Linux Administration

Users and groups

Adding an existing user to an existing group

usermod -a -G theExampleGroup theExampleUser

Changing the primary group of an existing user

usermod -g theExampleGroup theExampleUser

See wich groups the user belongs to

groups theExampleUser

Add an existing user to the sudo group

usermod -aG sudo username

 Add a new user with name, shell and home directory

sudo useradd -m -c "Samwise the Brave" sam  -s /bin/bash

 

https://www.cyberciti.biz/faq/howto-linux-add-user-to-group/

https://www.digitalocean.com/community/tutorials/how-to-create-a-sudo-user-on-ubuntu-quickstart

https://askubuntu.com/questions/643411/ubuntu-14-04-new-user-created-from-command-line-has-missing-features

 

Passwords

Use pwgen to generate ramdom passwords

pwgen will generate easy to remember passwords

# pwgen
Vi6yoo9K loisae4A Eeboo9Ci phahc9Ba Eic0teej Mithuij4 ahSah0oh Aiquao7t
Xai1mab1 sahx5veZ fai4Osah Hieg0Tai ohz0Ahth wa5ohLai Ol0ielah Phaeshi4
eemeKio8 AeNgei5i thohTh6u Ainoh0ae Engeir0w ool9teJ7 gaeFah3z ooJ0fieD
Ye8kaeNg YeeCha4D leiteCh6 Xi7lof3b Aen4dush eifue1Ui Ee3joosh Oe6ae0ei
Maibu7la Ief8uze3 jaeRoji6 yoxua5uL ooVae3eV Ungei2Ah vohWoh3i aiTh7noh
ahw0Vi2a Usaa0ooF eithe9Ph eiQueo4w Ex5aeghe eiVikuz6 aiV7Geix eiNgah1G
ai4Ookoo Aeteek8a IZo3ho3Z sohYoob4 Xaivohy0 mohV6ma2 Tho7ofai peeVoop2
cooBoo1o Vo4ivie8 ohve9Hah Oofoo7oo ahShu3eo pieree9O Eip6Luel kahl1ieW
Shoshei2 reeC2UPh aik4Shae Cohquif4 boh8iTeu iamu8Chu seuz2ieD ke2Aijut
Aequath7 ticieH9h athieGh1 ouB5eigo Saphe0ei iep3ieSh Pie1oowa Neix7yot
Okeequ8u vahng5Wa iedaiTe1 Iec6kahz Thu2gi9a saeNgo1k aigha3Th Ohghi3tu
Bohm9vie chueChu9 ESa9veu9 lahW8tha Ohpie2na we6Jaik7 ooG0oiP2 jae0Ooy6
eiThudo8 Chuud1Ph Ohyae2Th eiHoo5oH Tei3oobu cai0Quen Iej0Pahr gohThie3
oec4ooNu OD7ohFow eiGe7pah xahTai8E aethah9N Aeng6cei Hoh6jani Chiech1x
eiLah9Ri hee9doNg ooj9Aeth lu4Koh2k Yuzu0Cha jooxa8Ae AhFie8ie Nihe2wao
Oph5sieF eiMi8tus seeX8Oog Ien1imee uo7Xohn8 Kee0Aath Aigh0ahP eing6Ath
Aec6Oixu AhF9kipi Vai2ahMa eleeD3tu AelaiBa1 elie0Me1 JahTha9s Eitho9ko
Eec1sahs feixi7Wu sa3iB3qu Em4goxae el0Theik Eikeif0x Chee1xe9 CahS8thi
Aiweiy6Y iV0Vei5i OoJ4aeQu So2Baiph ve1Paepo big5oc6T Xa8pashu ieJoh1Ya
Aech6noh aiy3Zaeb eemai8IR Hei5aang aiz3Thah tho7fuNg ochoh5Ko sahk6aDi

with '-s' option, pwgen will generate completely random passwords

# pwgen -s
jtR8hxCL Bs0g0npf CppsPab4 zJ4S7uhd LfZQr9Ip f4eEIRbb Kt621WNi yh5KXh4p
88pAMDsH 9tYuCEbd DhxF948k pewAr9fc 3nWbKNP1 8j29MEf1 pw0XmT3k 2ccg4nqA
Znce74Gs LAMR4TZC ShC7QhF5 vGxwpg6l SiD1G2Gw feVyIzY4 aFZ2nFJw 1tgTOPlS
gj2M44VO PNK9BJJD pET0Q3Pn 06SbSqgP uVN2KHUu 96UIwCq3 DbYp25dy mibXb1u5
vZ1tplBW n0qoBkb0 7nKrGjHW Bbs78QuM BYV1ZNQM 2oj6YTUe Wyi6dbAo lCiZG3Rn
P39RDxDw i5RvRIi3 B5NQCDBx lAbdUc1j LmRW6OYc 23BITs0X 3eqz9OBh k0vQgYEj
o0uVjfme Uh9L5hmo 3Mfr3n7k E80gsBPV Bs0nX1hA zXCE0Fw4 M5rHGSWq VJK5Bs5a
8vCwTucw 5lytHncF S6UEhn5c VpOwlQt8 SBOS6VE0 uEpbs01C szKP5gNT lBJey27I
qI3ym27i ODEoz4DE EukP7kBq yX6jrrcS V8IN9DFV FBY3xrRX az7Re1mm iK254E4K
Bj5IOSnm owtDNU5H zf53TsJr kAoe0yL4 u06crJnW teGPK20e KOUY7MfT mP4V1Zz2
Id7DgpLV 9XN8kpHP NKH7msRm YM8IazE9 4YTOI1bg VkAnQl7O K3f5eOIf 09qS4qfJ
1d6jcBXl 73seQhP8 23BZsXUm bl5z7XFN 66qUxrA0 PrWP2IBz x6pZYdo5 F8z9mMS9
PT9uhGZr sGEO8hO2 M6AgxJku TsNbo4QO j7qdxwKa j7o4tasS nkkSLX2U v6OzVEGU
Kfh7zKsM NvB1x1VJ y02NP5rX xFgNEs4F cMZcoae7 uRBwME83 ZEigX30u pA8h0EHe
bs5mNjHh UY7a9l3U WEpt9BYX 6l9Yih3v 6VHae7QU nn2Hqrzy polQCe8g 1sOIA1wX
byZW6EEX ErB1TqLb uGVirfH2 7E6zoRMo Ru1TydTK M9Bop04R pmIF3ZDi X8gZsZkM
9cNm5frk bV266yam n5xLuvGT dUrINPA7 YzT3MQD6 BUJPh0cz Dt2D5kuv D4Se2smc
E09lZ0Ba MhpsER4d k2cSkw7D 4tFiARMY BSeiMKD1 7Sf1oFxe kq5EagRT 9OPfepnJ
BjiyU8PH C9kir7KO CPrHLq6e YjorH4FK YvjqOZ8u 9JZCcxrp a0UCqGIx 12bLTD5z
ZHgEV7Iy XrTlVP7r 0cl5rRLh 3XFZhB9k uNu5p3vP 3xY5GtMJ UZU19iV4 4mwLiFLJ

another useful option is to tell pwdgen the length and the number of password you want, this command will generate 21 password strings with 10 character of length each:

# pwgen -s 10 21
8ozwjX4zb9 1mNOblgkUM Miu9hFB9l5 OWPFmiHP3Q mPcTv0ngEM QGML7y7Ob8 w0wwDrY8Qo
ktjM4sjeFZ Pw6TyBABpV wmsxyaA0NK C60CV3P5UY sw5zzzn3I0 W78VvDpeQK 97GvzJpOy0
Mma8502oTY oIaUz5CL0B 4AX5BXJfaw S7btiGJm2K iqR83bBWvl KPRGGT5isc Pj8wAHtiuV

 

https://linuxconfig.org/how-to-use-a-command-line-random-password-generator-pwgen-on-linux

SSH / SCP without known_hosts check

When we want to connect to a remote host using different credentials and we have automatic login with public key, we have to use some tweaks adding some parameters to scp, like this:

-o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null

Example:

scp -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null root@10.5.0.154:/home/user/filename.ext .

Ubuntu startup mode

 

Show current default target

sudo systemctl get-default

To start in multi-user mode (text mode)

sudo systemctl set-default multi-user.target

 To start in graphical mode (X mode)

sudo systemctl set-default graphical.target

 

 

https://askubuntu.com/questions/870221/booting-into-text-mode-in-16-04

 

Testing networking services

Netcat

Testing networking services to troubleshoot communications can be easily done with netcat like so:

nc -l -p 8000

Source: https://ubidots.com/blog/how-to-simulate-a-tcpudp-client-using-netcat/

Services

Managing services with systemctl

Start

sudo systemctl start application.service

Stop

sudo systemctl stop application.service

Status

sudo systemctl status application.service

Enabling service autostart on system boot

sudo systemctl enable application.service

Disabling service autostart on system boot

sudo systemctl disable application.service

  

https://www.digitalocean.com/community/tutorials/how-to-use-systemctl-to-manage-systemd-services-and-units

 

Securely delete files and directories

Shred

shred -zvu -n 3 fileToDelete

Wipe

wipe -rfi privateDirectory/*

SRM (secure remove)

srm -vz privateDirectory/*

 

https://www.tecmint.com/permanently-and-securely-delete-files-directories-linux/

rsync

https://serverfault.com/questions/529287/rsync-creates-a-directory-with-the-same-name-inside-of-destination-directory

 

IPTables

Allow All Incoming HTTP

 

 

link: https://www.digitalocean.com/community/tutorials/iptables-essentials-common-firewall-rules-and-commands

Mounting ISO images under FreeBSD

https://makandracards.com/jan0sch/13431-mounting-iso-images-under-freebsd

 

Console on serial port

Example using RedHat Linux 6.0

Using lilo bootloader

Edit /etc/lilo.conf
append="console=tty0 console=ttyS0,9600n8"
boot=/dev/hda
map=/boot/map
install=/boot/boot.b
prompt
default=linux
# Changes for serial console on COM1: in global section
#   Deleted: message=/boot/message
serial=0,9600n8
timeout=100
restricted
password=de7mGPe3i8

image=/boot/vmlinuz-2.4.2-2
  label=linux
  read-only
  root=/dev/hda6
  initrd=/boot/initrd-2.4.2-2.img
  # Changes for serial console on COM1: in each image section
  append="console=tty0 console=ttyS0,9600n8"
bash# lilo
Added linux *
Edit /etc/inittab
S0:12345:respawn:/sbin/mingetty ttyS0 9600 vt100
Adding the terminal to the secure list so that root can login

Needed in this particular case but avoid doing this because it is not a good practice regarding security

Edit /etc/securetty
ttyS0

 

Links:

https://tldp.org/HOWTO/Remote-Serial-Console-HOWTO/configure-kernel-lilo.html

https://www.kernel.org/doc/html/v4.15/admin-guide/serial-console.html

 

Some useful commands

Here is how to join two files side by side in columns, delimited by ";"

paste file1 file2 -d ";"

 

Ramdisk

Creating a ramdisk for fast read/write and comparing it with HDD/SSD drive using dd:

# Creating a directory to mount RAM disk
mkdir /mnt/ramdisk

# mounting ramdisk
sudo mount -t tmpfs -o size=1G tmpfs /mnt/ramdisk

# Dropping caches before testing for fair disk results
sudo sh -c 'echo 3 > /proc/sys/vm/drop_caches'

# Running write speed test on RAM disk
sudo dd if=/dev/zero of=/mnt/ramdisk/testfile bs=1M count=1024 conv=fdatasync status=progress

# Running write speed test on HDD/SSD disk
sudo dd if=/dev/zero of=/root/testfile bs=1M count=1024 conv=fdatasync status=progress

# Running read speed test on RAM disk
sudo dd if=/mnt/ramdisk/testfile of=/dev/null bs=1M status=progress

# Running read speed test on HDD/SSD disk
sudo dd if=/root/testfile of=/dev/null bs=1M status=progress

More information (IOPS, latency) using fio:

# Installing fio
sudo apt install fio

# Basic write test (both paths):
fio --name=write --directory=/mnt/ramdisk --size=1G --bs=1M --rw=write --direct=1 --numjobs=1

Cleaning up:

# Cleaning up
rm /mnt/ramdisk/testfile /root/testfile

# unmounting ramdisk
sudo umount /mnt/ramdisk

Swap memory

https://docs.vultr.com/how-to-add-swap-memory-in-ubuntu-24-04