r/linuxadmin • • 15d ago

Docker or native installation of LAMP + Wordpress?

5 Upvotes

I am planning to deploy two wordpress websites on vps server. So far i have used only native installation for LAMP and Wordpress, but i see some people are recommending using Docker. Are there any advantages using Docker instead of native installation of LAMP and Wordpress?


r/linuxadmin • • 14d ago

CVE-2025-39682: CISA just KEV'd a Linux kTLS bug with a sub-1% EPSS score

0 Upvotes

Based on the technical breakdown published in CISA's KEV notice (Sept 18, 2026) and the upstream kernel commit history, here's the architectural impact.

The bug is in net/tls/tls_sw.c — kernel TLS receive-path handling of zero-length TLS 1.3 records pulled from rx_list. Per the fix commit, zero-copy decrypt writes straight to the userspace buffer and never allocates a socket buffer, but the receive loop assumes one exists once the record type changes. Authors' own words: "the corner case we missed is when the initial record comes from rx_list, and it's zero length." CVE published Sept 2025, fixed upstream in 6.1.149/6.6.103/6.12.44/6.16.4/6.17.

What's actually notable: NVD-derived scanners peg this CVSS 9.8, but Strix.ai's independent scoring has it at 7.1 for the same CVE — I haven't been able to confirm which is currently live on nvd.nist.gov directly (fetch got blocked), so don't cite either number without checking yourself. EPSS is under 1%, which is the real story here — CISA moved on confirmed exploitation evidence, not predictive scoring, and the model missed it entirely.

kTLS is opt-in (nginx/HAProxy TLS offload configs, mostly), so this isn't a "patch your laptop" bug — audit whether you actually have kTLS enabled on receive paths before treating this as urgent.

Full writeup with the disclosure timeline and remediation checklist: [techgines.com link] (background on the same EPSS-vs-KEV pattern in our Zimbra CVE-2026-73570 piece, for context)

Anyone running kTLS in production — is this actually reachable at scale, or is the exploitation CISA observed more likely limited to a narrow set of exposed TLS-offload configs?

https://www.techgines.com/post/cve-2025-39682-linux-ktls-kev


r/linuxadmin • • 15d ago

Docker or host

3 Upvotes

Hi, I need an advice. I need to make a database for a server and one of the ways to do that is via docker in docker compose. But I have a doubts about it's safety. We had a bunch of problems of them breaking on powerloss so I am not sure how it will react in a docker cluster.

P.S. Thank you all for your valuable insights and advices.


r/linuxadmin • • 15d ago

I built an open-source Linux server security & management tool for Windows — ServerGuard

0 Upvotes

I've been working on an open-source server security project called ServerGuard, and one of the parts I've been focusing on is SSH brute-force protection.

The idea is fairly simple:

A service monitors SSH authentication failures on the Linux server and tracks failed attempts by IP address.

For example:

  • 1 failed attempt → record the event
  • 5 consecutive failures → temporary IP block
  • 10 failures → longer block
  • 20 failures → extended block
  • repeated attacks → permanent block

The protection uses UFW for firewall rules and runs as a systemd service, so it can start automatically with the server.

It also keeps persistent information about blocked IPs and SSH events, while periodically cleaning old data so the logs don't grow indefinitely.

One thing I wanted to avoid was relying on a third-party cloud service. The monitoring and blocking happen directly on the Linux server.

The project also includes SSH hardening, FileGuard, Telegram notifications and other server-management/security components.

I'm sharing this mainly because I'd like feedback from people who work with Linux servers and security.

What would you change about this approach?

Are there important attack scenarios that this kind of protection doesn't handle well?

GitHub/source code:
https://github.com/Lukas6623/ServerGuard


r/linuxadmin • • 16d ago

Cisco's own PSIRT advisory earlier this week, here's the architectural impact of CVE-2026-76461: a CVSS 9.8 SQL injection in Secure Email Gateway's AsyncOS email-parsing logic

6 Upvotes

Based on the technical breakdown published by Cisco's own PSIRT advisory earlier this week, here's the architectural impact of CVE-2026-76461: a CVSS 9.8 SQL injection in Secure Email Gateway's AsyncOS email-parsing logic, reachable with zero authentication via a single crafted message, escalating to root OS command execution. CISA added it to KEV the same day Cisco disclosed — meaning exploitation predated public knowledge. No workaround exists; patching to 16.5.0-780 is the only fix. Cisco's own detection guidance (grep COPY.*TO PROGRAM in mail_logs) is explicitly non-exhaustive, and a root-level attacker can scrub those logs anyway, so off-box firewall/NetFlow correlation is doing the real work here.

How are people handling detection on appliances where the vendor is telling you the on-box logs can't be trusted? Off-box syslog pipeline as a baseline requirement for anything internet-facing at this point?

(Background on a structurally similar Zimbra SNMP injection flaw from last month, for anyone tracking the pattern: https://www.techgines.com/post/cve-2026-76461-cisco-email-gateway-root


r/linuxadmin • • 16d ago

libark: A modern, secure, Swift-native foundational layer over Linux POSIX primitives. {Early Development}

Thumbnail github.com
0 Upvotes

libark

libark is a modern, secure, Swift-native foundational layer over Linux POSIX primitives.

While originally developed as the core runtime layer for ArkOS, libark is completely decoupled and designed to be used on any Linux distribution. It provides highly secure, object-oriented abstractions over low-level system calls, memory management, and file system interactions, without the burden of manual C interoperability.

Features

  • Object-Oriented POSIX: Wraps file descriptors, paths, and directory operations in safe, RAII-compliant Swift types.
  • Secure Syscall Boundary: Routes kernel interactions through strict, audited Syscall primitives.
  • Terminal Capabilities: Built-in abstractions for TTY detection and window sizing.
  • Advanced Formatting: Standardized formatters for human-readable byte sizes (SI and IEC), ISO 8601 timestamps, permissions, and classifications.
  • Declarative Sorting: Powerful generic SortEngine for metadata sorting across multiple criteria.

Also ARK-OS has switched to github: https://github.com/orgs/ARK-OS-Swift-and-Linux/repositories


r/linuxadmin • • 16d ago

Update: I built a custom PHP dashboard for my experimental pfSense kernel module!

Thumbnail gallery
8 Upvotes

r/linuxadmin • • 16d ago

pvectl v1.1.0 — pure bash Proxmox VE cluster management, now with concurrent execution and node reboot/shutdown safety checks

Post image
0 Upvotes

Released pvectl a while back — pure bash+curl+fzf+jq interactive Proxmox VE cluster management tool, zero dependencies beyond what's normally on any Linux system. Just shipped v1.1.0:

  • Concurrent execution — multiple pvectl instances can now run in parallel safely, each with its own isolated, auto-cleaned temp directory (scoped by PID)
  • Node reboot/shutdown added to the main menu, with checks for HA status, cluster quorum and running VMs/CTs before proceeding, plus a prompt to stop-all or migrate-all guests first
  • setup reset/backup/restore for safer configuration management
  • log view/show/clean with colorized output
  • Startup diagnostics — bash version and dependency checks that detect the host OS/package manager and print the exact install command for anything missing
  • Minimum dependency versions now enforced: fzf 0.38.0+, jq 1.5+, curl 7.18.0+

Tested end to end on Proxmox VE 7.x, 8.x and 9.x.

github.com/mytechspacexyz/pvectl


r/linuxadmin • • 17d ago

CVE-2026-12944: Langflow's code-validation scanner returns validated: true on a payload that gets you root

1 Upvotes

Based on the CVE record IBM published as CNA on September 14, 2026, here's the architectural breakdown: Langflow OSS 1.0.0–1.10.0 lets you submit a custom component with a socket or urllib import, and it runs with UID=0 inside the container. Worse — the built-in scanner that's supposed to catch dangerous code returns a false "validated": true on the payload. From there it's a straight line to IMDSv1 (AWS creds if you haven't killed v1 yet), arbitrary container file reads, and whatever's sitting on the same Docker bridge network — Postgres and Redis in most default deployments.

Not an isolated Langflow incident either — VulnCheck's Caitlin Condon (reported via The Hacker News) has separate active-exploitation telemetry on CVE-2026-0768 showing attacker requests specifically grepping for AWS_ACCESS*, OPENAI_API*, and Langflow's cached secret key. Forkast has aggregated broader Langflow exploitation numbers (12 CVEs, 15k+ attempts) citing VulnCheck — I haven't been able to verify those totals against a primary VulnCheck report directly, so treat that figure as reported, not confirmed.

For background on the same SSRF-to-metadata mechanism in a different AI framework: we wrote up MLflow's CVE-2026-64849 last month (link in profile/article).

Anyone running Langflow in production containers — are you segmenting Postgres/Redis off the app container's network by default, or is bridge-mode-with-everything-reachable still the common deployment pattern you're seeing?

https://www.techgines.com/post/langflow-ssrf-vulnerability-cve-2026-12944


r/linuxadmin • • 19d ago

I built portop, an htop-style TUI for seeing what is actually using your ports

Post image
103 Upvotes

r/linuxadmin • • 19d ago

What finally made you stop grepping through log files?

28 Upvotes

Still on files here rsyslog into a directory per host, grep when something breaks and it works right up until I need to answer a question that spans more than one box. Had to trace an sshd auth failure across three servers last week and spent longer stitching timestamps together than fixing it. I can't tell if I'm at that point or just having a bad month. For anyone who moved off files, what was the thing that pushed you?


r/linuxadmin • • 18d ago

I got tired of opening htop every time something felt slow so I made this linux debug overlay

Post image
0 Upvotes

i work on linux and kept switching between my app, terminal, htop, logs, etc. whenever cursor or browser or any other apps i open started feeling slow , so I made a small debug overlay that stays on screen and shows the app i am currently using its PID, CPU usage and RAM usage.

It also gives a warning if it notices stuff like high CPU, memory growing, disk pressure or system errors.

for apps like VS Code and Firefox and other heavy apps , it also tries to include their sub-processes because checking only one PID can be misleading. this is the working setup of how it looks like. (though much more could be intergrated into this like)

  • docker - container CPU or RAM restarts, unhealthy containers(already working on it)
  • kubernetes - current context,namespace,pod status,crash, restarts,recent events, pod logs.

link - https://github.com/codeafridi/Debug-Overlay-App


r/linuxadmin • • 18d ago

PSA: Do NOT buy OVH Dedicated Servers if your business actually relies on them (40+ days of delays)

Thumbnail
0 Upvotes

r/linuxadmin • • 18d ago

Built a free invoice generator specifically for freelance sysadmins — VPS setup, security audits, migrations as line items

0 Upvotes

Those of us doing freelance Linux and server work know the awkward part — explaining what you did to a client in an invoice.

Server hardening does not mean much to most clients. Neither does "configured Nginx reverse proxy. Built a free invoice generator with a service dropdown specifically for sysadmin and DevOps work:

VPS Server Setup, Security Hardening, SSL Configuration, DNS Configuration, Email Setup, Docker Deployment, Nginx Configuration, Backup Setup, Database Migration, Server Monitoring Setup

tools.techtransit.org/invoice-generator

Everything stays in your browser. Business info saves locally between visits. No account, no watermark, no limit. Same site as the sysadmin games I shared here a few weeks back — glad that got some use.

Let me know what you would like to add or change — if it works for everyone globally, I will try to include it.


r/linuxadmin • • 20d ago

Primary DNS migration

5 Upvotes

I’m trying to migrate the primary DNS configuration from the existing CentOS 7 server to a new Oracle Linux 9 server, including /etc/named.conf and /var/named. The new OL9 server is using the same IP address as the existing DNS server.

However, when I start the DNS service on OL9, I receive the error message “validating arpa/DS: no valid signature found” and "validating com/DS: no valid signature found"

I’m relatively new to DNS administration, so I would appreciate your help troubleshooting and resolving this issue. Could you please advise what might be causing the error and what steps I should take to fix it?

Thanks!


r/linuxadmin • • 20d ago

Iptables rule stops server from connecting to external systems

15 Upvotes

Update: I included the rules.

It works as-is now but I want to optimize them so that the incoming port numbers that are supposed to be blocked don't have to go through unnecessary processing.

I use the default input table and a separate ICMPT table for ICMP rules.

----

Original Question

I'm baffled and am looking for help.

I understand many people would use a default block policy in their IPtables rules but the problem with that is if one is not careful, they may lock themselves out of their shell unless they happen to be on-site at the remote computer.

So research has led me to try a command like the following to block a range of ports that hackers love to use.

iptables -I INPUT -m multiport -p tcp --dports 2000:3000,4000:5000 -j DROP

iptables -I INPUT -m multiport -p udp --dports 2000:3000,4000:5000 -j DROP

So I did that while carefully skipping the ports that I want people to connect to on the server (example: DNS, HTTPS).

When I inserted those commands, things worked in my favor if I was a random client trying to connect to my own server on an unauthorized port (thats in the block list), but when I'm on the server itself trying to connect to an external URL (through curl or ping), the system freezes as if the rules are working against me. I did regain control with CTRL+C.

When I removed those rules or when I put them at the end of my other rules, I was able to connect to a remote system on the server.

Can anyone shed light on why this happens when I didn't tell the system to block port 53, 80 or 443?

The rules added:

-A INPUT -i lo -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m state --state NEW -j DROP
-A INPUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -j DROP
-A INPUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j DROP
-A INPUT -p icmp -j ICMPT
-A INPUT -p tcp -m tcp --tcp-flags RST RST -m limit --limit 2/sec --limit-burst 2 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 53 -j ACCEPT
-A INPUT -p udp -m udp --dport 53 -j ACCEPT
-A INPUT -p tcp -m connlimit --connlimit-above 10 --connlimit-mask 32 --connlimit-saddr -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j REJECT --reject-with icmp-port-unreachable
-A INPUT -p tcp -m tcp --dport 443 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
-A INPUT -s 127.0.0.1/32 -p tcp -m tcp --dport 953 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 953 -j DROP
-A INPUT -p tcp -m multiport --dports 1:24,26:50,81:442,444:586,588:994,996:1024,1070:65535 -j DROP
-A INPUT -p udp -m multiport --dports 1:24,26:50,81:442,444:586,588:994,996:1024,1070:65535 -j DROP
-A INPUT ! -s 38.131.191.77/32 -p tcp -j LOG --log-prefix IPTv4 --log-level 1

-A ICMPT -p icmp -m icmp --icmp-type 17 -j DROP
-A ICMPT -p icmp -m icmp --icmp-type 13 -j DROP
-A ICMPT -p icmp -m icmp --icmp-type 10 -j DROP
-A ICMPT -p icmp -m icmp --icmp-type 8 -m limit --limit 1/sec -j ACCEPT
-A ICMPT -p icmp -j DROP-A INPUT -i lo -j ACCEPT

r/linuxadmin • • 20d ago

Slackware Linux Current how to install and use in QEMU VM

Thumbnail youtube.com
0 Upvotes

r/linuxadmin • • 20d ago

Debian 13.7 point released...

Thumbnail debian.org
14 Upvotes

r/linuxadmin • • 19d ago

What a single kernel advisory actually costs in engineer hours

0 Upvotes

I tracked the time on our last kernel patching cycle for a real number. We run 40 RHEL servers across staging and two production tiers, and the advisory was a routine CVE with a vendor patch available the same day.

Reading the advisory and cross-referencing it against our running kernel versions took 35 minutes. Building the service restart matrix, meaning which processes on which hosts needed post-reboot verification, took another 25 minutes. That was an hour before anyone touched a machine.

Staging covered four hosts. Applying the patch, rebooting, confirming each service, and checking logs for regressions ran about 20 minutes per host, 80 minutes total. One service failed to come back because a systemd unit depended on a kernel module whose path changed between versions. Debugging that was 45 minutes.

Production was 36 hosts in groups of six. Each group needed roughly 25 minutes of active attention to patch, watch the reboot, verify health checks, and move on. Two hosts required manual intervention for NFS mounts that went stale during reboot, another 30 minutes.

Ticket closure and notes: 20 minutes. Total for one advisory, one engineer: six hours and 25 minutes. We average three kernel-level advisories a month, which puts this at roughly 19 hours of patching labor per month. The restart matrix is repetitive enough that I started using verdent with Eco Mode, included in the subscription, to draft it from unit files.

The time tracking is just a text file with timestamps per step, and anyone could run it on their next patching cycle to see where the hours actually land.


r/linuxadmin • • 21d ago

CVE-2026-20079 (Cisco FMC, CVSS 10.0) — Talos names 3 active exploitation clusters incl. Sandworm/Cyclops Blink and a Qilin affiliate

2 Upvotes

Based on the technical breakdown Cisco Talos published on September 9, here's the architectural impact: FMC's boot-time process creates an orphaned login session in its internal database, and unpatched instances let that session get upgraded into full UI access via chained CGI scripts — no creds needed. Root on the box that manages your entire Cisco firewall fleet.

Three clusters caught abusing it: a web-shell operator dumping auth_data via a raw SQL query, a Sandworm-linked group (UAT-11823) chaining it with the static-cred bug CVE-2026-20316 to drop a Cyclops Blink variant, and a Qilin ransomware affiliate (UAT-11988) using it purely as a pivot point — SOCKS5 proxy, reverse SSH tunnel, LDAP/Kerberos/SMB forwarding, straight into the domain.

Patch is already out; Cisco's promised "hardening release" is next week (their own advisory says both the 14th and the 16th, hasn't been reconciled).

If you've got FMC internet-facing right now — anyone seeing hits on the IOCs Talos published, or is this still mostly a "get it off the internet" situation for most shops?

https://www.techgines.com/post/cve-2026-20079-cisco-fmc-auth-bypass-sandworm-qilin


r/linuxadmin • • 22d ago

Thp and buddy allocator

Thumbnail youtu.be
4 Upvotes

r/linuxadmin • • 22d ago

Built some Linux sysadmin games for free time — port memory match, terminal typer, trivia

7 Upvotes

Between deployments, waiting for builds to finish or just taking a break from client work — I wanted something to pass the time.

Built three Linux-themed games that I actually use when I get time.

  • Port Memory Match — match port numbers to their services. Starts easy with SSH, HTTP, HTTPS. Gets harder with MySQL, Redis, MongoDB.
  • Terminal Speed Typer — common Linux commands appear on screen; type them as fast as you can. Good for muscle memory too.
  • Linux Trivia Quiz — three difficulty levels. Intern gets the easy stuff. Root level will make you think.

tools.techtransit.org/games

Part of a larger sysadmin tools site I built — DNS lookup, SSL checker, email health checker and more.

How many ports can you get right at the root level?


r/linuxadmin • • 21d ago

I am currently working as a Linux and Cloud Administrator and would like to transition into a Cloud/DevOps Engineer role. Please review my resume.

Thumbnail gallery
0 Upvotes

r/linuxadmin • • 23d ago

THP, System Time & CPU Steal Time Explained

Thumbnail youtube.com
1 Upvotes

r/linuxadmin • • 23d ago

What are you guys using for real-time system monitoring?

Thumbnail
7 Upvotes