School web server
I ran the multi-user server where my class published its websites, and I carried out its security audit.
Context
I ran the web server where the students in my class published their websites and projects. A real server, with real users, in production: not an exercise.
What I managed
An Ubuntu environment with Apache, MariaDB and PHP, shared by the whole class. Every student had their own space, isolated from the others with chrooted SFTP access: each person saw and edited only their own folder, never their classmates’ or the system files. A WordPress install used by about twenty people ran on top.
Running a multi-user environment means thinking about permissions, isolation and what happens when someone makes a mistake: the system has to absorb errors without one person breaking another’s work.
The security audit
At some point I decided to look at the server the way an outsider would, starting from zero information. Real problems came up: directory listing was open, some data was exposed where it shouldn’t have been, and everything travelled without HTTPS.
I fixed them: closed the listing, moved what shouldn’t be reachable, turned on encryption. What matters isn’t the list of problems but the method: looking at your own infrastructure from the outside is what keeps it secure over time.
What it taught me
That security isn’t a separate phase from administration: it’s the same job, seen from the other side of the wall.