Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Sichere ProgrammierungWe shipped guest play at 17:39 and deleted it at 18:35(21.09.2026 um 13:32 Uhr)
Sichere ProgrammierungBest MCP Servers 2026: 10 Worth Installing (Tested)(21.09.2026 um 13:42 Uhr)
Sichere ProgrammierungThe Resume Is Dying. What's Replacing It?(21.09.2026 um 13:44 Uhr)
Sichere Programmierung38 clamps, four probits, and one coefficient rounded to 15 digits(21.09.2026 um 13:46 Uhr)
Sichere ProgrammierungGmail deletes your SVG logo and Outlook ignores your flexbox(21.09.2026 um 13:47 Uhr)
Sichere Programmierung'2026-27' is a better database key than a date range(21.09.2026 um 13:49 Uhr)
Sichere ProgrammierungThe CoreDNS Black Hole: how one dead DNS pod broke our API gateway(21.09.2026 um 13:53 Uhr)
Sichere ProgrammierungWe shipped guest play at 17:39 and deleted it at 18:35(21.09.2026 um 13:32 Uhr)
Sichere ProgrammierungBest MCP Servers 2026: 10 Worth Installing (Tested)(21.09.2026 um 13:42 Uhr)
Sichere ProgrammierungThe Resume Is Dying. What's Replacing It?(21.09.2026 um 13:44 Uhr)
Sichere Programmierung38 clamps, four probits, and one coefficient rounded to 15 digits(21.09.2026 um 13:46 Uhr)
Sichere ProgrammierungGmail deletes your SVG logo and Outlook ignores your flexbox(21.09.2026 um 13:47 Uhr)
Sichere Programmierung'2026-27' is a better database key than a date range(21.09.2026 um 13:49 Uhr)
Sichere ProgrammierungThe CoreDNS Black Hole: how one dead DNS pod broke our API gateway(21.09.2026 um 13:53 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

We Hardened Ubuntu 24.04 for Security Tools (And Broke Everything First)

We Hardened Ubuntu 24.04 for Security Tools (And Broke Everything First) We maintain HailBytes reNgine, a web recon platform. Wanted to deploy hardened golden images to AWS and Azure following industry benchmarks. Should be simple. Run…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!




We Hardened Ubuntu 24.04 for Security Tools (And Broke Everything First)



We maintain HailBytes reNgine, a web recon platform. Wanted to deploy hardened golden images to AWS and Azure following industry benchmarks.



Should be simple. Run hardening script, create AMI, done.



Except our scanning tools immediately stopped working. 🔥




# Our "secure" kernel settings:
kernel.unprivileged_bpf_disabled = 1 # Block BPF
net.core.bpf_jit_harden = 2 # Maximum BPF hardening

# What our tools actually needed:
# BPF access. For packet capture. For scanning. For everything.






Here's the thing: security tools often need the exact privileges that security hardening removes. Fun paradox.









How Claude Code Helped



We used Claude Code to iterate on the hardening scripts. Three problems it helped us solve:






1. Azure VMs Were Detected as AWS



Both clouds use the same metadata IP. Our detection was just checking if the endpoint responded.




# This is wrong
METADATA_URL="http://169.254.169.254"
curl -s "$METADATA_URL/latest/meta-data/" && echo "AWS!"






The fix: actually validate the response format.




detect_cloud_provider() {
# Check Azure FIRST (it has a specific field)
local azure_check=$(curl -s -H "Metadata:true" \
"http://169.254.169.254/metadata/instance?api-version=2021-02-01" \
--connect-timeout 2 2>/dev/null)

if echo "$azure_check" | grep -q '"azEnvironment"'; then
echo "azure"
return
fi


# Then check AWS (validate instance ID format)
local aws_check=$(curl -s \
"http://169.254.169.254/latest/meta-data/instance-id" \
--connect-timeout 2 2>/dev/null)

if [[ "$aws_check" =~ ^i-[a-f0-9]+ ]]; then
echo "aws"
return
fi

echo "generic"
}






Azure returns JSON with azEnvironment. AWS returns plain text. Check the actual content, not just connectivity.






2. Ubuntu 24.04 Renamed the SSH Service



Worked fine on 22.04. Then:




systemctl restart sshd  # "Unit sshd.service not found" 💀






Ubuntu 24.04 changed it from sshd to ssh. Cool. Cool cool cool.




if systemctl restart ssh 2>/dev/null || systemctl restart sshd 2>/dev/null; then
log "SSH hardened"
else
error "Failed to restart SSH"
fi









3. Finding the Right Security Tradeoffs



This was the real work. Hardening that doesn't break the app:
































Setting CIS Says What We Used Why
unprivileged_bpf_disabled 1 (blocked) 0 (allowed) Scanning needs packet capture
bpf_jit_harden 2 (max) 1 (moderate) Performance matters
AppArmor enforce all complain for Docker Containers need flexibility


Each deviation is documented. Auditors will ask. Have your answers ready.









What You Get






# Auto-detect cloud provider
sudo ./harden_ubuntu_2404.sh

# Or force it
sudo ./harden_ubuntu_2404.sh --cloud azure
sudo ./harden_ubuntu_2404.sh --cloud aws






The script handles:




  • SSH hardening (Ed25519, modern ciphers only)

  • UFW firewall (ports 22, 443, 8082)

  • Kernel hardening (ASLR, SYN cookies, anti-spoofing)

  • Fail2Ban

  • Auditd logging

  • Auto security updates

  • Still runs Docker and security tools









What I Learned





  1. Test on the actual target platform. Ubuntu version differences will get you.


  2. Cloud metadata APIs are tricky. Validate the response format, not just reachability.


  3. Document your security tradeoffs. Future you and your auditors will need this.


  4. AI assistants catch edge cases. Claude flagged the SSH rename before we hit production.









Grab It






git clone https://github.com/HailBytes/rengine-ng-rc
cd rengine-ng-rc/scripts
sudo ./harden_ubuntu_2404.sh --help






Works for any Ubuntu 24.04 server, not just reNgine.



How do you handle the security vs. functionality tradeoff? Would love to hear what's worked for you. Update incoming this week.






#security #devops #ubuntu #cloudcomputing #opensource

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten We Hardened Ubuntu 24.04 for Security Tools (And Broke Everything First)

Thematisch verwandte Begriffe: Hardened, Ubuntu, 2404, Security · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-94040 | A flaw has been found in vas3k TaxHacker up to 0.8.5. Affected by this v…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick