Count your own attack surface, then reduce it
Task
Measure what your lab VM exposes, decide for each item whether it is needed, remove what is not, and measure again. The lesson's rule -- every thing an attacker could touch is either needed and defended, or not needed and gone -- is only useful when it is a number you have moved.
Steps
- Record the three surfaces into
/tmp/surface-before.txt: listening sockets (ss -ltnup), enabled services (systemctl list-unit-files --state=enabled --no-legend), and installed packages (dpkg -l | wc -lorrpm -qa | wc -l). - For each listening socket, write in
/tmp/justify.csvthe columnsport,service,needed,why. Be strict: 'it came with the install' is not a reason, and a management interface that answers on every address is the classic finding. - Disable and mask every service you marked not needed, one at a time, checking after each that the machine still behaves.
- Remove one package you genuinely do not need, and note that an uninstalled package needs no patching and produces no findings -- the only control with no ongoing cost.
- Record the three surfaces again into
/tmp/surface-after.txt. - Write the reduction into
/tmp/surface.mdas before-and-after counts for each of the three surfaces, and classify anything you kept but would not fully trust as unsupported, unpatched, obsolete or unmanaged.
Verify
python3 - <<'PY'
def n(p, needle):
return sum(1 for l in open(p) if needle in l)
b=n('/tmp/surface-before.txt','LISTEN'); a=n('/tmp/surface-after.txt','LISTEN')
print('listening sockets: %d -> %d' % (b,a))
assert a<=b, 'the surface grew'
assert a<b, 'nothing was removed - the lab was read, not done'
PY
awk -F, 'NR>1 && $3 ~ /no/ && length($4)<5 {n++} END {print (n+0)" unjustified removals"}' /tmp/justify.csv
The assertion requires the count to have actually fallen, so the lab cannot be passed by taking two identical measurements. The second must be 0: every service you turned off has a recorded reason, because an undocumented removal is indistinguishable from a mistake when something breaks next week.
Notes
Do this on a machine you own and never on one you do not. The same measurement against somebody else's estate is a port scan, whatever your intention -- and that distinction is decided by authorisation rather than by technique. Misconfiguration is the commonest real finding, and most of what you removed was a default nobody had questioned.
This is an independent study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.