plaintext
21 lines · 1 tab
Kai Nakamura
Apr 2026
1 tab
table inet filter {
chain input {
type filter hook input priority 0;
policy drop;
ct state established,related accept
iif lo accept
tcp dport { 22, 80, 443 } accept
ip protocol icmp accept
}
chain forward {
type filter hook forward priority 0;
policy drop;
}
chain output {
type filter hook output priority 0;
policy accept;
}
}
1 file · plaintext
Explain with highlit
I prefer a default-deny stance and then open only what the host actually serves. nftables is flexible enough to express that clearly without giant unreadable rule sets. A short explicit policy ages better than a sprawling inherited firewall script nobody trusts.
Related snips
python
import os
import stat
for root, _dirs, files in os.walk('/etc'):
for name in files:
path = os.path.join(root, name)
Python security audit script for exposed risky filesystem state
python
auditing
host-security
by Kai Nakamura
1 tab
plaintext
Protocol 2
PermitRootLogin no
PasswordAuthentication no
KbdInteractiveAuthentication no
PubkeyAuthentication yes
AllowUsers deploy ops
SSH daemon hardening and key based access only
ssh
linux
hardening
by Kai Nakamura
1 tab
bash
#!/usr/bin/env bash
set -euo pipefail
find / -perm -4000 -type f 2>/dev/null | sort
sudo -l
find /etc/systemd/system -type f -writable 2>/dev/null
Linux privilege escalation checks for suspicious local state
privilege-escalation
linux
auditing
by Kai Nakamura
1 tab
plaintext
local all postgres peer
hostssl app_production app_user 10.0.0.0/16 scram-sha-256
hostssl app_production reporting_user 10.0.1.0/24 scram-sha-256
host all all 0.0.0.0/0 reject
PostgreSQL hardening with pg_hba and strict role separation
postgresql
database-hardening
roles
by Kai Nakamura
1 tab
bash
#!/usr/bin/env bash
nmap -Pn -sV -O --top-ports 1000 10.10.20.15
nmap -Pn -sC -sV api.internal.example.com
nmap -Pn -sU --top-ports 50 dns.internal.example.com
Nmap reconnaissance profiles for safe internal assessments
nmap
reconnaissance
pentesting
by Kai Nakamura
1 tab
bash
#!/usr/bin/env bash
set -euo pipefail
OUT="/tmp/incident-$(date +%Y%m%d-%H%M%S)"
mkdir -p "$OUT"
Forensic collection script for volatile host evidence
forensics
incident-response
linux
by Kai Nakamura
1 tab
Share this code
Here's the card — post it anywhere.