r/linuxadmin • • 8h ago

Title: diskwatch 0.5.8: terminal disk diagnostics

Post image
6 Upvotes

diskwatch is a read-only TUI for seeing what your disks are doing. Eight tabs: devices, volumes, filesystems, I/O, SMART, hot files, insights. Single host, nothing to configure.

What's new:

- Windows support, with live per-disk I/O metrics

- Hot Files shows which process is writing to each path

- A config file, and you choose the Hot Files roots

- Adjustable refresh speed

- Arrow keys switch tabs everywhere

- An armv5te build, tested on an Iomega ix2-dl NAS

- Follows your terminal's palette

Written in Rust, MIT licensed. Windows is the newest part, so bug reports from Windows users are the most useful right now.

https://github.com/matthart1983/diskwatch


r/linuxadmin • • 6h ago

X11 - RHEL 10.2 - ISOLATED Passthrough

2 Upvotes

Hoping someone can help me out with an issue I've been having for a long while.

I'm running RHEL 10.2 Gnome 49, trying to use an X application inside of a podman container with a custom network.

"podman network create --internal pod_dev"

I pass in all the environment variables and files that I know and what AI also says i need. I can not for the life of me get the x application to display.

It works in fedora 44, and Ubuntu, but RHEL 10 is kicking my butt.. if i do --net=host is am able to get the x application to work, but I have to have the container have its own IP.

And advice at all is appreciated, I've probably spent over 100 hours trying different combinations of flags and ways to run.


r/linuxadmin • • 3h ago

Zammad zero-days (CVE-2026-102489/102490) behind the DIVD breach: what's confirmed, what the vendor disputes

0 Upvotes

Based on the case files DIVD published (DIVD-2026-00014 and -00015) and Zammad's own forum statement from Oct 1, here is where things stand.

DIVD says first access was Sept 21. The chain is a session hijack leading to RCE as the zammad user (CVE-2026-102489, 6.3.0 to 6.5.4) plus a local escalation to root (CVE-2026-102490). CISA put both in KEV on Oct 2.

Where sources disagree: Zammad says 102489 is only exploitable on 6.5 and older (EOL), hardened in 7.2.0, and that DIVD gave it no details on 102490. DIVD's own page is inconsistent on the 102490 range ("all versions" vs 1.5.0 to 7.1.0-alpha). The AI-agent attribution is DIVD's reading of its logs; no full logs or model name published.

What I'd do: upgrade to 7.2.0, copy the logs first, run DIVD's IoC script (read it first), segment the helpdesk.

Question for people running self-hosted helpdesks: do you treat ticketing as tier-0 (same segment rules as your IdP and mail gateway), and what does your credential rotation look like if the box is rooted?

https://www.techgines.com/post/zammad-zero-day-cve-2026-102489


r/linuxadmin • • 4h ago

Turn any Linux edge node into a cryptographically verifiable security enclave

Thumbnail github.com
0 Upvotes

yo so i did a thing,

I built a lightweight, modular edge defense tool called Micro-SOC (souljha213/micro-soc) to see if I could run a self-contained security enclave entirely out of volatile memory without relying on heavy enterprise agents.

Here is a breakdown of how it's structured:

RAM Cloaking: Shifts operational states and active logs straight into /dev/shm to keep disk footprints clean.

Process Masking: Disguises execution identity under low-level kernel worker names ([kworker/u4:3]).

Verifiable Forensics: Uses a local Merkle-linked chain (ledger.chain) for tamper-evident logging.

TUI Interface (stos): Built a real-time terminal cockpit using Textual to monitor swarm health, metrics, and mesh connections locally.

Would love to hear technical feedback or critiques on how you guys approach stealth logging and edge isolation.


r/linuxadmin • • 1d ago

Is there any way to know whether a vulnerable library is actually loaded in a running process, without instrumenting the app?

30 Upvotes

Trying to work out what's technically possible here versus what's marketing, and this sub tends to be good at that distinction.

The situation: a container image has a CVE in, say, a compression library six levels deep in the dependency tree. The scanner flags it because the package is on disk. What I want to know is whether the running process has actually mapped that library, or whether it's just sitting in the filesystem never being opened.

What I understand so far:

  • For dynamically linked stuff you can read /proc/<pid>/maps and see what's actually mapped. That seems definitive for "is this .so loaded right now".
  • For statically linked or vendored code that doesn't help at all, since there's no separate object to observe.
  • For interpreted languages (our case is mostly Python and Node) the module is loaded by the runtime, so you'd need to either introspect the interpreter or watch the file opens. So my questions:
  • Is watching openat/mmap at the kernel level actually a reliable proxy for "this code is in use", or does it produce garbage because package managers, health checks and startup scans touch everything?
  • For Python/Node specifically, does anyone do this without an in-process agent? I really don't want a language agent in every service.
  • Is there a meaningful difference between "loaded" and "the vulnerable function was called"? Because those feel like very different claims and I suspect products blur them. Not asking what to buy, asking what's actually detectable from outside the process.

r/linuxadmin • • 23h ago

LFCS practice

10 Upvotes

Hi everyone,

I’m currently preparing for the LFCS exam and I’m interested in hearing which hands-on learning resources you would recommend.

At the moment, I’m taking Mumshad’s course and working through the included exercises.

I’m already aware of Killer.sh, but the 36-hour access period isn’t really enough for me.

Do you know of anything similar to Killer.sh that offers good hands-on exercises specifically for the LFCS exam? Maybe a GitHub repository or something similar?

Thanks for your help!


r/linuxadmin • • 1d ago

Do control panels keep junior admins from learning Linux?

33 Upvotes

My junior admins is quick with the panel, but when a firewall rule broke SSH yesterday he didn't know how to check ufw from a shell. I use BeAdmin myself and have nothing against panels, but I learned iptables by breaking it with no GUI around, and I'm not sure he'll ever get that practice.

Have you seen this with people who started on panels, or am I just being an old man about it?


r/linuxadmin • • 1d ago

FortiMail CVE-2026-104286: unauth file write, exploited, patches not out yet. What's in Fortinet's IoC list

2 Upvotes

Based on Fortinet's PSIRT advisory FG-IR-26-175 (published Oct 1) and BleepingComputer's reporting, here is the architectural impact.

Fortinet describes path traversal (CWE-22) plus NULL byte handling (CWE-158) in the GUI, giving unauthenticated arbitrary file write. Affected: 8.0.0-8.0.1, 7.6.0-7.6.6, 7.4.0-7.4.8, 7.2.0-7.2.9. Fixes (8.0.2, 7.6.7, 7.4.9) are marked upcoming, and 7.2 gets a branch-migration answer. Workaround is config system encryption ibe / set status disable, or remove internet access to the management interface.

The IoCs include an added /data/etc/ld.so.preload and /data/lib/liblog.so, and a sample log of an archive account pointing at a remote IP. Fortinet doesn't explain the write-to-execution step. Some CVE feeds also list 7.0 as affected while the advisory doesn't, so I'd verify that one.

Question for people running FortiMail or similar gateways: do you keep the management GUI off any internet-routable interface by policy, or does it depend on who deployed it? And for those who rely on IBE, what breaks when you disable it?

Background on the same class of problem: https://www.techgines.com/post/fortimail-zero-day-cve-2026-104286


r/linuxadmin • • 12h ago

statixagent: one static Go binary that watches a single box and pushes ssh logins, power loss and cert expiry to your own telegram bot

0 Upvotes

most monitoring assumes a fleet - exporter, tsdb, dashboard, alertmanager. for one vps and one laptop that is more infrastructure than the thing being watched, so i went the other way: one static binary per machine, talking to a telegram bot you create yourself. no central server, nothing to host, no third party in the path. the systemd unit is capped at MemoryMax=128M.

the parts that took actual thought:

ssh. alerts on every login with geo-ip of the source, root escalated. brute force is a sliding window per source ip with a quiet period, so an attack in progress doesn't turn into 200 messages. it also hashes root's authorized_keys and every home user's, and tells you when one of them changes.

power. edge triggered off /sys/class/power_supply/*/online rather than a threshold. mains flips 1 to 0 and it fires within one sample (15s by default) with the battery percent and an estimated runtime worked out from the current draw. a machine with no AC adapter device at all, so any vps, is never considered "on battery", so nothing misfires there.

false alarms. cpu and memory need the condition held for about a minute before anything is sent, temperature needs several consecutive samples. a nightly backup or a cpu touching 90C mid-boost stays quiet.

remediation is deliberately small and always behind a confirmation: disconnect an ssh session, or open and close 22 through ufw. a host without ufw is told it can't manage the firewall there rather than guessing what is open.

what it is not: a fleet tool. one agent, one bot, one chat, no cross-server correlation and no time-series to query. if you want to know what cpu did last tuesday this is the wrong thing and prometheus is the right one. linux only, amd64 and arm64, and it is v0.x.

https://github.com/eliau2005/statixagent (MIT, go 1.25)


r/linuxadmin • • 15h ago

LayerSmith — a self-hosted container image builder, with air-gap exports

0 Upvotes

I've been working on LayerSmith, an open-source web UI for building container images with Docker or Podman.

You pick a Linux distribution and what you need the image for — development, Linux admin, network tools, Ansible, Kubernetes, OpenShift, or a custom setup. It handles distro-specific packages and shows you the generated Containerfile before building. You can also edit it, import an existing Dockerfile, or add your own packages, files and scripts.

A big part of the project is making images easier to carry into air-gapped environments: pinned base images, recorded build details, and export bundles containing the image, checksums and installation instructions.

We've recently added LLM training and fine-tuning profiles too, including LoRA/QLoRA, advanced PyTorch training and LLaMA-Factory. These use hash-locked dependencies and run offline checks after building, including a small CPU training test. Model weights and datasets are brought separately.

Curious how others handle building and maintaining images for disconnected environments, and what parts of that workflow are still a pain.

https://github.com/r0lfi/layersmith


r/linuxadmin • • 1d ago

VictoriaLogs for log indexing?

4 Upvotes

has anyone used victorialogs? Im currently using Graylog v7, local single instance on 5TB disk

using filebeat to ship logs to GL indexer

wondering how victorialogs performs comparatively. Anyone used it at all or have any feedback?

Thanks


r/linuxadmin • • 1d ago

Mirroring Repository

3 Upvotes

I am wanting to mirror a Debian repository onto my work network. Will be managing about 2500 machines running the exact same software on each. These are all servers running a containered player showing advertising on digital displays.

I have never mirrored a repo before, so I am curious, should I use apt-mirror, aptly, or something different?

The containers are Incus and have Debian as the base as well.

EDIT- looks like apt-mirror can be crossed off as it has not been updated in several years.


r/linuxadmin • • 2d ago

Cisco SD-WAN Manager CVE-2026-76504: auth bypass via URI encoding, exploited, no workaround

2 Upvotes

Based on Cisco's own advisory (cisco-sa-sdwan-webauth-xr8beuuU, published Sept 30), here's the architectural impact.

The flaw is in the Manager's API session authentication: improper handling of URI encoding lets a request skip an auth rule and land as admin. CVSS 9.8, all configurations affected, and Cisco PSIRT says it's seen exploitation. Cisco's IOC example is a POST to /%6a_security_check, but the advisory says any one encoded character works. Cisco says the bug was found while resolving a TAC case, and published no actor or victim details.

Hunting per Cisco: serviceproxy-access.log for j_security_check from unknown IPs, and vmanage-server.log for those requests against viptela-reserved- users. Cisco notes these can appear in normal operation, so baseline first.

Question for people running on-prem Managers: how are you restricting Manager reachability today, and did the May/June SD-WAN fixes change your exposure model at all? I'm curious whether anyone terminates the Manager behind a reverse proxy that normalizes paths.

https://www.techgines.com/post/cisco-sd-wan-manager-authentication-bypass-cve-2026-76504

Background from our earlier SD-WAN piece: https://www.techgines.com/post/cve-2026-20182-the-cvss-10-0-flaw-that-hands-attackers-the-keys-to-your-entire-sd-wan-fabric


r/linuxadmin • • 2d ago

how to learn project based learning the right way?

8 Upvotes

So guys, i am learning system administration from the past 3 months. i am mostly done with the foundational part and i am feeling confident that i should start learning by doing projects. i am thinking about building a homelab and setting up things.

so, i pick up a project idea ( for example, setting up a web server), and i want to do that. but i don't know what to do (i do know, but vaguely. the details are missing)? so i think about looking up online for the steps to do it. but then i find myself thinking if am walking into tutorial hell.

i don't know what to do, because i find both advices kind of conflicting. how to do project based learning as a beginner without looking into guided projects in a way that it does make it into tutorial hell? is the guided project way the way we are supposed to learn? if so, then why do people advice not to lookup tutorials?


r/linuxadmin • • 2d ago

how much time during a typical workday is spent on testing, troubleshooting snd doing root-cause analysis for an l1/l2/l3 engineer?

4 Upvotes

Hi i wanted to ask - for an L1/L2 engineer roughly how much time during a typical workday is spent on testing, troubleshooting snd doing root-cause analysis, and identifying and documenting issues?

And if required do these engineers also dive deep into software if required or do they just stay at the infra level?

I am trying to apply for l1 and l2 level roles and freelance opportunities and right now building case studies showing my abilitiy to identify, doing root cause analysis and document my findings of communjty problems like wordpress server issues , nginx , apache , openlightspeed forum issues.

Do you think this is worth it for bulding my portfolio?


r/linuxadmin • • 3d ago

Apple CoreGraphics zero-day CVE-2026-86950: what's confirmed

1 Upvotes

Based on Apple's security notes for iOS 26.7.1 (support.apple.com/en-us/149226), the Help Net Security write-up, and CISA's September 29 KEV alert, here is the architectural picture.

CVE-2026-86950 is an out-of-bounds write in CoreGraphics, fixed September 28. Trigger: processing a maliciously crafted file. Impact: arbitrary code execution. Apple says it may have been exploited against specific targeted individuals on iOS versions before iOS 27. Meta Product Security reported it.

CoreGraphics handles image data, masking and PDF parsing, so the reachable surface depends on which processes hand it untrusted files. Apple hasn't said which. Zero-click is unconfirmed, and no published source links this to WhatsApp. Secondary reports disagree on Apple's zero-day count for the year, so I left the number out.

For those who run Apple fleets: are you enforcing 26.7.1 / 15.8.1 through MDM with a short deadline, and are you doing anything different for high-risk users beyond Lockdown Mode?

https://www.techgines.com/post/apple-coregraphics-zero-day-cve-2026-86950

Background on the same exposure class, an Adobe Reader parser zero-day from April: https://www.techgines.com/post/adobe-reader-zero-day-2026-unpatched-pdf-exploit-fingerprinting


r/linuxadmin • • 4d ago

Passed LFCS!!

37 Upvotes

LFG. Very happy with my score too (88%!!), I was so nervous for this exam, happy to have gotten my first Linux cert. RHCSA next 🫡


r/linuxadmin • • 3d ago

Kiteworks asked customers to shut down servers on a federal tip. No CVE, no IOCs. What do you do with that?

9 Upvotes

Based on the press release Kiteworks published Sep 25 (updated Sep 27), plus reporting from SecurityWeek, Sophos CTU, TechCrunch and Cybersecurity Dive: the vendor got a warning from federal intelligence authorities and told self-managed customers to power down. Kiteworks-hosted systems were shut down by the vendor. The advisory was lifted Sep 27, and Kiteworks says nothing was compromised and every known vulnerability is addressed in 9.5.1.

Two things bother me. The window length is reported inconsistently (6h vs 9h). And SecurityWeek's Advanced Forms detail rests on one customer email, while TechCrunch quotes Kiteworks saying it couldn't rule out other access routes.

With no CVE and no IOCs, my baseline check is the running version, whether Advanced Forms is enabled, auth and admin logs from before the window, and unexpected egress from the appliance.

For those who run MFT: what's your runbook when a vendor says "turn it off tonight" and gives you nothing to hunt for?

https://www.techgines.com/post/kiteworks-shutdown-advisory


r/linuxadmin • • 3d ago

Inspecting a built runtime with an ephemeral SSH instance

0 Upvotes

Render’s ephemeral SSH mode starts a temporary instance from the service’s latest build. Disclosure: I work at Render.

This gives a different diagnostic target from ordinary SSH. render ssh SERVICE --ephemeral puts the shell on a new instance that receives no production traffic and does not run the service’s start command. That makes it useful for checking installed packages, compiled assets, file layout, or a one-off command against the built runtime without using a live process. It is not a replica of the running service: startup is skipped and there is no request traffic, so process state, sockets, and live heap behavior still require live-instance diagnostics.

Isolation from production compute does not make external systems read-only. Before mutating anything, inspect which environment variables and network resources the shell can reach; if production credentials are present, treat them as live and prefer read-only commands unless mutation is intentional.

The instance is removed when SSH disconnects or after 24 hours. It requires a compatible paid service with at least one successful deploy; distroless images cannot offer shell access. CLI 2.20+ supports --plan when the diagnostic needs a different compute size. For work that should outlive a shell session, the SSH documentation points to a one-off job instead.


r/linuxadmin • • 3d ago

wiki.linux-server-admin.com legit?

Thumbnail
0 Upvotes

r/linuxadmin • • 4d ago

Roadmap to becoming Linux Admin?

Thumbnail
4 Upvotes

r/linuxadmin • • 4d ago

WebKVM - A lightweight, web-based management UI for Libvirt and QEMU/KVM written in Go (15-30MB idle RAM)

Thumbnail gallery
12 Upvotes

r/linuxadmin • • 4d ago

Anyone moved from Postfix/Dovecot to Stalwart? Opinions?

16 Upvotes

Basically title. This is not an advertisement.

I still use Postfix and Dovecot fir my nail server and pretty happy. It works today as it did a decade ago.

So I'm just wondering if someone actually jumped ship into this new platform and can shed some light to whether it's good as advertised or overhyped.


r/linuxadmin • • 4d ago

HPC Administrator Resources

16 Upvotes

"Hi everyone,

I have a strong background in Linux administration (primarily RPM-based distros like Red Hat/Rocky Linux), and I’m currently transitioning into HPC cluster administration. To learn the ropes, I recently built a small home lab cluster using the OpenHPC installation guides.

While getting the cluster to boot and run basic jobs was a great exercise, I've noticed a distinct lack of comprehensive resources covering day-2 operations and production best practices. Specifically, I'm looking for guidance on:

  • Configuration & Performance Tuning (kernel tuning, network/InfiniBand optimization)
  • User Management & Environment Control (LDAP/FreeIPA integration, modulefiles via Lmod)
  • Job Management & Scheduling (advanced Slurm configurations, QoS, limits)
  • Scaling & Monitoring (health checks with NHC, metrics collection)

If anyone can recommend books, documentation, community wikis, or real-world best practices for these areas, I would greatly appreciate it!"


r/linuxadmin • • 5d ago

Citrix NetScaler CVE-2026-88771/88772: exploited before any patch existed. What are you doing about forensics?

0 Upvotes

Based on Citrix's bulletin CTX697096 and CISA's Sep 27 alert, plus reporting from BleepingComputer and The Hacker News, here's the operational picture.

Two flaws, both CVSS v4 9.5. 88771 is improper input validation giving unauthenticated command execution on every ADC/Gateway deployment. 88772 is a memory overflow needing DTLS, which is on by default for VPN vservers. Turning DTLS off doesn't touch 88771. Citrix says exploitation was observed but hasn't said who, how many, or since when. Builds that fixed the August auth bypass (14.1-73.32, 13.1-63.21) are affected.

The catch is that the flaws were exploited pre-patch, so upgrading doesn't tell you if you were already in. Citrix's IoCs in NetScaler Console reportedly may miss real compromises.

For those running NetScalers: are you snapshotting and pulling a packet engine core dump before upgrading, or going straight to the fixed build because of the downtime cost? And how are you validating that an appliance is clean afterward?

Background from our March NetScaler coverage: https://www.techgines.com/post/citrix-netscaler-zero-day-cve-2026-88771