{"id":3342,"date":"2024-12-21T11:12:00","date_gmt":"2024-12-21T18:12:00","guid":{"rendered":"https:\/\/yyc.ninja\/?p=3342"},"modified":"2026-01-25T17:50:27","modified_gmt":"2026-01-26T00:50:27","slug":"whats-running-on-this-server-discover-hidden-services-configs-and-risks","status":"publish","type":"post","link":"https:\/\/yyc.ninja\/index.php\/2024\/12\/21\/whats-running-on-this-server-discover-hidden-services-configs-and-risks\/","title":{"rendered":"Inherited a Black Box Server? Discover Hidden Services, Configs, and Risks"},"content":{"rendered":"<h2 class=\"wp-block-heading\"><strong>Introduction<\/strong><\/h2>\n<p>When you\u2019re handed the keys to a virtual machine (VM) without documentation (no network diagrams, no SOPs, or nothing), it\u2019s like walking into a datacenter blindfolded. This post shows how you can quickly profile the system, identify critical configurations, assess security posture, and inventory applications using a systematic Bash script.<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<h2 class=\"wp-block-heading\"><strong>Reality Check<\/strong><\/h2>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>Note:<\/strong> Many organizations restrict root access, direct file system scans, or bulk configuration dumps for valid security reasons. The level of access this script assumes is often only available in lab, dev, or smaller org setups. Always check with your security team before running such scripts in production.<\/p>\n<\/blockquote>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<h2 class=\"wp-block-heading\"><strong>1. Identify the Landscape<\/strong><\/h2>\n<p>Start with basic VM profiling:<\/p>\n<ul class=\"wp-block-list\">\n<li>Hostname and OS details<\/li>\n<li>Memory, disk, and root access check<\/li>\n<li>SSH status<\/li>\n<\/ul>\n<p><strong>Script Insight:<\/strong><\/p>\n<pre class=\"wp-block-preformatted\">hostname<br>cat \/etc\/*release<br>free -h<br>df -h \/<br>ss -tuln | grep :22<br><\/pre>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<h2 class=\"wp-block-heading\"><strong>2. Who\u2019s Been Here Before?<\/strong><\/h2>\n<p>Audit all user accounts, last login times, shells, and home directories. Look for any dormant or suspicious accounts.<\/p>\n<p><strong>Example:<\/strong><\/p>\n<pre class=\"wp-block-preformatted\">getent passwd<br>lastlog<br><\/pre>\n<h2 class=\"wp-block-heading\"><strong>3. Explore User Environments<\/strong><\/h2>\n<p>Understand user behavior:<\/p>\n<ul class=\"wp-block-list\">\n<li>Shell aliases<\/li>\n<li>Environment variables<\/li>\n<li>SSH keys and known hosts<\/li>\n<\/ul>\n<p>These give clues about frequently used tools and remote access patterns.<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<h2 class=\"wp-block-heading\"><strong>4. Inventory What\u2019s Installed<\/strong><\/h2>\n<p>Identify packages, services, and manually installed software:<\/p>\n<ul class=\"wp-block-list\">\n<li>Use <code>dpkg<\/code>, <code>rpm<\/code>, or <code>systemctl<\/code><\/li>\n<li>Parse command histories (<code>.bash_history<\/code>) for install commands<\/li>\n<\/ul>\n<p>This is especially useful for recreating environments or detecting manual tweaks.<\/p>\n<h2 class=\"wp-block-heading\"><strong>5. Configuration Files and Services<\/strong><\/h2>\n<p>Look for:<\/p>\n<ul class=\"wp-block-list\">\n<li>Config files in <code>\/etc\/<\/code><\/li>\n<li>VPN, firewall, and SSH configs<\/li>\n<li>Cron jobs and auto-start services<\/li>\n<\/ul>\n<p>You\u2019ll find both intended and legacy configurations here, some of which may need cleanup.<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<h2 class=\"wp-block-heading\"><strong>6. Web and Network Stack<\/strong><\/h2>\n<p>Check for:<\/p>\n<ul class=\"wp-block-list\">\n<li>Listening ports<\/li>\n<li>Apache\/Nginx server blocks<\/li>\n<li>Docker or Podman containers<\/li>\n<li>SSL certificate locations and expiration<\/li>\n<\/ul>\n<p>This helps identify publicly accessible apps and how traffic is routed.<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<h2 class=\"wp-block-heading\"><strong>7. Infrastructure Components<\/strong><\/h2>\n<p>The script scans for:<\/p>\n<ul class=\"wp-block-list\">\n<li>Kubernetes clusters<\/li>\n<li>LXD\/LXC containers<\/li>\n<li>Logging\/monitoring tools<\/li>\n<li>Configuration management (Chef, Puppet)<\/li>\n<\/ul>\n<p>Knowing what\u2019s managing what saves hours of troubleshooting.<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<h2 class=\"wp-block-heading\"><strong>8. Security Concerns<\/strong><\/h2>\n<p>Flag large files, git repos, and potentially suspicious processes. Also, look for:<\/p>\n<ul class=\"wp-block-list\">\n<li>SSO systems (LDAP, Okta, Kerberos)<\/li>\n<li>Cloud credentials or SDK configs (AWS, GCP, Azure)<\/li>\n<\/ul>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<h2 class=\"wp-block-heading\"><strong>Structure Before Strategy<\/strong><\/h2>\n<p>Once you\u2019ve mapped out the VM, only then can you:<\/p>\n<ul class=\"wp-block-list\">\n<li>Triage security risks<\/li>\n<li>Design automation<\/li>\n<li>Implement monitoring<\/li>\n<li>Apply hardening steps<\/li>\n<\/ul>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<h2 class=\"wp-block-heading\"><strong>Final Tip<\/strong><\/h2>\n<p>Turn this script into an Ansible playbook or systemd timer to periodically snapshot system state, especially in dev\/test VMs.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Introduction When you\u2019re handed the keys to a virtual machine (VM) without documentation (no network diagrams, no SOPs, or nothing), it\u2019s like walking into a datacenter blindfolded. This post shows how you can quickly profile the system, identify critical configurations, assess security posture, and inventory applications using a systematic Bash script. Reality Check Note: Many [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3343,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12],"tags":[],"class_list":["post-3342","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-how-to"],"blocksy_meta":{"styles_descriptor":{"styles":{"desktop":"","tablet":"","mobile":""},"google_fonts":[],"version":8}},"featured_image_urls_v2":{"full":["https:\/\/yyc.ninja\/wp-content\/uploads\/2025\/05\/linuxtree.jpg",718,630,false],"thumbnail":["https:\/\/yyc.ninja\/wp-content\/uploads\/2025\/05\/linuxtree-150x150.jpg",150,150,true],"medium":["https:\/\/yyc.ninja\/wp-content\/uploads\/2025\/05\/linuxtree-300x263.jpg",300,263,true],"medium_large":["https:\/\/yyc.ninja\/wp-content\/uploads\/2025\/05\/linuxtree.jpg",718,630,false],"large":["https:\/\/yyc.ninja\/wp-content\/uploads\/2025\/05\/linuxtree.jpg",718,630,false],"RoboGalleryMansoryImagesCenter":["https:\/\/yyc.ninja\/wp-content\/uploads\/2025\/05\/linuxtree-600x630.jpg",600,630,true],"RoboGalleryPreload":["https:\/\/yyc.ninja\/wp-content\/uploads\/2025\/05\/linuxtree.jpg",100,88,false],"1536x1536":["https:\/\/yyc.ninja\/wp-content\/uploads\/2025\/05\/linuxtree.jpg",718,630,false],"2048x2048":["https:\/\/yyc.ninja\/wp-content\/uploads\/2025\/05\/linuxtree.jpg",718,630,false]},"post_excerpt_stackable_v2":"<p>Introduction When you\u2019re handed the keys to a virtual machine (VM) without documentation (no network diagrams, no SOPs, or nothing), it\u2019s like walking into a datacenter blindfolded. This post shows how you can quickly profile the system, identify critical configurations, assess security posture, and inventory applications using a systematic Bash script. Reality Check Note: Many organizations restrict root access, direct file system scans, or bulk configuration dumps for valid security reasons. The level of access this script assumes is often only available in lab, dev, or smaller org setups. Always check with your security team before running such scripts in&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/yyc.ninja\/index.php\/category\/how-to\/\" rel=\"category tag\">How To Ninja<\/a>","author_info_v2":{"name":"YYC Ninja","url":"https:\/\/yyc.ninja\/index.php\/author\/admin\/"},"comments_num_v2":"0 comments","_links":{"self":[{"href":"https:\/\/yyc.ninja\/index.php\/wp-json\/wp\/v2\/posts\/3342","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/yyc.ninja\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/yyc.ninja\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/yyc.ninja\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/yyc.ninja\/index.php\/wp-json\/wp\/v2\/comments?post=3342"}],"version-history":[{"count":4,"href":"https:\/\/yyc.ninja\/index.php\/wp-json\/wp\/v2\/posts\/3342\/revisions"}],"predecessor-version":[{"id":3382,"href":"https:\/\/yyc.ninja\/index.php\/wp-json\/wp\/v2\/posts\/3342\/revisions\/3382"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/yyc.ninja\/index.php\/wp-json\/wp\/v2\/media\/3343"}],"wp:attachment":[{"href":"https:\/\/yyc.ninja\/index.php\/wp-json\/wp\/v2\/media?parent=3342"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/yyc.ninja\/index.php\/wp-json\/wp\/v2\/categories?post=3342"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/yyc.ninja\/index.php\/wp-json\/wp\/v2\/tags?post=3342"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}