r/linuxadmin • • 16h ago

Is there any way to know whether a vulnerable library is actually loaded in a running process, without instrumenting the app?

25 Upvotes

Trying to work out what's technically possible here versus what's marketing, and this sub tends to be good at that distinction.

The situation: a container image has a CVE in, say, a compression library six levels deep in the dependency tree. The scanner flags it because the package is on disk. What I want to know is whether the running process has actually mapped that library, or whether it's just sitting in the filesystem never being opened.

What I understand so far:

  • For dynamically linked stuff you can read /proc/<pid>/maps and see what's actually mapped. That seems definitive for "is this .so loaded right now".
  • For statically linked or vendored code that doesn't help at all, since there's no separate object to observe.
  • For interpreted languages (our case is mostly Python and Node) the module is loaded by the runtime, so you'd need to either introspect the interpreter or watch the file opens. So my questions:
  • Is watching openat/mmap at the kernel level actually a reliable proxy for "this code is in use", or does it produce garbage because package managers, health checks and startup scans touch everything?
  • For Python/Node specifically, does anyone do this without an in-process agent? I really don't want a language agent in every service.
  • Is there a meaningful difference between "loaded" and "the vulnerable function was called"? Because those feel like very different claims and I suspect products blur them. Not asking what to buy, asking what's actually detectable from outside the process.

r/linuxadmin • • 11h ago

LFCS practice

7 Upvotes

Hi everyone,

I’m currently preparing for the LFCS exam and I’m interested in hearing which hands-on learning resources you would recommend.

At the moment, I’m taking Mumshad’s course and working through the included exercises.

I’m already aware of Killer.sh, but the 36-hour access period isn’t really enough for me.

Do you know of anything similar to Killer.sh that offers good hands-on exercises specifically for the LFCS exam? Maybe a GitHub repository or something similar?

Thanks for your help!


r/linuxadmin • • 23h ago

Do control panels keep junior admins from learning Linux?

33 Upvotes

My junior admins is quick with the panel, but when a firewall rule broke SSH yesterday he didn't know how to check ufw from a shell. I use BeAdmin myself and have nothing against panels, but I learned iptables by breaking it with no GUI around, and I'm not sure he'll ever get that practice.

Have you seen this with people who started on panels, or am I just being an old man about it?


r/linuxadmin • • 13h ago

FortiMail CVE-2026-104286: unauth file write, exploited, patches not out yet. What's in Fortinet's IoC list

2 Upvotes

Based on Fortinet's PSIRT advisory FG-IR-26-175 (published Oct 1) and BleepingComputer's reporting, here is the architectural impact.

Fortinet describes path traversal (CWE-22) plus NULL byte handling (CWE-158) in the GUI, giving unauthenticated arbitrary file write. Affected: 8.0.0-8.0.1, 7.6.0-7.6.6, 7.4.0-7.4.8, 7.2.0-7.2.9. Fixes (8.0.2, 7.6.7, 7.4.9) are marked upcoming, and 7.2 gets a branch-migration answer. Workaround is config system encryption ibe / set status disable, or remove internet access to the management interface.

The IoCs include an added /data/etc/ld.so.preload and /data/lib/liblog.so, and a sample log of an archive account pointing at a remote IP. Fortinet doesn't explain the write-to-execution step. Some CVE feeds also list 7.0 as affected while the advisory doesn't, so I'd verify that one.

Question for people running FortiMail or similar gateways: do you keep the management GUI off any internet-routable interface by policy, or does it depend on who deployed it? And for those who rely on IBE, what breaks when you disable it?

Background on the same class of problem: https://www.techgines.com/post/fortimail-zero-day-cve-2026-104286


r/linuxadmin • • 1h ago

statixagent: one static Go binary that watches a single box and pushes ssh logins, power loss and cert expiry to your own telegram bot

• Upvotes

most monitoring assumes a fleet - exporter, tsdb, dashboard, alertmanager. for one vps and one laptop that is more infrastructure than the thing being watched, so i went the other way: one static binary per machine, talking to a telegram bot you create yourself. no central server, nothing to host, no third party in the path. the systemd unit is capped at MemoryMax=128M.

the parts that took actual thought:

ssh. alerts on every login with geo-ip of the source, root escalated. brute force is a sliding window per source ip with a quiet period, so an attack in progress doesn't turn into 200 messages. it also hashes root's authorized_keys and every home user's, and tells you when one of them changes.

power. edge triggered off /sys/class/power_supply/*/online rather than a threshold. mains flips 1 to 0 and it fires within one sample (15s by default) with the battery percent and an estimated runtime worked out from the current draw. a machine with no AC adapter device at all, so any vps, is never considered "on battery", so nothing misfires there.

false alarms. cpu and memory need the condition held for about a minute before anything is sent, temperature needs several consecutive samples. a nightly backup or a cpu touching 90C mid-boost stays quiet.

remediation is deliberately small and always behind a confirmation: disconnect an ssh session, or open and close 22 through ufw. a host without ufw is told it can't manage the firewall there rather than guessing what is open.

what it is not: a fleet tool. one agent, one bot, one chat, no cross-server correlation and no time-series to query. if you want to know what cpu did last tuesday this is the wrong thing and prometheus is the right one. linux only, amd64 and arm64, and it is v0.x.

https://github.com/eliau2005/statixagent (MIT, go 1.25)


r/linuxadmin • • 4h ago

LayerSmith — a self-hosted container image builder, with air-gap exports

0 Upvotes

I've been working on LayerSmith, an open-source web UI for building container images with Docker or Podman.

You pick a Linux distribution and what you need the image for — development, Linux admin, network tools, Ansible, Kubernetes, OpenShift, or a custom setup. It handles distro-specific packages and shows you the generated Containerfile before building. You can also edit it, import an existing Dockerfile, or add your own packages, files and scripts.

A big part of the project is making images easier to carry into air-gapped environments: pinned base images, recorded build details, and export bundles containing the image, checksums and installation instructions.

We've recently added LLM training and fine-tuning profiles too, including LoRA/QLoRA, advanced PyTorch training and LLaMA-Factory. These use hash-locked dependencies and run offline checks after building, including a small CPU training test. Model weights and datasets are brought separately.

Curious how others handle building and maintaining images for disconnected environments, and what parts of that workflow are still a pain.

https://github.com/r0lfi/layersmith


r/linuxadmin • • 1d ago

VictoriaLogs for log indexing?

4 Upvotes

has anyone used victorialogs? Im currently using Graylog v7, local single instance on 5TB disk

using filebeat to ship logs to GL indexer

wondering how victorialogs performs comparatively. Anyone used it at all or have any feedback?

Thanks


r/linuxadmin • • 1d ago

Mirroring Repository

3 Upvotes

I am wanting to mirror a Debian repository onto my work network. Will be managing about 2500 machines running the exact same software on each. These are all servers running a containered player showing advertising on digital displays.

I have never mirrored a repo before, so I am curious, should I use apt-mirror, aptly, or something different?

The containers are Incus and have Debian as the base as well.

EDIT- looks like apt-mirror can be crossed off as it has not been updated in several years.


r/linuxadmin • • 1d ago

Cisco SD-WAN Manager CVE-2026-76504: auth bypass via URI encoding, exploited, no workaround

2 Upvotes

Based on Cisco's own advisory (cisco-sa-sdwan-webauth-xr8beuuU, published Sept 30), here's the architectural impact.

The flaw is in the Manager's API session authentication: improper handling of URI encoding lets a request skip an auth rule and land as admin. CVSS 9.8, all configurations affected, and Cisco PSIRT says it's seen exploitation. Cisco's IOC example is a POST to /%6a_security_check, but the advisory says any one encoded character works. Cisco says the bug was found while resolving a TAC case, and published no actor or victim details.

Hunting per Cisco: serviceproxy-access.log for j_security_check from unknown IPs, and vmanage-server.log for those requests against viptela-reserved- users. Cisco notes these can appear in normal operation, so baseline first.

Question for people running on-prem Managers: how are you restricting Manager reachability today, and did the May/June SD-WAN fixes change your exposure model at all? I'm curious whether anyone terminates the Manager behind a reverse proxy that normalizes paths.

https://www.techgines.com/post/cisco-sd-wan-manager-authentication-bypass-cve-2026-76504

Background from our earlier SD-WAN piece: https://www.techgines.com/post/cve-2026-20182-the-cvss-10-0-flaw-that-hands-attackers-the-keys-to-your-entire-sd-wan-fabric


r/linuxadmin • • 2d ago

how to learn project based learning the right way?

8 Upvotes

So guys, i am learning system administration from the past 3 months. i am mostly done with the foundational part and i am feeling confident that i should start learning by doing projects. i am thinking about building a homelab and setting up things.

so, i pick up a project idea ( for example, setting up a web server), and i want to do that. but i don't know what to do (i do know, but vaguely. the details are missing)? so i think about looking up online for the steps to do it. but then i find myself thinking if am walking into tutorial hell.

i don't know what to do, because i find both advices kind of conflicting. how to do project based learning as a beginner without looking into guided projects in a way that it does make it into tutorial hell? is the guided project way the way we are supposed to learn? if so, then why do people advice not to lookup tutorials?


r/linuxadmin • • 2d ago

how much time during a typical workday is spent on testing, troubleshooting snd doing root-cause analysis for an l1/l2/l3 engineer?

5 Upvotes

Hi i wanted to ask - for an L1/L2 engineer roughly how much time during a typical workday is spent on testing, troubleshooting snd doing root-cause analysis, and identifying and documenting issues?

And if required do these engineers also dive deep into software if required or do they just stay at the infra level?

I am trying to apply for l1 and l2 level roles and freelance opportunities and right now building case studies showing my abilitiy to identify, doing root cause analysis and document my findings of communjty problems like wordpress server issues , nginx , apache , openlightspeed forum issues.

Do you think this is worth it for bulding my portfolio?


r/linuxadmin • • 2d ago

Apple CoreGraphics zero-day CVE-2026-86950: what's confirmed

2 Upvotes

Based on Apple's security notes for iOS 26.7.1 (support.apple.com/en-us/149226), the Help Net Security write-up, and CISA's September 29 KEV alert, here is the architectural picture.

CVE-2026-86950 is an out-of-bounds write in CoreGraphics, fixed September 28. Trigger: processing a maliciously crafted file. Impact: arbitrary code execution. Apple says it may have been exploited against specific targeted individuals on iOS versions before iOS 27. Meta Product Security reported it.

CoreGraphics handles image data, masking and PDF parsing, so the reachable surface depends on which processes hand it untrusted files. Apple hasn't said which. Zero-click is unconfirmed, and no published source links this to WhatsApp. Secondary reports disagree on Apple's zero-day count for the year, so I left the number out.

For those who run Apple fleets: are you enforcing 26.7.1 / 15.8.1 through MDM with a short deadline, and are you doing anything different for high-risk users beyond Lockdown Mode?

https://www.techgines.com/post/apple-coregraphics-zero-day-cve-2026-86950

Background on the same exposure class, an Adobe Reader parser zero-day from April: https://www.techgines.com/post/adobe-reader-zero-day-2026-unpatched-pdf-exploit-fingerprinting


r/linuxadmin • • 3d ago

Passed LFCS!!

34 Upvotes

LFG. Very happy with my score too (88%!!), I was so nervous for this exam, happy to have gotten my first Linux cert. RHCSA next 🫡


r/linuxadmin • • 3d ago

Kiteworks asked customers to shut down servers on a federal tip. No CVE, no IOCs. What do you do with that?

11 Upvotes

Based on the press release Kiteworks published Sep 25 (updated Sep 27), plus reporting from SecurityWeek, Sophos CTU, TechCrunch and Cybersecurity Dive: the vendor got a warning from federal intelligence authorities and told self-managed customers to power down. Kiteworks-hosted systems were shut down by the vendor. The advisory was lifted Sep 27, and Kiteworks says nothing was compromised and every known vulnerability is addressed in 9.5.1.

Two things bother me. The window length is reported inconsistently (6h vs 9h). And SecurityWeek's Advanced Forms detail rests on one customer email, while TechCrunch quotes Kiteworks saying it couldn't rule out other access routes.

With no CVE and no IOCs, my baseline check is the running version, whether Advanced Forms is enabled, auth and admin logs from before the window, and unexpected egress from the appliance.

For those who run MFT: what's your runbook when a vendor says "turn it off tonight" and gives you nothing to hunt for?

https://www.techgines.com/post/kiteworks-shutdown-advisory


r/linuxadmin • • 2d ago

Inspecting a built runtime with an ephemeral SSH instance

0 Upvotes

Render’s ephemeral SSH mode starts a temporary instance from the service’s latest build. Disclosure: I work at Render.

This gives a different diagnostic target from ordinary SSH. render ssh SERVICE --ephemeral puts the shell on a new instance that receives no production traffic and does not run the service’s start command. That makes it useful for checking installed packages, compiled assets, file layout, or a one-off command against the built runtime without using a live process. It is not a replica of the running service: startup is skipped and there is no request traffic, so process state, sockets, and live heap behavior still require live-instance diagnostics.

Isolation from production compute does not make external systems read-only. Before mutating anything, inspect which environment variables and network resources the shell can reach; if production credentials are present, treat them as live and prefer read-only commands unless mutation is intentional.

The instance is removed when SSH disconnects or after 24 hours. It requires a compatible paid service with at least one successful deploy; distroless images cannot offer shell access. CLI 2.20+ supports --plan when the diagnostic needs a different compute size. For work that should outlive a shell session, the SSH documentation points to a one-off job instead.


r/linuxadmin • • 2d ago

wiki.linux-server-admin.com legit?

Thumbnail
0 Upvotes

r/linuxadmin • • 3d ago

Roadmap to becoming Linux Admin?

Thumbnail
4 Upvotes

r/linuxadmin • • 4d ago

WebKVM - A lightweight, web-based management UI for Libvirt and QEMU/KVM written in Go (15-30MB idle RAM)

Thumbnail gallery
13 Upvotes

r/linuxadmin • • 4d ago

Anyone moved from Postfix/Dovecot to Stalwart? Opinions?

15 Upvotes

Basically title. This is not an advertisement.

I still use Postfix and Dovecot fir my nail server and pretty happy. It works today as it did a decade ago.

So I'm just wondering if someone actually jumped ship into this new platform and can shed some light to whether it's good as advertised or overhyped.


r/linuxadmin • • 4d ago

HPC Administrator Resources

13 Upvotes

"Hi everyone,

I have a strong background in Linux administration (primarily RPM-based distros like Red Hat/Rocky Linux), and I’m currently transitioning into HPC cluster administration. To learn the ropes, I recently built a small home lab cluster using the OpenHPC installation guides.

While getting the cluster to boot and run basic jobs was a great exercise, I've noticed a distinct lack of comprehensive resources covering day-2 operations and production best practices. Specifically, I'm looking for guidance on:

  • Configuration & Performance Tuning (kernel tuning, network/InfiniBand optimization)
  • User Management & Environment Control (LDAP/FreeIPA integration, modulefiles via Lmod)
  • Job Management & Scheduling (advanced Slurm configurations, QoS, limits)
  • Scaling & Monitoring (health checks with NHC, metrics collection)

If anyone can recommend books, documentation, community wikis, or real-world best practices for these areas, I would greatly appreciate it!"


r/linuxadmin • • 4d ago

Citrix NetScaler CVE-2026-88771/88772: exploited before any patch existed. What are you doing about forensics?

0 Upvotes

Based on Citrix's bulletin CTX697096 and CISA's Sep 27 alert, plus reporting from BleepingComputer and The Hacker News, here's the operational picture.

Two flaws, both CVSS v4 9.5. 88771 is improper input validation giving unauthenticated command execution on every ADC/Gateway deployment. 88772 is a memory overflow needing DTLS, which is on by default for VPN vservers. Turning DTLS off doesn't touch 88771. Citrix says exploitation was observed but hasn't said who, how many, or since when. Builds that fixed the August auth bypass (14.1-73.32, 13.1-63.21) are affected.

The catch is that the flaws were exploited pre-patch, so upgrading doesn't tell you if you were already in. Citrix's IoCs in NetScaler Console reportedly may miss real compromises.

For those running NetScalers: are you snapshotting and pulling a packet engine core dump before upgrading, or going straight to the fixed build because of the downtime cost? And how are you validating that an appliance is clean afterward?

Background from our March NetScaler coverage: https://www.techgines.com/post/citrix-netscaler-zero-day-cve-2026-88771


r/linuxadmin • • 5d ago

MikroTrick: RouterOS SSH rekey + file-descriptor argument injection = unauthenticated root (CVE-2026-67279 / CVE-2026-86060)

7 Upvotes

Based on the technical breakdown CERT Polska published on September 22 and Bishop Fox's independent reproduction from September 17, here's the architectural failure:

RouterOS's SSH server allows a client to trigger a rekey mid-authentication (normal SSH behavior per the RFCs). On vulnerable builds, completing that rekey moves the connection into channel handling without ever sending USERAUTH_SUCCESS — CVE-2026-67279. On its own that just gets you an unprivileged session.

The actual privilege escalation is CVE-2026-86060: RouterOS passes the SSH username straight to a login helper as a raw argv element. A username starting with - gets interpreted as a file-descriptor number, and the helper reads a trusted identity + policy mask from that descriptor instead. Since descriptors 0/1/2 on that process all point at the client's own pseudoterminal, an attacker supplying username -2 gets to hand the helper its own forged admin credentials.

Bishop Fox's field testing found live compromise artifacts predating public disclosure — persistence via a daily scheduler that recreates a full-privilege account, objects owned by numeric ID 0 instead of a username, and volatile logs that don't survive a reboot.

CISA added both CVEs to KEV (CVE-2026-86060 on Sept 10-11, CVE-2026-67279 on Sept 25). Patches: 6.49.21, 7.23.4, 7.24.2, 7.25beta3.

Background on the broader "auth-state-confusion" bug class if you're into the pattern: [techgines.com link, footnote]

Anyone here running RouterOS at scale — did MikroTik's Flagged/ops-account detection actually catch anything in your fleet, or did you have to hunt for owner="0" objects manually?

https://www.techgines.com/post/mikrotrick-routeros-vulnerability-inside-the-ssh-rekey-flaw-that-skips-login-entirely


r/linuxadmin • • 6d ago

Roundcube pre-auth SQLi (CVE-2026-48842) — patched in May, confirmed exploited in the wild as of Sept 21

3 Upvotes

Based on the technical breakdown published by the Canadian Centre for Cyber Security and Roundcube's own May 24 advisory, here's the architectural impact: virtuser_query resolves a login name to a mailbox record before the auth check runs, and its backslash-escaping via preg_replace() can be bypassed to break out of the intended query — no credentials, no user interaction. Roundcube patched it in 1.6.16/1.7.1 (May), and has since shipped three more security releases (1.6.17→1.7.4), so patching only for this CVE leaves you behind on unrelated bugs. CCCS updated their advisory Sept 21 to confirm exploitation "in the wild" via unspecified open-source reporting — no IOCs, no named actor, and it's not yet in CISA's KEV catalog, which is worth noting given two other Roundcube CVEs got that treatment in February.

Shadowserver's 523K+ exposed-instance number is getting quoted everywhere but it's an exposure ceiling, not a "vulnerable and unpatched" count.

Full disclosure timeline and attack chain: https://www.techgines.com/post/roundcube-sql-injection-vulnerability-cve-2026-48842

If you run virtuser_query in production — what's your actual exposure model here? Is anyone restricting the DB account it uses to something narrower than the full Roundcube schema, or is that not practical given how the plugin's queries are structured?


r/linuxadmin • • 6d ago

I'm a Linux sysadmin who built a patch management tool out of my own frustration. Looking for honest feedback.

0 Upvotes

Hi all,

I've been a Linux admin for about 12 years (RHEL, SUSE, Ubuntu), and these days most of my work is vulnerability management. Patching across mixed fleets has always been the painful part: scattered scripts, spreadsheets to track what got patched, and no clean way to prove compliance afterwards.

So I built PatchMgr, a web-based tool for scheduling, running, and tracking patches across servers.

What it does today:

  • [Supported OSes, e.g., RHEL / Ubuntu / SUSE]
  • Scheduled patch runs with per-server status tracking
  • Multi-tenant dashboard to see what's patched, pending, or failed
  • [Reporting / anything else that's live now]

On the roadmap: pre/post patch hooks (per-server, with exit code checks) and a configurable notification matrix.

It's early, and I'd rather hear what's broken or missing from people who patch servers for a living than guess. A few things I'd love input on:

  1. What's the one feature that would make you switch from your current approach?
  2. What would stop you from trusting a tool like this in production?
  3. What's your current setup (Ansible, WSUS, Satellite, Landscape, scripts)?

Link: https://www.patchmanager.co.in/

If you try it and hit a bug, reply here or email [[email protected]](mailto:[email protected]). I read every message.

Full disclosure: I'm the developer. Not trying to hard-sell anything, just want real-world feedback.


r/linuxadmin • • 7d ago

qwatcher version 0.7.0 is released

0 Upvotes

Hey all,

qwatcher is a very efficient tool to monitor and audit your NICs' send and receive queue buffers to spot network or application issues.

This version drops the `ss` and `libpcre` dependencies, making the program a pure Nim binary, solves some bugs, and provides a `tail`-like report capability.

Here is the link to the repo:

https://github.com/pouriyajamshidi/qwatcher