Server security
Linux Server Audit Fixes
These are the fixes for a server security audit: who can reach the box, what it is running, which files are writable by the wrong people, and how far behind it is on patches.
What these fixes cover
- Root login, key-based authentication, sudo grants and who can open a session
- Firewall state, listening ports, IPv6 coverage and services exposed beyond localhost
- World-writable paths, set-id binaries and sensitive file permissions
- Pending security updates, kernel state and whether a reboot is outstanding
What they do not
- Application-level bugs in the code you deploy. These checks read server configuration, not your source.
- Intrusion detection beyond whether Fail2Ban, sshguard or CrowdSec is present and running.
- Anything behind a managed platform you do not control. On Kubernetes or a PaaS there is no sshd to read.
How much of this is serious?
Severity of all 45 VPS & Server checks, as the scripts rate them.
- 13High severity29%
- 21Medium severity47%
- 11Low severity24%
7 audits, 45 checks
Grouped by the 7 audits they belong to. SSH and access is the front door; firewall and network decides how much of the rest is even reachable.
SSH & Access
Root login, password auth, port, idle timeout, authorized keys and sudo privileges
11 fixes2 need rootServices & Processes
Attack surface from services, listeners and scheduled jobs
9 fixes2 need rootFile System
Dangerous permissions, set-id binaries and sensitive files
7 fixes4 need rootFirewall & Network
Firewall state, exposed ports, Docker bypass and network policy
6 fixes4 need rootApplication Security
TLS certificates, runtime versions and database access
5 fixes2 need rootSystem Updates
Pending patches, automatic updates, kernel and reboot state
4 fixesLogging & Monitoring
Separated logging and monitoring checks
3 fixes3 need root
The other three platforms
Most hosts run more than one of these. The split shows how much of each platform the audit rates as high severity.
Database
MySQL, PostgreSQL, MongoDB and Redis - access, exposure and encryption.
37fixes across 6 audits
19 high15 medium3 low
Web Server
TLS, security headers, exposed content and request handling.
36fixes across 6 audits
8 high18 medium10 low
Docker
Daemon exposure, container privileges, images, volumes and limits.
39fixes across 6 audits
13 high15 medium11 low
VPS & Server fix questions
Run all 45 VPS & Server checks, in one click
CtrlOps runs these audits over your existing SSH connection - no agents, no scripts to manage. $7/user/month after a 1 month free trial - no credit card required.
✓ Start instantly·✓ No credit card·✓ No sneaky autorenewals