Close what does not need to be open, and confirm it from outside

short · 45 min · Objective 3.5

Task

Inventory everything listening on lin-b, remove or disable what the server does not need, put a default-deny host firewall in front of what remains, and confirm the result the way an attacker would see it: a port scan from another machine, before and after.

Steps

  1. On lin-b, save ss -tulpn to lab/surface/listening-before.txt.
  2. From lin-srv, run nmap -sT -p- 192.168.56.30 (lin-b's address) and save the output to lab/surface/scan-before.txt.
  3. For each listening service, decide keep or remove and record it in lab/surface/decisions.csv with header port,service,decision,reason. Remove or disable every service marked remove.
  4. Configure nftables or firewalld on lin-b to drop inbound traffic by default and allow only SSH from 192.168.56.10 and the services you kept. Save the ruleset to lab/surface/firewall.txt.
  5. Repeat both captures as listening-after.txt and scan-after.txt.

Verify

These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.

grep -c 'open' lab/surface/scan-before.txt
grep -c 'open' lab/surface/scan-after.txt
awk -F, 'NR>1 && $3=="remove" {n++} END {print n" service(s) removed"}' lab/surface/decisions.csv
grep -Eic 'policy drop|DROP|default.*(drop|deny)' lab/surface/firewall.txt
grep -Ec 'LISTEN' lab/surface/listening-before.txt lab/surface/listening-after.txt

The scan after shows fewer open ports than before -- ideally only SSH -- and the firewall's default policy is drop. The listening count fell as well as the scan count, which matters: a firewall hiding a service that still runs is one rule change away from exposing it again.

Notes

A full-range scan with -p- is slow but thorough. The default nmap scan checks only the thousand most common ports, and services moved to unusual ports are exactly the ones it misses.

This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.