jail: $JAIL ---&quot;; fail2ban-client status &quot;$JAIL&quot; 2&gt;\/dev\/null | head -30; printf &quot;\\n&quot;; done; IFS=$OLD_IFS; fi; else echo &quot;fail2ban-client not installed&quot;; fi; printf &quot;\\n%.0s&quot; {1..3}; echo &quot;7.13 APPARMOR \/ SELINUX&quot;; echo &quot;--- AppArmor ---&quot;; echo &quot;apparmor: $(systemctl is-active apparmor 2&gt;\/dev\/null || echo inactive\/not-installed)&quot;; if command -v aa-status &gt;\/dev\/null 2&gt;&amp;1; then aa-status 2&gt;\/dev\/null | head -40 || echo &quot;Unable to query AppArmor status&quot;; elif &#x5B; -f \/sys\/kernel\/security\/apparmor\/profiles ]; then echo &quot;AppArmor kernel interface detected&quot;; else echo &quot;AppArmor not detected&quot;; fi; printf &quot;\\n&quot;; echo &quot;--- SELinux ---&quot;; if command -v sestatus &gt;\/dev\/null 2&gt;&amp;1; then sestatus 2&gt;\/dev\/null; else echo &quot;SELinux tools not installed&quot;; fi; printf &quot;\\n%.0s&quot; {1..3}; echo &quot;7.14 FAILED LOGIN ATTEMPTS&quot;; if command -v journalctl &gt;\/dev\/null 2&gt;&amp;1; then journalctl -b 0 --no-pager 2&gt;\/dev\/null | grep -Ei 'failed password|invalid user|authentication failure|pam_unix.*authentication failure|maximum authentication attempts exceeded|connection closed by authenticating user' | tail -60 || echo &quot;No failed login attempts found in current boot&quot;; else grep -Eih 'failed password|invalid user|authentication failure|maximum authentication attempts exceeded' \/var\/log\/auth.log \/var\/log\/secure 2&gt;\/dev\/null | tail -60 || echo &quot;Authentication logs unavailable&quot;; fi; printf &quot;\\n&quot;; echo &quot;--- Failed Login Database ---&quot;; lastb 2&gt;\/dev\/null | head -30 || echo &quot;Failed login database unavailable or access restricted&quot;; printf &quot;\\n%.0s&quot; {1..3}; echo &quot;7.15 RECENT SUCCESSFUL LOGINS&quot;; last -a 2&gt;\/dev\/null | head -30 || echo &quot;Login history unavailable&quot;; printf &quot;\\n%.0s&quot; {1..3}; echo &quot;7.16 PASSWORD POLICY&quot;; echo &quot;--- login.defs ---&quot;; grep -E '^&#x5B;&#x5B;:space:]]*(PASS_MAX_DAYS|PASS_MIN_DAYS|PASS_WARN_AGE|PASS_MIN_LEN|ENCRYPT_METHOD|UMASK)&#x5B;&#x5B;:space:]]+' \/etc\/login.defs 2&gt;\/dev\/null || echo &quot;Password aging settings unavailable&quot;; printf &quot;\\n&quot;; echo &quot;--- PAM Password Configuration ---&quot;; grep -R -E 'pam_pwquality|pam_cracklib|pam_pwhistory|remember=|minlen=|retry=' \/etc\/pam.d\/ \/etc\/security\/pwquality.conf \/etc\/security\/pwquality.conf.d\/ 2&gt;\/dev\/null | head -60 || echo &quot;No explicit PAM password-quality settings found&quot;; printf &quot;\\n%.0s&quot; {1..3}; echo &quot;7.17 SSH AUTHORIZED KEYS&quot;; find \/root \/home -xdev -type f -path '*\/.ssh\/authorized_keys' -printf '%m %u:%g %p\\n' 2&gt;\/dev\/null || echo &quot;No authorized_keys files found or access restricted&quot;; printf &quot;\\n%.0s&quot; {1..3}; echo &quot;7.18 PENDING SECURITY UPDATES&quot;; if command -v apt-get &gt;\/dev\/null 2&gt;&amp;1; then echo &quot;--- Simulated APT Upgrade: Security-Origin Packages ---&quot;; apt-get -s upgrade 2&gt;\/dev\/null | grep -Ei 'Inst .*security|Debian-Security|Ubuntu.*security' | head -80 || echo &quot;No security-origin package upgrades detected in current APT metadata&quot;; printf &quot;\\n&quot;; echo &quot;Note: results depend on the freshness of local APT package metadata.&quot;; elif command -v dnf &gt;\/dev\/null 2&gt;&amp;1; then echo &quot;--- DNF Security Updates ---&quot;; dnf updateinfo list security 2&gt;\/dev\/null | head -80 || echo &quot;No security advisories detected in current DNF metadata&quot;; else echo &quot;Supported package manager not found&quot;; fi\n<\/pre><\/div>\n\n<div class=\"wp-block-syntaxhighlighter-code \"><pre class=\"brush: bash; title: ; notranslate\" title=\"\">\n# ==================== 07. SECURITY ASSESSMENT ====================\necho &quot;==================== 07. SECURITY ASSESSMENT ====================&quot;\nprintf &quot;\\n&quot;\n\n# --- 7.1 CURRENT USER ---\necho &quot;7.1 CURRENT USER&quot;\necho &quot;--- Account Identity ---&quot;\nid 2&gt;\/dev\/null || echo &quot;Unable to determine current identity&quot;\nprintf &quot;\\n&quot;\necho &quot;--- Environment Context ---&quot;\nenv | grep -E '^(USER|LOGNAME|HOME|SHELL|SUDO_USER|SUDO_COMMAND|SSH_CONNECTION|SSH_CLIENT|SSH_TTY)=' || echo &quot;No relevant session variables found&quot;\nprintf &quot;\\n%.0s&quot; {1..3}\n\n# --- 7.2 SUDO CONFIGURATION ---\necho &quot;7.2 SUDO CONFIGURATION&quot;\necho &quot;--- Non-Interactive Sudo Check ---&quot;\nif command -v sudo &gt;\/dev\/null 2&gt;&amp;1; then\n    timeout 3 sudo -n -l 2&gt;\/dev\/null || echo &quot;Passwordless sudo unavailable, credentials required, or sudo access denied&quot;\nelse\n    echo &quot;sudo not installed&quot;\nfi\nprintf &quot;\\n&quot;\necho &quot;--- Sudoers Files ---&quot;\nls -la \/etc\/sudoers \/etc\/sudoers.d\/ 2&gt;\/dev\/null || echo &quot;Sudoers configuration unavailable or access restricted&quot;\nprintf &quot;\\n&quot;\necho &quot;--- Sudoers Syntax Check ---&quot;\nif command -v visudo &gt;\/dev\/null 2&gt;&amp;1; then\n    timeout 5 sudo -n visudo -c 2&gt;\/dev\/null || echo &quot;Unable to validate sudoers without elevated privileges&quot;\nelse\n    echo &quot;visudo not installed&quot;\nfi\nprintf &quot;\\n%.0s&quot; {1..3}\n\n# --- 7.3 LOGGED-IN USERS ---\necho &quot;7.3 LOGGED-IN USERS&quot;\necho &quot;--- Active Sessions ---&quot;\nwho -a 2&gt;\/dev\/null || w 2&gt;\/dev\/null || echo &quot;Unable to inspect active sessions&quot;\nprintf &quot;\\n&quot;\necho &quot;--- systemd-logind Sessions ---&quot;\nloginctl list-sessions --no-pager 2&gt;\/dev\/null || echo &quot;systemd-logind session data unavailable&quot;\nprintf &quot;\\n%.0s&quot; {1..3}\n\n# --- 7.4 PRIVILEGED ACCOUNTS ---\necho &quot;7.4 PRIVILEGED ACCOUNTS&quot;\necho &quot;--- Accounts with UID 0 ---&quot;\nawk -F: '$3 == 0 {printf &quot;%-20s UID=%s SHELL=%s\\n&quot;, $1, $3, $7}' \/etc\/passwd 2&gt;\/dev\/null || echo &quot;Unable to inspect \/etc\/passwd&quot;\nprintf &quot;\\n&quot;\necho &quot;--- Administrative Groups ---&quot;\ngetent group sudo 2&gt;\/dev\/null || echo &quot;sudo group not found&quot;\ngetent group admin 2&gt;\/dev\/null || true\ngetent group wheel 2&gt;\/dev\/null || true\nprintf &quot;\\n%.0s&quot; {1..3}\n\n# --- 7.5 ACCOUNT STATUS ---\necho &quot;7.5 ACCOUNT STATUS&quot;\necho &quot;--- Accounts with Interactive Shells ---&quot;\nawk -F: '$7 !~ \/(nologin|false|sync)$\/ { printf &quot;%-20s UID=%-6s HOME=%-30s SHELL=%s\\n&quot;, $1, $3, $6, $7 }' \/etc\/passwd 2&gt;\/dev\/null || echo &quot;Unable to inspect account shells&quot;\nprintf &quot;\\n&quot;\necho &quot;--- Empty Password Fields ---&quot;\nif &#x5B; -r \/etc\/shadow ]; then\n    awk -F: '$2 == &quot;&quot; {print $1}' \/etc\/shadow\n    EMPTY_PASSWORD_COUNT=$(awk -F: '$2 == &quot;&quot; {count++} END {print count+0}' \/etc\/shadow)\n    &#x5B; &quot;${EMPTY_PASSWORD_COUNT:-0}&quot; -eq 0 ] &amp;&amp; echo &quot;No accounts with empty password fields&quot;\nelse\n    echo &quot;\/etc\/shadow requires elevated privileges&quot;\nfi\nprintf &quot;\\n&quot;\necho &quot;--- Locked Account Summary ---&quot;\nif &#x5B; -r \/etc\/shadow ]; then\n    awk -F: '$2 ~ \/^(!|\\*)\/ { printf &quot;%-20s LOCKED\\n&quot;, $1 }' \/etc\/shadow | head -40\nelse\n    echo &quot;\/etc\/shadow requires elevated privileges&quot;\nfi\nprintf &quot;\\n%.0s&quot; {1..3}\n\n# --- 7.6 SSH EFFECTIVE CONFIGURATION ---\necho &quot;7.6 SSH EFFECTIVE CONFIGURATION&quot;\nif command -v sshd &gt;\/dev\/null 2&gt;&amp;1; then\n    sshd -T 2&gt;\/dev\/null | grep -E '^(port|listenaddress|addressfamily|permitrootlogin|passwordauthentication|kbdinteractiveauthentication|pubkeyauthentication|authenticationmethods|maxauthtries|maxsessions|allowusers|allowgroups|denyusers|denygroups|x11forwarding|allowtcpforwarding|permitopen|clientaliveinterval|clientalivecountmax|loglevel|usepam) ' || echo &quot;Unable to read effective sshd configuration&quot;\nelse\n    echo &quot;sshd not installed&quot;\nfi\nprintf &quot;\\n&quot;\necho &quot;--- SSH Configuration Files ---&quot;\nls -la \/etc\/ssh\/sshd_config \/etc\/ssh\/sshd_config.d\/ 2&gt;\/dev\/null || echo &quot;SSH server configuration files unavailable&quot;\nprintf &quot;\\n%.0s&quot; {1..3}\n\n# --- 7.7 SSH LISTENING STATE ---\necho &quot;7.7 SSH LISTENING STATE&quot;\nss -ltnp 2&gt;\/dev\/null | grep -Ei 'sshd|ssh' || echo &quot;No active SSH listener associated with sshd&quot;\nprintf &quot;\\n%.0s&quot; {1..3}\n\n# --- 7.8 OPEN PORTS ---\necho &quot;7.8 OPEN PORTS&quot;\nss -tulpn 2&gt;\/dev\/null || echo &quot;Socket information unavailable&quot;\nprintf &quot;\\n%.0s&quot; {1..3}\n\n# --- 7.9 FIREWALL STATUS ---\necho &quot;7.9 FIREWALL STATUS&quot;\necho &quot;nftables : $(systemctl is-active nftables 2&gt;\/dev\/null || echo inactive\/not-installed)&quot;\necho &quot;ufw      : $(systemctl is-active ufw 2&gt;\/dev\/null || echo inactive\/not-installed)&quot;\necho &quot;firewalld: $(systemctl is-active firewalld 2&gt;\/dev\/null || echo inactive\/not-installed)&quot;\nprintf &quot;\\n&quot;\necho &quot;--- IPv4 Forwarding ---&quot;\nsysctl net.ipv4.ip_forward 2&gt;\/dev\/null || echo &quot;IPv4 forwarding status unavailable&quot;\nprintf &quot;\\n&quot;\necho &quot;--- IPv6 Forwarding ---&quot;\nsysctl net.ipv6.conf.all.forwarding 2&gt;\/dev\/null || echo &quot;IPv6 forwarding status unavailable&quot;\nprintf &quot;\\n%.0s&quot; {1..3}\n\n# --- 7.10 NFTABLES RULES ---\necho &quot;7.10 NFTABLES RULES&quot;\nif command -v nft &gt;\/dev\/null 2&gt;&amp;1; then\n    nft list ruleset 2&gt;\/dev\/null | head -120 || echo &quot;nftables rules unavailable or insufficient privileges&quot;\nelse\n    echo &quot;nft command not installed&quot;\nfi\nprintf &quot;\\n%.0s&quot; {1..3}\n\n# --- 7.11 IPTABLES RULES ---\necho &quot;7.11 IPTABLES RULES&quot;\nif command -v iptables &gt;\/dev\/null 2&gt;&amp;1; then\n    echo &quot;--- IPv4 Filter Rules ---&quot;\n    iptables -L -n -v --line-numbers 2&gt;\/dev\/null | head -120 || echo &quot;IPv4 iptables rules unavailable&quot;\n    printf &quot;\\n&quot;\n    echo &quot;--- IPv4 Default Policies ---&quot;\n    iptables -S 2&gt;\/dev\/null | grep '^-P ' || echo &quot;IPv4 default policies unavailable&quot;\nelse\n    echo &quot;iptables not installed&quot;\nfi\nprintf &quot;\\n&quot;\nif command -v ip6tables &gt;\/dev\/null 2&gt;&amp;1; then\n    echo &quot;--- IPv6 Filter Rules ---&quot;\n    ip6tables -L -n -v --line-numbers 2&gt;\/dev\/null | head -80 || echo &quot;IPv6 iptables rules unavailable&quot;\nfi\nprintf &quot;\\n%.0s&quot; {1..3}\n\n# --- 7.12 FAIL2BAN ---\necho &quot;7.12 FAIL2BAN&quot;\necho &quot;fail2ban: $(systemctl is-active fail2ban 2&gt;\/dev\/null || echo inactive\/not-installed)&quot;\nprintf &quot;\\n&quot;\nif command -v fail2ban-client &gt;\/dev\/null 2&gt;&amp;1; then\n    fail2ban-client status 2&gt;\/dev\/null || echo &quot;Unable to query fail2ban status&quot;\n    printf &quot;\\n&quot;\n    JAILS=$(fail2ban-client status 2&gt;\/dev\/null | awk -F: '\/Jail list\/ { gsub(\/&#x5B; \\t]\/, &quot;&quot;, $2); print $2 }')\n    if &#x5B; -n &quot;$JAILS&quot; ]; then\n        OLD_IFS=$IFS\n        IFS=','\n        for JAIL in $JAILS; do\n            echo &quot;--- Jail: $JAIL ---&quot;\n            fail2ban-client status &quot;$JAIL&quot; 2&gt;\/dev\/null | head -30\n            printf &quot;\\n&quot;\n        done\n        IFS=$OLD_IFS\n    fi\nelse\n    echo &quot;fail2ban-client not installed&quot;\nfi\nprintf &quot;\\n%.0s&quot; {1..3}\n\n# --- 7.13 APPARMOR \/ SELINUX ---\necho &quot;7.13 APPARMOR \/ SELINUX&quot;\necho &quot;--- AppArmor ---&quot;\necho &quot;apparmor: $(systemctl is-active apparmor 2&gt;\/dev\/null || echo inactive\/not-installed)&quot;\nif command -v aa-status &gt;\/dev\/null 2&gt;&amp;1; then\n    aa-status 2&gt;\/dev\/null | head -40 || echo &quot;Unable to query AppArmor status&quot;\nelif &#x5B; -f \/sys\/kernel\/security\/apparmor\/profiles ]; then\n    echo &quot;AppArmor kernel interface detected&quot;\nelse\n    echo &quot;AppArmor not detected&quot;\nfi\nprintf &quot;\\n&quot;\necho &quot;--- SELinux ---&quot;\nif command -v sestatus &gt;\/dev\/null 2&gt;&amp;1; then\n    sestatus 2&gt;\/dev\/null\nelse\n    echo &quot;SELinux tools not installed&quot;\nfi\nprintf &quot;\\n%.0s&quot; {1..3}\n\n# --- 7.14 FAILED LOGIN ATTEMPTS ---\necho &quot;7.14 FAILED LOGIN ATTEMPTS&quot;\nif command -v journalctl &gt;\/dev\/null 2&gt;&amp;1; then\n    journalctl -b 0 --no-pager 2&gt;\/dev\/null | grep -Ei 'failed password|invalid user|authentication failure|pam_unix.*authentication failure|maximum authentication attempts exceeded|connection closed by authenticating user' | tail -60 || echo &quot;No failed login attempts found in current boot&quot;\nelse\n    grep -Eih 'failed password|invalid user|authentication failure|maximum authentication attempts exceeded' \/var\/log\/auth.log \/var\/log\/secure 2&gt;\/dev\/null | tail -60 || echo &quot;Authentication logs unavailable&quot;\nfi\nprintf &quot;\\n&quot;\necho &quot;--- Failed Login Database ---&quot;\nlastb 2&gt;\/dev\/null | head -30 || echo &quot;Failed login database unavailable or access restricted&quot;\nprintf &quot;\\n%.0s&quot; {1..3}\n\n# --- 7.15 RECENT SUCCESSFUL LOGINS ---\necho &quot;7.15 RECENT SUCCESSFUL LOGINS&quot;\nlast -a 2&gt;\/dev\/null | head -30 || echo &quot;Login history unavailable&quot;\nprintf &quot;\\n%.0s&quot; {1..3}\n\n# --- 7.16 PASSWORD POLICY ---\necho &quot;7.16 PASSWORD POLICY&quot;\necho &quot;--- login.defs ---&quot;\ngrep -E '^&#x5B;&#x5B;:space:]]*(PASS_MAX_DAYS|PASS_MIN_DAYS|PASS_WARN_AGE|PASS_MIN_LEN|ENCRYPT_METHOD|UMASK)&#x5B;&#x5B;:space:]]+' \/etc\/login.defs 2&gt;\/dev\/null || echo &quot;Password aging settings unavailable&quot;\nprintf &quot;\\n&quot;\necho &quot;--- PAM Password Configuration ---&quot;\ngrep -R -E 'pam_pwquality|pam_cracklib|pam_pwhistory|remember=|minlen=|retry=' \/etc\/pam.d\/ \/etc\/security\/pwquality.conf \/etc\/security\/pwquality.conf.d\/ 2&gt;\/dev\/null | head -60 || echo &quot;No explicit PAM password-quality settings found&quot;\nprintf &quot;\\n%.0s&quot; {1..3}\n\n# --- 7.17 SSH AUTHORIZED KEYS ---\necho &quot;7.17 SSH AUTHORIZED KEYS&quot;\nfind \/root \/home -xdev -type f -path '*\/.ssh\/authorized_keys' -printf '%m %u:%g %p\\n' 2&gt;\/dev\/null || echo &quot;No authorized_keys files found or access restricted&quot;\nprintf &quot;\\n%.0s&quot; {1..3}\n\n# --- 7.18 PENDING SECURITY UPDATES ---\necho &quot;7.18 PENDING SECURITY UPDATES&quot;\nif command -v apt-get &gt;\/dev\/null 2&gt;&amp;1; then\n    echo &quot;--- Simulated APT Upgrade: Security-Origin Packages ---&quot;\n    apt-get -s upgrade 2&gt;\/dev\/null | grep -Ei 'Inst .*security|Debian-Security|Ubuntu.*security' | head -80 || echo &quot;No security-origin package upgrades detected in current APT metadata&quot;\n    printf &quot;\\n&quot;\n    echo &quot;Note: results depend on the freshness of local APT package metadata.&quot;\nelif command -v dnf &gt;\/dev\/null 2&gt;&amp;1; then\n    echo &quot;--- DNF Security Updates ---&quot;\n    dnf updateinfo list security 2&gt;\/dev\/null | head -80 || echo &quot;No security advisories detected in current DNF metadata&quot;\nelse\n    echo &quot;Supported package manager not found&quot;\nfi\n<\/pre><\/div>\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"734\" height=\"1024\" src=\"https:\/\/itgen.itbumper.com\/wp-content\/uploads\/2026\/07\/007_debian_security-assessment-01-734x1024.png\" alt=\"\" class=\"wp-image-1195\" style=\"width:800px\" srcset=\"https:\/\/itgen.itbumper.com\/wp-content\/uploads\/2026\/07\/007_debian_security-assessment-01-734x1024.png 734w, https:\/\/itgen.itbumper.com\/wp-content\/uploads\/2026\/07\/007_debian_security-assessment-01-215x300.png 215w, https:\/\/itgen.itbumper.com\/wp-content\/uploads\/2026\/07\/007_debian_security-assessment-01-768x1071.png 768w, https:\/\/itgen.itbumper.com\/wp-content\/uploads\/2026\/07\/007_debian_security-assessment-01.png 938w\" sizes=\"(max-width: 734px) 85vw, 734px\" \/><\/figure><\/div>\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"693\" src=\"https:\/\/itgen.itbumper.com\/wp-content\/uploads\/2026\/07\/007_debian_security-assessment-02-1024x693.png\" alt=\"\" class=\"wp-image-1196\" style=\"width:800px\" srcset=\"https:\/\/itgen.itbumper.com\/wp-content\/uploads\/2026\/07\/007_debian_security-assessment-02-1024x693.png 1024w, https:\/\/itgen.itbumper.com\/wp-content\/uploads\/2026\/07\/007_debian_security-assessment-02-300x203.png 300w, https:\/\/itgen.itbumper.com\/wp-content\/uploads\/2026\/07\/007_debian_security-assessment-02-768x520.png 768w, https:\/\/itgen.itbumper.com\/wp-content\/uploads\/2026\/07\/007_debian_security-assessment-02-1200x812.png 1200w, https:\/\/itgen.itbumper.com\/wp-content\/uploads\/2026\/07\/007_debian_security-assessment-02.png 1223w\" sizes=\"(max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure><\/div>\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"790\" height=\"986\" src=\"https:\/\/itgen.itbumper.com\/wp-content\/uploads\/2026\/07\/007_debian_security-assessment-03.png\" alt=\"\" class=\"wp-image-1197\" style=\"width:800px\" srcset=\"https:\/\/itgen.itbumper.com\/wp-content\/uploads\/2026\/07\/007_debian_security-assessment-03.png 790w, https:\/\/itgen.itbumper.com\/wp-content\/uploads\/2026\/07\/007_debian_security-assessment-03-240x300.png 240w, https:\/\/itgen.itbumper.com\/wp-content\/uploads\/2026\/07\/007_debian_security-assessment-03-768x959.png 768w\" sizes=\"(max-width: 790px) 85vw, 790px\" \/><\/figure><\/div>\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"763\" height=\"1024\" src=\"https:\/\/itgen.itbumper.com\/wp-content\/uploads\/2026\/07\/007_debian_security-assessment-04-763x1024.png\" alt=\"\" class=\"wp-image-1198\" style=\"width:800px\" srcset=\"https:\/\/itgen.itbumper.com\/wp-content\/uploads\/2026\/07\/007_debian_security-assessment-04-763x1024.png 763w, https:\/\/itgen.itbumper.com\/wp-content\/uploads\/2026\/07\/007_debian_security-assessment-04-223x300.png 223w, https:\/\/itgen.itbumper.com\/wp-content\/uploads\/2026\/07\/007_debian_security-assessment-04-768x1031.png 768w, https:\/\/itgen.itbumper.com\/wp-content\/uploads\/2026\/07\/007_debian_security-assessment-04.png 869w\" sizes=\"(max-width: 763px) 85vw, 763px\" \/><\/figure><\/div>\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"800\" src=\"https:\/\/itgen.itbumper.com\/wp-content\/uploads\/2026\/07\/007_debian_security-assessment-05-1024x800.png\" alt=\"\" class=\"wp-image-1199\" style=\"width:800px\" srcset=\"https:\/\/itgen.itbumper.com\/wp-content\/uploads\/2026\/07\/007_debian_security-assessment-05-1024x800.png 1024w, https:\/\/itgen.itbumper.com\/wp-content\/uploads\/2026\/07\/007_debian_security-assessment-05-300x234.png 300w, https:\/\/itgen.itbumper.com\/wp-content\/uploads\/2026\/07\/007_debian_security-assessment-05-768x600.png 768w, https:\/\/itgen.itbumper.com\/wp-content\/uploads\/2026\/07\/007_debian_security-assessment-05.png 1093w\" sizes=\"(max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure><\/div>","protected":false},"excerpt":{"rendered":"","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"categories":[21,26],"tags":[],"_links":{"self":[{"href":"https:\/\/itgen.itbumper.com\/index.php?rest_route=\/wp\/v2\/pages\/1193"}],"collection":[{"href":"https:\/\/itgen.itbumper.com\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/itgen.itbumper.com\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/itgen.itbumper.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/itgen.itbumper.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1193"}],"version-history":[{"count":2,"href":"https:\/\/itgen.itbumper.com\/index.php?rest_route=\/wp\/v2\/pages\/1193\/revisions"}],"predecessor-version":[{"id":1200,"href":"https:\/\/itgen.itbumper.com\/index.php?rest_route=\/wp\/v2\/pages\/1193\/revisions\/1200"}],"wp:attachment":[{"href":"https:\/\/itgen.itbumper.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1193"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/itgen.itbumper.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1193"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/itgen.itbumper.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1193"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}