install-debian-server.sh 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403
  1. #!/bin/sh
  2. # bachir soussi chiadmi
  3. #
  4. # http://www.debian.org/doc/manuals/securing-debian-howto/
  5. # https://www.thefanclub.co.za/how-to/how-secure-ubuntu-1204-lts-server-part-1-basics
  6. # https://www.linode.com/docs/websites/lamp/lamp-server-on-debian-7-wheezy/
  7. # http://web-74.com/blog/reseaux/gerer-le-deploiement-facilement-avec-git/
  8. #
  9. echo '\033[35m
  10. ____ __ _ _____
  11. / __ \___ / /_ (_)___ _____ / ___/___ ______ _____ _____
  12. / / / / _ \/ __ \/ / __ `/ __ \ \__ \/ _ \/ ___/ | / / _ \/ ___/
  13. / /_/ / __/ /_/ / / /_/ / / / / ___/ / __/ / | |/ / __/ /
  14. /_____/\___/_.___/_/\__,_/_/ /_/ /____/\___/_/ |___/\___/_/
  15. \033[0m'
  16. echo "\033[35;1mThis script has been tested only on Linux Debian 7 \033[0m"
  17. echo "Please run this script as root"
  18. echo -n "Should we start? [Y|n] "
  19. read yn
  20. yn=${yn:-y}
  21. if [ "$yn" != "y" ]; then
  22. echo "aborting script!"
  23. exit
  24. fi
  25. # get the current position
  26. _cwd="$(pwd)"
  27. echo '\033[35m
  28. __ ______ __________ ___ ____ ______
  29. / / / / __ \/ ____/ __ \/ | / __ \/ ____/
  30. / / / / /_/ / / __/ /_/ / /| | / / / / __/
  31. / /_/ / ____/ /_/ / _, _/ ___ |/ /_/ / /___
  32. \____/_/ \____/_/ |_/_/ |_/_____/_____/
  33. \033[0m'
  34. apt-get update
  35. apt-get upgrade
  36. echo '\033[35m
  37. __ ____
  38. / |/ (_)_________
  39. / /|_/ / / ___/ ___/
  40. / / / / (__ ) /__
  41. /_/ /_/_/____/\___/
  42. \033[0m'
  43. apt-get install vim
  44. echo '\033[35m
  45. __ _____ ____ ____ _______ __
  46. / / / / | / __ \/ __ \/ ____/ | / /
  47. / /_/ / /| | / /_/ / / / / __/ / |/ /
  48. / __ / ___ |/ _, _/ /_/ / /___/ /| /
  49. /_/ /_/_/ |_/_/ |_/_____/_____/_/ |_/
  50. \033[0m'
  51. echo "\033[35;1mInstalling harden \033[0m"
  52. sleep 3
  53. apt-get install harden
  54. echo "Harden instaled"
  55. echo "\033[92;1m* * *\033[Om"
  56. echo '\033[35m
  57. ______________ _______ _____ __ __
  58. / ____/ _/ __ \/ ____/ | / / | / / / /
  59. / /_ / // /_/ / __/ | | /| / / /| | / / / /
  60. / __/ _/ // _, _/ /___ | |/ |/ / ___ |/ /___/ /___
  61. /_/ /___/_/ |_/_____/ |__/|__/_/ |_/_____/_____/
  62. \033[0m'
  63. echo "\033[35;1mInstalling ufw and setup firewall (allowing only ssh and http) \033[0m"
  64. sleep 3
  65. apt-get install ufw
  66. ufw allow ssh
  67. ufw allow http
  68. ufw enable
  69. ufw status verbose
  70. echo "ufw installed and firwall configured"
  71. echo "\033[92;1m* * *\033[Om"
  72. echo '\033[35m
  73. ______ _ _____ __
  74. / ____/___ _(_) /__ \ / /_ ____ _____
  75. / /_ / __ `/ / /__/ // __ \/ __ `/ __ \
  76. / __/ / /_/ / / // __// /_/ / /_/ / / / /
  77. /_/ \__,_/_/_//____/_.___/\__,_/_/ /_/
  78. \033[0m'
  79. echo "\033[35;1mInstalling fall2ban \033[0m"
  80. apt-get install fail2ban
  81. cat "$_cwd"/assets/fail2ban.jail.conf > /etc/fail2ban/jail.conf
  82. echo "fail2ban installed and configured"
  83. echo "\033[92;1m* * *\033[Om"
  84. echo '\033[35m
  85. __ __ __
  86. / /______ ____ _____/ /______/ /
  87. / //_/ __ \/ __ \/ ___/ //_/ __ /
  88. / ,< / / / / /_/ / /__/ ,< / /_/ /
  89. /_/|_/_/ /_/\____/\___/_/|_|\__,_/
  90. \033[0m'
  91. echo "\033[35;1mInstalling knockd \033[0m"
  92. sleep 3
  93. apt-get install knockd
  94. echo -n "define a sequence number for opening (as 7000,8000,9000) : "
  95. read sq1
  96. echo -n "define a sequence number for closing (as 9000,8000,7000) : "
  97. read sq2
  98. sed -i "s/7000,8000,9000/$sq1/g" /etc/knockd.conf
  99. sed -i "s/9000,8000,7000/$sq2/g" /etc/knockd.conf
  100. sed -i 's/START_KNOCKD=0/START_KNOCKD=1/g' /etc/default/knockd
  101. echo "knockd installed and configured"
  102. echo "\033[92;1mplease note these sequences for future knocking\033[Om"
  103. echo "opening : $sq1 ; closing : $sq2"
  104. echo "\033[92;1m* * *\033[Om"
  105. echo '\033[35m
  106. __ _______ __________
  107. / / / / ___// ____/ __ \
  108. / / / /\__ \/ __/ / /_/ /
  109. / /_/ /___/ / /___/ _, _/
  110. \____//____/_____/_/ |_|
  111. \033[0m'
  112. echo "\033[35;1mCreate new user (you will be asked a user name and a password) \033[0m"
  113. sleep 3
  114. echo -n "Enter user name: "
  115. read user
  116. # read -p "Continue? (Y/N): " confirm && [[ $confirm == [yY] || $confirm == [yY][eE][sS] ]] || exit 1
  117. adduser "$user"
  118. echo "adding $user to admin group and limiting su to the admin group"
  119. groupadd admin
  120. usermod -a -G admin "$user"
  121. dpkg-statoverride --update --add root admin 4750 /bin/su
  122. echo "user $user configured"
  123. echo "\033[92;1m* * *\033[Om"
  124. echo '\033[35m
  125. __________ __ __
  126. / ___/ ___// / / /
  127. \__ \\__ \/ /_/ /
  128. ___/ /__/ / __ /
  129. /____/____/_/ /_/
  130. \033[0m'
  131. while [ "$securssh" != "y" ] && [ "$securssh" != "n" ]
  132. do
  133. echo -n "Securing ssh (disabling root login)? [y|n] "
  134. read securssh
  135. # securssh=${securssh:-y}
  136. done
  137. if [ "$securssh" = "y" ]; then
  138. sed -i 's/PermitRootLogin\ yes/PermitRootLogin no/g' /etc/ssh/sshd_config
  139. sed -i 's/PermitEmptyPasswords\ yes/PermitEmptyPasswords no/g' /etc/ssh/sshd_config
  140. sed -i 's/Protocol\ [0-9]/Protocol 2/g' /etc/ssh/sshd_config
  141. service ssh reload
  142. echo "SSH secured"
  143. else
  144. echo 'root user can still conect through ssh'
  145. fi
  146. echo "\033[92;1m* * *\033[Om"
  147. # TODO : allow ssh/ftp connection only from given ips
  148. echo "\033[35;1mInstalling AMP web server \033[0m"
  149. echo '\033[35m
  150. ___ __ ___
  151. / | ____ ____ ______/ /_ ___ |__ \
  152. / /| | / __ \/ __ `/ ___/ __ \/ _ \__/ /
  153. / ___ |/ /_/ / /_/ / /__/ / / / __/ __/
  154. /_/ |_/ .___/\__,_/\___/_/ /_/\___/____/
  155. /_/
  156. \033[0m'
  157. echo "\033[35;1mInstalling Apache2 \033[0m"
  158. sleep 3
  159. apt-get install apache2
  160. a2enmod rewrite
  161. cat "$_cwd"/assets/apache2.conf > /etc/apache2/apache2.conf
  162. # Change logrotate for Apache2 log files to keep 10 days worth of logs
  163. sed -i 's/\tweekly/\tdaily/' /etc/logrotate.d/apache2
  164. sed -i 's/\trotate .*/\trotate 10/' /etc/logrotate.d/apache2
  165. # Remove Apache server information from headers.
  166. sed -i 's/ServerTokens .*/ServerTokens Prod/' /etc/apache2/conf.d/security
  167. sed -i 's/ServerSignature .*/ServerSignature Off/' /etc/apache2/conf.d/security
  168. service apache2 restart
  169. echo "Apache2 installed"
  170. echo "\033[92;1m* * *\033[Om"
  171. echo '\033[35m
  172. __ ___ __
  173. / |/ /_ ___________ _/ /
  174. / /|_/ / / / / ___/ __ `/ /
  175. / / / / /_/ (__ ) /_/ / /
  176. /_/ /_/\__, /____/\__, /_/
  177. /____/ /_/
  178. \033[0m'
  179. echo "\033[35;1minstalling Mysql \033[0m"
  180. sleep 3
  181. apt-get install mysql-server
  182. mysql_secure_installation
  183. echo "mysql installed"
  184. echo "\033[92;1m* * *\033[Om"
  185. echo '\033[35m
  186. ____ __ ______
  187. / __ \/ / / / __ \
  188. / /_/ / /_/ / /_/ /
  189. / ____/ __ / ____/
  190. /_/ /_/ /_/_/
  191. \033[0m'
  192. echo "\033[35;1mInstalling PHP \033[0m"
  193. sleep 3
  194. apt-get install php5 php-pear php5-gd
  195. echo "Configuring PHP"
  196. cp /etc/php5/apache2/php.ini /etc/php5/apache2/php.ini.back
  197. sed -i "s/max_execution_time\ =\ [0-9]\+/max_execution_time = 60/g" /etc/php5/apache2/php.ini
  198. sed -i "s/max_input_time\ =\ [0-9]\+/max_input_time = 60/g" /etc/php5/apache2/php.ini
  199. sed -i "s/memory_limit\ =\ [0-9]\+M/memory_limit = 512M/g" /etc/php5/apache2/php.ini
  200. sed -i "s/;\?error_reporting\ =\ [^\n]\+/error_reporting = E_COMPILE_ERROR|E_RECOVERABLE_ERROR|E_ERROR|E_CORE_ERROR/g" /etc/php5/apache2/php.ini
  201. sed -i "s/;\?display_errors\ =\ On/display_errors = Off/g" /etc/php5/apache2/php.ini
  202. sed -i "s/;\?log_errors\ =\ Off/log_errors = On/g" /etc/php5/apache2/php.ini
  203. # following command doesn't work, make teh change manualy
  204. #sed -ri ":a;$!{N;ba};s/;\?\ \?error_log\ =\ [^\n]\+([^\n]*\n(\n|$))/error_log = \/var\/log\/php\/error.log\1/g" /etc/php5/apache2/php.ini
  205. echo "register_globals = Off" >> /etc/php5/apache2/php.ini
  206. mkdir /var/log/php
  207. chown www-data /var/log/php
  208. apt-get install php5-mysql
  209. echo "php installed"
  210. echo "\033[92;1m* * *\033[Om"
  211. echo '\033[35m
  212. __ __ ___ ___ __ _
  213. ____ / /_ ____ / |/ /_ __/ | ____/ /___ ___ (_)___
  214. / __ \/ __ \/ __ \/ /|_/ / / / / /| |/ __ / __ `__ \/ / __ \
  215. / /_/ / / / / /_/ / / / / /_/ / ___ / /_/ / / / / / / / / / /
  216. / .___/_/ /_/ .___/_/ /_/\__, /_/ |_\__,_/_/ /_/ /_/_/_/ /_/
  217. /_/ /_/ /____/
  218. \033[0m'
  219. echo "\033[35;1mInstalling phpMyAdmin \033[0m"
  220. apt-get install phpmyadmin
  221. echo "phpMyAdmin installed"
  222. echo "\033[92;1m* * *\033[Om"
  223. echo '\033[35m
  224. __ __
  225. _ __/ /_ ____ _____/ /_
  226. | | / / __ \/ __ \/ ___/ __/
  227. | |/ / / / / /_/ (__ ) /_
  228. |___/_/ /_/\____/____/\__/
  229. \033[0m'
  230. echo "\033[35;1mVHOST install \033[0m"
  231. while [ "$vh" != "y" ] && [ "$vh" != "n" ]
  232. do
  233. echo -n "Should we install a vhost? [y|n] "
  234. read vh
  235. # vh=${vh:-y}
  236. done
  237. if [ "$vh" = "y" ]; then
  238. while [ "$_host_name" = "" ]
  239. do
  240. read -p "enter a hostname ? " _host_name
  241. if [ "$_host_name" != "" ]; then
  242. read -p "is hostname $_host_name correcte [y|n] " validated
  243. if [ "$validated" = "y" ]; then
  244. break
  245. else
  246. _host_name=""
  247. fi
  248. fi
  249. done
  250. cp "$_cwd"/assets/example.org.conf /etc/apache2/sites-available/"$_host_name".conf
  251. sed -ir "s/example\.org/$_host_name/g" /etc/apache2/sites-available/"$_host_name".conf
  252. mkdir -p /srv/www/"$_host_name"/public_html
  253. mkdir /srv/www/"$_host_name"/logs
  254. #set proper right to user will handle the app
  255. chown -R root:admin /srv/www/"$_host_name"/
  256. chmod -R g+w /srv/www/"$_host_name"/
  257. chmod -R g+r /srv/www/"$_host_name"/
  258. # create a shortcut to the site
  259. mkdir /home/"$user"/www/
  260. chown "$user":admin /home/"$user"/www/
  261. ln -s /srv/www/"$_host_name" /home/"$user"/www/"$_host_name"
  262. #activate the vhost
  263. a2ensite "$_host_name".conf
  264. #restart apache
  265. service apache2 restart
  266. echo "vhost $_host_name configured"
  267. else
  268. echo "Vhost installation aborted"
  269. fi
  270. echo "\033[92;1m* * *\033[Om"
  271. echo '\033[35m
  272. ___ __ __
  273. / |_ _______/ /_____ _/ /_
  274. / /| | | /| / / ___/ __/ __ `/ __/
  275. / ___ | |/ |/ (__ ) /_/ /_/ / /_
  276. /_/ |_|__/|__/____/\__/\__,_/\__/
  277. \033[0m'
  278. echo "\033[35;1mInstalling Awstat \033[0m"
  279. sleep 3
  280. apt-get install awstats
  281. # Configure AWStats
  282. temp=`grep -i sitedomain /etc/awstats/awstats.conf.local | wc -l`
  283. if [ $temp -lt 1 ]; then
  284. echo SiteDomain="$_host_name" >> /etc/awstats/awstats.conf.local
  285. fi
  286. # Disable Awstats from executing every 10 minutes. Put a hash in front of any line.
  287. sed -i 's/^[^#]/#&/' /etc/cron.d/awstats
  288. echo "Awstat installed"
  289. echo "\033[92;1m* * *\033[Om"
  290. # echo '\033[35m
  291. # ______________ _______
  292. # /_ __/ ____/ |/ / __ \
  293. # / / / __/ / /|_/ / /_/ /
  294. # / / / /___/ / / / ____/
  295. # /_/ /_____/_/ /_/_/
  296. # \033[0m'
  297. # function check_tmp_secured {
  298. # temp1=`grep -w "/var/tempFS /tmp ext3 loop,nosuid,noexec,rw 0 0" /etc/fstab | wc -l`
  299. # temp2=`grep -w "tmpfs /tmp tmpfs rw,noexec,nosuid 0 0" /etc/fstab | wc -l`
  300. # if [ $temp1 -gt 0 ] || [ $temp2 -gt 0 ]; then
  301. # return 1
  302. # else
  303. # return 0
  304. # fi
  305. # } # End function check_tmp_secured
  306. # function secure_tmp_tmpfs {
  307. # cp /etc/fstab /etc/fstab.bak
  308. # # Backup /tmp
  309. # cp -Rpf /tmp /tmpbackup
  310. # rm -rf /tmp
  311. # mkdir /tmp
  312. # mount -t tmpfs -o rw,noexec,nosuid tmpfs /tmp
  313. # chmod 1777 /tmp
  314. # echo "tmpfs /tmp tmpfs rw,noexec,nosuid 0 0" >> /etc/fstab
  315. # # Restore /tmp
  316. # cp -Rpf /tmpbackup/* /tmp/ >/dev/null 2>&1
  317. # #Remove old tmp dir
  318. # rm -rf /tmpbackup
  319. # # Backup /var/tmp and link it to /tmp
  320. # mv /var/tmp /var/tmpbackup
  321. # ln -s /tmp /var/tmp
  322. # # Copy the old data back
  323. # cp -Rpf /var/tmpold/* /tmp/ >/dev/null 2>&1
  324. # # Remove old tmp dir
  325. # rm -rf /var/tmpbackup
  326. # echo -e "\033[35;1m /tmp and /var/tmp secured using tmpfs. \033[0m"
  327. # } # End function secure_tmp_tmpfs
  328. # check_tmp_secured
  329. # if [ $? = 0 ]; then
  330. # secure_tmp_tmpfs
  331. # else
  332. # echo -e "\033[35;1mFunction canceled. /tmp already secured. \033[0m"
  333. # fi
  334. echo '\033[35m
  335. ____ __ _______ __
  336. / __ \____ / /_ / ____(_) /__ _____
  337. / / / / __ \/ __/ / /_ / / / _ \/ ___/
  338. / /_/ / /_/ / /_ / __/ / / / __(__ )
  339. /_____/\____/\__/ /_/ /_/_/\___/____/
  340. \033[0m'
  341. #installing better prompt and some goodies for root
  342. echo "\033[35;1mInstalling shell prompt for root \033[0m"
  343. sleep 3
  344. echo "cloning github.com/bachy/dotfiles-server"
  345. git clone git://github.com/bachy/dotfiles-server.git ~/.dotfiles-server && cd ~/.dotfiles-server && ./install.sh && cd ~
  346. source ~/.bashrc
  347. echo "done"
  348. echo "\033[92;1m* * *\033[Om"
  349. echo '\033[35m
  350. __
  351. ___ ____ ____/ /
  352. / _ \/ __ \/ __ /
  353. / __/ / / / /_/ /
  354. \___/_/ /_/\__,_/
  355. \033[0m'
  356. echo "\033[35;1m* * script done * *\033[0m"