Defensive Assessment  ·  Read-Only  ·  NIST CSF 2.0

Host
Security Audit

A fully read-only, passive audit of a Linux workstation — 10 domains, 46 findings, mapped to the NIST Cybersecurity Framework.

Walkthrough

Every Step, in the Terminal

A replayable recording of the evaluation — snapshot collection → ten domain audits → de-duplication → report. Press play, or scrub the progress bar to step through every command.

asciinema recording · generated from the real audit commands & findings

Executive Summary

Posture at a Glance

This workstation's posture is dominated by an un-firewalled, multi-product remote-access surface layered on poor secrets hygiene and unencrypted storage.

3
Critical
7
High
10
Medium
16
Low
10
Info

The four systemic problems

1. Un-firewalled remote-access over-exposure

The host firewall is installed but disabled, while three independent remote-control products (RDP, TeamViewer, NoMachine) are simultaneously bound to the wildcard address — two of them running with root-level daemons and recoverable or world-readable credentials.

2. Plaintext secrets on unencrypted disk

Live API keys, a bot token, and deployment credentials sit in world/group-readable plaintext files and have leaked into logs and session transcripts. The root partition and swap are unencrypted, so a single disk theft exposes everything at rest.

3. Open privilege-escalation paths

The interactive user holds lxd group membership (a well-known unprivileged→root vector), SUID core dumps are enabled, and a third-party remote-access suite contributes a large setuid/setgid surface.

4. Weak patch, monitoring & recovery hygiene

34 stale packages, unattended-upgrades silently skipping the point-release suite, no kernel audit trail, no brute-force lockout, and no backup process — harder to detect an incident and potentially unrecoverable after one.

✓ What was clean

No malware, no reverse shells, no covert persistence (crontab, systemd timers, authorized_keys, and RC hooks all stock). No secrets committed to any git repository. Core memory-protection controls (ASLR, dmesg_restrict, mmap_min_addr, ptrace scope) correctly configured. Default/legacy accounts locked, root password locked.

Risk Summary

Critical & High Findings

Critical

C-01

Host firewall disabled — ufw installed but inactive; no nftables/iptables rules enforced. Every wildcard-bound listener is LAN-reachable (and internet-reachable if forwarded).

C-02

Remote Desktop exposed with recoverable credentials — RDP enabled on all interfaces, full control, password auth, plaintext-recoverable credentials, and a world-readable TLS private key.

C-05

World-readable credentials file — a .netrc (mode 0664) holds a live deployment password in plaintext.

High

C-03

TeamViewer unattended daemon running as root on the wildcard address, two releases out of date.

C-04

NoMachine NX server exposed, installed from an unverified source (no apt repo → no patch path), with a setuid/setgid service account.

C-06

SUID core dumps enabled (fs.suid_dumpable=2) piped into a world-writable crash dir.

C-07

Interactive user is a member of the lxd group — trivial unprivileged→root escalation.

C-08

No encryption at rest — root partition and swap are unencrypted (no LUKS full-disk encryption).

C-09

Multiple live, long-lived API keys and a bot token stored in plaintext environment/config files.

C-10

Secrets leaked into persistent logs and session transcripts (deployment token, bot token).

Adversary Perspective

How the Findings Chain into Compromise

The 46 findings aren't independent problems — they compose into a short, reliable path from nothing to root and credential theft. This exploitability narrative maps each finding to a kill-chain stage so remediation can be prioritized by real risk. It is a thought experiment on the host's own findings — not an operational how-to.

watch it happen — scripted, anonymized red-team demo

1

Recon — the host advertises itself

C-01 (firewall off) + C-16 (mDNS broadcast) + C-24 (dual-stack :: binds) mean the box announces its three remote-control daemons to the LAN with no filtering. Discovery is a single scan pass.

2

Initial Access — three open doors

  • C-02 · RDP:3389 — password auth, plaintext-recoverable credentials, world-readable TLS key; brute-force is viable because there is no lockout and no complexity policy.
  • C-03 · TeamViewer:5938 — daemon runs as root, two releases behind; a known CVE here is instant root.
  • C-04 · NoMachine:4000 — setuid/setgid service account, no patch path, default auth.
3

Privilege Escalation — user → root

  • C-07 · lxd group — mount the host root filesystem inside a privileged container → root in one command. A designed feature abused; no exploit required.
  • C-06 + C-20 — SUID core dumps (suid_dumpable=2) + kernel pointer leak (kptr_restrict=1) → info-leak primitives that feed a kernel exploit.
  • C-22 / C-23 — unprivileged userns + io_uring/kexec at defaults: recurring local-privilege-escalation CVE classes.
  • C-04 again — NoMachine ships dozens of setuid-root scripts; another local escalation surface.
4

Credential Access — what they walk away with

  • C-05 — world-readable ~/.netrc → live deployment credential.
  • C-09 — five live API keys/tokens in plaintext env files (including a Telegram bot token → read/impersonate the bot).
  • C-10 + C-39 — secrets leaked into logs, and logs are world-readable.
  • C-17 — world-readable config backup with more secrets.

→ These extend the compromise beyond the host: connected cloud, chat, and email services fall via the stolen tokens.

5

Persistence & Cover-up — a silent hold

C-18 (no auditd) + C-40 (default logging, no central collector) → no kernel audit trail and blind detection; privileged actions leave no record. C-11 / C-12 (stale packages, unattended-upgrades skipping the point-release suite) keep the host vulnerable for easy re-entry.

6

Impact

C-08 (no disk encryption) — physical theft or a full disk read exposes everything, including the plaintext secrets above. C-19 (no backups) — ransomware or a wipe is unrecoverable.

The shortest path to full compromise

1.

Reach RDP:3389 on the LAN — firewall off, no lockout, weak/recoverable credentials → interactive session as the user.

2.

Abuse lxd group membership → mount the host filesystem → root (or, landing on TeamViewer's root daemon via CVE, already root).

3.

Read .netrc / .env / logs → exfiltrate every token.

4.

No auditd, no backups → silent, untraceable, unrecoverable.

What this means for prioritization

The CRITICAL/HIGH findings form one short chain, not 46 items to triage independently. A handful of fixes collapse most of it at once:

C-01

Enable the default-deny firewall — kills all three access doors at the network layer.

C-03 / C-04

Retire two of the three remote-control products.

C-07

Remove lxd group membership — kills the trivial root path.

C-05 / C-09 / C-10

Rotate the leaked credentials immediately.

NIST CSF 2.0

Findings → NIST CSF Mapping

Every finding is mapped to a NIST Cybersecurity Framework (CSF 2.0) Function and Category. The distribution below is itself a finding: Protect is over-weighted, while Detect, Respond, and Recover are nearly unrepresented.

GV
Govern
ID
Identify
PR
Protect
DE
Detect
RS
Respond
RC
Recover

Findings by CSF Function

Govern4
Identify3
Protect35
Detect3
Respond0
Recover1

Interpretation: the audit is almost entirely a Protect-function gap assessment (76% of findings). There is no incident-response (Respond) capability evidenced at all, and only a single Recover finding — meaning the organization's ability to detect, respond to, and recover from an incident lags well behind its prevention posture. A mature program would rebalance toward Detect (audit logging, monitoring) and Recover (backups, tested restore).

Complete Finding → CSF Mapping

IDFindingSevFunctionCSF Category
Govern (GV) — organizational context, risk strategy, supply chain
C-04NoMachine installed from unverified source, setuid service accountHIGHGVGV.SC — Supply Chain Risk Mgmt
C-21Out-of-tree NVIDIA module taints the kernelLOWGVGV.SC — Supply Chain Risk Mgmt
C-25Three overlapping remote-access productsINFOGVGV.RM — Risk Management Strategy
C-33sudo-rs setuid binaries in non-standard pathLOWGVGV.SC — Supply Chain Risk Mgmt
Identify (ID) — asset management, risk assessment
C-35Orphaned files owned by a non-existent UIDLOWIDID.AM — Asset Management
C-43Persistent agent gateway service (outbound)INFOIDID.AM — Asset Management
C-46Kernel CVE status (report-only)INFOIDID.RA — Risk Assessment
Protect (PR) — identity/access, data security, platform security, resilience
C-01Host firewall disabledCRITPRPR.IR — Technology Infrastructure Resilience
C-02Remote Desktop exposed, recoverable credentials, world-readable keyCRITPRPR.AA — Identity Mgmt, Auth & Access Control
C-03TeamViewer root daemon, outdatedHIGHPRPR.PS — Platform Security
C-05World-readable .netrc with plaintext credentialCRITPRPR.DS — Data Security
C-06SUID core dumps enabledHIGHPRPR.PS — Platform Security
C-07User in lxd group (privilege escalation)HIGHPRPR.AA — Identity Mgmt, Auth & Access Control
C-08No encryption at restHIGHPRPR.DS — Data Security
C-09Live API keys in plaintext env/config filesHIGHPRPR.DS — Data Security
C-10Secrets leaked into logs/transcriptsHIGHPRPR.DS — Data Security
C-1134 stale packagesMEDPRPR.PS — Platform Security
C-12unattended-upgrades skips point-release suiteMEDPRPR.PS — Platform Security
C-13No brute-force lockout / fail2banMEDPRPR.AA — Identity Mgmt, Auth & Access Control
C-14Weak password policy (no expiry, no complexity)MEDPRPR.AA — Identity Mgmt, Auth & Access Control
C-15Default umask 0002MEDPRPR.DS — Data Security
C-16mDNS/DNS-SD broadcast on LANMEDPRPR.PS — Platform Security
C-17World-readable config backup with secretsMEDPRPR.DS — Data Security
C-20kernel.kptr_restrict=1 (should be 2)MEDPRPR.PS — Platform Security
C-22Unprivileged user namespaces enabledLOWPRPR.PS — Platform Security
C-23Kernel attack-surface locks at defaultsLOWPRPR.PS — Platform Security
C-24Services dual-stack IPv6 bound, no IPv6 firewallLOWPRPR.IR — Technology Infrastructure Resilience
C-26OpenSSH server absent (positive)INFOPRPR.IR — Technology Infrastructure Resilience
C-27Orphaned SSH host keysLOWPRPR.PS — Platform Security
C-28SSH client GSSAPI enabled unconditionallyLOWPRPR.PS — Platform Security
C-29authorized_keys hygiene clean (positive)INFOPRPR.AA — Identity Mgmt, Auth & Access Control
C-30sssd enabled but unconfiguredINFOPRPR.AA — Identity Mgmt, Auth & Access Control
C-31sudo delegation needs reviewLOWPRPR.AA — Identity Mgmt, Auth & Access Control
C-32Default/legacy accounts locked (positive)INFOPRPR.AA — Identity Mgmt, Auth & Access Control
C-34World-writable venv lock filesLOWPRPR.DS — Data Security
C-36World-readable agent database filesLOWPRPR.DS — Data Security
C-37Non-standard world-writable metrics dirINFOPRPR.DS — Data Security
C-38Leftover removed-package configsLOWPRPR.PS — Platform Security
C-41ComfyUI installed without auth (loopback-bound)LOWPRPR.AA — Identity Mgmt, Auth & Access Control
C-42CUPS browsing active with dnssdLOWPRPR.PS — Platform Security
C-44Shell RC files modified (benign PATH hook)INFOPRPR.PS — Platform Security
C-45Plaintext proxy password in client configLOWPRPR.DS — Data Security
Detect (DE) — continuous monitoring, adverse event analysis
C-18auditd not installed (no kernel audit trail)MEDDEDE.CM — Continuous Monitoring
C-39World-readable files under /var/logLOWDEDE.CM — Continuous Monitoring
C-40journald persistence relies on defaultINFODEDE.CM — Continuous Monitoring
Recover (RC) — recovery planning & execution
C-19No backup process for user dataMEDRCRC.RP — Recovery Planning
Respond (RS) — incident management & mitigation
—No findings map to the Respond function — no incident-response capability was evidenced on this host—RS(gap)
Coverage

Ten Audit Domains

78 raw finding records across 10 domains, de-duplicated into the 46 canonical findings above.

Attack Surface & Network

Firewall off; RDP, TeamViewer, NoMachine bound to all interfaces; mDNS broadcast. 1 CRIT / 3 HIGH

OS & Kernel Hardening

ASLR/memory mitigations correct; SUID core dumps and kptr leak remain. 1 HIGH

Identity & Access Control

lxd-group escalation path; weak password policy; no lockout. 2 HIGH

Remote Access

No SSH server (clean); RDP key world-readable; no rate-limiting. 1 HIGH

Filesystem & Permissions

World-readable .netrc; NoMachine setuid surface; permissive umask. 2 HIGH

Package Hygiene

NoMachine without repo; outdated root daemons; 34 stale packages. 2 HIGH

Secrets & Credentials

Live keys in plaintext files; secrets in logs/transcripts. 1 CRIT / 3 HIGH

Services & Applications

RDP credentials recoverable in plaintext; ComfyUI unauth (loopback). 1 CRIT / 4 HIGH

Persistence & Malware

Clean — no malware, reverse shells, or covert persistence found.

Logging & Data-at-Rest

No auditd, no backups, no disk encryption. 2 HIGH

Remediation

Prioritized Roadmap

Tier 1 · Quick Wins

≤ 30 min · no root

  • Lock down & rotate exposed credentials
  • Fix world-readable RDP TLS key
  • Restrict config backups, DBs, lock files
  • Rotate leaked API keys & bot token

Tier 2 · Hardening

needs sudo/owner

  • Enable default-deny firewall
  • Retire redundant remote-access products
  • Remove lxd group membership
  • Harden sysctls + apply 34 updates
  • Add lockout, password policy, umask

Tier 3 · Strategic

planning / reimage

  • Full-disk encryption (LUKS)
  • Install & configure auditd
  • Off-system backups with tested restore
  • Secrets-management vault + rotation policy
  • Centralized logging & monitoring

Methodology

This assessment was read-only, passive, and localhost-only: no exploitation, no privilege-escalation attempts, no system modification, no network scanning of other hosts, and no use of elevated privileges. A collection harness snapshotted the machine into structured JSON; ten domain auditors (one per domain) produced the 78 raw findings, which were then consolidated to 46. Every finding is tagged with severity, confidence, remediation effort, and a CIS reference. The audit is re-runnable and framework-based — the same harness and domain decomposition can be applied to any Linux host.